Network Isolation for Non-Disruptive Disaster Recovery Testing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Disaster recovery testing in complex multi-tier data centers poses challenges due to the need for non-disruptive validation of secondary sites, which must mimic primary sites with varying physical, virtual, and hybrid computing environments, without affecting normal operations or disrupting communication.

Innovation Solution

Implementing network isolation between primary and secondary sites using a firewall to allow selective data transfer while preventing disruptive communications, allowing for customizable testing and validation of application readiness and data correctness without requiring additional hardware or software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network isolation is implemented between primary and secondary sites, then disruptive communications are prevented and testing can be performed without affecting normal operations, but communication capabilities during testing may be restricted

Engineering Contradiction:
Improvenon-disruptive testingVSAvoiddisruptive communications
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

A network isolation system acts as an intermediary between the primary and secondary sites, using a firewall with customized rules to control and monitor communications. The system allows specific types of communications (such as replication traffic) while blocking disruptive communications, thus enabling non-disruptive testing without completely isolating the sites.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network isolation system applies different communication rules to different types of traffic and different directions of communication. Instead of a blanket block, the firewall implements localized quality control that permits essential communications while preventing disruptive ones, allowing selective data transfer based on communication type and direction.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If the secondary site is isolated from the primary site for testing, then testing can be performed without affecting primary site operations, but the secondary site cannot access external resources or communicate with other primary sites

Engineering Contradiction:
Improvetesting operationsVSAvoidcommunication functionality
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The network isolation system segments communications into different categories or zones. It creates distinct rules for different types of traffic (e.g., replication traffic vs. application traffic) and different communication directions. This segmentation allows the system to permit essential testing communications while blocking disruptive ones, maintaining versatility during isolated testing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network isolation system dynamically adjusts communication rules based on the testing scenario and current network conditions. The firewall can be configured to allow or block specific protocols, ports, and communication directions based on the testing requirements, enabling flexible communication control that adapts to different testing needs while maintaining isolation.

Inventive Principle:
Principle #15Dynamics

3Reliability

If comprehensive network isolation is implemented, then complete testing independence is achieved, but data replication and synchronization between sites are blocked

Engineering Contradiction:
Improvetesting independenceVSAvoiddata replication
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The network isolation system includes specific rules that allow data replication traffic to pass through the firewall between primary and secondary sites. The firewall acts as an intermediary that monitors and permits replication communications while blocking other disruptive traffic, ensuring that data synchronization is maintained despite network isolation during testing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes communication parameters such as allowed protocols, ports, and data types based on the isolation level required. For data replication, the system permits specific parameters (replication protocols, synchronization ports) while blocking others, enabling selective data transfer that maintains replication functionality within the isolated testing environment.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9389961B1Automated network isolation for providing non-disruptive disaster recovery testing of multi-tier applications spanning physical and virtual hosts
Publication Date: 2016.07.12 COHESITY INC
  • US9389961B1 patent drawing
  • US9389961B1 patent drawing
  • US9389961B1 patent drawing

AI summary

Various systems, methods and apparatuses for creating network isolation spanning physical and virtual hosts are presented. In one embodiment, network isolation may be created between a primary (e.g., production) site and a secondary (e.g., a disaster recovery or sandbox) site. The network isolation allows testing (or other uses) on the secondary site to be non-disruptive to the normal operations of the sites, including the ability to failover during testing. Such non-disruptive network isolation allows certain communications to continue, especially communications between ports having replicated data. The network isolation may be customized in various other ways to allow certain communications to continue while preventing other communications. This invention can be used to validate application readiness, as well as to validate data correctness of individual tiers, and may be used with systems that contain multiple tiers, and include physical hosts, virtual hosts, and/or combinations of both.