Network Device Lockout Prevention via Configuration Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network administrators often inadvertently lock themselves out of networking devices when applying access control lists, leading to wasted time, productivity losses, and embarrassment, due to the inability to recognize the impact of configuration changes on their own access interfaces.

Innovation Solution

An information handling system with a lockout prevention engine that analyzes configuration instructions and warns administrators before applying them, ensuring that the system does not inhibit its own communications, thereby preventing lockouts by displaying warning messages and allowing for corrective actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control lists are applied to networking devices to control interface access, then security and access control are improved, but the risk of locking out administrator IHS and losing management access increases

Engineering Contradiction:
Improveaccess controlVSAvoidmanagement access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary analysis of configuration instructions before applying them to the networking device. The lockout prevention engine evaluates whether the configuration will inhibit management communications and provides warning messages to administrators before the configuration is applied, allowing corrective action to be taken in advance

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides feedback to the administrator by displaying warning messages that indicate potential lockout conditions. This feedback loop allows the administrator to review the configuration impact and modify the access control list before it is applied, preventing the lockout from occurring

Inventive Principle:
Principle #23Feedback

2Productivity

If configuration instructions are applied without verification, then productivity and configuration speed are improved, but the likelihood of erroneous lockout configurations increases

Engineering Contradiction:
Improveconfiguration speedVSAvoidconfiguration accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The lockout prevention engine performs preliminary evaluation of configuration instructions before they are applied to the networking device. This pre-verification step identifies potential lockout conditions without delaying the configuration process, allowing administrators to maintain high productivity while ensuring configuration accuracy through automated analysis

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9559908B2Lockout prevention system
Publication Date: 2017.01.31 DELL PROD LP
  • US9559908B2 patent drawing
  • US9559908B2 patent drawing
  • US9559908B2 patent drawing

AI summary

A lockout prevention system includes a management Information Handling System (IHS) that is coupled through a network to network interface on a networking device. The networking device receives a configuration instruction through the network interface from the management IHS. The networking device then determines that the application of the configuration instruction will inhibit the communication between the management IHS and the networking device through the network interface. The networking device then provide a warning message for display on the management IHS in response to determining that the application of the configuration instruction will inhibit the communication between the management IHS and the networking device through the network interface.