IPSec Tunnel Mapping for VRF-Based SD-WAN Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies do not effectively segment traffic from routers that rely on IPSec Tunnels, preventing seamless connection to cloud-based networks and limiting the use of network segmentation technologies.

Innovation Solution

The integration of a Virtual Routing and Forwarding (VRF) Router with IPSec-WAN fabric, utilizing a Software Defined Cloud Interconnect (SDCI) Router to route traffic from IPSec-WAN fabric to cloud services, enabling network segmentation and multiplexing of VRF segments over IPSec tunnels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If devices utilize IPSec Tunnels, then connectivity is established, but network segmentation capability is lost

Engineering Contradiction:
ImproveconnectivityVSAvoidnetwork segmentation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies segmentation by introducing VRF (Virtual Routing and Forwarding) instances that divide the network into isolated virtual routing domains. Each VRF instance can independently route traffic, enabling network segmentation while maintaining IPSec tunnel connectivity. The mapping between IPSec tunnels and VRF instances allows traffic to be segmented into different virtual routing contexts without breaking the underlying IPSec connection.

Inventive Principle:
Principle #1Segmentation

2Reliability

If IPSec Tunnels are used, then basic connectivity is achieved, but integration with cloud-based networks is prevented

Engineering Contradiction:
ImproveconnectivityVSAvoidcloud-based network integration
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent uses VRF instances as intermediary components between IPSec tunnel endpoints and cloud-based networks. The VRF instances act as mediators that receive traffic from IPSec tunnels, perform routing decisions, and forward traffic to cloud destinations. This intermediary layer enables integration with cloud-based networks while preserving the simplicity of IPSec tunnel connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If traffic is not segmented, then routing is simple, but cloud service access is limited

Engineering Contradiction:
Improverouting complexityVSAvoidcloud service access
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements multi-functionality by enabling VRF instances to perform multiple functions: routing traffic from IPSec tunnels, segmenting traffic into different virtual routing domains, and forwarding traffic to various cloud-based services. This universal approach allows a single routing infrastructure to handle diverse traffic types and destinations without requiring separate routing mechanisms for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250392546A1Mapping of ipsec tunnels to sd-wan segmentation
Publication Date: 2025.12.25 CISCO TECHNOLOGY INC
  • US20250392546A1 patent drawing
  • US20250392546A1 patent drawing
  • US20250392546A1 patent drawing

AI summary

Generally, Software-Defined Wide Area Networks (SD-WAN) generally do not support network segmentation. The concepts disclosed herein connects IPSec SD-WAN fabric to a Virtual Routing and Forwarding (VRF) router and make use of a Software Defined Cloud Interconnect (SDCI) Router to route traffic from IPSec SD-WAN to various cloud services from the SDCI Router in the fabric. The concepts disclosed herein also provides for tunnel multi-plexing that takes incoming and outgoing traffic and maps VPNs to any service VRF associated with the cloud based services.