Dynamic VPN Tunnel Establishment Using BGP EVPN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing and managing IPSec security associations between numerous branch network elements in large enterprises is inefficient due to the need for separate configuration and management of each tunnel, leading to resource wastage and scalability issues, especially when branch-to-branch traffic is rare and multi-tenant IPSec tunnel solutions are not effectively supported.
Innovation Solution
A method and apparatus for dynamically establishing VPN tunnels between network elements, where a network element detects data destined for a private subnet and establishes a VPN tunnel only when necessary, using Border Gateway Protocol (BGP) Ethernet Virtual Private Network (EVPN) and Internet Protocol Security (IPSec) transport mode, allowing for efficient resource allocation and support for multiple virtual routing and forwarding (VRF) instances.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate IPSec tunnels are configured for each branch network element pair, then security is maintained, but device complexity and configuration management become unmanageable at scale
Solution Approach 1:
The patent merges multiple individual IPSec tunnel configurations into a single VRF instance that can handle multiple destinations. Instead of configuring separate tunnels for each branch pair, a single VRF instance consolidates the routing and security functions, dramatically reducing configuration complexity while maintaining security through the underlying IPSec infrastructure.
Solution Approach 2:
The VRF instance is designed with multi-functionality to handle multiple destination networks and branch offices through a single configuration. This universal structure allows the same VRF instance to serve multiple purposes - routing to different private subnets, supporting multiple VRF instances, and managing various branch connections - eliminating the need for dedicated configurations for each scenario.
2Adaptability or versatility
If IPSec tunnels are established between all possible router pairs, then complete network connectivity is achieved, but resource consumption increases significantly
Solution Approach 1:
The patent implements dynamic tunnel establishment where IPSec tunnels are created on-demand based on actual traffic requirements. Instead of pre-establishing all possible tunnels, the system dynamically provisions tunnels only when needed, allowing the network to adapt to changing connectivity requirements while minimizing resource consumption by maintaining only necessary active tunnels.
Solution Approach 2:
The patent extracts and separates the control plane from the data plane, allowing routing decisions to be made independently of tunnel establishment. This extraction enables the network to determine connectivity requirements through routing protocols and then establish only the necessary tunnels, rather than maintaining all possible connections regardless of actual traffic needs.
3Adaptability or versatility
If multiple IPSec tunnels are provisioned for each VRF instance, then multi-tenant support is achieved, but configuration complexity and resource usage increase
Solution Approach 1:
The patent merges multiple VRF instances into a single VRF instance that can handle multiple virtual tenants through internal virtualization. This consolidation allows the system to support multi-tenancy while reducing the number of external tunnel configurations needed, as a single VRF instance can manage multiple tenant isolations and routing requirements internally.
Solution Approach 2:
The VRF instance acts as an intermediary layer between the physical network infrastructure and multiple virtual tenants. This intermediary structure allows the system to provide multi-tenant isolation and routing without requiring separate physical or tunnel configurations for each tenant, simplifying the provisioning while maintaining security and isolation between tenants.
Data Source
AI summary
A method and apparatus of a network element that dynamically establishes a first virtual private network (VPN) tunnel is described. In an exemplary embodiment, the network element detects data destined for a first private subnet. In response to the detecting, the network element determines that a next hop for the data does not have an established VPN tunnel that allows access to the first private subnet. The network element further establishes the VPN tunnel and sends the data using the VPN tunnel.


