Network Policy Configuration for Virtual Machine Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual configuration of network policies is inadequate for server virtualization, as it fails to adapt to the dynamic nature of virtual machine migration and creation events, leading to inefficiencies in network policy updates.

Innovation Solution

A method where a management device automatically sends network policy configuration messages to virtual and physical switches correlated with virtual machines during events like creation, deletion, or migration, using pre-established correlation information to ensure timely policy updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual configuration of network policies is used, then network policies can be configured on switches, but it cannot adapt to dynamic virtual machine migration and creation events in real-time

Engineering Contradiction:
ImproveAdaptability to virtualization technologyVSAvoidNetwork policy update efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system enables self-service automation where the network management device automatically detects virtual machine operations (creation, deletion, migration) and triggers corresponding network policy configuration actions without manual intervention. The device subscribes to operation events and autonomously sends configuration messages to virtual and physical switches, making the network policy management system self-adapting to virtualization dynamics.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms by establishing event subscription relationships where the network management device subscribes to virtual machine operation events from the server management device. When operations occur, event notifications are fed back to the network management device, which then automatically updates network policies on relevant switches, creating a closed-loop adaptive system.

Inventive Principle:
Principle #23Feedback

2Productivity

If automatic network policy configuration is implemented, then real-time adaptation to virtual machine operations is achieved, but system complexity increases due to multiple device correlations

Engineering Contradiction:
ImproveNetwork policy configuration automationVSAvoidSystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments the network management functionality into distinct specialized devices: a server management device that handles virtual machine operation events, and a network management device that handles network policy configuration. This segmentation allows each device to focus on its specific function, reducing individual device complexity while achieving overall system automation through coordinated interaction between devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network management device acts as an intermediary between the server management device and the switches. It receives operation events from the server management device, determines which virtual and physical switches are affected, and sends appropriate configuration messages to them. This intermediary role simplifies the interaction model by providing a single point of coordination rather than requiring direct complex interactions between all components.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If network policy messages are sent to both virtual and physical switches, then complete policy coverage is achieved, but message transmission overhead increases

Engineering Contradiction:
ImprovePolicy configuration completenessVSAvoidPolicy update time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-establishing correlation information between virtual switches and physical switches before actual virtual machine operations occur. The network management device stores the mapping relationships between virtual switches and their corresponding physical switches in advance. When operation events occur, the device can immediately query this pre-stored correlation information to quickly determine which physical switches need configuration, avoiding time-consuming real-time discovery and reducing message transmission overhead.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2725737B1Network policy configuration method, management device and network management centre device
Publication Date: 2016.01.20 HUAWEI TECH CO LTD
  • EP2725737B1 patent drawingFigure 1~2
  • EP2725737B1 patent drawingFigure 3~4
  • EP2725737B1 patent drawingFigure 5~6

AI summary

The present invention provides a network policy configuration method, a management device, a network management center device, and a server management center device. The network policy configuration method includes: establishing correlation information between a virtual switch and physical network devices; when an operation event aimed at a virtual machine occurs, sending a first network policy configuration message aimed at the virtual machine to a virtual switch corresponding to the virtual machine, where the first network policy configuration message is used to instruct the virtual switch to perform network policy configuration; and acquiring, according to the correlation information, physical network devices correlated to the virtual switch, and sending second network policy configuration messages aimed at the virtual machine to the physical network devices correlated to the virtual switch, where the second network policy configuration messages are used to instruct the physical network devices to perform network policy configuration. The technical solution of the present invention is capable of automatically configuring a network policy, thereby supporting the server virtualization technology.