Sub-Interface MAC Binding for Virtual Network Throughput

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VLAN architectures require the use of an intermediate front-end transparent VDOM to facilitate communication between virtual domains and external network devices, which does not support High Availability active-active mode and reduces concurrent sessions, leading to degraded throughput.

Innovation Solution

Creating sub-interfaces of a physical Ethernet interface with unique MAC addresses and binding applications to these sub-interfaces, allowing the virtualized network device to learn associations between source MAC addresses and sub-interfaces, and transmitting packets without replacing the source MAC address, thereby enabling efficient communication with external network devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If an intermediate front-end transparent VDOM is used to facilitate communication between virtual domains and external network devices, then communication capability is enabled, but device complexity increases and High Availability active-active mode is not supported

Engineering Contradiction:
Improvecommunication capabilityVSAvoidarchitecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts and removes the intermediate transparent VDOM from the communication path. By allowing virtual domain interfaces to be directly bound to physical network interfaces, the solution eliminates the need for the intermediate TP VDOM component, thereby reducing architectural complexity while maintaining communication capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the network interface binding at the virtual domain level rather than requiring a unified intermediate layer. Each virtual domain can independently bind to physical interfaces, enabling direct communication paths and supporting High Availability active-active mode without the constraints of a centralized transparent VDOM.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If an intermediate front-end transparent VDOM is used to enable communication with external network devices, then external connectivity is achieved, but concurrent sessions are reduced to half

Engineering Contradiction:
Improveexternal connectivityVSAvoidconcurrent sessions
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

By removing the intermediate transparent VDOM from the communication path, the patent eliminates the session translation and forwarding overhead that halved the concurrent session capacity. Virtual domains can now establish direct sessions with external network devices, doubling the effective session capacity.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If packets traverse through the intermediate TP VDOM twice, then communication is enabled, but system throughput is degraded

Engineering Contradiction:
Improvecommunication functionalityVSAvoidsystem throughput
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent extracts the intermediate TP VDOM from the packet path, eliminating the double traversal requirement. Packets can now flow directly from virtual domain interfaces to physical network interfaces in a single pass, doubling the effective throughput by removing the redundant forwarding and processing steps.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10868792B2Configuration of sub-interfaces to enable communication with external network devices
Publication Date: 2020.12.15 FORTINET INC
  • US10868792B2 patent drawing
  • US10868792B2 patent drawing
  • US10868792B2 patent drawing

AI summary

Systems and methods for facilitating communication between applications associated with virtual domains (VDOMs) of a virtualized network device and an external network are provided. According to one embodiment, a sub-interface is created for a physical Ethernet interface of the network device. A unique MAC address is assigned to the sub-interface. An application associated with a first VDOM is bound to the sub-interface. When the first VDOM is operating in transparent mode and an egress packet is received via the sub-interface by an internal switch running on the network device: (i) a forwarding database of the network device is caused to learn an association between a source MAC address of the egress packet and the sub-interface; and (ii) the egress packet is transmitted to the external network device via the physical Ethernet interface without replacing the source MAC address with the unique MAC address of the sub-interface.