Service Function Chaining via VLAN-Vsys Multi-Service Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In service function chain masquerading proxy networking, providing multiple application services increases networking costs due to the need for multiple service function forwarders to bypass service functions like firewall devices, each of which can only perform one type of service.
Innovation Solution
Deploy a switch between service function forwarders and service functions, supporting multiple virtual local area networks (VLANs) and virtual systems (Vsys) on the service function, associating different VLANs with distinct Vsys and application service policies, allowing the service function to determine and process packets based on VLAN identifiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple service function forwarders bypass service functions to provide different application services, then service diversity is improved, but networking costs increase
Solution Approach 1:
The service function device is configured with multiple virtual local area networks (VLANs) and virtual systems (Vsys), allowing a single physical device to provide multiple different application services (such as different firewall security services) through logical segmentation. Each Vsys can be associated with different VLANs and configured with different application service policies, enabling one SF to replace multiple SFs while maintaining service diversity
Solution Approach 2:
The service function device is segmented into multiple virtual systems (Vsys) that are associated with different VLANs. This segmentation allows different application services to be isolated and managed independently within the same physical device, enabling multi-service capability without requiring multiple separate physical service function devices
2Reliability
If each service function provides only one type of service, then service quality is improved, but device utilization deteriorates
Solution Approach 1:
A single service function device is designed to perform multiple application services through the configuration of multiple VLANs and Vsys. Each Vsys maintains dedicated application service policies ensuring service quality, while the physical device resources are shared across multiple services, improving overall device utilization
Solution Approach 2:
The patent introduces a new dimension of virtualization by adding VLAN and Vsys layers above the physical hardware. This allows the service function device to operate in both physical and virtual dimensions simultaneously, maintaining service quality through logical isolation while improving resource utilization through physical consolidation
Data Source
Figure 1~3
Figure 4~5
Figure 6~8
AI summary
Embodiments of the present disclosure provide an application service implementation method and apparatus in service function chain masquerading proxy networking. In the embodiments, a switch is deployed between a service function forwarder (SFF) and a service function (SF), the switch and the SF are configured to support a plurality of virtual local area networks (VLANs), different VLANs supported by the SF are associated to corresponding virtual systems (Vsys) on the SF, a corresponding application service policy is configured for each of the Vsys, a VLAN identifier is carried on a packet sent by the SFF to the SF through the switch, the SF determines, based on the VLAN identifier carried in the packet, a virtual system Vsys associated with a VLAN corresponding to the VLAN identifier, and performs corresponding service processing on the packet according to an application service policy corresponding to the Vsys, so that different application services are provided on the same SF by combining multiple VLANs and Vsys on the SF, networking costs are reduced, and resource utilization of the SF is also improved.