Switch Inner Packet Inspection for Tunnel Traffic Visibility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network switches lack visibility into tunnel traffic flows, preventing them from managing and identifying flows that require additional management, such as rogue traffic, due to their inability to inspect inner packets encapsulated with headers.
Innovation Solution
A switch is designed to inspect inner packets encapsulated with headers without decapsulation, applying rules based on virtual network identifiers and storing information in a tunnel information table to facilitate selective rule management and traffic flow management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If a switch inspects inner packets encapsulated with headers without decapsulation, then visibility into tunnel traffic flows is achieved, but device complexity increases
Solution Approach 1:
The patent extracts only the necessary information from inner packets (source/destination addresses, protocol types) without performing full decapsulation. The inner packet module selectively extracts flow identification information while leaving the encapsulation intact, thus achieving visibility without the complexity of complete decapsulation processing.
Solution Approach 2:
The patent introduces an intermediary inner packet module that sits between the packet processor and the rule management module. This module acts as a mediator that provides the switch with visibility into inner packet contents through selective extraction, without requiring the switch's core forwarding logic to handle decapsulation, thus managing complexity.
2Adaptability or versatility
If rules are applied selectively based on inner packet inspection, then traffic flow management capability is improved, but processing time increases
Solution Approach 1:
The patent applies partial action by inspecting only specific fields of inner packets (source/destination addresses, protocol types) rather than performing full packet analysis. This selective inspection provides sufficient information for rule application while minimizing processing overhead and time loss.
Solution Approach 2:
The patent performs preliminary action by pre-processing and extracting key information from inner packets before rule matching. The inner packet module prepares flow identification data in advance, so that when rules need to be applied, the switch already has the necessary information readily available, reducing processing time.
3Reliability
If the switch learns traffic patterns within tunnels, then network security is improved, but the switch's processing load increases
Solution Approach 1:
The patent extracts only essential traffic pattern information (flow identifiers, packet counts, byte counts) needed for security monitoring without performing comprehensive packet analysis. This selective extraction provides security insights while keeping processing load manageable.
Solution Approach 2:
The patent implements self-service by having the inner packet module automatically learn and store traffic patterns in local tables (tunnel information table, flow table) without requiring external intervention or complex processing. The switch serves its own security monitoring needs through automated, lightweight information gathering and storage.
Data Source
AI summary
One embodiment of the present invention provides a switch. The switch includes a storage device, a rule management module, an inner packet module, and a packet processor. During operation, the rule management module obtains a rule associated with a data flow within tunnel encapsulation of a tunnel. This rule indicates how the flow is to be processed at the switch. The rule management module then applies an initial rule to a respective line card of the switch. The initial rule is derived from a virtual network identifier, which is associated with the tunnel, of the obtained rule. The inner packet module determines that a first inner packet, which is encapsulated with a first encapsulation header, belongs to the flow without decapsulating the first encapsulation header. The rule management module applies the obtained rule to a line card associated with an ingress port of the encapsulated first inner packet.


