Network Assurance Appliance for Configuration Error Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network configurations in large data center networks are complex and prone to errors, leading to inconsistencies and security vulnerabilities, with existing monitoring methods failing to accurately identify and address these issues in a timely manner.

Innovation Solution

A network assurance appliance that models network behavior to predict and detect inconsistencies, performing consistency checks and generating reports on memory usage across logical and hardware levels, allowing for proactive identification and resolution of configuration errors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network configurations are manually specified at a centralized controller, then network control and management are achieved, but configuration errors and inconsistencies occur frequently

Engineering Contradiction:
Improvenetwork configuration managementVSAvoidconfiguration accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements automated consistency checking that continuously monitors network configurations and provides feedback about detected errors and inconsistencies. The controller receives configuration data, automatically validates it against defined policies and constraints, and reports back any configuration issues before they are deployed to network devices, thereby maintaining configuration accuracy while enabling centralized management.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs configuration validation and consistency checking in advance before configurations are deployed to network devices. By pre-checking configurations for errors, conflicts, and policy violations, the system prevents problematic configurations from being implemented, thereby ensuring configuration accuracy while maintaining ease of centralized management.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If complex network configurations are deployed across multiple network devices, then network functionality is achieved, but identification of configuration issues becomes extremely difficult

Engineering Contradiction:
Improvenetwork functionalityVSAvoidconfiguration issue identification
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system implements automated consistency checking that continuously monitors network configurations and provides feedback about detected errors and inconsistencies. The controller receives configuration data, automatically validates it against defined policies and constraints, and reports back any configuration issues before they are deployed to network devices, thereby maintaining configuration accuracy while enabling centralized management.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The centralized controller acts as an intermediary between network administrators and network devices. It receives configuration intent from administrators, automatically validates and translates it into device-specific configurations, and manages the deployment across multiple devices. This intermediary layer simplifies the complexity by providing a unified point of control and automated validation, making it easier to detect and resolve configuration issues.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Extent of automation

If configurations are defined at a centralized controller, then network intent specification is achieved, but configuration errors create significant network problems

Engineering Contradiction:
Improveconfiguration specificationVSAvoidnetwork performance
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The system performs configuration validation and consistency checking in advance before configurations are deployed to network devices. By pre-checking configurations for errors, conflicts, and policy violations, the system prevents problematic configurations from being implemented, thereby ensuring configuration accuracy while maintaining ease of centralized management.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements automated consistency checking that continuously monitors network configurations and provides feedback about detected errors and inconsistencies. The controller receives configuration data, automatically validates it against defined policies and constraints, and reports back any configuration issues before they are deployed to network devices, thereby maintaining configuration accuracy while enabling centralized management.

Inventive Principle:
Principle #23Feedback

4Reliability

If automated consistency checking is implemented, then configuration errors are detected early, but monitoring and analysis resources are consumed

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidmonitoring resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system implements automated consistency checking that continuously monitors network configurations and provides feedback about detected errors and inconsistencies. The controller receives configuration data, automatically validates it against defined policies and constraints, and reports back any configuration issues before they are deployed to network devices, thereby maintaining configuration accuracy while enabling centralized management.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11736351B2Identifying components for removal in a network configuration
Publication Date: 2023.08.22 CISCO TECHNOLOGY INC
  • US11736351B2 patent drawing
  • US11736351B2 patent drawing
  • US11736351B2 patent drawing

AI summary

Systems, methods, and computer-readable media analyzing memory usage in a network node. A network assurance appliance may be configured to determine a hit count for a concrete level rule implemented on a node and identify one or more components of a logical model, wherein each of the one or more components are associated with the concrete level rule. The network assurance appliance may attribute the hit count for the concrete level rule to each of the components of the logical model, determine a number of hardware level entries associated with the each of the one or more components, and generate a report comprising the one or more components of the logical model, the hit count attributed to each of the one or more components of the logical model, and the number of hardware level entries associated with the one or more components of the logical model.