Label-Based Policy Enforcement in MPLS WAN Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network segmentation methods, such as ACL rules and centralized solutions, are inefficient and unmanageable for enforcing policies across multiple branches and campuses in a Wide Area Network, leading to throughput issues and scalability challenges.
Innovation Solution
A distributed MPLS-based segmentation model that uses VXLAN and MPLS labels to enforce network policies across branches, allowing for the translation of labels between different network entities, enabling macro and micro-segmentation without disrupting existing configurations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If ACL rules and centralized solutions are used for network segmentation, then policy enforcement is achieved, but throughput decreases and scalability becomes difficult
Solution Approach 1:
The patent applies segmentation by dividing network policies into macro-segmentation (between branches/campuses using MPLS labels) and micro-segmentation (within branches using VXLAN labels). This hierarchical segmentation allows policy enforcement at appropriate levels without centralizing all traffic, thereby maintaining throughput while achieving reliable policy enforcement.
Solution Approach 2:
The patent introduces MPLS labels as intermediaries for macro-segmentation between branches and VXLAN labels for micro-segmentation within branches. These label-based intermediaries enable distributed policy enforcement without requiring centralized ACL rule processing, thus maintaining throughput while ensuring reliable policy compliance.
2Reliability
If ACL rules and centralized solutions are used for network segmentation, then policy enforcement is achieved, but device complexity and manageability increase
Solution Approach 1:
The patent segments policy enforcement into distributed MPLS label-based macro-segmentation and VXLAN label-based micro-segmentation. This segmentation simplifies manageability by allowing each network entity to enforce policies locally based on label matching, rather than requiring complex centralized ACL rule management across all devices.
Solution Approach 2:
The patent changes the enforcement parameter from complex ACL rules to simple label matching (MPLS and VXLAN labels). This parameter change simplifies device complexity and manageability while maintaining reliable policy enforcement, as label matching is inherently simpler and more scalable than traditional ACL processing.
3Reliability
If existing network configurations are modified for segmentation, then policy enforcement improves, but network disruption occurs
Solution Approach 1:
The patent nests VXLAN label-based micro-segmentation within MPLS label-based macro-segmentation. This nested structure allows policy enforcement to be added layer by layer without disrupting existing network configurations, as each layer operates independently at its appropriate level (branch-level MPLS, device-level VXLAN).
Solution Approach 2:
The patent enables policy enforcement to be implemented preliminarily through label assignment and translation mechanisms before full deployment. The label translation functionality allows gradual integration without disrupting existing configurations, as labels can be introduced and translated incrementally across the network.
Data Source
AI summary
Examples disclosed herein relate to a method comprising receiving a data packet originating from a first device and intended for a second device, wherein the first device and the first access device belong to a first branch of a Wide Area Network (WAN) using a MPLS overlay and the second device belongs to a second branch of the WAN. The method includes encapsulating the data packet in VXLAN including a VXLAN label identifying a role type and transmitting the data packet to a first core device. The method includes determining an MPLS label corresponding to the role type and transmitting the data packet over the MPLS overlay to a second core device belonging to the second branch of the WAN. The method includes translating the MPLS label into the VXLAN label and transmitting the data packet including the VXLAN label to a second access device for an enforcement action.


