Service VTEP VLAN Tag Replacement for Network Traffic Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network traffic inspection methods struggle with efficiently segmenting layer-2 domains and intercepting network traffic for inspection without requiring significant re-design or reconfiguration of data centers, and they typically limit communication to two zones.

Innovation Solution

The method involves using a service virtual tunnel end point (VTEP) to receive virtual layer-3 frames, decapsulate them to obtain MAC frames, replace VLAN tags as necessary, and bridge these frames to a service device for inspection, while allowing communication within and between zones through dedicated and common virtual network identifiers and broadcast domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a transparent service device is inserted in the network traffic path to inspect network traffic, then network traffic inspection capability is improved, but the layer-2 domain is segmented into two zones which limits communication flexibility

Engineering Contradiction:
Improvenetwork traffic inspection capabilityVSAvoidcommunication flexibility between zones
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the layer-2 domain into multiple zones (first zone and second zone) with different VLAN tags, allowing granular control over traffic inspection. Service VTEPs are selectively deployed in specific zones to inspect traffic between particular end points without forcing all traffic through a single service device, thus maintaining communication flexibility while enabling targeted inspection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces service VTEPs as intermediary devices that mediate traffic between zones. These VTEPs perform VLAN tag replacement to redirect traffic through service devices for inspection when needed, while allowing direct communication when inspection is not required. This intermediary mechanism enables flexible control over traffic flow without permanently segmenting the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If dedicated VLAN tags are used for each intercept host to enable targeted traffic inspection, then traffic inspection precision is improved, but device complexity increases due to multiple VLAN tag management

Engineering Contradiction:
Improvetraffic inspection precisionVSAvoidVLAN tag management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies local quality by assigning dedicated VLAN tags only to specific intercept hosts that require inspection, while other hosts use common VLAN tags. Service VTEPs perform VLAN tag replacement only for traffic involving intercept hosts, enabling precise targeted inspection without the overhead of managing dedicated VLAN tags for all hosts. This selective approach maintains inspection precision while reducing overall device complexity.

Inventive Principle:
Principle #3Local quality

3Reliability

If service VTEPs perform VLAN tag replacement to redirect traffic through service devices, then traffic inspection effectiveness is improved, but processing time increases due to additional frame manipulation steps

Engineering Contradiction:
Improvetraffic inspection effectivenessVSAvoidframe processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements partial action by having service VTEPs perform VLAN tag replacement only when traffic involves intercept hosts that require inspection. For traffic between non-intercept hosts, the VTEPs allow direct forwarding without VLAN tag manipulation. This selective application of VLAN tag replacement maintains inspection effectiveness for critical traffic while minimizing processing time overhead for the majority of traffic that does not require inspection.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10237230B2Method and system for inspecting network traffic between end points of a zone
Publication Date: 2019.03.19 ARISTA NETWORKS INC
  • US10237230B2 patent drawing
  • US10237230B2 patent drawing
  • US10237230B2 patent drawing

AI summary

In general, embodiments of the disclosure relate to a method for handling media access control (MAC) frames. The method includes receiving, by a service virtual tunnel end point (VTEP) and from a source VTEP, a first virtual layer-3 (VL3) frame comprising a dedicated virtual network identifier (VNI), decapsulating the first VL3 frame to obtain a first media access control (MAC) frame comprising a dedicated virtual local area network (VLAN) tag, replacing, in the first MAC frame, the dedicated VLAN tag with an original VLAN tag, and bridging the first MAC frame to a service device directly connected to a first network element on which the service VTEP is executing.