Network Assurance System for Configuration Error Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network configurations in both centralized and non-centralized environments are prone to errors and inconsistencies, leading to significant problems due to their complexity, making it difficult to identify and rectify configuration issues that can cause network failures or performance degradations.

Innovation Solution

A system and method for network assurance that collects and compares configuration sets from network devices to perform VLAN consistency checks, subnet consistency checks, and topology consistency checks, determining configuration errors or rule violations, and providing detailed analysis to identify root problems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network configurations are managed at individual network devices in traditional networks, then network devices can operate independently with flexible configurations, but configuration errors and inconsistencies become extremely difficult to identify and rectify

Engineering Contradiction:
Improveindependent device configuration flexibilityVSAvoidconfiguration error detection difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an intermediary system that collects configurations from multiple network devices, normalizes them into a common format, and performs consistency checks. This intermediary layer enables centralized analysis of distributed configurations without requiring changes to individual device operation, thus maintaining independence while enabling error detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms by collecting configuration data from network devices, analyzing consistency across the network, and providing reports on detected errors and inconsistencies. This feedback loop enables continuous monitoring and identification of configuration problems in traditionally independent devices.

Inventive Principle:
Principle #23Feedback

2Reliability

If network configurations are centralized at a controller, then configuration consistency can be maintained across the network, but the complexity of managing low level and high level configurations increases significantly

Engineering Contradiction:
Improveconfiguration consistencyVSAvoidconfiguration management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments configuration analysis into distinct types (VLAN consistency checks, subnet consistency checks, topology consistency checks). This segmentation allows the complex task of configuration management to be broken down into manageable, specialized analysis components that can be performed independently and systematically.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs multiple types of consistency checks (VLAN, subnet, topology) using a unified configuration collection and analysis platform. This multi-functional approach consolidates various configuration management tasks into a single system, reducing overall complexity while maintaining comprehensive coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If detailed configuration checks are performed across all network devices, then configuration errors can be identified accurately, but the time and resources required for analysis increase substantially

Engineering Contradiction:
Improveconfiguration error identification accuracyVSAvoidconfiguration analysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements targeted configuration checks focused on specific consistency types (VLAN, subnet, topology) rather than exhaustive analysis of all configuration parameters. This partial action approach identifies the most critical configuration errors while reducing overall analysis time and computational resources required.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10554483B2Network policy analysis for networks
Publication Date: 2020.02.04 CISCO TECHNOLOGY INC
  • US10554483B2 patent drawing
  • US10554483B2 patent drawing
  • US10554483B2 patent drawing

AI summary

Systems, methods, and computer-readable media for performing network assurance in a traditional network. In some examples, a system can collect respective sets of configurations programmed at network devices in a network and, based on the respective sets of configurations, determine a network-wide configuration of the network, the network-wide configuration including virtual local area networks (VLANs), access control lists (ACLs) associated with the VLANs, subnets, and/or a topology. Based on the network-wide configuration of the network, the system can compare the ACLs for each of the VLANs to yield a VLAN consistency check, compare respective configurations of the subnets to yield a subnet consistency check, and perform a topology consistency check based on the topology. Based on the VLAN consistency check, the subnet consistency check, and the topology consistency check, the system can determine whether the respective sets of configurations programmed at the network devices contain a configuration error.