Underlay-overlay correlation for virtualized network troubleshooting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Virtualization in data centers complicates network analysis and troubleshooting due to the challenge of correlating physical underlay network infrastructure with virtual overlay networks, making it difficult to identify the physical path of data flows and pinpoint connectivity issues.
Innovation Solution
Collecting and correlating underlay flow data and overlay flow data to enrich the understanding of network operations, allowing for the identification of relevant underlay network devices and paths, thereby facilitating efficient troubleshooting and analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If virtualization is implemented in data centers to improve resource efficiency and simplify network configuration, then computing resource utilization and management ease are improved, but network analysis and troubleshooting complexity increase due to the difficulty of correlating physical underlay infrastructure with virtual overlay networks
Solution Approach 1:
The patent applies nesting by embedding overlay flow data within underlay flow data records. Each underlay record contains nested overlay flow information, creating a hierarchical data structure where virtual network flows are contained within physical network flow records. This allows the system to maintain both underlay and overlay information in a unified structure, enabling efficient correlation without increasing overall system complexity.
Solution Approach 2:
The patent introduces an intermediary enrichment process that bridges underlay and overlay data. The enrichment module acts as a mediator that receives underlay flow data, augments it with corresponding overlay flow information, and produces enriched records that contain both physical and virtual network data. This intermediary layer simplifies troubleshooting by automatically correlating the two network planes without requiring manual analysis.
2Productivity
If virtualization is implemented to improve resource efficiency, then ROI and management advantages are improved, but visibility into physical network infrastructure corresponding to overlay flows deteriorates
Solution Approach 1:
The patent merges underlay and overlay flow data into unified enriched records. By combining physical network flow information with virtual network flow data in a single data structure, the system preserves visibility into the physical infrastructure while maintaining virtual network abstraction. This merging allows administrators to trace overlay flows back to their corresponding underlay paths without losing physical network context.
Solution Approach 2:
The patent performs preliminary enrichment of underlay flow data with overlay information before analysis or troubleshooting occurs. By pre-augmenting the underlay records with virtual network data, the system ensures that visibility information is already prepared and correlated when needed. This preliminary action eliminates the need for complex real-time correlation during troubleshooting operations.
3Measurement precision
If comprehensive flow data collection is implemented to improve network visibility, then analysis capability is improved, but data volume and processing requirements increase
Solution Approach 1:
The patent applies partial action by selectively enriching only those underlay flow records that have corresponding overlay flows. Rather than processing or storing all possible network data, the system performs enrichment only where needed - when an underlay flow corresponds to a virtual network flow. This partial enrichment approach maintains high analysis capability while avoiding the overhead of processing excessive data that would not contribute to overlay-underlay correlation.
Data Source
AI summary
This disclosure describes techniques that include collecting underlay flow data along with overlay flow data within a network and correlating the data to enable insights into network operation and performance. In one example, this disclosure describes a method that includes collecting flow data for a network having a plurality of network devices and a plurality of virtual networks established within the network; storing the flow data in a data store; receiving a request for information about a data flow, wherein the request for information specifies a source virtual network for the data flow and further specifies a destination virtual network for the data flow; and querying the data store with the specified source virtual network and the specified destination virtual network to identify, based on the stored flow data, one or more network devices that have processed at least one packet in the data flow.


