Integrated L2/L3 Gateway Service Node for Cloud Policy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The separation of Layer 2 (L2) and Layer 3 (L3) gateways in networking systems leads to inconvenient policy changes, scaling challenges, and increased risk of conflicts due to the need to manage policies across different devices from different vendors, along with issues like ARP flooding and complex inter-virtual routing and forwarding (VRF) communication.

Innovation Solution

Integrating L2 and L3 functionalities into a Service Node that includes a centralized gateway (CGW) and service gateway (SGW) to manage both L2 and L3 policies, utilizing a well hierarchy and ARP suppression techniques to simplify policy management and reduce conflicts, while supporting seamless communication between VRFs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If L2 and L3 gateways are separated into different devices, then each device can be optimized for its specific function, but policy management becomes complex and error-prone due to needing to download and manage policies across multiple devices from different vendors

Engineering Contradiction:
Improvepolicy consistencyVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines L2 gateway and L3 gateway functionalities into a single integrated gateway device. This merger eliminates the need to manage separate L2 and L3 policies across multiple devices, reducing policy management complexity while ensuring consistency. The integrated gateway maintains distinct L2 and L3 functional components but unifies their policy management under a single device architecture.

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If L2 and L3 gateways are separate devices, then each device can be independently managed, but scaling the network becomes challenging as customers must consider both L2 and L3 capabilities on different devices

Engineering Contradiction:
Improvenetwork scalabilityVSAvoidscaling difficulty
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The integrated gateway is designed to provide both L2 and L3 gateway capabilities within a single device, offering multi-functionality that simplifies network scaling. Customers can scale the network by deploying additional integrated gateways that each provide both L2 and L3 functions, eliminating the complexity of coordinating separate L2 and L3 device deployments while maintaining full functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If L2 and L3 gateways are separate devices, then each device can be optimized for its specific layer, but ARP flooding occurs from L2 GW to L3 GW causing network inefficiency

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidARP flooding
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

By integrating L2 and L3 gateway functions into a single device, the patent eliminates the ARP flooding issue that occurs when L2 and L3 gateways are separate devices. The integrated architecture allows ARP messages to be processed internally without being flooded across device boundaries, improving network efficiency while maintaining the distinct functional separation of L2 and L3 operations within the same device.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If L3 gateway separates tenants into different VRFs, then tenant isolation is improved, but communication between different VRFs requires additional VASI interfaces limiting connectivity

Engineering Contradiction:
Improvetenant isolationVSAvoidinter-VRF communication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The integrated gateway uses an internal intermediary mechanism to enable communication between different VRFs without requiring external VASI interfaces. The single device architecture provides internal routing and forwarding capabilities that allow controlled inter-VRF communication while maintaining tenant isolation, overcoming the limitation of pair-wise VASI interface requirements in separate device architectures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12452171B2Enhanced service node network infrastructure for L2/L3 GW in cloud
Publication Date: 2025.10.21 CISCO TECHNOLOGY INC
  • US12452171B2 patent drawing
  • US12452171B2 patent drawing
  • US12452171B2 patent drawing

AI summary

Disclosed herein are systems, methods, and computer-readable media for managing Layer 2 (L2) and Layer 3 (L3) policies. Traffic is routed from a first VM to a first CGW within a Service Node, where the Service Node can include a centralized policy for both L2 functions and L3 functions, and the first CGW can integrate both L2 gateways and L3 gateways. Based on a floating IP address of the packet, the traffic is routed within the Service Node, the traffic being routed by an access BD from an ingress BD-VIF to an egress BD-VIF. The traffic is then routed from a second CGW that integrates both L2 gateways and L3 gateways to the destination VM.