BGP Export Policy for Automatic IPSec Endpoint Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for IPSec VPN tunnels in communication networks face scalability issues as they require manual configuration of IPSec tunnel endpoints, which is not feasible for large numbers of Customer Edge (CE) devices, and current solutions either rely on a Group Controller Key Server (GCKS) to maintain endpoint lists or require enhancements to the MPBGP protocol.

Innovation Solution

Implementing a BGP export route policy that replaces the BGP-next hop field with the IPSec tunnel endpoint address in VPN route updates, allowing CEs to automatically learn IPSec tunnel endpoints without manual configuration or additional messaging, thereby eliminating the need for GCKS to maintain endpoint lists and enhancing MPBGP functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of IPSec tunnel endpoints is used, then security and reliability are maintained, but scalability deteriorates as the number of CE devices increases

Engineering Contradiction:
ImproveIPSec tunnel endpoint configuration reliabilityVSAvoidNetwork scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables automatic learning of IPSec tunnel endpoints through BGP route updates. CEs autonomously extract and configure endpoint addresses from received routing information without manual intervention, while the export route policy automatically replaces next-hop fields with endpoint addresses. This self-configuration mechanism maintains reliability through structured protocols while achieving scalability.

Inventive Principle:
Principle #25Self-service

2Loss of information

If GCKS maintains endpoint lists, then endpoint information is available, but system complexity and administrative burden increase

Engineering Contradiction:
ImproveIPSec tunnel endpoint information availabilityVSAvoidGCKS maintenance complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The invention extracts the endpoint address information from the BGP next-hop field and makes it directly available in routing updates. By removing the need for a separate endpoint maintenance system like GCKS, the solution simplifies the architecture while ensuring endpoint information is continuously available through standard routing protocols. The export route policy automatically performs the extraction and replacement.

Inventive Principle:
Principle #2Taking out (Extraction)

3Extent of automation

If MPBGP protocol is enhanced to support endpoint learning, then automatic learning is achieved, but protocol complexity and compatibility issues arise

Engineering Contradiction:
ImproveIPSec endpoint automatic learningVSAvoidMPBGP protocol complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The solution makes the existing BGP protocol multi-functional by using the next-hop field for dual purposes: traditional routing next-hop indication and IPSec tunnel endpoint address carrier. The export route policy enables this universal usage without modifying the MPBGP protocol, achieving automatic endpoint learning while maintaining protocol compatibility and avoiding additional complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7907595B2Method and apparatus for learning endpoint addresses of IPSec VPN tunnels
Publication Date: 2011.03.15 PULSELINK SYSTEMS LLC
  • US7907595B2 patent drawing
  • US7907595B2 patent drawing
  • US7907595B2 patent drawing

AI summary

Customer Edge (CE) network elements can automatically learn IPSec tunnel endpoints for other CEs connected to sites in a Virtual Private Network (VPN) so that manual configuration of IPSec tunnel endpoints is not required and so that a centralized database of IPSec tunnel endpoints is not required to be separately maintained. According to an embodiment of the invention, a BGP export route policy is set on all CEs, so that when they announce their VPN routes in the standard format, the application of this export route policy changes the announcement to replace the BGP peering point address that would ordinarily be advertised with the IPSec tunnel endpoint address. When any given site receives a VPN route update formatted in this manner, it processes the VPN route update and learns from the update the IPSec tunnel endpoint as well as the associated VPN routes.