Network Fabric Control Plane Inter-Segment Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The enforcement of inter-segment traffic policies in networks utilizing Virtual Routing and Forwarding (VRF) technology becomes complex and costly due to the need for external firewalls and routers, especially in environments with a large number of mobile devices and network segments.

Innovation Solution

The implementation of a network fabric control plane that determines and enforces stateless firewall policies, leveraging the Locator/ID Separation Protocol (LISP) and its extensions, to manage inter-VRF communication without relying on expensive router access control lists (ACL) or ternary content-addressable memory (TCAM) resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If external firewalls and fusion routers are used to enforce inter-VRF policies, then security control is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity controlVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the policy enforcement function from external firewalls and fusion routers into the border routers themselves. The border router now directly applies inter-VRF firewall policies using its own routing table and forwarding capabilities, eliminating the need for separate external enforcement devices and reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The border router is enhanced to perform multiple functions: it maintains VRF routing tables, applies inter-VRF firewall policies, and performs packet forwarding all within a single device. This multi-functionality consolidates what previously required separate specialized devices into one universal network element.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If external firewalls and fusion routers are deployed to regulate inter-VRF communication, then policy enforcement capability is improved, but cost increases

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidcost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent combines the policy enforcement capability into existing border routers that are already present in the network architecture. By utilizing the existing router infrastructure rather than adding separate firewall and fusion router devices, the solution reduces hardware costs while maintaining enforcement capability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The border router performs policy enforcement for itself and other border routers in the network. Each border router can independently apply inter-VRF firewall policies to packets it forwards between VRFs, eliminating the need for centralized external enforcement devices and reducing overall system cost.

Inventive Principle:
Principle #25Self-service

3Reliability

If traditional firewall and fusion router architecture is used, then inter-VRF security is improved, but configuration complexity increases

Engineering Contradiction:
Improveinter-VRF securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges inter-VRF security enforcement into the border router configuration, allowing administrators to define and apply firewall policies directly at the border router. This consolidation simplifies the overall configuration architecture by eliminating the need to separately configure multiple external devices for policy enforcement.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12244560B2Enforcement of inter-segment traffic policies by network fabric control plane
Publication Date: 2025.03.04 CISCO TECHNOLOGY INC
  • US12244560B2 patent drawing
  • US12244560B2 patent drawing
  • US12244560B2 patent drawing

AI summary

This disclosure describes techniques to operate a control plane in a network fabric. The techniques include determining a stateless rule corresponding to communication between a first segment of the network fabric and a second segment of the network fabric. The techniques further include configuring the control plane to enforce the stateless rule.