EVPN Route-Type Updates for Consistent VTEP Firewall Tables
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In datacenters with distributed firewall services, the inconsistent firewall rules across VTEPs can lead to traffic blocking and latency due to the lack of synchronized updates, especially during workload movements or link failures.
Innovation Solution
Synchronize firewall tables between VTEPs using an EVPN route type, generating control packets for rule updates and adhering to a specific format to ensure consistent firewall rules across network devices, with local policies for security verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If distributed firewall services are implemented at each VTEP, then traffic latency is reduced and network throughput is improved, but firewall rule consistency deteriorates leading to traffic blocking and security vulnerabilities
Solution Approach 1:
The patent implements a feedback mechanism where VTEPs periodically exchange firewall rule status information through EVPN control packets. When a VTEP detects a change in its local firewall rules, it generates an EVPN route advertisement containing the updated rules and sends it to peer VTEPs. Peer VTEPs receive these advertisements and update their local firewall tables accordingly, ensuring all VTEPs maintain consistent firewall policies while preserving the performance benefits of distributed filtering
Solution Approach 2:
The patent introduces EVPN control packets as an intermediary mechanism for synchronizing firewall rules between VTEPs. These control packets serve as a standardized communication medium that carries firewall rule updates across the network fabric, enabling automatic propagation of security policies without requiring manual configuration at each node or creating a centralized bottleneck
2Ease of manufacture
If manual firewall rule updates are used across VTEPs, then implementation simplicity is maintained, but synchronization time increases causing traffic interruptions during workload movements
Solution Approach 1:
The patent implements preliminary action by having VTEPs proactively detect firewall rule changes and immediately generate EVPN advertisements containing the updated rules. This proactive approach ensures that firewall policy updates are propagated to all relevant VTEPs before traffic interruptions occur, particularly during workload migrations. The system continuously monitors for rule changes and triggers automatic synchronization, eliminating the need for manual updates and reducing synchronization delays
Data Source
AI summary
Examples described herein relate to synchronization of distributed firewall tables using an EVPN route type. Examples include detecting an update to a firewall table at a network device and generating a control packet indicating that update. The control packet is consistent with an EVPN route type, which is a format to incorporate changes to firewall rules of the firewall table. Examples include advertising the control packet, which specifies the update to neighboring network devices. A neighboring network device may receive the advertised control packet and synchronize a respective firewall table with the update based on a local policy.


