One-Arm Data Center Topology with Layer 4 and 7 Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional n-tier data center topologies are expensive, difficult to manage, and require numerous physical devices, making them costly to set up and maintain, while prior art simplifications still face challenges in configuration complexity and traffic segmentation.

Innovation Solution

Implementing a data center topology that combines Layer 7 and Layer 4 services on a common chassis, featuring a transparent firewall and a load-balancing content switch, which reduces the number of devices needed and simplifies configuration by eliminating the need for separate firewalls and switches, and allowing efficient routing and load balancing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional n-tier data center topology is used, then security and routing functions are provided, but the number of physical devices increases and cost increases

Engineering Contradiction:
Improvesecurity functionVSAvoidnumber of physical devices
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple network functions (firewall, routing, load balancing, content switching) into a single integrated device, eliminating the need for separate physical devices for each function while maintaining all required security and networking capabilities

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The integrated device performs multiple functions simultaneously - it acts as a firewall, router, load balancer, and content switch, allowing one device to replace multiple specialized devices and reduce overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple physical devices are used for firewall and routing, then security and connectivity are ensured, but ease of operation deteriorates due to difficult management

Engineering Contradiction:
Improvesecurity and connectivityVSAvoidease of management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

By consolidating firewall, routing, and other network functions into a single device, the system reduces the number of devices that need to be managed and configured, thereby improving ease of operation while maintaining security and connectivity

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If separate firewall and content switch devices are used, then traffic segmentation is maintained, but device complexity increases

Engineering Contradiction:
Improvetraffic segmentationVSAvoiddevice configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent integrates firewall and content switch functions into a single device, maintaining traffic segmentation capabilities through virtualization or logical separation within the unified device, thereby reducing device complexity while preserving network segmentation

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7571470B2One arm data center topology with layer 4 and layer 7 services
Publication Date: 2009.08.04 CISCO TECHNOLOGY INC
  • US7571470B2 patent drawing
  • US7571470B2 patent drawing
  • US7571470B2 patent drawing

AI summary

A one-arm data center topology routes traffic between internal sub-nets and between a sub-net and an outside network through a common chain of services. The data center topology employs layer 4 services on a common chassis or platform to provide routing and firewall services while reducing the number of devices necessary to implement the data center and simplifying configuration. Load balancing is provided by a load balancing device. In the one-arm topology, policy based routing or client network address translations or NAT pushes traffic to the CSM.