Overlay Fabric Router Extranet Connectivity via Border Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network overlay fabrics face challenges in efficiently facilitating external network connectivity, particularly in accessing extranet shared services, due to the complexity and inefficiency of existing routing protocols and the need for secure and reliable access mechanisms.

Innovation Solution

Implement publish-subscribe-based methods and apparatus within network overlay fabrics to provide auto-configurable external network connectivity, secure group-based access, and reliable failsafe access using tunneling protocols like LISP, along with a probing mechanism, which eliminates the need for complex routing protocols and ensures secure and reliable communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complex routing protocols are used to facilitate external network connectivity, then network connectivity is achieved, but device complexity and configuration difficulty increase

Engineering Contradiction:
Improveexternal network connectivityVSAvoidrouting protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a border router as an intermediary device between the overlay fabric routers and external networks. The border router runs complex routing protocols (BGP, OSPF) and handles external network connectivity, while overlay fabric routers use simplified protocols (LISP, VXLAN). This mediator approach allows external connectivity to be achieved without exposing the complexity of routing protocols to the overlay fabric routers, resolving the contradiction between reliability of external connectivity and device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual configuration methods are used for external network access, then connectivity can be established, but ease of operation and configuration time deteriorate

Engineering Contradiction:
Improveexternal network accessVSAvoidconfiguration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements automated configuration mechanisms where overlay fabric routers automatically discover external network resources and configure their routing tables using LISP mapping systems and VXLAN gateway discovery protocols. The system performs self-service functions including automatic route advertisement, dynamic path selection, and failover configuration without manual intervention. This eliminates the need for manual configuration while maintaining reliable external network access, resolving the contradiction between reliability and ease of operation.

Inventive Principle:
Principle #25Self-service

3Reliability

If traditional routing protocols are used for extranet access, then connectivity is provided, but productivity and network efficiency decrease

Engineering Contradiction:
Improveextranet accessVSAvoidnetwork efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic path selection and load balancing mechanisms where overlay fabric routers can dynamically adjust routing paths based on current network conditions, server availability, and traffic patterns. The LISP mapping system and VXLAN gateways provide dynamic route updates without requiring full routing protocol convergence. This dynamic approach maintains reliable extranet access while significantly improving network efficiency and productivity compared to static traditional routing protocols.

Inventive Principle:
Principle #15Dynamics

4Reliability

If secure access mechanisms are implemented for extranet services, then security is improved, but device complexity increases

Engineering Contradiction:
Improvesecure accessVSAvoidaccess mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security functions into distinct layers: overlay fabric routers handle LISP/VXLAN encapsulation and basic access control, border routers implement security policies and authentication, and external servers provide service-specific security. This segmentation allows secure extranet access to be achieved without requiring every overlay fabric router to implement complex security mechanisms, resolving the contradiction between secure access and device complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10791004B2Methods and apparatus for use in network overlay fabrics to facilitate external network connectivity including access to extranet shared services
Publication Date: 2020.09.29 CISCO TECHNOLOGY INC
  • US10791004B2 patent drawing
  • US10791004B2 patent drawing
  • US10791004B2 patent drawing

AI summary

In one example, a router is configured to process communications according to a tunneling protocol to provide network overlay tunnels to facilitate virtual private networks (VPNs) for hosts, and to process communications associated with an external network with use of a provider virtualization routing and forwarding (VRF) instance. With use of a subscription function, the router receives an initial set of extranet VPN prefixes associated with the network overlays for storage in association with the provider VRF, as well as regularly receive publications of updates to extranet VPN prefixes associated with the network overlays. With use of a route obtaining function, the router, in response to receiving a communication associated with one of the stored extranet VPN prefixes at the provider VRF, sends to a communications management server a message indicating request for a host-to-router mapping and receive from the communications management server a reply including the host-to-router mapping.