Forwarding Policy Configuration for Overlay-Underlay Consistency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Virtual Local Area Network (VLAN) architecture is limited in supporting a rapidly increasing number of tenants due to its restricted logic isolation capabilities, which are not effectively reflected in the underlay network when using Software Defined Network (SDN) and Virtual eXtensible Local Area Network (VXLAN) technologies, leading to inconsistent processing between the overlay and underlay networks.

Innovation Solution

A method is introduced to configure forwarding policies that align the processing in the overlay network with the underlay network by maintaining mappings between virtual machines and network devices, allowing packets to be forwarded according to specific policies, ensuring secure transmission and efficient resource management within the SDN and VXLAN framework.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If SDN and VXLAN technologies are used to support rapidly increasing number of tenants, then the network's adaptability and tenant isolation capability are improved, but the processing consistency between overlay and underlay networks deteriorates

Engineering Contradiction:
Improvetenant isolation capabilityVSAvoidprocessing consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a forwarding policy configuration mechanism that acts as an intermediary between the overlay network (VXLAN) and underlay network (SDN). The controller configures forwarding policies on underlay network devices based on overlay network requirements, ensuring that packet forwarding in the underlay network is consistent with the intended overlay network processing. This mediator approach resolves the inconsistency by translating overlay requirements into underlay forwarding rules.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If centralized control is implemented in SDN to flexibly control traffic, then the network's ease of operation and traffic control capability are improved, but the device complexity increases

Engineering Contradiction:
Improvetraffic control capabilityVSAvoidnetwork architecture complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent applies segmentation by separating the control plane (residing in the controller) from the forwarding plane (residing in network devices). The controller handles high-level forwarding policy decisions based on overlay network requirements, while underlay network devices execute specific forwarding actions. This segmentation allows centralized traffic control capability while distributing the actual forwarding complexity to simpler edge devices, thus improving ease of operation without concentrating all complexity in one device.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11086653B2Forwarding policy configuration
Publication Date: 2021.08.10 NEW H3C TECH CO LTD
  • US11086653B2 patent drawing
  • US11086653B2 patent drawing
  • US11086653B2 patent drawing

AI summary

A method of configuring a forwarding policy, a cloud management platform and an intelligent network management center are provided in the present disclosure. In an examples, the cloud management platform obtains a first mapping between a virtual machine and a network device, and transmits a first notification message to an intelligent network management center associated with the network device in a way that the intelligent network management center configures a forwarding policy associated with the virtual machine for the network device according to the first notification message, wherein the first notification message comprises virtual machine information of the virtual machine and network device information of the network device, and the forwarding policy instructs the network device to perform processing for a packet associated with the virtual machine.