Simulated Endpoints for Network Policy Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network policies applied to virtual local area networks (VLANs) and virtual extensible local area networks (VXLANs) face challenges in verifying the correct application of policies across endpoint groups, leading to potential mismanagement of traffic forwarding and security within modern network environments.
Innovation Solution
A method is introduced where a network connected device provisions simulated endpoints on switches to test policy application by sending packets with varying five-tuple headers, using traceroute and ACL logging to verify if policies are correctly applied, allowing for the identification of any discrepancies in policy implementation across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If simulated endpoints are provisioned on switches to verify policy application, then policy verification accuracy is improved, but device complexity increases
Solution Approach 1:
The patent creates simulated endpoints that are virtual copies of actual network endpoints. These simulated endpoints replicate the behavior and characteristics of real endpoints without requiring physical hardware, thereby improving verification accuracy while avoiding the complexity of additional physical devices. The simulated endpoints are provisioned on existing switch infrastructure through software-based virtualization.
Solution Approach 2:
The simulated endpoints act as intermediaries between the policy verification system and the actual network traffic. They receive and respond to test packets in a controlled manner, allowing verification of policy application without directly involving real endpoints. This intermediary layer simplifies the verification process by providing a controlled testing environment.
2Reliability
If multiple packets are sent to simulated endpoint for each policy outcome, then policy verification completeness is improved, but loss of time increases
Solution Approach 1:
The system pre-provisions simulated endpoints on suitable switches before verification begins. This preliminary setup includes configuring the simulated endpoints with appropriate characteristics and establishing their readiness to receive test packets. By preparing the verification environment in advance, the actual verification process can proceed more efficiently without setup delays during execution.
Solution Approach 2:
The verification process sends packets periodically or in structured batches to simulated endpoints rather than continuously. This approach allows the system to verify multiple policy outcomes systematically while managing the time required for verification. The periodic sending of test packets enables comprehensive coverage of policy scenarios without overwhelming the network infrastructure.
Data Source
AI summary
A determination is made at a network connected device that a network policy is to be verified. The network policy is applied to network packets sent to an endpoint within a network, and the application of the policy to network traffic can result in at least two outcomes. Another determination is made at the network connected device that a switch is provisionable to host the endpoint. The network connected device provisions a simulated endpoint version of the endpoint at the switch to host the policy. At least one packet is sent to the simulated endpoint via the network connected device for each of the at least two outcomes of the policy. At least one response is received by the network connected device from the simulated endpoint indicating how the policy was applied to each of the packets.


