Private VLAN Access List Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional networks fail to effectively isolate traffic between private VLANs terminated on different switches using the same primary VLAN, leading to potential security breaches and requiring cumbersome IP address changes and manual ACL configurations.

Innovation Solution

Implementing a private VLAN access list that automatically restricts traffic between virtual machines on the same switch domain, using MAC addresses and VLAN designations to ensure isolation without reconfiguring IP addresses or manually setting ACLs, allowing for a standard configuration across environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If different primary VLANs are configured to prevent traffic leakage across switches, then VLAN isolation reliability is improved, but device complexity and configuration difficulty increase

Engineering Contradiction:
ImproveVLAN isolation reliabilityVSAvoidVLAN configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the VLAN isolation function into two parts: primary VLAN configuration (shared across switches) and private VLAN access lists (switch-specific). This allows each switch to independently enforce isolation rules using switch-specific access lists while maintaining a common primary VLAN configuration, resolving the contradiction between reliability and complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces switch-specific private VLAN access lists as an intermediary mechanism between the shared primary VLAN configuration and the actual traffic isolation enforcement. These access lists act as local policy enforcers that prevent traffic leakage without requiring different primary VLAN configurations across switches.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual ACL configurations are implemented to enforce isolation, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables switches to automatically generate and enforce private VLAN access lists based on their local VLAN configurations and learned MAC addresses. This self-service approach eliminates the need for manual ACL configuration while maintaining security, as each switch autonomously creates the necessary isolation rules.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent pre-configures private VLAN parameters (primary VLAN ID, secondary VLAN IDs, port assignments) in a standardized format. The switches then automatically use these pre-configured parameters to generate the appropriate access lists, eliminating the need for manual security policy creation while maintaining strong isolation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If IP address changes are required to implement isolation, then isolation effectiveness is improved, but adaptability deteriorates

Engineering Contradiction:
Improveisolation effectivenessVSAvoidconfiguration adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the isolation enforcement parameter from IP-based (requiring IP address changes) to MAC address-based using switch-specific access lists. This allows isolation to be enforced at the data link layer using MAC addresses, which are inherently tied to the VLAN configuration and do not require IP address modifications, thereby maintaining adaptability while ensuring effectiveness.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2724497B1Private virtual local area network isolation
Publication Date: 2020.12.23 CISCO TECHNOLOGY INC
  • EP2724497B1 patent drawingFigure 1
  • EP2724497B1 patent drawingFigure 2
  • EP2724497B1 patent drawingFigure 3

AI summary

In one embodiment, a method includes obtaining addresses of end hosts at a switch, the switch configured with a primary virtual local area network and a secondary virtual local area network, creating a private virtual local area network access list comprising the addresses of end hosts permitted to communicate on the secondary virtual local area network, and applying the private virtual local area network access list to interfaces connected to the end hosts permitted to communicate on the secondary virtual local area network. An apparatus is also disclosed.