Virtual Network Switch Control Plane Rule Consistency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtual network switches in virtualized computer systems fail to consistently implement network rules, filters, and security features, leading to inconsistent handling of network traffic and potential security and management issues, as they lack features like ACLs, intrusion detection, and flow tables compared to external communication networks.
Innovation Solution
A method is introduced where a configuration signal is sent to a virtual network switch module within a control plane to define network rules, and a packet forwarding module is configured to implement these rules, ensuring that network traffic is processed consistently with external network elements by applying rules, filters, ACLs, mirroring capabilities, and other features defined in a configuration file.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If virtual network switches process network traffic internally without external network elements, then network traffic handling efficiency is improved, but consistency with external network processing and security features is lost
Solution Approach 1:
The patent introduces a virtual network switch that acts as an intermediary between virtualized computer systems and external communication networks. This virtual switch receives network traffic from virtual machines, processes it according to rules defined by external network elements, and forwards it appropriately. The virtual switch includes a control plane that communicates with external network elements to obtain configuration rules, ensuring that internal processing remains efficient while external consistency is maintained through rule-based mediation.
Solution Approach 2:
The virtual network switch is divided into functional segments: a control plane for receiving and interpreting network rules from external elements, and a data plane for actual packet forwarding and processing. This segmentation allows the control plane to maintain consistency with external networks by receiving updated rules, while the data plane efficiently handles traffic processing locally without requiring constant external intervention.
2Device complexity
If virtual network switches operate independently without external network element features, then system simplicity is improved, but security and management capabilities are degraded
Solution Approach 1:
The virtual network switch receives network rules, filters, ACLs, and other security configurations from external network elements before processing traffic. These rules are prepared and loaded into the virtual switch's control plane in advance, enabling the system to maintain simple independent operation while possessing robust security and management capabilities when needed.
Solution Approach 2:
The virtual network switch establishes feedback mechanisms with external network elements to receive updated security rules and configuration information. This feedback loop allows the virtual switch to maintain security and management capabilities aligned with external networks while continuing to operate independently for day-to-day traffic processing.
Data Source
AI summary
In one embodiment, a method includes sending a configuration signal to a virtual network switch module within a control plane of a communications network. The configuration signal is configured to define a first network rule at the virtual network switch module. The method also includes configuring a packet forwarding module such that the packet forwarding module implements a second network rule, and receiving status information from the virtual network switch module and status information from the packet forwarding module. The status information is received via the control plane.


