Virtual Network in Server Farm Using Distributed Switch

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtualization technologies face limitations in creating isolated network configurations across multiple physical servers, particularly in segregating virtual machines into private networks, managing MAC addresses, and providing external access while maintaining isolation and transparency, which is crucial for testing and deployment scenarios in server farms.

Innovation Solution

Implementing a host-level virtual network device that intercepts and routes network traffic between virtual machines, using a distributed virtual switch and virtual router to manage fenced configurations across multiple physical hosts, ensuring isolation, transparency, and external access without modifying virtual machines or guest operating systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtual machines are cloned with identical MAC addresses for easy deployment, then deployment efficiency is improved, but network equipment malfunction occurs due to MAC address conflicts

Engineering Contradiction:
Improvedeployment efficiencyVSAvoidnetwork equipment functionality
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a distributed virtual switch as an intermediary component that sits between virtual machines and physical network equipment. This switch performs MAC address translation and forwarding, allowing cloned virtual machines to use identical MAC addresses internally while the switch handles the complexity of unique addressing and forwarding to physical networks, thus resolving the conflict between deployment efficiency and network equipment reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network into virtual network segments managed by distributed virtual switches on each host. This segmentation allows cloned virtual machines to operate within isolated virtual segments with identical MAC addresses, while the segmentation architecture prevents MAC address conflicts from propagating to physical network equipment, maintaining both deployment efficiency and network reliability

Inventive Principle:
Principle #1Segmentation

2Reliability

If virtual machines are isolated into separate network segments for security and testing, then network security is improved, but network connectivity and communication capability deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork connectivity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent adds a virtual networking dimension above the physical network infrastructure. Virtual switches and virtual routers create logical network segments that can isolate virtual machines for security purposes while simultaneously providing controlled connectivity through virtual network interfaces. This dimensional addition allows both isolation and connectivity to coexist by operating at different network layers

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The distributed virtual switch acts as an intermediary that enables controlled communication between isolated virtual network segments. It provides selective forwarding and routing capabilities, allowing secure isolation within segments while maintaining necessary connectivity through the virtual switch infrastructure, thus resolving the contradiction between security isolation and network connectivity

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If multiple virtual machines run on a single physical server to maximize resource utilization, then resource efficiency is improved, but network management complexity increases

Engineering Contradiction:
Improveresource utilizationVSAvoidnetwork management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges network management functions into the virtualization layer through distributed virtual switches that run on each physical host. This consolidation allows multiple virtual machines to share physical resources while the virtual switch automatically handles network switching, MAC address management, and forwarding decisions, eliminating the need for complex external network management infrastructure

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The distributed virtual switch implements self-service network management by automatically performing MAC address translation, packet forwarding, and segment isolation based on virtual machine configurations. This automation eliminates manual network management complexity while supporting dense virtual machine deployment, allowing the system to manage itself without additional administrative overhead

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7802000B1Virtual network in server farm
Publication Date: 2010.09.21 VMWARE INC
  • US7802000B1 patent drawing
  • US7802000B1 patent drawing
  • US7802000B1 patent drawing

AI summary

A plurality of virtual machines execute on a network of physical computers. The virtual machines are deployed in fenced and unfenced configurations across multiple physical computers. Host level virtual network devices execute on the physical computers, and intercept the virtual machine network traffic. For each fenced configuration of virtual machines, a distributed virtual switch transmits network traffic between the virtual machines deployed in that fenced configuration, and a virtual router routes network traffic between virtual machines deployed in that fenced configuration and external components.