One-Arm Data Center Topology with Layer 4 and 7 Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional n-tier data center topologies are expensive, difficult to manage, and require numerous physical devices, making them costly to set up and maintain, while prior art simplifications still face challenges in configuration complexity and traffic segmentation.
Innovation Solution
Implementing a data center topology that combines Layer 7 and Layer 4 services on a common chassis, featuring a transparent firewall and a load-balancing content switch, which reduces the number of devices needed and simplifies configuration by eliminating the need for separate firewalls and switches, and allowing efficient routing and load balancing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional n-tier data center topology is used, then security and routing functions are provided, but the number of physical devices increases and cost increases
Solution Approach 1:
The patent combines multiple network functions (firewall, routing, load balancing, content switching) into a single integrated device, eliminating the need for separate physical devices for each function while maintaining all required security and networking capabilities
Solution Approach 2:
The integrated device performs multiple functions simultaneously - it acts as a firewall, router, load balancer, and content switch, allowing one device to replace multiple specialized devices and reduce overall system complexity
2Reliability
If multiple physical devices are used for firewall and routing, then security and connectivity are ensured, but ease of operation deteriorates due to difficult management
Solution Approach 1:
By consolidating firewall, routing, and other network functions into a single device, the system reduces the number of devices that need to be managed and configured, thereby improving ease of operation while maintaining security and connectivity
3Reliability
If separate firewall and content switch devices are used, then traffic segmentation is maintained, but device complexity increases
Solution Approach 1:
The patent integrates firewall and content switch functions into a single device, maintaining traffic segmentation capabilities through virtualization or logical separation within the unified device, thereby reducing device complexity while preserving network segmentation
Data Source
AI summary
A one-arm data center topology routes traffic between internal sub-nets and between a sub-net and an outside network through a common chain of services. The data center topology employs layer 4 services on a common chassis or platform to provide routing and firewall services while reducing the number of devices necessary to implement the data center and simplifying configuration. Load balancing is provided by a load balancing device. In the one-arm topology, policy based routing or client network address translations or NAT pushes traffic to the CSM.


