Global In-Filter for Tenant Route Control in SDDC
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-tenancy scenarios of software-defined data centers, existing technologies lack the ability to effectively manage route advertisements between tenant and provider logical routers, leading to inadequate control over network policies, where tenant users want to control which routes to advertise and provider users want to control which routes to accept or deny.
Innovation Solution
Implementing a global in-filter configuration at the control plane of the software-defined data center, which includes filter rules applicable to all southbound logical routers, allowing the control plane to determine allowable and disallowed routes and distribute routing information accordingly, ensuring that only allowed routes are propagated to the provider logical router.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If route advertisement rules are configured for lower-tier logical routers in multi-tenancy scenarios, then tenant users can control which routes to advertise, but provider users lack control over which advertised routes to accept or deny
Solution Approach 1:
The patent segments route advertisement control into two distinct layers: tenant-level control (lower-tier logical routers) and provider-level control (higher-tier logical routers). This segmentation allows each user type to exercise control at their appropriate level, resolving the contradiction between tenant route advertisement capabilities and provider acceptance control.
Solution Approach 2:
The higher-tier logical router acts as an intermediary between tenant logical routers and external networks. It receives route advertisements from tenants, applies provider-defined acceptance policies, and selectively propagates routes upward. This intermediary mechanism enables both tenant advertisement control and provider acceptance control to coexist.
2Device complexity
If multiple tenant logical routers connect to a single provider logical router, then network consolidation is achieved, but control over individual tenant route policies becomes difficult
Solution Approach 1:
The patent segments the control plane into tenant-managed lower-tier logical routers and provider-managed higher-tier logical routers. Each tenant router maintains independent route advertisement capabilities while connecting to the shared provider router, enabling both consolidation and individual control.
Solution Approach 2:
Each tenant logical router is configured with its own route advertisement rules specific to that tenant's needs, while the provider logical router applies global acceptance policies. This local quality approach allows customized control for each tenant despite architectural consolidation.
Data Source
AI summary
An example method of implementing a logical network in a software-defined data center (SDDC) includes: receiving, at a control plane, first configurations for first logical routers comprising advertised routes and a second configuration for a second logical router comprising a global in-filter, the global in-filter including filter rules, applicable to all southbound logical routers, which determine a set of allowable routes for the second logical router, the first logical routers connected to a southbound interface of the second logical router; determining, based on the filter rules, that a first advertised route is an allowed route; determining, based on the filter rules, that a second advertised route is a disallowed route; and distributing routing information to a host that implements at least a portion of the second logical router, the routing information including a route for the first advertised route and excluding any route for the second advertised route.


