NAT Group-to-Subnet Mapping for Legacy Network Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy and third-party network devices in enterprise fabric networks struggle to apply group-based policies due to their reliance on IP addresses, leading to inefficiencies in policy application, particularly in environments where group tags are not understood or utilized.

Innovation Solution

Implement network address translation (NAT) based on group tags to convert group tags into subnets, allowing legacy and third-party devices to apply subnet-based policies effectively by assigning dynamic IP addresses to endpoint groups, thereby maintaining policy effectiveness across different network environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If group-based policies are implemented in enterprise fabric networks, then policy application efficiency is improved for modern network devices, but legacy and third-party network devices cannot effectively apply these policies due to their reliance on IP addresses

Engineering Contradiction:
Improvepolicy application efficiencyVSAvoidcompatibility with legacy devices
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary mechanism (NAT gateway or network device) that translates between group tag-based policies and IP address-based policies. This intermediary performs address translation to map endpoint groups to specific IP addresses, allowing legacy devices to apply policies based on translated IP addresses while the core network maintains group tag-based policy enforcement. The intermediary acts as a bridge between the two policy paradigms without requiring changes to legacy devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If group tags are used for policy application, then network scalability and security management are improved, but additional configuration complexity and translation mechanisms are required for legacy device compatibility

Engineering Contradiction:
Improvenetwork scalabilityVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements self-service automation where the NAT gateway automatically performs address translation, mapping, and policy application without requiring manual configuration for each legacy device. The system autonomously discovers endpoint groups, assigns IP addresses from appropriate pools, and enforces policies based on translated addresses. This automation reduces configuration complexity while maintaining scalability benefits of group tags.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12603841B2Grouping endpoints of a network for NAT to organize IP address space for policy applications
Publication Date: 2026.04.14 CISCO TECHNOLOGY INC
  • US12603841B2 patent drawing
  • US12603841B2 patent drawing
  • US12603841B2 patent drawing

AI summary

Techniques and architecture are described that utilize network address translation (NAT) based on a group tag such that legacy and third-party devices may utilize and apply “subnet” based policies, thereby allowing the subnet based policies to be as effective as “group” based policies. In particular, a subnet may be applied to a group tag where the group tag is not understandable outside an access network such as, for example, a fabric network. Thus, when a packet originates from a fabric network utilizing group tags representing source groups of endpoints and is destined for a legacy or a third-party device-based network that does not utilize and/or understand group tags, then the group is converted into a subnet. Since that subnet is different from the source host within the fabric network, network address translation (NAT) is utilized.