Virtual I/O Server Policy-Based Network Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtualized computing environments, existing network filtering techniques such as IPsec tunneling and firewall configurations on physical routers significantly degrade network communication performance by requiring complex setups and resource-intensive operations.
Innovation Solution
A physical host executes a hypervisor that instantiates virtual machines and a virtual input/output server (VIOS), which determines the disposition of network packets based on policy data structures, allowing for efficient packet forwarding or dropping within the same packet flow without involving external routers, thus enhancing network filtering.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IPsec tunneling or firewall configurations on physical routers are used for network filtering, then network security is improved, but network communication performance significantly degrades
Solution Approach 1:
The patent extracts the network filtering function from external physical routers and relocates it into the virtualized environment through the virtual switch. This allows filtering to be performed internally within the virtual network infrastructure, eliminating the performance degradation caused by external router processing while maintaining security requirements.
Solution Approach 2:
The virtual switch acts as an intermediary component between virtual machines and physical networks, implementing policy-based filtering rules. This intermediary approach enables efficient packet filtering at the virtualization layer without requiring complex firewall configurations on physical routers, thus maintaining both security and performance.
2Reliability
If IPsec tunneling or firewall configurations are implemented, then network filtering capability is improved, but setup complexity significantly increases
Solution Approach 1:
The virtual switch is designed to provide multiple functions including packet forwarding, switching, and policy-based filtering within a single component. This multi-functionality eliminates the need for separate firewall configurations and complex router setups, simplifying the overall network filtering implementation while maintaining comprehensive filtering capability.
Solution Approach 2:
The system enables self-service network filtering by allowing virtual machines to be assigned security groups and filtering policies through automated configurations. This eliminates the need for manual firewall rule creation and complex setup procedures, reducing setup complexity while maintaining effective network filtering capability.
Data Source
AI summary
A physical host executes a hypervisor or virtual machine monitor (VMM) that instantiates at least one virtual machine (VM) and a virtual input/output server (VIOS). The VIOS determines by reference to a policy data structure a disposition of a packet of network communication with the VM, where the disposition includes one of dropping the packet and forwarding the packet. Thereafter, the determined disposition is applied to a subsequent packet in a same packet flow as the packet.


