NAT Route Tagging for SDWAN Symmetric Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large-scale Software-Defined Wide Area Network (SDWAN) deployments face challenges in maintaining unique Network Address Translation (NAT) addresses across multiple client sites, leading to route conflicts and failures in automatic NAT public address distribution.

Innovation Solution

The implementation of NAT route tagging, where each NAT route is tagged with a unique tag value indicative of a preferred router for return traffic, allows the SDWAN controller to apply control policies matching the tag values, ensuring symmetric routing even with overlapping NAT addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If automatic NAT public address distribution is implemented in large-scale SDWAN deployments, then NAT address uniqueness should be maintained, but route conflicts occur due to overlapping NAT addresses across multiple client sites

Engineering Contradiction:
ImproveNAT address uniquenessVSAvoidroute distribution complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a tag-based intermediary mechanism that mediates between overlapping NAT addresses and route distribution. Each NAT route is tagged with identification information indicating the client site, allowing the SDWAN controller to distinguish and distribute routes correctly despite address overlaps. This tag acts as a mediator that resolves the conflict between NAT address reuse and route uniqueness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If NAT routes are distributed without tagging, then distribution process is simple, but symmetric routing cannot be ensured with overlapping NAT addresses

Engineering Contradiction:
Improveroute distribution simplicityVSAvoidsymmetric routing consistency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the parameter space of NAT routes by adding tag values to the route distribution process. Instead of relying solely on NAT addresses for route identification, the system now uses composite parameters including the tag value that identifies the client site. This parameter enhancement allows symmetric routing to be maintained while preserving distribution simplicity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If unique NAT addresses are assigned to each client site, then route conflicts are prevented, but scalability is limited in large-scale deployments

Engineering Contradiction:
Improveroute conflict preventionVSAvoiddeployment scalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the NAT address space by introducing client site-specific tag values. Instead of requiring globally unique NAT addresses across all client sites, the system segments route identification into two parts: the NAT address and the client site tag. This segmentation allows NAT addresses to be reused across different client sites while maintaining route uniqueness through the combined identifier, thereby enabling large-scale deployment scalability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250126091A1NAT route distribution based on tag information in an sdwan overlay network
Publication Date: 2025.04.17 CISCO TECHNOLOGY INC
  • US20250126091A1 patent drawing
  • US20250126091A1 patent drawing
  • US20250126091A1 patent drawing

AI summary

A process can include determining a plurality of Network Address Translation (NAT) routes associated with respective edge routers included in a same virtual private network (VPN) for communicating with a software-defined wide area network (SDWAN). A process can include identifying a first subset of the plurality of NAT routes as mapped to a first public NAT address included in a NAT pool associated with the VPN. A process can include tagging each NAT route of the first subset with a tag value indicative of a preferred router for receiving return traffic of the respective NAT route. A process can include routing traffic on a respective NAT route of the plurality of NAT routes based on applying, at an SDWAN controller, a corresponding control policy matching the tag value of the respective NAT route.