Network Access Control via MAC Portal Authentication in VxLAN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In Virtual Extensible Local Area Networks (VxLAN), the separation of control and data planes prevents the use of traditional portal authentication, making it challenging to manage network access for terminals, especially when IP addresses need to be changed from temporary to service addresses.
Innovation Solution
The implementation of MAC Portal authentication, which involves interactions between a RADIUS Server, a Network Attached Server (NAS), and a terminal, using temporary and service roles to manage network access, including a process where a terminal is initially authenticated with a temporary IP address and later switched to a service IP address using a minimum lease mechanism to facilitate seamless network access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional portal authentication is used in VxLAN, then network access control can be implemented, but it cannot work due to the separation of control and data planes
Solution Approach 1:
The patent introduces a MAC Portal authentication mechanism that uses the terminal's MAC address as an intermediary identifier instead of relying on IP addresses. This allows authentication to proceed through the control plane independently of data plane IP address allocation, making it compatible with VxLAN's separated architecture while maintaining authentication reliability
2Adaptability or versatility
If IP address follows the terminal in VxLAN, then mobility is supported, but traditional portal authentication cannot be used
Solution Approach 1:
The patent uses MAC address as a stable intermediary identifier that remains constant regardless of IP address changes. The MAC Portal authentication binds the terminal's identity to its MAC address rather than IP address, enabling reliable authentication even when IP addresses follow the terminal during mobility
Solution Approach 2:
The patent performs MAC Portal authentication before IP address allocation, establishing the terminal's identity and service role in advance. This preliminary authentication ensures that subsequent IP address changes do not affect the authenticated session, supporting terminal mobility while maintaining authentication reliability
3Ease of operation
If temporary IP address is allocated to terminal, then initial network access is enabled, but service quality deteriorates without service IP address
Solution Approach 1:
The patent performs MAC Portal authentication and service role determination before allocating the service IP address. This preliminary action ensures that terminals receive appropriate service quality parameters (such as bandwidth, priority, and access rights) based on their authenticated identity, rather than relying on generic temporary IP address allocations
Solution Approach 2:
The patent changes the network parameters allocated to terminals based on their service role determined through MAC Portal authentication. Terminals transition from temporary IP address parameters to service IP address parameters with appropriate quality of service settings, ensuring both initial access capability and sustained service quality
Data Source
AI summary
The present disclosure discloses methods of controlling network access, NASs and non-transitory machine-readable storage mediums. In an example of the present disclosure, when a terminal comes online for a first time, a NAS obtains a temporary role for a terminal; when receiving an IP address request from the terminal, the NAS requests an IP address for the terminal, wherein a lease for the temporary IP address is a set minimum lease; the NAS forces the terminal to go offline when the portal authentication is successful; when the terminal comes online for a second time, the NAS obtains a service role for the terminal; when receiving an IP address request sent by the terminal at expiry of the lease for the temporary IP address, the NAS requests a service IP address for the terminal, wherein the service IP address belongs to an IP network segment corresponding to the service role.


