Virtual Inline Proxy Configuration for Network Traffic Redirection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network device configurations, such as inline and parallel installations, face challenges including physical re-wiring requirements, downtime, lack of transparency, and performance overhead, which hinder efficient deployment and operation of performance enhancing proxy network devices.

Innovation Solution

A virtual inline configuration where a performance enhancing proxy network device is coupled to a router in a parallel setup, allowing data packets to be redirected and processed without changing their destination addresses, maintaining transparency and reducing physical re-wiring and downtime.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a network device is deployed in an inline configuration with the WAN link, then all traffic passes through the device for processing, but physical re-wiring and downtime are required for installation

Engineering Contradiction:
Improvetraffic processingVSAvoidinstallation downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the network traffic flow by introducing a parallel path through the performance enhancing proxy. Instead of requiring all traffic to physically pass through the device (inline), the router segments traffic by copying packets to the proxy while maintaining the original inline path intact. This allows installation without breaking the WAN link.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The router acts as an intermediary that coordinates between the inline WAN link and the parallel proxy device. It receives original packets, copies them to the proxy for processing, and combines the processed packets with the original flow, enabling the proxy to function inline-capably without physical inline installation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a network device is deployed in an inline configuration, then transparency is maintained for source and destination systems, but physical re-wiring and incompatible standards pose challenges

Engineering Contradiction:
ImprovetransparencyVSAvoidphysical installation
Core Design Contradiction:
Ease of operationVSEase of manufacture

Solution Approach 1:

The patent separates the transparency function from the physical inline requirement. The router segments the packet flow by creating a copy for the proxy while maintaining the original packet path unchanged. This preserves endpoint transparency without requiring physical re-wiring or dealing with interface compatibility issues.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The router creates a copy of the original data packets and forwards them to the performance enhancing proxy. This copying mechanism allows the proxy to process packets as if it were inline, while the original packet path remains intact, eliminating the need for physical re-wiring and maintaining compatibility with existing network standards.

Inventive Principle:
Principle #26Copying

3Ease of manufacture

If parallel installation is used to avoid re-wiring, then ease of installation is improved, but data packets must be addressed to the network device and lack transparency

Engineering Contradiction:
Improveinstallation easeVSAvoidtransparency
Core Design Contradiction:
Ease of manufactureVSEase of operation

Solution Approach 1:

The router serves as an intermediary that restores transparency to the parallel installation. It receives packets destined for the proxy, processes them through the proxy, and then forwards them to the final destination with the original destination address intact. This mediation eliminates the need for endpoint configuration changes while maintaining installation ease.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of having endpoints address packets to the proxy (traditional parallel approach), the patent inverts the approach: the router actively redirects copies of original packets to the proxy while preserving original addressing. This inversion maintains both installation ease and transparency simultaneously.

Inventive Principle:
Principle #13The other way round (Inversion)

4Ease of operation

If encapsulation is used to maintain transparency, then endpoint transparency is preserved, but performance overhead is introduced

Engineering Contradiction:
Improveendpoint transparencyVSAvoidperformance
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent extracts the encapsulation overhead by having the router handle packet copying and routing directly at the network layer. Instead of encapsulating packets in additional protocol headers (which adds overhead), the router extracts only the necessary packet copies and forwards them to the proxy with original packet integrity maintained, eliminating performance penalties.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9100449B2Virtual inline configuration for a network device
Publication Date: 2015.08.04 CITRIX SYSTEMS INC
  • US9100449B2 patent drawing
  • US9100449B2 patent drawing
  • US9100449B2 patent drawing

AI summary

A performance enhancing proxy network device is configured to operate in a virtual inline mode, in which selected network traffic is redirected to and through the network device by a router using simple routing policies. In this way, the network device can be coupled to the router in series but can still operate as if it were physically connected inline.