Cross-Virtual Network Firewall Insertion via Security Group Tag Resolution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies limit the use of security source group tags and security destination group tags for steering traffic to firewalls within virtual networks, as these tags are typically confined to use within a single virtual network, restricting firewall insertion and traffic steering across different virtual networks.
Innovation Solution
The proposed solution involves configuring a border of a first virtual network as a service egress tunnel router (ETR) to monitor service prefixes across multiple virtual networks, allowing for the registration of the border as a service ETR for firewall services across different virtual networks. This enables the dynamic resolution of security source and destination group tags, facilitating the steering of traffic to firewalls regardless of the virtual network boundaries.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security group tags are used for steering traffic to firewalls within a single virtual network, then access control policy enforcement is effective, but firewall insertion across different virtual networks is restricted
Solution Approach 1:
The patent makes security group tags universal by enabling them to function across multiple virtual networks. The border router resolves destination group tags for remote virtual networks, allowing the same security tag mechanism to enforce policies across VN boundaries. This transforms the tag system from being VN-specific to being network-wide, achieving multi-functionality.
Solution Approach 2:
The border router acts as an intermediary between local security policies and remote virtual networks. It receives packets, resolves destination group tags by querying remote VRFs, and enables cross-VN security policy enforcement. This intermediary mechanism allows security tags to work across virtual networks without requiring direct integration between all VNs.
2Reliability
If IP-SGT bindings are stored within a forwarding context for access control, then policy enforcement within a virtual network is effective, but firewall insertion based on group policy across virtual networks is not supported
Solution Approach 1:
The patent extends the forwarding context from a single virtual network dimension to multiple virtual networks. By storing and resolving IP-SGT bindings across VRF boundaries, the system adds a cross-VN dimension to the forwarding context, enabling firewall insertion based on group policies to work across virtual networks while maintaining within-VN enforcement.
3Reliability
If traffic steering is limited to within the same virtual network, then security policy enforcement is simple and reliable, but network flexibility and cross-VN security routing are restricted
Solution Approach 1:
The border router performs self-service by automatically resolving destination group tags when receiving packets for remote virtual networks. Instead of requiring manual configuration of cross-VN security policies, the system autonomously queries remote VRFs to resolve tags and enforce appropriate policies, making cross-VN traffic steering as simple as within-VN steering.
Data Source
AI summary
Techniques and architecture are described for providing a service, e.g., a security service such as a firewall, across different virtual networks/VRFs/VPN IDs. The techniques and architecture provide modifications in enterprise computing fabrics by modifying pull-based overlay protocols such as, for example, locator/identifier separation protocol (LISP), border gateway protocol ethernet virtual private network (BGP EVPN), etc. A map request carries additional information to instruct a map-server that even though mapping (destination prefix and firewall service RLOC for the destination) is known within the map-server's own virtual network/VRF for firewall service insertion, the map-server still should do a lookup across virtual networks/VRFs and discover the final destination's DGT (destination group tag) and include that in the map reply.


