IP Library › Granted Patent US 11,736,351
Granted Patent B2
US 11,736,351 · App. 17/670,036 · Granted Aug 22, 2023

Identifying components for removal in a network configuration

Inventors: Ramana Rao Kompella (Cupertino, CA); Chandra Nagarajan (Fremont, CA); John Thomas Monk (Palo Alto, CA); Purna Mani Kumar Ghantasala (Sunnyvale, CA)
Assignee: Cisco Technology Inc.
H04L41/0853H04L41/0893H04L41/145H04L41/0813H04L41/12H04L45/64H04L45/74591H04L47/2441H04L49/10H04L49/1515
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,736,351
App. No.
17/670,036
Granted
Aug 22, 2023
Kind
B2
Abstract

Systems, methods, and computer-readable media analyzing memory usage in a network node. A network assurance appliance may be configured to determine a hit count for a concrete level rule implemented on a node and identify one or more components of a logical model, wherein each of the one or more components are associated with the concrete level rule. The network assurance appliance may attribute the hit count for the concrete level rule to each of the components of the logical model, determine a number of hardware level entries associated with the each of the one or more components, and generate a report comprising the one or more components of the logical model, the hit count attributed to each of the one or more components of the logical model, and the number of hardware level entries associated with the one or more components of the logical model.

Claims (56)

1. A computer-implemented method comprising:

determining, by at least one processor, a hit count for a concrete level rule implemented on a node;

identifying one or more components from a logical model, wherein the one or more components are associated with the concrete level rule;

attributing the hit count for the concrete level rule to each of the one or more components;

determining one or more ternary content-addressable memory (TCAM) entries associated with the one or more components;

calculating a number of stale TCAM entries based at least in part on the hit count; and

generating a report, based at least in part on the number of stale TCAM entries, identifying a removal candidate of the one or more components.

2. The computer-implemented method of claim 1 , further comprising:

identifying the concrete level rule implemented on the node by querying the node for rule identifiers for the concrete level rule.

3. The computer-implemented method of claim 1 , further comprising:

identifying a logical level intent associated with the concrete level rule, the logical level intent associated with the one or more components.

4. The computer-implemented method of claim 1 , further comprising:

determining, by querying the node, a number of hardware level entries associated with one or more logical level components, wherein the number of hardware level entries comprises one or more TCAM entries.

5. The computer-implemented method of claim 1 , wherein the determining of the hit count for the concrete level rule comprises querying the node for the hit count for the concrete level rule.

6. The computer-implemented method of claim 1 , wherein the determining of the hit count for the concrete level rule comprises querying a network controller for the hit count for the concrete level rule.

7. The computer-implemented method of claim 1 , wherein the concrete level rule comprises an access control rule.

8. The computer-implemented method of claim 1 , wherein the one or more components comprise an endpoint and a protocol.

9. The computer-implemented method of claim 1 ,

wherein,

the one or more components include one or more contracts, and

the removal candidate is an identified one of the one or more contracts with no hits and most entries.

10. The computer-implemented method of claim 1 , wherein the node is a leaf node.

11. A system comprising:

one or more processors; and

at least one computer-readable storage medium having stored therein instructions which, when executed by the one or more processors, cause the system to:

determine a hit count for a concrete level rule implemented on a node;

identify one or more components from a logical model, wherein the one or more components are associated with the concrete level rule;

attribute the hit count for the concrete level rule to each of the one or more components;

determine one or more ternary content-addressable memory (TCAM) entries associated with the one or more components;

calculate a number of stale TCAM entries based at least in part on the hit count; and

generate a report, based at least in part on the number of stale TCAM entries, identifying a removal candidate of the one or more components.

12. The system of claim 11 , further comprising instructions, which when executed by the one or more processors, cause the system to:

identify the concrete level rule implemented on the node by querying the node for rule identifiers for the concrete level rule.

13. The system of claim 11 , further comprising instructions, which when executed by the one or more processors, cause the system to:

identify a logical level intent associated with the concrete level rule, the logical level intent associated with the one or more components.

14. The system of claim 11 , wherein the one or more components comprise an endpoint and a protocol.

15. The system of claim 11 ,

wherein,

the one or more components include one or more contracts, and

the removal candidate is an identified one of the one or more contracts with no hits and most entries.

16. At least one non-transitory computer-readable storage medium having stored therein instructions which, when executed by one or more processors, cause the one or more processors to:

determine a hit count for a concrete level rule implemented on a node;

identify one or more components from a logical model, wherein the one or more components are associated with the concrete level rule;

attribute the hit count for the concrete level rule to each of the one or more components;

determine one or more ternary content-addressable memory (TCAM) entries associated with the one or more components;

calculate a number of stale TCAM entries based at least in part on the hit count; and

generate a report, based at least in part on the number of stale TCAM entries, identifying a removal candidate of the one or more components.

17. The at least one non-transitory computer-readable storage medium of claim 16 , further comprising instructions, which when executed by the one or more processors, cause the one or more processors to:

identify the concrete level rule implemented on the node by querying the node for rule identifiers for the concrete level rule.

18. The at least one non-transitory computer-readable storage medium of claim 16 , further comprising instructions, which when executed by the one or more processors, cause the one or more processors to:

identify a logical level intent associated with the concrete level rule, the logical level intent associated with the one or more components.

19. The at least one non-transitory computer-readable storage medium of claim 16 , wherein the one or more components comprise an endpoint and a protocol.

20. The at least one non-transitory computer-readable storage medium of claim 16 ,

wherein,

the one or more components include one or more contracts, and

the removal candidate is an identified one of the one or more contracts with no hits and most entries.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2022
From: KOMPELLA, RAMANA RAO; NAGARAJAN, CHANDRA; MONK, JOHN THOMAS; GHANTASALA, PURNA MANI KUMAR
To: CISCO TECHNOLOGY, INC.
Reel/Frame 058992/0336 →
Continuity (3)
Continuation 15661889 · Jul 27, 2017
Provisional Application 62521629 · Jun 19, 2017
Related Publication 20220166673A1 · May 26, 2022