Network Orchestrator VLAN Extension Loop Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In complex wide area networks (WANs), extending virtual local area networks (VLANs) across multiple physical LANs can lead to inefficiencies due to single points of failure, misconfiguration risks, and performance degradation from tunnel loops, especially when using software-defined wide area network (SD-WAN) technology.
Innovation Solution
A method is introduced where a network orchestrator determines VLAN sharing across LANs, establishing WAN uplink tunnels with standby tunnels for failover and intracluster tunnel meshes, while automatically or manually configuring these to prevent tunnel loops through loop detection and remediation processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If VLANs are extended across multiple physical LANs using SD-WAN technology, then network connectivity and resource sharing are improved, but the risk of tunnel loops and performance degradation increases
Solution Approach 1:
The patent implements a feedback mechanism where the network orchestrator continuously monitors the SD-WAN network for tunnel loops by analyzing tunnel topology and routing information. When potential loops are detected, the system provides feedback to adjust tunnel configurations or routing paths, preventing performance degradation while maintaining VLAN extension capabilities across multiple physical LANs.
Solution Approach 2:
The network orchestrator acts as an intermediary between the SD-WAN controllers and the extended VLAN infrastructure. It mediates tunnel establishment and configuration, ensuring that tunnels are properly configured to avoid loops while enabling VLAN extension across the wide area network. The orchestrator coordinates tunnel lifecycle management to maintain network reliability.
2Adaptability or versatility
If manual configuration of WAN uplink tunnels is used, then flexibility in tunnel setup is improved, but administrative overhead and misconfiguration risks increase
Solution Approach 1:
The network orchestrator implements self-service automation for tunnel configuration by automatically discovering network topology, generating appropriate tunnel configurations, and provisioning WAN uplink tunnels without requiring manual administrator intervention. The system autonomously manages tunnel lifecycle events including creation, modification, and teardown based on network conditions and policies.
Solution Approach 2:
The network orchestrator provides universal tunnel management capabilities that work across diverse SD-WAN implementations and network topologies. It offers multi-functional support for different tunnel types, encryption protocols, and failure scenarios, reducing the need for specialized manual configuration while maintaining flexibility through policy-based management.
3Reliability
If standby tunnels are implemented for failover, then high availability is improved, but device complexity and resource consumption increase
Solution Approach 1:
The system implements dynamic tunnel management where standby tunnels are automatically activated or deactivated based on real-time network conditions and failure detection. The network orchestrator continuously monitors tunnel health and dynamically adjusts the active/standby tunnel configuration, providing failover capability while maintaining manageable complexity through automated state transitions.
Solution Approach 2:
The network orchestrator pre-configures standby tunnels as a cushion against potential failures before they occur. These standby tunnels are prepared in advance with proper routing and security configurations, enabling immediate failover when primary tunnels fail. This beforehand cushioning approach ensures high availability while the orchestrator manages the complexity of maintaining multiple tunnel states.
Data Source
AI summary
An example network orchestrator includes processing circuitry and a memory including instructions that, when executed by the processing circuitry, cause the network orchestrator to determine that a branch site of a WAN includes multiple branch gateways. The network orchestrator further determines that devices of a core site of the WAN and devices of the branch site are members of an extended VLAN. The network orchestrator further transmits a first command to a first branch gateway and a first headend gateway to establish a WAN uplink tunnel to forward data traffic of the extended VLAN. The network orchestrator further transmits a second command to a set of branch gateways of the branch gateway cluster to establish intracluster tunnels with the first branch gateway.


