Centralized Overlay Gateway for Cloud VPC Peering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Integrating overlay logical networks into cloud provider networks poses challenges, such as limited transitive routing and compatibility issues with cloud-provider assigned addresses, particularly in virtual private clouds (VPCs), which hinder seamless connectivity and service integration between VPCs.

Innovation Solution

A centralized overlay-network cloud gateway in a transit VCN provides connectivity and services across multiple compute VCNs, enabling transitive routing and seamless integration by using the same address space as the cloud provider network, with a managed forwarding element and arbiter module determining optimal routing methods based on destination VPCs and required services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple overlay-network cloud gateways are deployed in multiple non-transit VCNs, then connectivity between compute nodes is provided, but cost and management overhead increase

Engineering Contradiction:
ImproveconnectivityVSAvoidmanagement overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple distributed cloud gateways across non-transit VCNs are consolidated into a single centralized overlay-network cloud gateway located in a transit VCN. This merger maintains connectivity functionality while eliminating the need to manage multiple gateway instances, directly resolving the contradiction between providing reliable connectivity and reducing management overhead

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If transitive routing is enabled through the cloud provider network, then routing flexibility between VPCs is improved, but integration with cloud-provider assigned addresses becomes complex

Engineering Contradiction:
Improverouting flexibilityVSAvoidintegration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The centralized overlay-network cloud gateway in the transit VCN serves as an intermediary routing point between source and destination VPCs. This intermediary approach enables transitive routing flexibility while simplifying integration with cloud-provider assigned addresses by providing a single point of control and address translation, rather than requiring direct complex integration between all VPC pairs

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If cloud gateway services are distributed across multiple VCNs, then service availability is maintained, but cost increases

Engineering Contradiction:
Improveservice availabilityVSAvoidcost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

Multiple distributed cloud gateway services are merged into a single centralized gateway in the transit VCN. This consolidation reduces the total number of gateway instances required, thereby reducing cost while maintaining service availability through the centralized architecture that can serve multiple VCNs from a single location

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10491466B1Intelligent use of peering in public cloud
Publication Date: 2019.11.26 VMWARE INC
  • US10491466B1 patent drawing
  • US10491466B1 patent drawing
  • US10491466B1 patent drawing

AI summary

Some embodiments provide a method and system for configuring a plurality of managed forwarding elements (MFEs) in a plurality of cloud-provider virtual networks (CPVNs) to make routing decisions that efficiently use a peered transit CPVN and peering with other CPVNs in the plurality of CPVNs. In some embodiments, a controller set receives an identification of peering relationships between CPVNs in the plurality of CPVNs and generates configuration data for configuring each MFE. The configuration data is used to configure the MFE to forward data messages received at the MFE using a peering between a source CPVN and a destination CPVN when possible and to forward data messages received at the MFE to a transit gateway device in a transit CPVN when it is not possible to use a peering between the source and destination CPVNs.