L2 Proxy Router for Hybrid Cloud Subnet Extension

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of disparate cloud and datacenter environments is hindered by the lack of uniformity in policy models and configuration restrictions, limiting scalability and uniformity of policies and routing in hybrid cloud implementations.

Innovation Solution

The method involves creating a private address space in a cloud environment, configuring secondary IP addresses in a Layer 2 proxy router, and forwarding traffic to a cloud overlay router via a Layer 2 tunnel, allowing seamless extension of Layer 2 networks across platforms and updating IP addresses based on reachability states, thereby enabling consistent policy and routing models across on-premises and cloud sites.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If disparate cloud and datacenter environments are integrated using traditional methods, then connectivity between on-premises and cloud sites is achieved, but policy uniformity and routing consistency are compromised due to different policy models and configuration restrictions

Engineering Contradiction:
Improvepolicy uniformityVSAvoidintegration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a border router as an intermediary device that sits between the on-premises datacenter network and the cloud provider network. This border router runs a host overlay that translates and mediates between the different policy models of Cisco ACI and AWS, enabling policy uniformity without requiring changes to either the ACI fabric or the AWS infrastructure. The border router acts as a policy translation layer that reconciles the disparate configuration restrictions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the hybrid cloud architecture into distinct functional layers: the ACI fabric layer, the border router layer with host overlay, and the AWS cloud layer. This segmentation allows each layer to operate with its own native policy model while the border router layer provides the translation mechanism. By dividing the integration function into separate components rather than attempting direct peer-to-peer integration, the system achieves policy uniformity without excessive complexity.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If Layer 2 network extension is implemented across hybrid cloud environments, then seamless mobility and communication are enabled, but IP address reassignment and network reconfiguration are required

Engineering Contradiction:
Improveseamless mobilityVSAvoidreconfiguration time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent pre-establishes a border router in the AWS cloud environment with a host overlay configured before any workloads need to migrate. This border router is pre-configured with the ACI fabric's policy model and routing information. When workloads need to move between on-premises and cloud environments, the pre-positioned border router immediately provides the necessary Layer 2 extension and routing, eliminating reconfiguration delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The border router with host overlay serves as an intermediary that maintains Layer 2 connectivity across the Layer 3 boundary between on-premises and cloud networks. It translates ACI fabric policies into AWS-compatible configurations and maintains routing tables that enable seamless workload migration. This intermediary layer abstracts the complexity of IP address management and network reconfiguration from the migrating workloads.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If cloud providers use their native networking constructs for policy extension, then resource utilization is optimized, but fabric rules cannot be scaled across cloud sites due to provider restrictions

Engineering Contradiction:
Improveresource utilizationVSAvoidpolicy scalability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The border router with host overlay provides universal functionality that works across multiple cloud providers and on-premises environments. It implements a standardized ACI policy model that can translate to various cloud provider native constructs (AWS security groups, Azure network security groups, etc.). This universal approach allows fabric rules to be scaled across hybrid multi-cloud environments without being constrained by any single provider's restrictions, while still utilizing each provider's native networking capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11057350B2Layer 2 mobility for hybrid multi-cloud deployments without host-overlay
Publication Date: 2021.07.06 CISCO TECHNOLOGY INC
  • US11057350B2 patent drawing
  • US11057350B2 patent drawing
  • US11057350B2 patent drawing

AI summary

Technologies for extending a subnet across on-premises and cloud-based deployments are provided. An example method may include creating a VPC in a cloud for hosting an endpoint being moved from an on-premises site. For the endpoint to retain its IP address, a subnet range assigned to the VPC, based on the smallest subnet mask allowed by the cloud, is selected to include the IP address of the endpoint. The IP addresses from the assigned subnet range corresponding to on-premises endpoints are configured as secondary IP addresses on a Layer 2 (L2) proxy router instantiated in the VPC. The L2 proxy router establishes a tunnel to a cloud overlay router and directs traffic destined to on-premises endpoints, with IP addresses in the VPC subnet range thereto for outbound transmission. The cloud overly router updates the secondary IP addresses on the L2 proxy router based on reachability information for the on-premises site.