Virtual Storage Appliance Firewall for Inter-SP Packet Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized data storage systems, there is a risk of mis-configuration of inter-storage processor connections, leading to incoherent communications between non-peer storage processors, which can disrupt system operation, especially when multiple virtual storage appliances share the same internal network and use the same static IP addresses.

Innovation Solution

The method involves configuring a network firewall on each storage processor to accept packets from peer storage processors by using a unique peer-SP identifier, such as a MAC address, to filter out non-peer packets, ensuring only proper communications occur within the virtualized environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If multiple virtual storage appliances share the same internal network with static IP addresses, then network simplicity and ease of deployment are improved, but mis-configuration risk and communication reliability deteriorate

Engineering Contradiction:
Improveease of deploymentVSAvoidcommunication reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a virtual switch as an intermediary component between storage processors. The virtual switch manages network connections and uses MAC address filtering to ensure that storage processors only communicate with their intended peers, preventing mis-configuration errors while maintaining the simplicity of shared network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses MAC addresses as unique identifiers (analogous to color changes) to distinguish between different storage processors. Each storage processor has a unique MAC address that is used for filtering and identification, allowing the system to differentiate between peers and non-peers in the shared network environment.

Inventive Principle:
Principle #32Color changes

2Adaptability or versatility

If storage processors use shared internal networks for cost efficiency, then resource utilization is improved, but risk of incoherent communications from non-peer processors increases

Engineering Contradiction:
Improveresource utilizationVSAvoidincoherent communications
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The virtual switch acts as a mediator that controls and filters communications between storage processors on the shared network. It uses MAC address-based filtering to allow only legitimate peer-to-peer communications while blocking potentially harmful connections from non-peer processors.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network communication logic by introducing virtual switch instances that manage specific storage processor connections. This segmentation allows multiple storage processors to share the physical network infrastructure while maintaining logical separation and control over communication paths.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If administrator-configured virtual networks are used, then flexibility and adaptability are improved, but configuration errors and mis-connections increase

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidconnection accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The virtual switch automatically performs MAC address filtering and connection validation without requiring manual configuration of each connection detail. The system self-manages the filtering rules based on the virtual machine's identifier, reducing the likelihood of human error while maintaining configuration flexibility.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10291708B1Multi-node virtual data storage appliance with internal communications filtering
Publication Date: 2019.05.14 EMC IP HLDG CO LLC
  • US10291708B1 patent drawing
  • US10291708B1 patent drawing
  • US10291708B1 patent drawing

AI summary

A storage processor of a set of virtual-machine-implemented storage processors (SPs) of a virtual storage appliance (VSA) is operated to avoid potential mis-communications among non-peer SPs in a virtualized environment having multiple VSAs. An operating method includes receiving a peer-SP identifier that uniquely identifies a peer storage processor of the VSA in network packets sent by the peer storage processor via an internal inter-SP network. The peer-SP identifier, which may be a machine-level network address such as a MAC address, is used to configure a network firewall to accept peer-SP packets and reject non-peer-SP packets from the internal inter-SP network. The network firewall is subsequently operated as configured to accept the peer-SP packets for delivery to the main operating logic of the one storage processor and to reject the non-peer-SP network packets.