Virtual Network in Server Farm Using Distributed Switch
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtualization technologies face limitations in creating isolated network configurations across multiple physical servers, particularly in segregating virtual machines into private networks, managing MAC addresses, and providing external access while maintaining isolation and transparency, which is crucial for testing and deployment scenarios in server farms.
Innovation Solution
Implementing a host-level virtual network device that intercepts and routes network traffic between virtual machines, using a distributed virtual switch and virtual router to manage fenced configurations across multiple physical hosts, ensuring isolation, transparency, and external access without modifying virtual machines or guest operating systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If virtual machines are cloned with identical MAC addresses for easy deployment, then deployment efficiency is improved, but network equipment malfunction occurs due to MAC address conflicts
Solution Approach 1:
The patent introduces a distributed virtual switch as an intermediary component that sits between virtual machines and physical network equipment. This switch performs MAC address translation and forwarding, allowing cloned virtual machines to use identical MAC addresses internally while the switch handles the complexity of unique addressing and forwarding to physical networks, thus resolving the conflict between deployment efficiency and network equipment reliability
Solution Approach 2:
The patent segments the network into virtual network segments managed by distributed virtual switches on each host. This segmentation allows cloned virtual machines to operate within isolated virtual segments with identical MAC addresses, while the segmentation architecture prevents MAC address conflicts from propagating to physical network equipment, maintaining both deployment efficiency and network reliability
2Reliability
If virtual machines are isolated into separate network segments for security and testing, then network security is improved, but network connectivity and communication capability deteriorate
Solution Approach 1:
The patent adds a virtual networking dimension above the physical network infrastructure. Virtual switches and virtual routers create logical network segments that can isolate virtual machines for security purposes while simultaneously providing controlled connectivity through virtual network interfaces. This dimensional addition allows both isolation and connectivity to coexist by operating at different network layers
Solution Approach 2:
The distributed virtual switch acts as an intermediary that enables controlled communication between isolated virtual network segments. It provides selective forwarding and routing capabilities, allowing secure isolation within segments while maintaining necessary connectivity through the virtual switch infrastructure, thus resolving the contradiction between security isolation and network connectivity
3Productivity
If multiple virtual machines run on a single physical server to maximize resource utilization, then resource efficiency is improved, but network management complexity increases
Solution Approach 1:
The patent merges network management functions into the virtualization layer through distributed virtual switches that run on each physical host. This consolidation allows multiple virtual machines to share physical resources while the virtual switch automatically handles network switching, MAC address management, and forwarding decisions, eliminating the need for complex external network management infrastructure
Solution Approach 2:
The distributed virtual switch implements self-service network management by automatically performing MAC address translation, packet forwarding, and segment isolation based on virtual machine configurations. This automation eliminates manual network management complexity while supporting dense virtual machine deployment, allowing the system to manage itself without additional administrative overhead
Data Source
AI summary
A plurality of virtual machines execute on a network of physical computers. The virtual machines are deployed in fenced and unfenced configurations across multiple physical computers. Host level virtual network devices execute on the physical computers, and intercept the virtual machine network traffic. For each fenced configuration of virtual machines, a distributed virtual switch transmits network traffic between the virtual machines deployed in that fenced configuration, and a virtual router routes network traffic between virtual machines deployed in that fenced configuration and external components.


