Layer 2 VPNs on IP Networks via MP-BGP Encapsulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Layer 2 Virtual Private Networks (VPNs) require expensive MPLS infrastructure for implementation and maintenance, limiting their deployment in enterprise networks where simpler solutions are desired.

Innovation Solution

Configuring MP-BGP VPN infrastructure based on IETF RFC 4364/2547 to establish Layer 2 VPNs on IP networks using service IP addresses and VPN-VLAN IDs, allowing for IP encapsulation to carry VPN traffic without relying on MPLS infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MPLS infrastructure is used to implement Layer 2 VPNs, then VPN functionality and reliability are improved, but implementation cost and device complexity increase significantly

Engineering Contradiction:
ImproveVPN functionalityVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses IP encapsulation to copy the VPN functionality normally provided by MPLS. Instead of requiring actual MPLS infrastructure, the invention creates a virtual copy of MPLS VPN behavior using standard IP routing and encapsulation protocols, thereby achieving VPN functionality without the complexity and cost of real MPLS networks

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical MPLS infrastructure (specialized hardware and protocols) with a software-based IP encapsulation solution. By substituting the physical/mechanical MPLS system with an intellectual/software-based IP tunneling approach, the invention eliminates the need for expensive MPLS equipment while maintaining VPN functionality

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If MPLS infrastructure is deployed for Layer 2 VPNs, then VPN service quality is improved, but maintenance complexity and operational difficulty worsen

Engineering Contradiction:
ImproveVPN service qualityVSAvoidmaintenance complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables the network to self-configure VPN tunnels using standard IP routing protocols and automated encapsulation. The system automatically establishes and maintains VPN connections without requiring specialized MPLS maintenance procedures, thereby improving ease of operation while preserving service quality

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The invention makes standard IP routers universal by enabling them to perform both normal IP routing and VPN encapsulation functions. This multi-functionality eliminates the need for specialized MPLS equipment and simplifies maintenance, as the same infrastructure handles both regular traffic and VPN traffic

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If specialized MPLS infrastructure is used for VPNs, then VPN performance is improved, but network adaptability and ease of deployment worsen

Engineering Contradiction:
ImproveVPN performanceVSAvoidnetwork adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes standard IP networks universal by enabling them to provide VPN services through IP encapsulation. This allows any IP network, regardless of whether it has MPLS infrastructure, to deploy Layer 2 VPNs, thereby dramatically improving network adaptability while maintaining VPN performance through proper encapsulation and routing

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8098656B2Method and apparatus for implementing L2 VPNs on an IP network
Publication Date: 2012.01.17 PULSELINK SYSTEMS LLC
  • US8098656B2 patent drawing
  • US8098656B2 patent drawing
  • US8098656B2 patent drawing

AI summary

MP-BGP VPN infrastructure based on IETF RFC 4364/2547 is used to configure a layer 2 VPN on an IP network. VRFs for the VPN are configured on Ethernet switches and service IP addresses are associated with each configured VRF. The service IP addresses are exchanged to enable VPN traffic to be encapsulated for transport over the IP network. To enable a L2 VPN to be established on the network, a VPN-VLAN ID will be configured for the L2 VPN and import/export route targets for the VPN-VLAN will be set in each VRF and UNI-VLAN that is part of the VPN. The VPN-VLAN will be announced to all PEs using MP-iBGP with export route targets set for this VPN-VLAN. The PE's control plane learns the VPN-VLAN on a logical port if the import RT matches the export RT received by the MP-iBGP control plane. Once the VPN-VLAN is learned on a logical port, the PE will perform MAC learning on that logical port and treat the logical port as if it were part of the L2 VLAN.