SDN FCoE Initialization Protocol Snooping Bridge
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Software Defined Networking (SDN) protocols lack a mechanism to realize the functionality of a Fibre Channel over Ethernet (FCoE) Initialization Protocol (FIP) Snooping Bridge (FSB), preventing the use of SDN on Fibre Channel networks that utilize FCoE and Ethernet bridges between server devices and Storage Area Networks (SANs).
Innovation Solution
An Information Handling System (IHS) with a Software Defined Networking (SDN) FCoE Initialization Protocol (FIP) Snooping Bridge (FSB) engine is implemented, which prevents FCoE data traffic between server and FCF devices, allows FIP traffic, forwards FC login communications, and enables FCoE data traffic based on valid source identifiers, ensuring secure and controlled data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If an Ethernet bridge is provided between server device and FCF device to increase flexibility, then network flexibility and SDN compatibility are improved, but point-to-point assurance is lost and network security deteriorates
Solution Approach 1:
The patent introduces an FSB (FIP Snooping Bridge) as an intermediary device between the Ethernet bridge and the FCF device. This FSB snoops on FIP packets during discovery and login phases, implementing dynamic integrity mechanisms such as ACLs that permit only valid FCoE traffic. This intermediary restores the point-to-point assurance by validating traffic at the FSB layer while maintaining the Ethernet bridge's flexibility for SDN operations.
2Reliability
If FSB functionality is implemented in traditional networks to ensure traffic validity, then network security is improved, but SDN protocol compatibility deteriorates
Solution Approach 1:
The patent segments the FSB functionality into two distinct parts: a control plane component that communicates with the SDN controller via standard SDN protocols (OpenFlow, ONOS, OVN), and a data plane component that performs FIP snooping and traffic validation. This segmentation allows the SDN controller to program the FSB's forwarding behavior while the FSB independently validates FCoE traffic, thus achieving both SDN compatibility and traffic validity enforcement.
3Ease of operation
If centralized control is implemented through SDN controller to manage FCoE traffic, then network manageability is improved, but real-time traffic control capability deteriorates
Solution Approach 1:
The patent implements preliminary action by having the SDN controller pre-program the FSB with forwarding rules and ACLs based on FIP snooping results. The FSB receives these pre-configured rules via SDN protocols and then enforces them in real-time at the data plane level without requiring continuous controller intervention. This preliminary configuration enables both centralized manageability and real-time enforcement.
Data Source
AI summary
An FSB-enabled SDN system includes an FC storage device coupled to an FSB device by an FCF device. An SDN FSB device couples a server device to the FCF device, and is also coupled to an SDN controller device. The SDN FSB device prevents first FCoE data traffic while allowing FIP data traffic between the server device and the FCF device based on SDN communications from the SDN controller device. The SDN FSB device then forwards FC login communications included in the FIP data traffic to the SDN controller device. If the FSB device then receives a third SDN communication from the SDN controller device that includes an FC source identifier for the server device, it may allow second FCoE data traffic between the server device and the FC storage device if that second FCoE data traffic is associated with the FC source identifier.


