Gateway Overlay Flow Control for BGP Route Redistribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing site-to-site VPNs are resource-intensive to set up and maintain, and there is a need for simplified management of dynamic routing protocols across computer networks, particularly in enterprise environments with multiple branch offices and data centers.
Innovation Solution
A system and method for overlay flow control that uses a gateway to redistribute routes learned through routing protocols into BGP, setting gateway precedence to influence traffic steering and simplify configuration across networks, allowing for automatic prioritization of routes and traffic steering without requiring extensive protocol configuration changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If site-to-site VPN is used to establish secure connection between branch offices and data center, then network security and resource access are improved, but resource intensity and configuration complexity increase
Solution Approach 1:
The patent introduces a gateway as an intermediary device that simplifies VPN configuration by automatically generating and managing site-to-site VPN connections. The gateway acts as a mediator between branch offices and data centers, handling the complex cryptographic key exchange and certificate management automatically, thus maintaining security while reducing configuration complexity.
Solution Approach 2:
The system implements self-service capabilities where the gateway automatically discovers branch offices, generates VPN configurations, and establishes secure connections without manual intervention. The automatic configuration generation and peer-to-peer direct connection establishment eliminate the need for administrators to manually configure complex VPN parameters, reducing resource intensity while maintaining security.
2Reliability
If site-to-site VPN is established between multiple branch offices and data center, then secure resource access is improved, but resource intensity increases
Solution Approach 1:
The gateway performs automatic discovery of branch offices and self-configures VPN connections without requiring manual setup for each connection. This automation reduces the computational resources and time required to establish and maintain multiple secure connections across the network.
Solution Approach 2:
The patent combines multiple VPN connection management functions into a single gateway device that centrally manages all secure connections between branch offices and data centers. By merging configuration, key management, and connection establishment functions into one system, the overall resource intensity is reduced compared to distributed manual configuration.
3Adaptability or versatility
If routing protocols are distributed across multiple gateways, then network coverage and connectivity are improved, but difficulty of managing routing protocols increases
Solution Approach 1:
The gateway serves as an intermediary that automatically redistributes routing information across the network using BGP protocol. It receives routes from internal routing protocols and automatically advertises them to peer gateways, eliminating the need for manual routing configuration and simplifying management while maintaining extensive network coverage.
Solution Approach 2:
The system automatically adjusts routing parameters such as BGP local preference and metric values based on gateway precedence settings. This automatic parameter adjustment allows the network to adapt to changing conditions and optimize traffic flow without requiring manual reconfiguration of routing protocols, reducing management difficulty while maintaining versatility.
4Productivity
If gateway precedence is set to influence traffic steering, then traffic optimization and performance are improved, but device complexity increases
Solution Approach 1:
The patent implements gateway precedence as a simple numerical parameter that automatically influences BGP route selection and traffic steering. By changing this single parameter, the system optimizes traffic flow without requiring complex policy configurations, maintaining productivity improvements while minimizing device complexity.
Data Source
AI summary
In one aspect, A computerized method of a gateway distributing routes learned through routing protocols (RP) into a Border Gateway Protocol (BGP) includes the step of providing a first gateway that receives a route over a routing protocol. The method includes the step of with the first gateway, redistributing the route to one or more peer routers as a BGP route based on one or more specified criteria. The method includes the step of setting a gateway precedence based on the redistribution of the route to the one or more peer routers as the BGP route. The method includes the step of, based on the gateway precedence, setting a second, gateway to automatically redistribute the route with different priorities to influence steering of traffic to a preferred gateway,


