Virtual Switch PVLAN Packet Filtering Headless Mode

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtual local area networks (VLANs), existing technologies face challenges in managing data communications between virtual machines, particularly in ensuring that packets are only forwarded between virtual machines belonging to the same private VLAN, and in handling disconnections of virtual switches from the controller, which can lead to outdated mapping information and unauthorized packet transmission.

Innovation Solution

A method and apparatus are provided where a first virtual switch in a physical server evaluates packets for source and destination identifier information to determine if they belong to the same private VLAN, and drops packets if they do not, while also detecting disconnections from the virtual supervisor module to prevent unauthorized communications by using MAC context databases for mapping and routing decisions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If virtual switches operate in headless mode without continuous controller connection, then system reliability and autonomy improve, but mapping information becomes outdated leading to security vulnerabilities

Engineering Contradiction:
Improvesystem reliabilityVSAvoidmapping information accuracy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The virtual switch performs preliminary actions by locally validating packet destinations against stored mapping information before forwarding, ensuring security checks continue even when controller connection is lost. This preliminary validation mechanism maintains security functionality during headless operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The virtual switch implements self-service capability by autonomously performing security validation using locally cached mapping information without requiring continuous controller guidance. The switch independently determines whether to forward packets based on stored PVLAN mapping data, enabling autonomous operation during controller disconnection.

Inventive Principle:
Principle #25Self-service

2Object-affected harmful factors

If strict PVLAN packet filtering is implemented, then network security improves, but packet loss increases for legitimate traffic

Engineering Contradiction:
Improveunauthorized packet transmissionVSAvoidpacket loss
Core Design Contradiction:
Object-affected harmful factorsVSLoss of energy

Solution Approach 1:

The system implements feedback mechanisms where the virtual switch continuously monitors and validates packet destinations against mapping information, providing feedback to correct potential misrouting while maintaining strict security filtering. This feedback loop ensures only legitimate PVLAN traffic is forwarded.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent replaces complex mechanical routing decisions with simplified software-based PVLAN mapping validation. Instead of relying on physical network topology for security, the system substitutes software-driven mapping verification that is more precise and easier to manage.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If virtual switches continuously validate packet destinations, then communication accuracy improves, but processing time increases

Engineering Contradiction:
Improvecommunication accuracyVSAvoidpacket processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The virtual switch performs preliminary validation of packet destinations against stored mapping information before forwarding decisions are made. This preliminary check ensures accuracy while optimizing the overall process by preparing validation data in advance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the validation parameter from real-time complex routing analysis to simplified PVLAN mapping lookup. By transforming the validation mechanism into a faster mapping-based approach, the system maintains high communication accuracy while significantly reducing processing time.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8989188B2Preventing leaks among private virtual local area network ports due to configuration changes in a headless mode
Publication Date: 2015.03.24 CISCO TECHNOLOGY INC
  • US8989188B2 patent drawing
  • US8989188B2 patent drawing
  • US8989188B2 patent drawing

AI summary

Techniques are provided for hosting a first virtual switch and one or more virtual machines (VMs) configured to be part of a virtual LAN (VLAN). The first virtual switch enables communications among the VMs arranged in one or more private VLANs (PVLANs). The first virtual switch receives a packet from a source VM that is evaluated for source identifier information associated and destination identifier information associated with a destination VM serviced by a second virtual switch for which the packet is destined. An evaluation result is obtained. Based on the evaluation result, the first virtual switch determines whether the source and destination VMs belong to a same PVLAN and drops the packet if the source VM and the destination VM do not belong to the same PVLAN.