Router Remote Mirroring via Layer 2 Virtual Interface and VPWS Tunnel
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current port mirroring techniques in routers are limited to local monitoring, lacking the capability for remote traffic monitoring, which is essential for network security and management, especially with the increasing demand for remote monitoring and interception in Virtual Private Network (VPN) environments.
Innovation Solution
The method involves configuring a remote mirroring port on a source router to establish a layer two virtual interface and a Virtual Private Wire Service (VPWS) tunnel, filtering and forwarding mirroring data streams to a destination router, where the packets are further processed and sent to a monitoring port, enabling remote mirroring across different locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If port mirroring is implemented locally on a router, then traffic monitoring capability is provided, but the monitoring location is limited to the router itself
Solution Approach 1:
The patent introduces a monitoring device as an intermediary component separate from the router. The router forwards mirrored traffic to this external monitoring device through designated ports, enabling remote monitoring capability without requiring the monitoring function to be embedded within the router itself. This resolves the contradiction by providing monitoring location flexibility while keeping the router's core functions simple.
Solution Approach 2:
The patent segments the monitoring function from the routing function by implementing them as separate components. The router handles packet forwarding and traffic selection, while the external monitoring device handles the actual traffic analysis. This segmentation allows the monitoring location to be flexible while maintaining clear functional boundaries and reducing overall system complexity.
2Reliability
If all network traffic is monitored, then complete security coverage is achieved, but network performance is significantly affected
Solution Approach 1:
The patent extracts only the necessary traffic copies for monitoring purposes from the main traffic flow. By using port mirroring to create separate copies of traffic and forwarding them to the monitoring device, the original network traffic continues to flow through the router without being blocked or significantly slowed down. This achieves complete security coverage through comprehensive monitoring while maintaining normal network throughput.
Solution Approach 2:
The patent creates copies of network traffic packets and forwards these copies to the monitoring device for analysis. The original packets continue their normal transmission path without interruption. This copying mechanism enables comprehensive traffic monitoring for security purposes while the original network performance remains unaffected, as the monitoring operates on duplicate packets rather than the primary data flow.
3Area of stationary object
If remote mirroring is implemented across different locations, then monitoring coverage is expanded, but system complexity increases
Solution Approach 1:
The patent uses the router's network infrastructure as an intermediary to transport mirrored traffic between different physical locations. By leveraging existing network connections and protocols, the system can monitor traffic across multiple locations without requiring complex dedicated monitoring infrastructure at each site. This expands monitoring coverage area while keeping the added system complexity manageable through reuse of existing network resources.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention discloses a method for implementing mirroring of a router, including: configuring a remote mirroring port on a source router, establishing a corresponding layer two virtual interface for said remote mirroring port, and specifying a data stream requiring mirroring and a corresponding physical egress port for said layer two virtual interface; establishing a layer two virtual interface corresponding to the layer two virtual interface of said source router on a destination router; forming one VPWS tunnel between the layer two virtual interfaces of said source router and said destination router; filtering out the mirroring data stream from the packet received at the remote mirroring port of said source router, and sending obtained mirroring packet from the physical egress port on said source router to said destination router; said destination router searching the layer two virtual interface on said destination router after receiving mirroring packet, and sending mirroring packet without a label from a physical port corresponding to its layer two virtual interface to a monitoring port, thereby implementing router remote mirroring. The present invention further discloses a router to support implementing remote mirroring.