IPSec Tunnel Mapping for VRF-Based SD-WAN Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies do not effectively segment traffic from routers that rely on IPSec Tunnels, preventing seamless connection to cloud-based networks and limiting the use of network segmentation technologies.
Innovation Solution
The integration of a Virtual Routing and Forwarding (VRF) Router with IPSec-WAN fabric, utilizing a Software Defined Cloud Interconnect (SDCI) Router to route traffic from IPSec-WAN fabric to cloud services, enabling network segmentation and multiplexing of VRF segments over IPSec tunnels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If devices utilize IPSec Tunnels, then connectivity is established, but network segmentation capability is lost
Solution Approach 1:
The patent applies segmentation by introducing VRF (Virtual Routing and Forwarding) instances that divide the network into isolated virtual routing domains. Each VRF instance can independently route traffic, enabling network segmentation while maintaining IPSec tunnel connectivity. The mapping between IPSec tunnels and VRF instances allows traffic to be segmented into different virtual routing contexts without breaking the underlying IPSec connection.
2Reliability
If IPSec Tunnels are used, then basic connectivity is achieved, but integration with cloud-based networks is prevented
Solution Approach 1:
The patent uses VRF instances as intermediary components between IPSec tunnel endpoints and cloud-based networks. The VRF instances act as mediators that receive traffic from IPSec tunnels, perform routing decisions, and forward traffic to cloud destinations. This intermediary layer enables integration with cloud-based networks while preserving the simplicity of IPSec tunnel connectivity.
3Device complexity
If traffic is not segmented, then routing is simple, but cloud service access is limited
Solution Approach 1:
The patent implements multi-functionality by enabling VRF instances to perform multiple functions: routing traffic from IPSec tunnels, segmenting traffic into different virtual routing domains, and forwarding traffic to various cloud-based services. This universal approach allows a single routing infrastructure to handle diverse traffic types and destinations without requiring separate routing mechanisms for each function.
Data Source
AI summary
Generally, Software-Defined Wide Area Networks (SD-WAN) generally do not support network segmentation. The concepts disclosed herein connects IPSec SD-WAN fabric to a Virtual Routing and Forwarding (VRF) router and make use of a Software Defined Cloud Interconnect (SDCI) Router to route traffic from IPSec SD-WAN to various cloud services from the SDCI Router in the fabric. The concepts disclosed herein also provides for tunnel multi-plexing that takes incoming and outgoing traffic and maps VPNs to any service VRF associated with the cloud based services.


