Global In-Filter for Tenant Route Control in SDDC

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tenancy scenarios of software-defined data centers, existing technologies lack the ability to effectively manage route advertisements between tenant and provider logical routers, leading to inadequate control over network policies, where tenant users want to control which routes to advertise and provider users want to control which routes to accept or deny.

Innovation Solution

Implementing a global in-filter configuration at the control plane of the software-defined data center, which includes filter rules applicable to all southbound logical routers, allowing the control plane to determine allowable and disallowed routes and distribute routing information accordingly, ensuring that only allowed routes are propagated to the provider logical router.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If route advertisement rules are configured for lower-tier logical routers in multi-tenancy scenarios, then tenant users can control which routes to advertise, but provider users lack control over which advertised routes to accept or deny

Engineering Contradiction:
Improveroute advertisement controlVSAvoidnetwork policy control flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent segments route advertisement control into two distinct layers: tenant-level control (lower-tier logical routers) and provider-level control (higher-tier logical routers). This segmentation allows each user type to exercise control at their appropriate level, resolving the contradiction between tenant route advertisement capabilities and provider acceptance control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The higher-tier logical router acts as an intermediary between tenant logical routers and external networks. It receives route advertisements from tenants, applies provider-defined acceptance policies, and selectively propagates routes upward. This intermediary mechanism enables both tenant advertisement control and provider acceptance control to coexist.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If multiple tenant logical routers connect to a single provider logical router, then network consolidation is achieved, but control over individual tenant route policies becomes difficult

Engineering Contradiction:
Improvelogical router architectureVSAvoidindividual tenant route control
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The patent segments the control plane into tenant-managed lower-tier logical routers and provider-managed higher-tier logical routers. Each tenant router maintains independent route advertisement capabilities while connecting to the shared provider router, enabling both consolidation and individual control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each tenant logical router is configured with its own route advertisement rules specific to that tenant's needs, while the provider logical router applies global acceptance policies. This local quality approach allows customized control for each tenant despite architectural consolidation.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240403097A1Filters for advertised routes from tenant gateways in a software-defined data center
Publication Date: 2024.12.05 VMWARE INC
  • US20240403097A1 patent drawing
  • US20240403097A1 patent drawing
  • US20240403097A1 patent drawing

AI summary

An example method of implementing a logical network in a software-defined data center (SDDC) includes: receiving, at a control plane, first configurations for first logical routers comprising advertised routes and a second configuration for a second logical router comprising a global in-filter, the global in-filter including filter rules, applicable to all southbound logical routers, which determine a set of allowable routes for the second logical router, the first logical routers connected to a southbound interface of the second logical router; determining, based on the filter rules, that a first advertised route is an allowed route; determining, based on the filter rules, that a second advertised route is a disallowed route; and distributing routing information to a host that implements at least a portion of the second logical router, the routing information including a route for the first advertised route and excluding any route for the second advertised route.