Network Policy Fault Localization via TCAM Equivalency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network configurations in large data center networks are complex and prone to errors, making it difficult to identify and resolve inconsistencies that can lead to significant problems, such as incorrect traffic processing and configuration conflicts.

Innovation Solution

The system employs network assurance models and methods to model network behavior, perform consistency checks, and analyze smart events to predict and identify faults, allowing for the localization of faults in network policies across a network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network configurations are manually specified and deployed at a centralized controller, then network policy deployment is achieved, but configuration errors and inconsistencies are difficult to identify

Engineering Contradiction:
Improvenetwork policy deployment accuracyVSAvoidfault detection difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system implements feedback by collecting actual network device configurations and comparing them against the intended network policy specifications. This closed-loop feedback mechanism automatically identifies deviations and inconsistencies between desired and actual states, resolving the difficulty of detecting configuration errors in large-scale deployments

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

A centralized controller acts as an intermediary between network policy specifications and actual device configurations. The controller mediates the deployment process by translating high-level policies into device-specific configurations and verifying consistency, thereby improving deployment accuracy while maintaining centralized control

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If network configurations involve multiple layers and complex policies, then comprehensive network control is achieved, but error identification becomes extremely difficult

Engineering Contradiction:
Improvenetwork policy coverageVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments complex network configurations into manageable components organized by device type and policy layer. By dividing the configuration space into discrete, analyzable units, the system maintains comprehensive policy coverage while making error identification tractable through structured analysis of individual segments

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds an analytical dimension by implementing multi-layer consistency checking across different configuration levels. This dimensional approach to verification allows comprehensive policy validation without being overwhelmed by the complexity of individual configuration elements

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of operation

If configurations are defined at a centralized controller to reflect intent specification, then network intent implementation is achieved, but errors create significant network problems

Engineering Contradiction:
Improveintent specification easeVSAvoidnetwork operation reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary validation of intent specifications before deployment by checking for internal consistency and feasibility. This advance verification prevents erroneous configurations from reaching the network, maintaining both ease of intent specification and operational reliability

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11258657B2Fault localization in large-scale network policy deployment
Publication Date: 2022.02.22 CISCO TECHNOLOGY INC
  • US11258657B2 patent drawing
  • US11258657B2 patent drawing
  • US11258657B2 patent drawing

AI summary

Systems, methods, and computer-readable media for localizing faults in a network policy are disclosed. In some examples, a system or method can obtain TCAM rules across a network and use the TCAM rules to perform an equivalency check between the logical model and the hardware model of the network policy. One or more risk models are annotated with output from the equivalency check and the risk models are used to identify a set of policy objects of the network policy that are likely responsible for the faults.