Ingress Device EPG Isolation via Packet Marking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data center security solutions, such as private VLANs, struggle to provide intra-Endpoint Group (EPG) isolation efficiently, especially in virtualized environments, leading to complexity and resource constraints, and do not support VxLAN-based endpoints effectively.
Innovation Solution
Implementing techniques that allow an ingress network device to mark packets with source EPG information, enabling intra-EPG isolation by incorporating security tags and QoS fields into packet headers, and using policy-based models to restrict communication within isolated EPGs, thereby preventing unauthorized traffic without the need for additional VLANs or promiscuous ports.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If private VLANs are used to provide intra-EPG isolation, then security between endpoints is improved, but device complexity and resource usage increase
Solution Approach 1:
The patent changes the parameter of security enforcement from port-level (traditional VLANs) to packet-level (header marking). By marking packets with EPG identifiers in the header and enforcing policies at the network fabric level, the system achieves intra-EPG isolation without requiring complex private VLAN configurations with promiscuous ports, thereby improving security while reducing device complexity
Solution Approach 2:
The patent extracts the security enforcement function from the access layer switches to the network fabric core. By implementing EPG isolation policies at the fabric level using header markings, the system removes the need for complex private VLAN implementations at the edge devices, reducing their complexity while maintaining security
2Reliability
If multiple VLANs are used to support VxLAN-based endpoints, then endpoint isolation is improved, but resource constraints worsen
Solution Approach 1:
The patent makes the packet header fields universal by using existing QoS and security tag fields for dual purposes: traditional QoS classification and EPG identification. This multi-functionality allows VxLAN-based endpoints to be isolated without requiring additional VLAN resources, as the same header fields serve both QoS and security isolation functions
3Reliability
If traditional VLAN-based security models are used, then endpoint security is improved, but adaptability to virtualized environments worsens
Solution Approach 1:
The patent substitutes the mechanical VLAN switching system with a software-based policy enforcement mechanism. By marking packets with EPG identifiers and using policy-based routing in the network fabric, the system replaces hardware-based VLAN isolation with a more flexible software-defined approach that adapts to virtualized environments while maintaining security
Data Source
AI summary
An ingress network device of a network fabric mark packets with source endpoint group information to enable intra-EPG isolation. The ingress network device receives an indication of endpoints associated with an isolated endpoint group that restricts network traffic among members of the isolated endpoint group. The ingress network device receives a packet from a source and detects that the source endpoint belongs to the isolated endpoint group. The ingress network device incorporates source endpoint group information into a header of the packet. The source endpoint group information indicates that the source endpoint belongs to the isolated endpoint group.


