Distributed Gateway Services in Data Center Edge Nodes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Edge devices in datacenters can become bottlenecks due to high volumes of north-south traffic, necessitating solutions that alleviate this congestion while maintaining edge services.
Innovation Solution
Managed forwarding elements (MFEs) provide gateway service processing, with a network control system assigning gateway services to MFEs based on capacity, allowing for load balancing and distributing gateway service processing across multiple MFEs or edge nodes, preventing centralized bottlenecks by using encapsulation protocols like VXLAN or GENEVE for communication between datacenters.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If gateway service processing is centralized at dedicated edge nodes, then service management is simplified, but bottlenecks occur due to high north-south traffic volumes
Solution Approach 1:
The patent segments gateway service processing from centralized edge nodes and distributes it across multiple managed forwarding elements (MFEs) in the datacenter. Each MFE can independently provide gateway services for assigned logical networks, eliminating the single-point bottleneck while maintaining service functionality through distributed architecture.
Solution Approach 2:
The patent transitions from a single-dimensional centralized service model to a multi-dimensional distributed model where gateway services operate across multiple spatial dimensions (different MFEs, different hosts) and functional dimensions (routing, firewall, NAT, VPN). This dimensional expansion increases overall system capacity while preserving management simplicity through abstraction layers.
2Productivity
If gateway services are distributed across multiple MFEs, then traffic bottlenecks are reduced, but system complexity increases
Solution Approach 1:
The patent implements universal MFEs that can perform multiple functions: packet forwarding, gateway service processing (routing, firewall, NAT, VPN), and participation in distributed service delivery. This multi-functionality reduces the need for specialized components while achieving distribution, thereby managing complexity through consolidation rather than proliferation of specialized elements.
Solution Approach 2:
The patent introduces intermediary components including the network virtualization layer and control plane that mediate between the distributed MFEs and external networks. These intermediaries abstract the complexity of distributed operations, providing unified management interfaces and automated service assignment, thereby hiding architectural complexity from operators while enabling high-capacity distributed processing.
3Stability of the object's composition
If edge services are provided at centralized edge nodes, then service consistency is maintained, but performance degrades under high traffic loads
Solution Approach 1:
The patent applies local quality by enabling each MFE to provide gateway services locally for its assigned logical networks, processing traffic at the datacenter edge where it originates rather than funneling all traffic through centralized nodes. This local processing maintains service consistency through standardized MFE functionality while achieving high-speed performance by eliminating centralized bottlenecks.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Some embodiments provide a novel method for configuring managed forwarding elements (MFEs) to handle data messages for multiple logical networks that are implemented in a data center at the MFEs and to provide gateway service processing (e.g., firewall, DNS, etc.). A controller, in some embodiments, identifies logical networks implemented in the datacenter and MFEs available to provide gateway service processing and assigns gateway service processing for each logical network to a particular MFE. The MFEs, in some embodiments, receive data messages from endpoints in the logical networks that are destined for an external network. In some embodiments, the MFEs identify that the data messages require gateway service processing before being sent to the external network. The MFEs, in some embodiments, identify a particular MFE that is assigned to provide the gateway service processing for logical networks associated with the data messages.