Integrated L2/L3 Gateway Service Node for Cloud Policy Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The separation of Layer 2 (L2) and Layer 3 (L3) gateways in networking systems leads to inconvenient policy changes, scaling challenges, and increased risk of conflicts due to the need to manage policies across different devices from different vendors, along with issues like ARP flooding and complex inter-virtual routing and forwarding (VRF) communication.
Innovation Solution
Integrating L2 and L3 functionalities into a Service Node that includes a centralized gateway (CGW) and service gateway (SGW) to manage both L2 and L3 policies, utilizing a well hierarchy and ARP suppression techniques to simplify policy management and reduce conflicts, while supporting seamless communication between VRFs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If L2 and L3 gateways are separated into different devices, then each device can be optimized for its specific function, but policy management becomes complex and error-prone due to needing to download and manage policies across multiple devices from different vendors
Solution Approach 1:
The patent combines L2 gateway and L3 gateway functionalities into a single integrated gateway device. This merger eliminates the need to manage separate L2 and L3 policies across multiple devices, reducing policy management complexity while ensuring consistency. The integrated gateway maintains distinct L2 and L3 functional components but unifies their policy management under a single device architecture.
2Adaptability or versatility
If L2 and L3 gateways are separate devices, then each device can be independently managed, but scaling the network becomes challenging as customers must consider both L2 and L3 capabilities on different devices
Solution Approach 1:
The integrated gateway is designed to provide both L2 and L3 gateway capabilities within a single device, offering multi-functionality that simplifies network scaling. Customers can scale the network by deploying additional integrated gateways that each provide both L2 and L3 functions, eliminating the complexity of coordinating separate L2 and L3 device deployments while maintaining full functionality.
3Productivity
If L2 and L3 gateways are separate devices, then each device can be optimized for its specific layer, but ARP flooding occurs from L2 GW to L3 GW causing network inefficiency
Solution Approach 1:
By integrating L2 and L3 gateway functions into a single device, the patent eliminates the ARP flooding issue that occurs when L2 and L3 gateways are separate devices. The integrated architecture allows ARP messages to be processed internally without being flooded across device boundaries, improving network efficiency while maintaining the distinct functional separation of L2 and L3 operations within the same device.
4Reliability
If L3 gateway separates tenants into different VRFs, then tenant isolation is improved, but communication between different VRFs requires additional VASI interfaces limiting connectivity
Solution Approach 1:
The integrated gateway uses an internal intermediary mechanism to enable communication between different VRFs without requiring external VASI interfaces. The single device architecture provides internal routing and forwarding capabilities that allow controlled inter-VRF communication while maintaining tenant isolation, overcoming the limitation of pair-wise VASI interface requirements in separate device architectures.
Data Source
AI summary
Disclosed herein are systems, methods, and computer-readable media for managing Layer 2 (L2) and Layer 3 (L3) policies. Traffic is routed from a first VM to a first CGW within a Service Node, where the Service Node can include a centralized policy for both L2 functions and L3 functions, and the first CGW can integrate both L2 gateways and L3 gateways. Based on a floating IP address of the packet, the traffic is routed within the Service Node, the traffic being routed by an access BD from an ingress BD-VIF to an egress BD-VIF. The traffic is then routed from a second CGW that integrates both L2 gateways and L3 gateways to the destination VM.


