Overlay Network Traffic Routing via Security Policy Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data center infrastructure lacks visibility into virtual overlay network traffic, preventing intermediate network devices from routing packets to physical security appliances and thus hindering the implementation of sophisticated network security services.
Innovation Solution
A system and method that enables communication between physical switches and an overlay network to determine the destination of packets and apply security policies, routing packets through a security appliance when necessary, while directly connecting switches when no security policy is required.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If overlay network encapsulation is used to create location transparency, then network virtualization and location transparency are improved, but visibility of original packet information by intermediate network devices is lost
Solution Approach 1:
The patent introduces VXLAN gateways as intermediary devices that understand both overlay and underlay protocols. These gateways perform decapsulation of overlay packets, extract the original packet information, and make it visible to intermediate network devices. The gateways act as mediators between the overlay virtual network and the physical network infrastructure, enabling security appliances and other INEs to inspect and process packets based on their original content while maintaining the benefits of overlay encapsulation.
2Reliability
If physical security appliances are used to apply security services to overlay traffic, then network security is improved, but routing complexity increases due to lack of visibility by intermediate devices
Solution Approach 1:
The patent implements preliminary routing decisions based on VXLAN header information (such as VNI - Virtual Network Identifier) before packets reach security appliances. Border gateways and VXLAN-aware routers use the encapsulated packet information to pre-determine routing paths, selecting appropriate security appliances or direct routes in advance. This preliminary action reduces the complexity at security appliances themselves, as they receive already-routed packets that only need security processing rather than full routing decisions.
3Reliability
If all overlay traffic is routed to physical security appliances for inspection, then security coverage is improved, but network performance deteriorates due to unnecessary routing overhead
Solution Approach 1:
The patent implements partial security inspection by selectively routing only certain overlay traffic to physical security appliances based on predefined policies, packet characteristics, or security requirements. Not all overlay packets are subjected to full security appliance inspection - only those that match security policies or require deep inspection are diverted. This partial action approach maintains comprehensive security coverage for necessary traffic while allowing bulk traffic to flow directly through the network without security appliance overhead, thus preserving network performance.
Data Source
AI summary
In one embodiment, an apparatus includes a processor and logic integrated with and/or executable by the processor. The logic is configured to communicate with a first physical switch, a second physical switch, and an overlay network that connects the first physical switch to the second physical switch. The logic is also configured to receive a request for a communication path through the overlay network for a packet, the request including at least the packet, first information about a source of the packet, the source of the packet being connected to the first physical switch, and second information about a most closely connected physical switch to a destination of the packet. Moreover, the logic is configured to determine the destination of the packet, the destination of the packet being connected to the second physical switch. Also, the logic is configured to determine whether to apply a security policy to the packet.


