Service VTEP VLAN Tag Replacement for Network Traffic Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network traffic inspection methods struggle with efficiently segmenting layer-2 domains and intercepting network traffic for inspection without requiring significant re-design or reconfiguration of data centers, and they typically limit communication to two zones.
Innovation Solution
The method involves using a service virtual tunnel end point (VTEP) to receive virtual layer-3 frames, decapsulate them to obtain MAC frames, replace VLAN tags as necessary, and bridge these frames to a service device for inspection, while allowing communication within and between zones through dedicated and common virtual network identifiers and broadcast domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a transparent service device is inserted in the network traffic path to inspect network traffic, then network traffic inspection capability is improved, but the layer-2 domain is segmented into two zones which limits communication flexibility
Solution Approach 1:
The patent segments the layer-2 domain into multiple zones (first zone and second zone) with different VLAN tags, allowing granular control over traffic inspection. Service VTEPs are selectively deployed in specific zones to inspect traffic between particular end points without forcing all traffic through a single service device, thus maintaining communication flexibility while enabling targeted inspection.
Solution Approach 2:
The patent introduces service VTEPs as intermediary devices that mediate traffic between zones. These VTEPs perform VLAN tag replacement to redirect traffic through service devices for inspection when needed, while allowing direct communication when inspection is not required. This intermediary mechanism enables flexible control over traffic flow without permanently segmenting the network.
2Measurement precision
If dedicated VLAN tags are used for each intercept host to enable targeted traffic inspection, then traffic inspection precision is improved, but device complexity increases due to multiple VLAN tag management
Solution Approach 1:
The patent applies local quality by assigning dedicated VLAN tags only to specific intercept hosts that require inspection, while other hosts use common VLAN tags. Service VTEPs perform VLAN tag replacement only for traffic involving intercept hosts, enabling precise targeted inspection without the overhead of managing dedicated VLAN tags for all hosts. This selective approach maintains inspection precision while reducing overall device complexity.
3Reliability
If service VTEPs perform VLAN tag replacement to redirect traffic through service devices, then traffic inspection effectiveness is improved, but processing time increases due to additional frame manipulation steps
Solution Approach 1:
The patent implements partial action by having service VTEPs perform VLAN tag replacement only when traffic involves intercept hosts that require inspection. For traffic between non-intercept hosts, the VTEPs allow direct forwarding without VLAN tag manipulation. This selective application of VLAN tag replacement maintains inspection effectiveness for critical traffic while minimizing processing time overhead for the majority of traffic that does not require inspection.
Data Source
AI summary
In general, embodiments of the disclosure relate to a method for handling media access control (MAC) frames. The method includes receiving, by a service virtual tunnel end point (VTEP) and from a source VTEP, a first virtual layer-3 (VL3) frame comprising a dedicated virtual network identifier (VNI), decapsulating the first VL3 frame to obtain a first media access control (MAC) frame comprising a dedicated virtual local area network (VLAN) tag, replacing, in the first MAC frame, the dedicated VLAN tag with an original VLAN tag, and bridging the first MAC frame to a service device directly connected to a first network element on which the service VTEP is executing.


