Overlay Fabric Router Extranet Connectivity via Border Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network overlay fabrics face challenges in efficiently facilitating external network connectivity, particularly in accessing extranet shared services, due to the complexity and inefficiency of existing routing protocols and the need for secure and reliable access mechanisms.
Innovation Solution
Implement publish-subscribe-based methods and apparatus within network overlay fabrics to provide auto-configurable external network connectivity, secure group-based access, and reliable failsafe access using tunneling protocols like LISP, along with a probing mechanism, which eliminates the need for complex routing protocols and ensures secure and reliable communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complex routing protocols are used to facilitate external network connectivity, then network connectivity is achieved, but device complexity and configuration difficulty increase
Solution Approach 1:
The patent introduces a border router as an intermediary device between the overlay fabric routers and external networks. The border router runs complex routing protocols (BGP, OSPF) and handles external network connectivity, while overlay fabric routers use simplified protocols (LISP, VXLAN). This mediator approach allows external connectivity to be achieved without exposing the complexity of routing protocols to the overlay fabric routers, resolving the contradiction between reliability of external connectivity and device complexity.
2Reliability
If manual configuration methods are used for external network access, then connectivity can be established, but ease of operation and configuration time deteriorate
Solution Approach 1:
The patent implements automated configuration mechanisms where overlay fabric routers automatically discover external network resources and configure their routing tables using LISP mapping systems and VXLAN gateway discovery protocols. The system performs self-service functions including automatic route advertisement, dynamic path selection, and failover configuration without manual intervention. This eliminates the need for manual configuration while maintaining reliable external network access, resolving the contradiction between reliability and ease of operation.
3Reliability
If traditional routing protocols are used for extranet access, then connectivity is provided, but productivity and network efficiency decrease
Solution Approach 1:
The patent implements dynamic path selection and load balancing mechanisms where overlay fabric routers can dynamically adjust routing paths based on current network conditions, server availability, and traffic patterns. The LISP mapping system and VXLAN gateways provide dynamic route updates without requiring full routing protocol convergence. This dynamic approach maintains reliable extranet access while significantly improving network efficiency and productivity compared to static traditional routing protocols.
4Reliability
If secure access mechanisms are implemented for extranet services, then security is improved, but device complexity increases
Solution Approach 1:
The patent segments security functions into distinct layers: overlay fabric routers handle LISP/VXLAN encapsulation and basic access control, border routers implement security policies and authentication, and external servers provide service-specific security. This segmentation allows secure extranet access to be achieved without requiring every overlay fabric router to implement complex security mechanisms, resolving the contradiction between secure access and device complexity.
Data Source
AI summary
In one example, a router is configured to process communications according to a tunneling protocol to provide network overlay tunnels to facilitate virtual private networks (VPNs) for hosts, and to process communications associated with an external network with use of a provider virtualization routing and forwarding (VRF) instance. With use of a subscription function, the router receives an initial set of extranet VPN prefixes associated with the network overlays for storage in association with the provider VRF, as well as regularly receive publications of updates to extranet VPN prefixes associated with the network overlays. With use of a route obtaining function, the router, in response to receiving a communication associated with one of the stored extranet VPN prefixes at the provider VRF, sends to a communications management server a message indicating request for a host-to-router mapping and receive from the communications management server a reply including the host-to-router mapping.


