Orchestrated Network Flow Tracing With Stage-Level Rule Metadata
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network appliances struggle with tracing the application of network rules in packet processing pipelines, as existing tracing data lacks clarity on which rules are implemented, making debugging and optimization difficult.
Innovation Solution
A system and method for sending trace directives to network appliances to generate metadata indicating which processing stages apply which network rules, using configuration maps to identify specific rules, and assembling trace reports across multiple appliances.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network appliances process network traffic flows by examining packet header data and applying network rules through packet processing pipelines, then network traffic can be effectively routed and controlled, but tracing the application of network rules becomes difficult and debugging optimization is hindered due to lack of clarity on which rules are implemented
Solution Approach 1:
The patent introduces an intermediary tracing mechanism that acts as a mediator between the packet processing pipeline and the tracing system. This intermediary captures metadata about which network rules are applied at each processing stage without interfering with the actual packet processing flow. The tracing system uses this intermediary to collect and report rule application information, thereby resolving the difficulty of detecting and measuring rule application while maintaining reliable network rule enforcement.
Solution Approach 2:
The patent implements a feedback mechanism where the packet processing pipeline provides information back to the tracing system about rule applications. The tracing system receives feedback metadata indicating which network rules were applied at each processing stage, processes this feedback information, and generates trace reports. This feedback loop enables effective tracing and debugging of network rule application while maintaining the reliability of the original packet processing function.
2Productivity
If multiple network appliances are used to process network flows across different network segments, then network processing capacity and functionality are improved, but assembling comprehensive trace reports across multiple appliances becomes complex
Solution Approach 1:
The patent implements a universal trace directive format and metadata structure that can be applied across multiple different network appliance types and processing stages. The tracing system uses a standardized approach that works universally across different network segments and appliances, allowing trace reports to be assembled from multiple sources without increasing complexity. The same tracing mechanisms and data structures are used regardless of which specific network appliance is processing the packet.
Data Source
AI summary
An orchestrator can send trace directives to network appliances that indicate a network flow to trace. The network appliances can include packet processing pipelines that each include numerous processing stages. The network appliances implement network rules for processing network flows by configuring the pipeline's processing stages to execute specific policies for specific network packets in accordance with the network rules. The processing stages can also be configured to produce metadata indicating the policies implemented at each stage to process certain network packets in network flows indicated by trace directives. The metadata can be used to produce a trace report that indicates a network packet of the network flow, a first network rule that was applied to the network packet by a one of the first appliance processing stages, and the one of the first appliance processing stages that applied the first network rule to the network packet.


