Dynamic VPN Tunnel Establishment Using BGP EVPN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Establishing and managing IPSec security associations between numerous branch network elements in large enterprises is inefficient due to the need for separate configuration and management of each tunnel, leading to resource wastage and scalability issues, especially when branch-to-branch traffic is rare and multi-tenant IPSec tunnel solutions are not effectively supported.

Innovation Solution

A method and apparatus for dynamically establishing VPN tunnels between network elements, where a network element detects data destined for a private subnet and establishes a VPN tunnel only when necessary, using Border Gateway Protocol (BGP) Ethernet Virtual Private Network (EVPN) and Internet Protocol Security (IPSec) transport mode, allowing for efficient resource allocation and support for multiple virtual routing and forwarding (VRF) instances.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate IPSec tunnels are configured for each branch network element pair, then security is maintained, but device complexity and configuration management become unmanageable at scale

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple individual IPSec tunnel configurations into a single VRF instance that can handle multiple destinations. Instead of configuring separate tunnels for each branch pair, a single VRF instance consolidates the routing and security functions, dramatically reducing configuration complexity while maintaining security through the underlying IPSec infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The VRF instance is designed with multi-functionality to handle multiple destination networks and branch offices through a single configuration. This universal structure allows the same VRF instance to serve multiple purposes - routing to different private subnets, supporting multiple VRF instances, and managing various branch connections - eliminating the need for dedicated configurations for each scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If IPSec tunnels are established between all possible router pairs, then complete network connectivity is achieved, but resource consumption increases significantly

Engineering Contradiction:
Improvenetwork connectivityVSAvoidresource consumption
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent implements dynamic tunnel establishment where IPSec tunnels are created on-demand based on actual traffic requirements. Instead of pre-establishing all possible tunnels, the system dynamically provisions tunnels only when needed, allowing the network to adapt to changing connectivity requirements while minimizing resource consumption by maintaining only necessary active tunnels.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent extracts and separates the control plane from the data plane, allowing routing decisions to be made independently of tunnel establishment. This extraction enables the network to determine connectivity requirements through routing protocols and then establish only the necessary tunnels, rather than maintaining all possible connections regardless of actual traffic needs.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If multiple IPSec tunnels are provisioned for each VRF instance, then multi-tenant support is achieved, but configuration complexity and resource usage increase

Engineering Contradiction:
Improvemulti-tenant supportVSAvoidtunnel provisioning
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple VRF instances into a single VRF instance that can handle multiple virtual tenants through internal virtualization. This consolidation allows the system to support multi-tenancy while reducing the number of external tunnel configurations needed, as a single VRF instance can manage multiple tenant isolations and routing requirements internally.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The VRF instance acts as an intermediary layer between the physical network infrastructure and multiple virtual tenants. This intermediary structure allows the system to provide multi-tenant isolation and routing without requiring separate physical or tunnel configurations for each tenant, simplifying the provisioning while maintaining security and isolation between tenants.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10469595B2System and method of dynamic establishment of virtual private networks using border gateway protocol ethernet virtual private networks technology
Publication Date: 2019.11.05 ARISTA NETWORKS INC
  • US10469595B2 patent drawing
  • US10469595B2 patent drawing
  • US10469595B2 patent drawing

AI summary

A method and apparatus of a network element that dynamically establishes a first virtual private network (VPN) tunnel is described. In an exemplary embodiment, the network element detects data destined for a first private subnet. In response to the detecting, the network element determines that a next hop for the data does not have an established VPN tunnel that allows access to the first private subnet. The network element further establishes the VPN tunnel and sends the data using the VPN tunnel.