Virtual Network Appliance Insertion via Packet Interception
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In computer networks, physically reconnecting network cables to add or insert network appliances like IPS and WAN accelerators is cumbersome and limits their placement in the data path, especially in dynamic environments.
Innovation Solution
The implementation of a virtual insertion module that allows network appliances to be dynamically inserted into the data path using data taps and application path descriptors, enabling them to receive and reinject packets in their original form without physical re-cabling, utilizing components like virtual insertion modules, interception modules, and forwarding circuitry.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If network appliances are physically connected to the network using cables, then reliable data transmission is achieved, but flexibility and ease of placement are reduced
Solution Approach 1:
A network device acts as an intermediary between the data path and network appliances. The network device intercepts data packets and forwards them to network appliances for processing, eliminating the need for physical re-cabling. This mediator approach allows appliances to be dynamically added or removed without disrupting the physical network infrastructure.
Solution Approach 2:
The system creates a logical copy of the data path through the network device. Instead of physically altering the network topology, the network device copies packets to network appliances while maintaining the original data flow path. This allows multiple appliances to receive identical packet copies without requiring separate physical connections for each appliance.
2Adaptability or versatility
If network appliances are physically inserted into the data path, then direct packet access is achieved, but adaptability to dynamic environments is reduced
Solution Approach 1:
The system implements dynamic placement of network appliances through software configuration rather than fixed physical connections. Network appliances can be dynamically added, removed, or moved between different data paths by modifying routing rules in the network device, allowing rapid adaptation to changing network requirements without time-consuming physical reconfiguration.
Solution Approach 2:
The network device pre-establishes interception points and forwarding rules that enable rapid deployment of network appliances. When a new appliance needs to be added, the system can quickly activate pre-configured data taps and routing rules, eliminating the need for time-consuming physical cable reconnections and allowing immediate operational readiness.
3Adaptability or versatility
If policy based routing is used to forward packets, then packet forwarding flexibility is improved, but packet modification occurs which may not be desired
Solution Approach 1:
The packet handling process is segmented into distinct stages: interception, forwarding to appliance, and re-injection. The network device intercepts packets at a specific point in the data path, forwards them to network appliances for processing, and then re-injects them back into the data path. This segmentation allows the appliance to receive packets in their original form without policy-based routing modifications, while still achieving flexible forwarding through the interception and re-injection mechanism.
Data Source
AI summary
A network appliance is virtually inserted in a data path within a network. Packet data that matches a criteria is intercepted at a logical point within the data path. The intercepted packet data is forwarded to an application running on the virtually inserted network appliance.


