Border Device Mapping for Multi-Site Network Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network architectures for multi-site computer networks face inefficiencies and increased complexity due to the use of separate overlay instances for virtual networks, leading to suboptimal resource utilization and scalability issues as the number of virtual networks grows.
Innovation Solution
Implementing a shared network infrastructure with border devices that utilize mapping entries and control policy nodes to facilitate communication between multiple fabric sites and virtual networks, reducing the need for multiple transit networks by using transit mapping entries and local mapping entries, and enabling efficient deployment of security services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate overlay instances are used for each virtual network, then security isolation between tenants and applications is improved, but device complexity and storage requirements increase as the number of virtual networks grows
Solution Approach 1:
The patent merges multiple separate overlay instances into a single shared network infrastructure. Instead of maintaining distinct overlay networks for each virtual network, the system uses a common underlay network with virtual network identifiers (VNI) to distinguish different virtual networks. This consolidation reduces device complexity and storage requirements while maintaining security isolation through VLAN tagging and VRF instances that logically separate traffic within the shared infrastructure.
Solution Approach 2:
The shared network infrastructure is designed to serve multiple virtual networks simultaneously through a single overlay instance. The border devices and core routers are configured with multiple VRF instances and VLAN configurations that enable them to handle traffic from different virtual networks through a unified forwarding plane, making the infrastructure universal and multi-functional rather than dedicated to single virtual networks.
2Reliability
If separate overlay instances are used for each virtual network, then security isolation between tenants and applications is improved, but resource utilization efficiency deteriorates due to redundant network infrastructure
Solution Approach 1:
The patent consolidates multiple virtual network overlays into a single shared overlay instance that runs over a common underlay network. This merging eliminates redundant network infrastructure and improves resource utilization by allowing the same physical network resources to be shared across multiple virtual networks through virtualization techniques such as VLANs and VRFs, while security isolation is maintained through logical separation mechanisms.
Solution Approach 2:
The system uses parameter changes in the form of virtual network identifiers (VNI), VLAN tags, and VRF routing tables to dynamically differentiate and isolate traffic from different virtual networks within the shared infrastructure. By changing these identification parameters rather than creating separate physical or logical overlay instances, the system achieves both security isolation and efficient resource utilization.
3Adaptability or versatility
If multiple transit networks are deployed to support multiple virtual networks, then network scalability is improved, but device complexity and storage requirements increase
Solution Approach 1:
The patent merges the function of multiple transit networks into a single shared overlay network that can carry traffic for multiple virtual networks simultaneously. Instead of deploying separate transit networks for each virtual network, the system uses one consolidated overlay with virtualization mechanisms that enable multiple virtual networks to share the same physical infrastructure, thereby maintaining scalability while reducing device complexity.
Solution Approach 2:
The patent introduces a virtualization dimension to the network architecture by adding VLAN tags and VRF instances as additional layers of abstraction over the shared physical infrastructure. This dimensional change allows the network to scale to support multiple virtual networks without proportionally increasing device complexity, as the scaling is achieved through software-based virtualization rather than additional hardware overlays.
4Adaptability or versatility
If multiple transit networks are deployed to support multiple virtual networks, then network scalability is improved, but storage complexity increases due to multiple mapping tables
Solution Approach 1:
The patent consolidates multiple mapping tables from separate transit networks into a single unified mapping structure within the shared overlay network. The border devices maintain one set of mapping entries that associate virtual network identifiers with underlay network addresses, rather than maintaining separate mapping tables for each virtual network. This unified approach reduces storage complexity while enabling the network to scale to support multiple virtual networks through the shared infrastructure.
Data Source
AI summary
This disclosure describes techniques for enabling multiple subnets across multiple fabric sites and associated with multiple network segments (e.g., virtual networks (VNs)) to communicate with each other using a shared network infrastructure, such as a service provider network. In some cases, the techniques described herein include using a common transit VN (e.g., a common transit VN with or without a common firewall) in the shared network infrastructure as well as border devices that enable switching traffic between the common transit VNs and segment VNs (e.g., subscriber VNs) for data transmission to and/or from the common transit VN. In some cases, a border device maintains two types of mapping entries (e.g., map-caches): transit mapping entries and local mapping entries. A transit and a local mapping entry may be configured to represent (e.g., installed to program) forwarding information for packets received on a transit VN and on a segment VN, respectively.


