IP Map and Encap Overlay for MPLS VPN Interconnection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional MPLS VPN services face limitations in providing global connectivity due to inconsistencies in services like address family, QoS, multicast, and SLA when interconnecting with partner SPs, leading to operational complexity and security issues, as they require physical infrastructure extension and complex business agreements.
Innovation Solution
An IP Map and Encap system operates as an overlay within existing MPLS VPN infrastructure, mapping and encapsulating traffic to provide virtual end-to-end global connectivity without physically extending the primary SP's infrastructure, using LISP and integrating with partner SP networks to reduce operational complexity and enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If MPLS VPN services are extended globally through physical infrastructure, then connectivity coverage is improved, but device complexity and operational complexity increase significantly
Solution Approach 1:
The patent introduces a gateway device as an intermediary between the primary SP MPLS VPN and partner SP networks. This gateway performs encapsulation and decapsulation of packets, enabling the primary SP to extend its VPN services over partner networks without direct physical infrastructure. The gateway acts as a mediator that translates between different VPN domains, achieving global connectivity while avoiding the complexity of direct physical extension.
Solution Approach 2:
The patent transitions from physical infrastructure extension to virtual overlay extension by introducing encapsulation layers. Instead of physically extending MPLS infrastructure across partner networks, the solution creates a virtual tunnel through encapsulation (outer IP header with source/destination gateway addresses, inner original packet). This dimensional shift from physical to virtual space enables global connectivity without proportional increase in physical complexity.
2Adaptability or versatility
If MPLS VPN services interconnect with partner SPs through physical infrastructure, then service reachability is improved, but service consistency deteriorates due to inconsistencies in address family, QoS, multicast, and SLA
Solution Approach 1:
The gateway device serves as a mediator that enforces service consistency policies. It performs service awareness functions including address family translation, QoS parameter mapping, multicast translation, and SLA enforcement. By positioning the gateway as an intermediary between the primary SP MPLS VPN and partner networks, the patent ensures that services maintain consistency standards set by the primary SP while still achieving extended reachability through partner infrastructures.
3Adaptability or versatility
If physical infrastructure is extended to provide global VPN services, then connectivity coverage is improved, but operational complexity and security issues increase
Solution Approach 1:
The gateway device centralizes operational management by serving as a single point of control for extending VPN services over partner networks. Instead of managing multiple physical infrastructure extensions across different partner networks, operations are simplified to configuring and managing gateway devices that handle encapsulation, service policy enforcement, and partner network interconnection. This intermediary approach consolidates operational complexity into manageable functions at the gateway level.
4Adaptability or versatility
If MPLS VPN services are interconnected with partner SPs, then global connectivity is improved, but security risks increase due to direct infrastructure interconnection
Solution Approach 1:
The gateway device acts as a security intermediary between the primary SP MPLS VPN and partner networks. It performs security functions including authentication of packets entering and leaving the primary SP network, enforcement of security policies, and isolation of the primary SP core network from direct exposure to partner networks. The encapsulation mechanism itself provides security by creating a protected tunnel where only authenticated packets can traverse, reducing security risks while maintaining global connectivity.
Data Source
AI summary
In one embodiment, a method includes receiving at a first network device in a first virtual private network, a packet destined for a second network device in communication with a second virtual private network, and transmitting the packet over the second network, wherein the packet is encapsulated for transmittal on a tunnel extending from the first network device to the second network device. The first network device is in communication with a system operable to map and encapsulate the packet and provide an overlay that traverses over the second virtual private network. An apparatus and logic are also disclosed herein.


