Transparent VLAN Flooding for Scalable Network Traffic Duplication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network monitoring tools are limited in their ability to create multiple copies of network traffic for various monitoring roles and destinations, and existing solutions like port mirroring and physical taps face issues such as signal degradation and scalability limitations.
Innovation Solution
The method involves using transparent VLAN flooding to duplicate network traffic, where a network device with switching fabric and configurable ports creates a duplicate copy of network traffic and forwards it to multiple monitoring ports within a virtual local area network (VLAN), allowing for arbitrary copies to be generated and dispatched to different destinations without the need for additional expensive hardware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If port mirroring is used to create a single copy of traffic, then monitoring capability is provided, but the ability to create multiple copies and send to different destinations is lost
Solution Approach 1:
The patent segments the monitoring function by creating separate monitoring ports within VLANs, allowing traffic to be distributed to multiple destinations independently. Each monitoring port can be configured separately, enabling flexible multi-destination traffic replication without requiring a completely new system architecture.
Solution Approach 2:
The patent introduces VLANs as an additional dimension for organizing monitoring traffic. By using VLAN identifiers, the system can create multiple logical copies of traffic and route them to different destinations simultaneously, adding a layer of abstraction that enables versatile multi-destination monitoring.
2Reliability
If physical taps are used to divert signal, then traffic copying is achieved, but signal degradation and equipment cost increase
Solution Approach 1:
The patent uses software-based packet copying within the network device to create duplicate traffic copies. Instead of physically tapping the signal and risking degradation, the system copies data at the packet level through the switching fabric, maintaining signal integrity while achieving traffic duplication.
Solution Approach 2:
The patent replaces the mechanical/physical tap system with a software-defined packet copying mechanism. The network device uses its switching fabric and control plane to replicate packets, eliminating the need for physical signal diversion hardware and associated signal degradation issues.
3Adaptability or versatility
If software solutions are used to create traffic copies, then flexibility is provided, but scalability at high speeds is limited
Solution Approach 1:
The patent merges the packet copying function with the existing hardware switching fabric infrastructure. By combining software control with hardware acceleration, the system achieves both flexibility in traffic selection and high-speed copying capability, as the switching fabric handles the actual packet duplication at line rate.
Solution Approach 2:
The patent makes the network device universally capable of performing traffic copying for multiple monitoring purposes simultaneously. The same hardware infrastructure supports various copying scenarios (single copy, multiple copies, different destinations) through software configuration, achieving both flexibility and scalability.
4Adaptability or versatility
If multiple monitoring roles are supported, then monitoring versatility is improved, but device complexity increases
Solution Approach 1:
The patent applies local quality by allowing each monitoring port to have independent configuration and characteristics. Each port can be individually configured for specific monitoring roles, and the VLAN structure provides localized scoping that isolates different monitoring functions, making the system manageable despite supporting multiple roles.
Data Source
AI summary
Provided are methods, non-transitory computer-readable medium, and network devices for duplicating network traffic through transparent VLAN flooding. In some implementations, a network device comprises a plurality of ports. The plurality of ports may include a first port configured as a receiving port for a VLAN configured for the network device. The plurality of ports may further include a set of ports configured as I/O ports of the VLAN. MAC learning may be disabled for the receiving port. In some implementations, the network device is configured to determine, based on contents of a packet received at the receiving port, that the packet is to be sent to one or more monitoring devices. The network device may further be configure to, upon receiving the packet at the receiving port of the VLAN, cause a copy of the packet to be sent to each of one or more I/O ports of the VLAN.


