Network Address Grouping for Virtual Interface Service Rules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In software-defined data centers with virtualized networking, efficiently implementing many firewall rules across a logical network is challenging due to the need for optimized management of service rules, particularly in distributed environments where existing methods do not adequately reduce the number of flow entries or minimize churn caused by rule changes.
Innovation Solution
A method that groups network addresses into non-overlapping sets and generates flow entries based on these groups, reducing the number of flow entries required for service rules and minimizing changes by assigning priority values in a manner that minimizes re-assignment when rules are added or modified, using techniques like conjunctive matching and address set normalization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional methods are used to implement firewall rules in distributed environments, then service rules can be applied to multiple virtual interfaces, but the number of flow entries increases significantly and management complexity increases
Solution Approach 1:
The patent combines service rules from multiple virtual interfaces by identifying common network addresses and merging their flow entries. Instead of maintaining separate flow entries for each virtual interface, the system merges rules that apply to multiple interfaces, reducing the total number of flow entries while maintaining the ability to apply service rules across distributed environments.
Solution Approach 2:
The patent creates universal flow entries that can serve multiple virtual interfaces simultaneously. By identifying network addresses that are common across multiple virtual interfaces and creating a single flow entry that applies to all of them, the system achieves multi-functionality where one flow entry performs the service rule enforcement for multiple interfaces.
2Reliability
If firewall rules are implemented across multiple virtual interfaces, then distributed firewall services are achieved, but the number of flow entries required increases
Solution Approach 1:
The patent merges flow entries for common network addresses across multiple virtual interfaces. When the same network address appears in service rules for multiple virtual interfaces, the system creates a single merged flow entry that handles all instances, thereby reducing the total quantity of flow entries while maintaining distributed firewall service reliability.
Solution Approach 2:
The patent segments the flow entry management by separating unique network addresses from common network addresses. Unique addresses get individual flow entries, while common addresses across multiple virtual interfaces are segmented out and handled by shared flow entries, reducing the overall number of flow entries required.
3Adaptability or versatility
If service rules are added or modified in distributed environments, then firewall functionality is updated, but churn increases causing more re-assignments
Solution Approach 1:
The patent merges service rules that apply to multiple virtual interfaces into unified flow entries. When rules are added or modified, the system updates the merged flow entry once rather than updating separate flow entries for each virtual interface, significantly reducing churn and re-assignment time while maintaining the ability to adapt firewall functionality.
4Reliability
If traditional flow entry management is used, then service rules can be implemented, but network resource usage increases and transaction time increases
Solution Approach 1:
The patent merges flow entries for common network addresses across multiple virtual interfaces, reducing the total number of flow entries that need to be processed. This merging reduces network resource usage and decreases transaction time for service rule implementation while maintaining reliable service rule enforcement.
Data Source
AI summary
Certain embodiments described herein are generally directed to normalizing service rules across multiple virtual interfaces (VIFs). For example, certain embodiments described herein relate to a method for managing service rules. The method may include receiving a plurality of service rules for a set of VIFs, wherein each service rule corresponds to at least one network address and grouping the network addresses into non-overlapping groups of network addresses, wherein the grouping is performed over the service rules corresponding to the set of VIFs. In certain embodiments, flow entries may be generated based on the grouping of the network addresses.


