Overlay Switch Role Segmentation via Fabric Route Packets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-fabric overlay networks, efficiently managing and distributing role information for fine-grained role-based traffic segmentation is challenging, leading to disruptions when end devices move between fabrics and requiring extensive policy programming in access switches.
Innovation Solution
Incorporating role information into fabric route packets and maintaining it in local data structures at switches, allowing switches to learn and distribute network addresses with associated roles, thereby enabling seamless role-based segmentation across the network without re-authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If role information is distributed across multiple switches in overlay networks, then role-based traffic segmentation can be enforced, but network complexity and policy programming overhead increase significantly
Solution Approach 1:
The patent implements self-service by enabling switches to automatically learn and distribute role information through fabric route packets without requiring manual policy programming. Switches autonomously populate their local data structures with role information received from other switches, eliminating the need for administrators to manually configure segmentation policies on each device.
Solution Approach 2:
The patent segments role information distribution by maintaining it at the granularity of individual network addresses in local data structures at each switch. This allows role information to be distributed independently for each network address, enabling fine-grained traffic segmentation while reducing overall system complexity through modular, address-specific role management.
2Adaptability or versatility
If role information is maintained at fine-grained network address level, then seamless role-based segmentation is achieved during device migration, but data structure and processing overhead increase
Solution Approach 1:
The patent applies preliminary action by pre-distributing role information associated with network addresses through fabric route packets before device migration occurs. When an end device moves between fabrics, its role information is already present in the new fabric's switches, enabling seamless continuation of role-based segmentation without re-authentication or service interruption.
Solution Approach 2:
The patent achieves universality by using fabric route packets, which are existing overlay network control plane messages, to carry both network address information and role information. This multi-functional use of standard packets reduces the need for specialized data structures while enabling fine-grained role-based segmentation and seamless device migration.
3Ease of manufacture
If role information is distributed through existing control plane packets, then implementation complexity is reduced, but role information may not be propagated efficiently across all switches
Solution Approach 1:
The patent implements feedback by utilizing the existing control plane packet routing mechanisms that already ensure complete propagation of routing information across all switches in the overlay network. Fabric route packets are naturally distributed to all relevant switches through established control plane protocols, ensuring that role information associated with network addresses is propagated efficiently and completely without requiring additional distribution logic.
Data Source
AI summary
A system for facilitating segmentation by a first switch of an overlay tunnel fabric is provided. During operation, the system can receive a route update packet for the fabric. The packet can be based on a control plane that allows the exchange of route information via the tunnel and can include a first media access control (MAC) address learned at a second switch and a first role identifier of a first role. The first role can indicate a level of access granted to a first device associated with the first MAC address. The system can store the first MAC address and the first role identifier in a local address data structure. Upon receiving a packet from the first device, the system can then determine, based on the first role identifier and a first segmentation policy, whether a local device is allowed to receive the packet from the first device.


