Intent-Based Policy Management for Enterprise SD-WAN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Policy configuration and management in enterprise SD-WAN environments are intricate and time-consuming due to the proliferation of applications, user types, and devices, requiring manual configuration per device and lacking an automated process to discover and organize device configurations for building intents across multiple sites.
Innovation Solution
A web-based portal that discovers device configurations, normalizes data, and assists users in creating policy intents, enabling automated intent building and management through an Intent-Based Policy Management system, providing a unified view across vendor implementations and simplifying the migration between vendors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Manufacturing precision
If manual configuration per device is used, then device-specific policy settings can be accurately configured, but the process becomes time-consuming and complex across multiple sites
Solution Approach 1:
The system creates a virtual copy of the physical network topology by discovering and modeling all network elements (routers, switches, firewalls) across multiple sites. This virtual copy allows policy configuration to be performed once and automatically applied to all physical devices, eliminating repetitive manual configuration while maintaining accuracy through the automated discovery process that maps physical to virtual elements.
Solution Approach 2:
The patent replaces manual mechanical configuration processes with automated software-based discovery and modeling. The system uses network protocols to automatically discover device configurations, extract topology information, and generate virtual network models, substituting the manual task of configuring each device individually with an automated software process that achieves both speed and accuracy.
2Adaptability or versatility
If separate firewall policies and WAN settings are used at each site, then local-specific requirements can be met, but the overall system complexity increases
Solution Approach 1:
The system segments the network into virtual elements (virtual routers, virtual firewalls, virtual WAN controllers) that correspond to physical network components. Each virtual element can be independently configured with site-specific policies while being managed through a unified virtual topology. This segmentation allows local adaptability at each site while reducing overall complexity by providing a standardized virtual layer above the physical infrastructure.
Solution Approach 2:
The virtual network elements serve multiple functions simultaneously. A single virtual router instance can provide routing, firewalling, and WAN control functions that were previously distributed across multiple physical devices. This multi-functionality reduces system complexity by consolidating roles while maintaining the ability to implement site-specific policies through virtual configuration.
3Reliability
If proprietary WAN technology with fixed circuits is used, then reliable connectivity can be ensured, but flexibility and cost efficiency decrease
Solution Approach 1:
The system implements dynamic network configuration where connectivity parameters (routing paths, firewall rules, WAN settings) can be automatically adjusted based on real-time network conditions and changing requirements. The virtual network layer enables dynamic resource allocation and policy application without requiring physical circuit reconfiguration, maintaining reliability through automated optimization while providing flexibility for adapting to changing business needs.
Solution Approach 2:
The patent enables changes in network parameters (IP addresses, routing metrics, security policies) to be modified through software configuration rather than physical reconfiguration. The virtual network model allows parameter changes to be propagated automatically across the entire network, maintaining connectivity reliability through consistent parameter application while enabling flexible adaptation to new requirements without costly fixed circuit changes.
Data Source
AI summary
Systems and methods described herein provide a network tool that discovers device configurations for selected enterprise sites and automatically organizes the data to assist users, so they can build intents for network function policies in enterprise networks. An intent builder performs device discovery of network function (NF) instances in a customer network; retrieves configuration elements from the NF instances; normalizes the configuration elements; and generates a graphical user interface with rule paths based on the configuration elements. The network device receives, via the graphical user interface, user input to map source Internet protocol (IP) addresses in the rule paths to a user label and to map destination IP address in the rule paths to an application label. Based on the user input, the network device presents, via the graphical user interface, consolidated intents and generates vendor-agnostic policy rules from the consolidated intents.


