Virtual Links for Network Isolation Without VLAN Complexity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network technologies face limitations in restricting communication between different network nodes, particularly in multitenancy scenarios where overlapping IP address ranges are used, and in isolating traffic between various applications within an enterprise, without the need for extensive reconfiguration of VLANs or physical infrastructure.
Innovation Solution
The implementation of virtual links, which establish a layer three tunnel to carry layer two and three traffic between network appliances, creating a private overlay topology without modifying the underlying infrastructure, allowing for secure and isolated communication between specific nodes or applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VLANs are used to restrict communication at layer two, then communication isolation between different network nodes is improved, but device complexity and reconfiguration requirements increase
Solution Approach 1:
The patent introduces virtual machine interfaces and virtual switches as intermediary layers between physical network infrastructure and applications. These intermediaries handle communication isolation at the virtualization layer, eliminating the need for complex VLAN configurations on physical switches while maintaining reliable communication isolation between different virtual machines and network segments.
Solution Approach 2:
The patent transitions from traditional layer two VLAN-based isolation to a multi-dimensional isolation approach that operates at multiple layers including virtual machine interfaces, virtual switches, and overlay networks. This dimensional shift allows communication isolation to be implemented through virtualization abstractions rather than physical network layer configurations, reducing device complexity while maintaining isolation effectiveness.
2Reliability
If VLANs are configured to isolate traffic, then communication security is improved, but ease of operation and scalability deteriorate
Solution Approach 1:
The patent implements self-service mechanisms where the virtualization management system automatically handles network isolation configuration. When virtual machines are created, moved, or modified, the system automatically configures appropriate virtual switches, interfaces, and overlay network parameters without requiring manual VLAN reconfiguration. This maintains communication security while dramatically improving ease of operation and scalability.
Solution Approach 2:
The patent introduces dynamic network isolation that can be adjusted in real-time based on workload requirements. Virtual machine interfaces and virtual switches can be dynamically created, modified, or removed without physical network reconfiguration. This dynamic approach maintains security isolation while allowing flexible operational changes and scaling as needed.
3Reliability
If physical infrastructure is modified to restrict communication, then network isolation is improved, but loss of time and productivity increase
Solution Approach 1:
The patent pre-configures virtual network interfaces, virtual switches, and overlay network parameters during virtual machine provisioning or migration preparation. This preliminary configuration ensures that when virtual machines need to be moved or isolated, the network infrastructure is already prepared, eliminating the need for time-consuming physical reconfiguration while maintaining effective network isolation.
Solution Approach 2:
The patent replaces mechanical physical network reconfiguration with software-based virtual network configuration. Instead of physically moving cables, reconfiguring switches, or modifying physical infrastructure to achieve network isolation, the system uses virtual machine interfaces, virtual switches, and overlay networks that can be configured and modified through software, dramatically reducing reconfiguration time while maintaining isolation effectiveness.
Data Source
AI summary
Passing data over virtual links is disclosed, including: encapsulating a layer three data packet as an inner payload of a network data packet; and generating an outer header of the network data packet with a layer two header and a layer three header, wherein the network data packet is configured to communicate over a virtual link between a first interface of a first network appliance and a first interface of a second network appliance.


