Overlay Underlay Flow Correlation via Encapsulation Tags
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In fabric networks, the loss of visibility into inner packets at intermediate nodes hinders the correlation of flows between fabric edge nodes and intermediate nodes, making it difficult for conventional collectors/analyzers to troubleshoot and manage network traffic effectively, especially when overlays are present.
Innovation Solution
The solution involves creating a tag using a hash function based on source and destination information, which is used to encapsulate packets and route them through intermediate network devices, allowing for correlation of overlay flows with underlying flows without stripping traffic down to inner packets, thus maintaining visibility and enabling effective troubleshooting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If packets are routed through intermediate network devices in overlay networks, then network traffic can be transmitted between edge nodes, but visibility into inner packets is lost at intermediate nodes, preventing flow correlation
Solution Approach 1:
The patent implements encapsulation where the original packet (inner packet) is nested within a new packet structure (outer packet) that includes correlation tags. The outer packet contains the inner packet along with additional metadata such as source/destination edge node identifiers and flow correlation information. This nested structure allows intermediate nodes to handle the outer packet while preserving visibility into the inner packet's flow characteristics through the embedded tags, thus resolving the visibility loss problem without changing intermediate node complexity
Solution Approach 2:
The patent introduces correlation tags as intermediary elements that bridge the gap between overlay and underlay networks. These tags are inserted into the packet structure and contain information that enables flow correlation across network boundaries. The tags act as mediators that carry flow identification information through intermediate nodes, allowing collectors/analyzers to correlate flows without requiring intermediate nodes to perform complex stripping or inspection operations
2Measurement precision
If conventional collectors/analyzers are used to monitor network traffic, then basic traffic monitoring is possible, but they cannot correlate flows between edge nodes and intermediate nodes due to lack of visibility
Solution Approach 1:
The patent applies preliminary action by pre-calculating and inserting correlation tags into packets at the source edge node before packets enter the overlay network. These tags contain flow identification information that is prepared in advance, allowing collectors/analyzers to perform correlation operations without complex real-time processing. The preliminary insertion of tags enables conventional collectors to achieve enhanced flow correlation capabilities without requiring sophisticated real-time analysis algorithms
3Difficulty of detecting and measuring
If traffic is stripped down to inner packets for analysis, then detailed inspection is possible, but visibility into overlay flows is lost and troubleshooting becomes difficult
Solution Approach 1:
The patent merges overlay and underlay flow information by combining the inner packet with outer packet metadata including correlation tags. This merged packet structure preserves both the original traffic content and the overlay flow identification information simultaneously. Collectors/analyzers can inspect the combined structure to obtain both detailed traffic inspection capability and overlay flow visibility, eliminating the need to choose between stripping packets or maintaining visibility
Data Source
AI summary
A network device may receive a flow having source information corresponding to a first client device and destination information corresponding to a second client device. A tag may then be created by the network device for the flow based upon the source information and the destination information. Next, the network device may encapsulate a packet corresponding to the flow. The packet may be encapsulated with encapsulation information including the created tag. The encapsulated packet may then be routed through a plurality of intermediate network devices in the network. The created tag encapsulated with the packet may identify the packet as being a part of the flow as the packet is routed through the plurality of intermediate network devices.


