Remote Network Switch Management via Firewall Command Channel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network switch management systems require local administration, lacking centralized remote management capabilities and automated Virtual Local Area Network (VLAN) configuration, which complicates control and security checks across multiple switches.

Innovation Solution

A system that automatically discovers firewall security devices within a network, establishes a command channel, and configures VLANs remotely, allowing for centralized management and security checks through a switching device, using methods like broadcast, multicast, static IP, or DHCP for discovery and CAPUTP/CAPWAP for command channel establishment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If local CLI interface is used for network switch management, then administrative control is achieved, but physical presence near the switch is required and remote management of multiple switches is inefficient

Engineering Contradiction:
Improveremote management capabilityVSAvoidtime for administrator to access each switch individually
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

A centralized network management system acts as an intermediary between administrators and multiple network switches. The system establishes command channels with switches and receives/forwards configuration commands, enabling remote management without requiring administrators to physically access each switch or directly connect to individual CLIs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network management system provides universal control capabilities across multiple different network switches through a single centralized interface. It can discover, connect to, and manage various switches uniformly, allowing one system to perform the function of multiple individual switch管理 interfaces.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If manual VLAN configuration is performed on each switch, then VLAN setup is achieved, but the process is time-consuming and error-prone

Engineering Contradiction:
ImproveVLAN configuration speedVSAvoidcomplexity of manual configuration process
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The network management system enables automated VLAN configuration where the system itself performs the configuration tasks across multiple switches without requiring manual intervention for each device. The system automatically discovers switches, establishes connections, and applies VLAN configurations, making the management system serve itself in configuring the network infrastructure.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

VLAN configurations can be prepared and staged in the network management system before being deployed to switches. The system allows administrators to define VLAN parameters once, and then automatically applies these pre-configured settings across multiple switches, eliminating the need to manually configure each switch individually.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If centralized management system is implemented, then remote control of multiple switches is enabled, but system complexity increases

Engineering Contradiction:
Improvecentralized management capabilityVSAvoidcomplexity of management system architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The network management system is divided into distinct functional modules: a discovery module for finding switches, a communication module for establishing command channels, and a configuration module for managing VLANs. This segmentation allows each component to perform its specific function independently, reducing overall system complexity while maintaining centralized management capabilities.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10263839B2Remote management system for configuring and/or controlling a computer network switch
Publication Date: 2019.04.16 FORTINET INC
  • US10263839B2 patent drawing
  • US10263839B2 patent drawing
  • US10263839B2 patent drawing

AI summary

Methods and systems for remotely managing a switching device are provided. According to one embodiment the existence of a firewall security device within a network is automatically determined by a discovery module of a switching device. Upon determining the existence of the firewall security device, a command channel is established with the firewall security device by a communication module of the switching device. The switching device may then receive commands issued by the firewall security device through the command channel relating to configuration of one or more Virtual Local Area Networks (VLANs).