Network Edge Policy Enforcement via Control Plane SGT Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network technologies face challenges in making group-based classification and policy enforcement decisions at the network edge for external destinations, as these destinations cannot be preconfigured with security group tags, leading to difficulties in determining whether a destination is internal or external.
Innovation Solution
The implementation of an enhanced Locator/Identifier Separation Protocol (LISP) method of border registration, which involves provisioning a border node with an egress tunnel router type and assigning a security group tag to external traffic, allows for the registration of security group tags at the control plane and storage in a border/service registration table.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If external network destinations are treated as unknown destination group tags, then default categorization is simple, but uniform policy application and security enforcement cannot be achieved
Solution Approach 1:
The control plane performs preliminary actions by pre-provisioning border nodes with egress tunnel router types and assigning security group tags to external traffic before traffic arrives at the fabric edge. This allows the edge nodes to have ready-to-apply policy information when external destinations are encountered, eliminating the need for complex real-time determination.
Solution Approach 2:
The control plane acts as an intermediary between the fabric edge and external destinations. It receives requests from edge nodes, determines destination types, assigns appropriate security group tags, and provides mapping data back to edge nodes. This intermediary function enables uniform policy application without requiring edge nodes to make complex decisions about external destinations.
2Adaptability or versatility
If security group tags are assigned to external traffic at the control plane, then uniform policy application is enabled, but additional control plane processing complexity is introduced
Solution Approach 1:
The system segments the policy enforcement function by separating control plane processing (destination type determination and SGT assignment) from data plane processing (traffic forwarding and policy application). This segmentation allows the control plane to handle complexity centrally while edge nodes focus on simple policy application based on received mapping data.
Solution Approach 2:
The control plane creates and distributes copies of security group tag mappings to edge nodes. Instead of requiring each edge node to independently determine and apply policies, the control plane generates the mapping data (effectively copying policy information) and distributes it to relevant edge nodes, simplifying their operation while maintaining uniform policy application.
3Adaptability or versatility
If border nodes are provisioned with egress tunnel router types, then external traffic routing is enabled, but hardware configuration complexity increases
Solution Approach 1:
The system changes the operational parameters of border nodes by provisioning them with egress tunnel router types. This parameter change enables border nodes to handle external traffic routing differently from standard nodes, allowing the network to distinguish and route external traffic appropriately while maintaining a unified hardware platform.
Data Source
AI summary
Techniques for group-based classification and policy enforcement at a network fabric edge for traffic that is being sent to external network destinations are disclosed herein. The techniques may include receiving, at a control plane of a network and from an edge node of the network, a request to provide mapping data associated with sending a packet to a destination. Based at least in part on an address prefix value associated with the destination, the control plane may determine that the destination is located in an external network. Additionally, a group identifier that is associated with the destination may be determined. In this way, an indication of the group identifier may be sent to the edge node such that the edge node may determine, based at least in part on the group identifier, a policy decision for routing the packet to the external network.


