Network Assurance System for L3OUT Configuration Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Complex computer networks face challenges in accurate and efficient error detection and configuration validation due to their intricate configurations, leading to difficulties in troubleshooting and ensuring proper network behavior.
Innovation Solution
The system and method for network assurance involve receiving a global logical model and converting it into a local model, comparing software and hardware configurations, and generating events based on validation results to ensure accurate deployment and configuration of network policies across different layers, including Layer 1, Layer 2, and Layer 3, within and outside the network fabric.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network operators use a wide array of configuration options to tailor the network, then flexibility and control over the network are improved, but network complexity increases
Solution Approach 1:
The patent introduces an intermediary validation system that sits between the network configuration process and the actual network deployment. This system validates configurations against predefined rules and policies before they are applied to the network, acting as a mediator that enables complex configurations while preventing errors. The validation system includes configuration validators, policy checkers, and automated testing mechanisms that verify network setups without limiting the available configuration options.
2Adaptability or versatility
If network configurations become highly complex, then network tailoring capability is improved, but error-proneness increases
Solution Approach 1:
The patent implements preliminary validation actions that are performed before network configurations are deployed. The system conducts automated validation checks, policy compliance verification, and conflict detection during the configuration phase rather than during deployment or operation. This preliminary action includes syntax validation, semantic checking, and simulation of configuration effects to identify potential errors before they impact the actual network.
Solution Approach 2:
The validation system provides continuous feedback to network operators during the configuration process. When configurations are submitted, the system automatically validates them and returns detailed feedback about compliance issues, potential errors, and recommended corrections. This feedback loop enables operators to iteratively refine their configurations while maintaining high tailoring capability and reducing error-proneness through guided correction.
3Adaptability or versatility
If network configurations are made more complex, then network customization is improved, but troubleshooting difficulty increases
Solution Approach 1:
The system performs preliminary validation and documentation actions during the configuration phase. It automatically generates validation reports, compliance certificates, and configuration verification records that document the expected behavior of customized network configurations. This preliminary documentation creates a baseline for future troubleshooting without limiting customization options.
Solution Approach 2:
The validation system acts as an intermediary that maintains a record of configuration validity and expected behavior. When troubleshooting is needed, this intermediary provides validation history, compliance status, and configured policy information that simplifies the detection and measurement of network issues, even in highly customized environments.
Data Source
AI summary
Disclosed are systems, methods, and computer-readable media for assuring tenant forwarding in a network environment. Network assurance can be determined in layer 1, layer 2 and layer 3 of the networked environment including, internal-internal (e.g., inter-fabric) forwarding and internal-external (e.g., outside the fabric) forwarding in the networked environment. The network assurance can be performed using logical configurations, software configurations and/or hardware configurations.


