Network Device Service Chaining via Access Control Lists
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network technologies face challenges in dynamically configuring network services without hardware changes, particularly in efficiently directing network traffic through service chains with existing equipment, lacking transparent and high-performance solutions for health monitoring and failure handling.
Innovation Solution
The implementation of service chaining techniques on network devices using existing hardware, such as ASICs and linecards, that allow for selective traffic redirection based on access control lists without additional packet headers, enabling transparent insertion of network processing appliances and automatic failure handling with wire-speed performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If service chaining is implemented using existing network hardware without hardware changes, then adaptability and ease of operation are improved, but device complexity increases due to software configuration requirements
Solution Approach 1:
The network device is configured to perform multiple functions including service chaining, health monitoring, and automatic failure handling using existing hardware components (ASICs, linecards). The same hardware infrastructure is utilized for both traditional networking functions and service chaining operations, eliminating the need for dedicated service chaining hardware and reducing overall system complexity.
Solution Approach 2:
The system implements automatic failure handling and health monitoring capabilities that enable the network device to self-diagnose and self-correct service chain failures without manual intervention. The processor automatically detects failures through health monitoring mechanisms and reroutes traffic through alternative service chain paths, reducing operational complexity for network administrators.
2Loss of information
If selective traffic redirection is implemented without additional packet headers, then loss of information is reduced and wire-speed performance is maintained, but device complexity increases due to hardware module programming requirements
Solution Approach 1:
The patent extracts the service chaining functionality from the data plane packet processing path, implementing it through separate control plane mechanisms. Access control lists and routing tables are programmed in advance to redirect traffic without modifying packet headers during forwarding operations. This separation allows wire-speed performance to be maintained while avoiding the need for additional packet headers that would increase information overhead.
Solution Approach 2:
Service chain paths are pre-configured and programmed into the hardware modules (ASICs, linecards) before traffic arrives. Access control lists and routing tables are populated with service chain identifiers and next-hop information in advance, enabling the hardware to perform rapid lookup and redirection without real-time computation or packet header modification, thus maintaining wire-speed performance.
3Ease of operation
If transparent insertion of network processing appliances is implemented, then ease of operation is improved and hardware changes are avoided, but reliability challenges arise in health monitoring and failure handling
Solution Approach 1:
The system implements health monitoring mechanisms that continuously probe service chain appliances and monitor their operational status. When failures are detected through these feedback mechanisms, the processor automatically reroutes traffic through alternative service chain paths. The system maintains routing tables with multiple service chain options and uses health monitoring feedback to dynamically update traffic forwarding decisions, ensuring high availability even when appliances are transparently inserted and removed.
Data Source
AI summary
In one embodiment, a network device is provided that comprises a plurality of ports at which network packets are received at the network device and sent from the network device. At least hardware module includes one or more memories that store entries for one or more networking features to be performed to direct network packets with respect to the plurality of ports. A processor is coupled to the at least one hardware module and configured to communicate with the at least one hardware module to store in the one or more memories attributes for one or more access control lists and associated actions that cause network packets which are received that match the attributes for the one or more access control lists, to be directed in a service chain that includes one or more network processing appliances connected to one or more of the plurality of ports.


