Dynamic Prefix Learning for Intent-Based SD-WAN Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems struggle to implement fine-grained intent-based security policies in software-defined wide area networks (SD-WAN) due to the dynamic learning of LAN segment prefixes, which are not synchronized across sites without manual intervention, leading to potential human errors and misconfigurations.
Innovation Solution
A network service orchestrator controller translates intent-based security policies into segment-specific queries, automatically updating forwarding tables in CPE devices with dynamically learned LAN segment prefixes, enabling distributed synchronization without human intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual synchronization of network segment prefixes is used, then configuration accuracy is improved, but operation complexity and time consumption increase
Solution Approach 1:
The system enables automatic self-synchronization where the network management system automatically queries and updates network segment prefixes at remote sites without requiring manual administrator intervention. The CPE devices autonomously learn and report prefix changes, eliminating manual configuration while maintaining accuracy.
Solution Approach 2:
The system implements continuous feedback mechanisms where CPE devices monitor network segment prefix changes and automatically report them to the service orchestrator controller. This feedback loop ensures real-time synchronization of network state across all sites without manual intervention.
2Measurement precision
If manual configuration of security policies is used, then policy precision is improved, but human error increases
Solution Approach 1:
The system automatically translates high-level intent-based security policies into detailed technical security rules without manual configuration. The service orchestrator controller autonomously generates and updates security policies based on learned network segment prefixes, eliminating manual policy creation while maintaining precision through automated intent translation.
3Productivity
If automated prefix learning is used, then operational efficiency is improved, but configuration accuracy deteriorates
Solution Approach 1:
The automated prefix learning process incorporates continuous feedback verification where the service orchestrator controller receives and validates prefix information from CPE devices. This feedback mechanism ensures that automatically learned prefixes are accurate and properly synchronized across the network, maintaining configuration precision while achieving operational efficiency.
4Ease of operation
If distributed synchronization without manual intervention is used, then ease of operation is improved, but device complexity increases
Solution Approach 1:
The system merges the synchronization functionality into the existing service orchestrator controller and CPE device architecture. By integrating prefix learning, querying, and updating operations into the existing SD-WAN control plane, the system achieves automated distributed synchronization without adding significant external complexity to the network infrastructure.
Data Source
AI summary
In an example, systems and methods enable automatic implementation of intent-based security policies in a network system, such as a software-defined wide area network system, in which network segment prefixes for network segments at one or more sites are dynamically learned. A service orchestrator controller translates an intent-based security policy input by a user to a security policy for a first site. The security policy for the first site specifies a segment-specific queryable resource associated with a second site. To implement the security policy, a device associated with the first site queries the segment-specific queryable resource associated with the second site, and updates one or more forwarding tables of the device with the network segment prefixes associated with one or more network segments at the second site received in response to the query. The first site forwards network traffic to the second site based on the updated forwarding tables.


