Virtual Switch PVLAN Packet Filtering Headless Mode
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtual local area networks (VLANs), existing technologies face challenges in managing data communications between virtual machines, particularly in ensuring that packets are only forwarded between virtual machines belonging to the same private VLAN, and in handling disconnections of virtual switches from the controller, which can lead to outdated mapping information and unauthorized packet transmission.
Innovation Solution
A method and apparatus are provided where a first virtual switch in a physical server evaluates packets for source and destination identifier information to determine if they belong to the same private VLAN, and drops packets if they do not, while also detecting disconnections from the virtual supervisor module to prevent unauthorized communications by using MAC context databases for mapping and routing decisions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If virtual switches operate in headless mode without continuous controller connection, then system reliability and autonomy improve, but mapping information becomes outdated leading to security vulnerabilities
Solution Approach 1:
The virtual switch performs preliminary actions by locally validating packet destinations against stored mapping information before forwarding, ensuring security checks continue even when controller connection is lost. This preliminary validation mechanism maintains security functionality during headless operation.
Solution Approach 2:
The virtual switch implements self-service capability by autonomously performing security validation using locally cached mapping information without requiring continuous controller guidance. The switch independently determines whether to forward packets based on stored PVLAN mapping data, enabling autonomous operation during controller disconnection.
2Object-affected harmful factors
If strict PVLAN packet filtering is implemented, then network security improves, but packet loss increases for legitimate traffic
Solution Approach 1:
The system implements feedback mechanisms where the virtual switch continuously monitors and validates packet destinations against mapping information, providing feedback to correct potential misrouting while maintaining strict security filtering. This feedback loop ensures only legitimate PVLAN traffic is forwarded.
Solution Approach 2:
The patent replaces complex mechanical routing decisions with simplified software-based PVLAN mapping validation. Instead of relying on physical network topology for security, the system substitutes software-driven mapping verification that is more precise and easier to manage.
3Measurement precision
If virtual switches continuously validate packet destinations, then communication accuracy improves, but processing time increases
Solution Approach 1:
The virtual switch performs preliminary validation of packet destinations against stored mapping information before forwarding decisions are made. This preliminary check ensures accuracy while optimizing the overall process by preparing validation data in advance.
Solution Approach 2:
The system changes the validation parameter from real-time complex routing analysis to simplified PVLAN mapping lookup. By transforming the validation mechanism into a faster mapping-based approach, the system maintains high communication accuracy while significantly reducing processing time.
Data Source
AI summary
Techniques are provided for hosting a first virtual switch and one or more virtual machines (VMs) configured to be part of a virtual LAN (VLAN). The first virtual switch enables communications among the VMs arranged in one or more private VLANs (PVLANs). The first virtual switch receives a packet from a source VM that is evaluated for source identifier information associated and destination identifier information associated with a destination VM serviced by a second virtual switch for which the packet is destined. An evaluation result is obtained. Based on the evaluation result, the first virtual switch determines whether the source and destination VMs belong to a same PVLAN and drops the packet if the source VM and the destination VM do not belong to the same PVLAN.


