L3 VPN Network Controller Proxy for Multi-Tenant WAN Extension

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network management systems face challenges in scalability, mobility, and multi-tenancy, particularly in virtualized data centers where unique IP addresses are required, limiting the use of private addressing schemes and complicating packet forwarding across wide area networks.

Innovation Solution

The implementation of Layer 3 Virtual Private Networks (L3 VPNs) using Provider Edge and Customer Edge routers, along with Virtual Routing and Forwarding tables, allows for the extension of virtualized data center networks across wide area networks using private addressing, enabling non-unique IP addresses and correct packet forwarding through customer-specific identifiers and virtual interfaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If unique public IP addresses are required for tunnel termination in virtualized data centers, then packet forwarding across WAN is enabled, but network scalability and multi-tenancy are hampered due to address space exhaustion and complexity

Engineering Contradiction:
Improvepacket forwardingVSAvoidnetwork configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces L3 VPN technology as an intermediary layer between the virtualized data center network and the WAN infrastructure. This intermediary enables packet forwarding across WAN using private IP addresses by translating and routing packets through VPN-aware network elements, thus eliminating the requirement for unique public IP addresses at tunnel termination points while maintaining reliable cross-WAN connectivity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transitions from traditional L2 networking to L3 VPN networking, adding a new dimensional layer of abstraction. By operating at Layer 3 with VPN routing and forwarding (VRF) tables, the system creates a separate routing dimension that allows multiple tenants to use overlapping private IP address spaces simultaneously, resolving the address conflict problem while enabling scalable multi-tenant deployments

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If L2 domains are used to provide network mobility for virtual machines, then mobility is enabled, but the domain cannot scale to large sizes

Engineering Contradiction:
Improvenetwork mobilityVSAvoiddomain size
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent segments the large L2 domain into multiple smaller L3 VPN domains, each capable of independent scaling. By dividing the network into discrete L3 VPN instances with their own routing tables and address spaces, the system enables mobility within each segment while allowing the overall network to scale to large sizes through the aggregation of multiple segmented domains

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from L2 to L3 networking, adding a routing dimension that enables scalability. At Layer 3, routing protocols and VRF tables provide a new dimensional framework for managing large networks, allowing virtual machine mobility to extend across L3 boundaries through VPN routing rather than being constrained by L2 domain size limitations

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If tenant isolation is retained in virtualized networks, then security is maintained, but mobility across sites becomes complicated

Engineering Contradiction:
Improvetenant isolationVSAvoidmobility management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements universal L3 VPN routing functionality that simultaneously provides tenant isolation and mobility support. The VRF-based architecture creates universal routing templates that can be applied across multiple sites and tenants, where the same routing and forwarding mechanisms maintain isolation boundaries while enabling standardized mobility procedures across the entire multi-site network infrastructure

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3367616B1Configuring the extension of logical networks across layer 3 virtual private networks
Publication Date: 2020.05.20 NICIRA INC
  • EP3367616B1 patent drawingFigure 1
  • EP3367616B1 patent drawingFigure 2
  • EP3367616B1 patent drawingFigure 3

AI summary

The application describes network controllers that configure service nodes and remote extenders to effectuate the extension of logical networks in a multi-tenant site 1205 into tenants' private sites 1210 that are remote to the multi-tenant site 1205. A network controller 1225 in the multi-tenant site 1205 configures both a pool node 1215 and an extender 1220 by generating configuration data and sending the configuration data to the pool node 1215 and to the extender 1220. The network controller 1225 sends the configuration data to configure the extender 1220 in the tenant's site 1210 via the pool node 1215 so that the network controller does not have to expose the network address (e.g., an IP address) of the network controller 1225 to the extender in the remote site. Arrow-headed lines 1201 and 1202 conceptually indicate the paths of the configuration commands/data traversing from the network controller 1225 to inside of the extender 1220 and inside of the pool node 1215, respectively. Proxy daemon 1265 is an application that runs in the pool node 1215. The proxy daemon 1265 functions as a proxy network controller cluster for the extenders in the remote sites. That is, the proxy daemon 1265 receives commands from the network controller 1225 regarding operations for processing and forwarding packets that the extenders receive. The proxy daemon relays the commands to the extenders through the NICs 1245 using pool node network stack 1230. Since the proxy daemon operates like a network controller for the extenders at the remote sites, the network controller 1225, which actually generates the commands, does not have to directly interface with the extenders, thereby hiding the IP address of the controller from the extenders.