Overlay Header Policy Enforcement in SD-WAN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large and complex software-defined wide-area networks (SD-WAN), ensuring consistent policy application across multiple paths is challenging due to dynamic path changes and scalability issues with existing solutions.
Innovation Solution
Devices in the overlay network determine an application identifier for both forward and reverse traffic flows, adding an overlay header with a policy identifier and action to packets, ensuring policies are applied consistently across the SD-WAN by forcing flows through specific devices and using default policies for unidentified applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a central controller distributes flow information to SD-WAN gateways on all possible paths, then policy consistency can be maintained, but scalability deteriorates
Solution Approach 1:
The patent extracts the policy enforcement logic from the central controller and embeds it directly in the overlay header at the source device. This eliminates the need for the central controller to distribute flow information to all gateways, resolving the scalability issue while maintaining policy consistency through the portable overlay header.
Solution Approach 2:
The overlay header acts as an intermediary carrier that transports policy information from the source device through multiple hops to the destination. This mediator approach allows policy enforcement without requiring central controller involvement at each hop, improving both scalability and consistency.
2Reliability
If multiple appliances at a single site synchronize flow state, then policy application can be coordinated, but system complexity increases
Solution Approach 1:
The patent removes the need for state synchronization between appliances by extracting policy information into the overlay header. Each appliance independently reads the policy from the header without needing to synchronize state with other appliances, eliminating the complexity of state sharing techniques.
Solution Approach 2:
Each SD-WAN device independently enforces policy by reading the overlay header attached to packets, without requiring coordination or state synchronization with other devices. This self-service approach simplifies the system while maintaining policy consistency across multiple appliances.
3Adaptability or versatility
If traffic routing paths change dynamically, then network adaptability improves, but policy enforcement consistency deteriorates
Solution Approach 1:
The patent performs preliminary action by attaching the overlay header with policy information at the source device before traffic enters the dynamic routing environment. This pre-attached header travels with the traffic regardless of path changes, ensuring policy consistency is maintained even as routing dynamically adapts to network conditions.
Solution Approach 2:
The patent moves policy enforcement from the routing path dimension to the packet header dimension. By embedding policy in the overlay header rather than relying on path-based enforcement, the system achieves both dynamic routing adaptability and policy consistency across changing paths.
Data Source
AI summary
Systems and techniques are described for ensuring that policies are consistently applied to traffic across an overlay network. An application identifier associated with a forward traffic flow and a corresponding reverse traffic flow can be determined by a device that routes packets of both the forward traffic flow and the corresponding reverse traffic flow. Next, an overlay header can be added to each packet in the forward traffic flow and to each packet in the corresponding reverse traffic flow, wherein the overlay header comprises the application identifier, a policy identifier, and a policy action. Each device in the overlay network can then apply the policy action specified in the overlay header of each packet that it routes.


