Switch Virtual Network Identifier Rewrite for Multi-VSAN Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current virtual switching technologies, such as VSAN, are limited in that a host device and its virtual devices can only operate within a single virtual network, restricting their ability to communicate across different virtual networks despite sharing the same physical infrastructure.
Innovation Solution
A switch with a virtual network identifier rewrite component and rule set that allows data frames to be rewritten with new virtual network identifiers, enabling communication between host devices and virtual devices across multiple virtual networks by inserting and rewriting VSAN identifiers in data frames.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a host device is assigned to operate in only one VSAN, then the VSAN isolation and security are maintained, but the host device cannot communicate with virtual devices in other VSANs
Solution Approach 1:
The switch acts as an intermediary between the host device and multiple VSANs. It receives data frames from the host device, rewrites the VSAN identifier in the frame header to match the destination VSAN, and forwards the frame to the appropriate virtual device. This mediator approach enables communication across VSAN boundaries while maintaining isolation for devices that don't need cross-VSAN access.
Solution Approach 2:
The system dynamically changes the VSAN identifier parameter in the data frame header during transmission. When a data frame is received from a host device, the switch modifies the VSAN ID in the frame header to match the destination VSAN, allowing the same physical connection to carry traffic for multiple virtual networks without compromising security or isolation.
2Reliability
If separate physical switches are used for each VSAN, then complete VSAN isolation is achieved, but the physical infrastructure cost and complexity increase
Solution Approach 1:
The patent merges multiple VSAN functionalities into a single physical switch. Instead of requiring separate physical switches for each VSAN, the switch can handle multiple VSANs simultaneously by rewriting VSAN identifiers in data frame headers. This consolidation reduces the number of physical devices needed while maintaining VSAN isolation through logical separation and identifier manipulation.
Solution Approach 2:
The switch is designed with multi-functionality to handle multiple VSANs through a single device. It can simultaneously process and route traffic for different VSANs by dynamically rewriting VSAN identifiers in data frame headers, making the switch universal across multiple virtual networks rather than dedicated to a single VSAN.
3Device complexity
If a single physical switch handles multiple VSANs without identifier rewriting, then the switch configuration is simpler, but host devices cannot communicate across different VSANs
Solution Approach 1:
The system dynamically changes the VSAN identifier parameter in the data frame header during transmission. When a data frame is received from a host device, the switch modifies the VSAN ID in the frame header to match the destination VSAN, allowing the same physical connection to carry traffic for multiple virtual networks without compromising security or isolation.
4Reliability
If virtual devices are restricted to their host's assigned VSAN, then network security is maintained, but network flexibility and efficiency are reduced
Solution Approach 1:
The switch acts as an intermediary between the host device and multiple VSANs. It receives data frames from the host device, rewrites the VSAN identifier in the frame header to match the destination VSAN, and forwards the frame to the appropriate virtual device. This mediator approach enables communication across VSAN boundaries while maintaining isolation for devices that don't need cross-VSAN access.
Data Source
AI summary
A switch includes a processor, an ingress port having ingress port logic, and an egress port. It may also include a virtual network identifier rewrite component for rewriting a virtual network identifier in a data frame received the ingress port with a new virtual network identifier. Also included is a virtual network identifier rewrite rule set, where a rule may have one or more of the following: a received virtual network identifier, a source Fibre Channel identifier (FCID) address, an ingress port identifier, and a new virtual network identifier. The ingress port logic may insert a received virtual network identifier into the data frame received at the ingress port, where the virtual network identifier may correspond to the ingress port. The virtual network identifier rewrite component may assign the new virtual network identifier to the data frame according to a specific virtual network identifier rewrite rule.


