PE Device VxLAN Packet Processing for Tenant Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In data center scenarios, the addition of new tenants requires allocating new sub-interfaces on DC-side PE devices, leading to occupied interface resources and complex configuration processes due to the need for extensive interface management and binding with VRF tables.

Innovation Solution

A packet processing method and system that involves receiving VxLAN encapsulated packets, parsing for VNI, and using BGP protocol extensions to automatically update and learn VTEP addresses within VRF tables, thereby simplifying the configuration by eliminating the need for new sub-interface allocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a new sub-interface is allocated on the DC-side PE device when a new tenant is added, then the tenant can be properly integrated into the network with dedicated interface resources, but relatively many interface resources on the DC-side PE device are occupied and the configuration process becomes complex

Engineering Contradiction:
Improvetenant integration capabilityVSAvoidinterface resource occupation and configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The invention applies universality by enabling a single sub-interface to serve multiple VRF tables simultaneously. Instead of allocating one sub-interface per tenant-VRF combination, the system allows one sub-interface to be bound to multiple VRF tables, making the interface resource universal and multi-functional. This resolves the contradiction by maintaining tenant integration capability while dramatically reducing interface resource occupation and configuration complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The invention merges the binding relationship between sub-interfaces and VRF tables. Traditionally, one sub-interface binds to one VRF table, but this invention combines multiple VRF table bindings to a single sub-interface. This merging approach allows multiple tenants to share the same interface resource while maintaining their network isolation through VRF tables, thus reducing overall interface resource requirements and simplifying configuration.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If multiple sub-interfaces are allocated for different tenants, then each tenant gets dedicated interface resources for network isolation, but the configuration process becomes increasingly complex with extensive interface management

Engineering Contradiction:
Improvenetwork isolation between tenantsVSAvoidconfiguration process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system makes the sub-interface universal by allowing it to bind to multiple VRF tables simultaneously. This multi-functionality enables the same interface to serve multiple tenants while maintaining network isolation through VRF table boundaries. The configuration complexity is reduced because administrators don't need to create and manage separate sub-interfaces for each tenant, instead they configure one sub-interface to bind to multiple VRF tables.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The VRF table acts as an intermediary between the shared sub-interface and different tenants. Instead of requiring direct one-to-one mapping between sub-interfaces and tenants, the VRF table mediates the connection, providing network isolation while allowing multiple tenants to share the same physical interface. This intermediary mechanism maintains reliability for network isolation while simplifying the configuration process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10476796B2Packet processing method, and device and system
Publication Date: 2019.11.12 HUAWEI TECH CO LTD
  • US10476796B2 patent drawing
  • US10476796B2 patent drawing
  • US10476796B2 patent drawing

AI summary

A packet processing method, and a device and a system includes receiving, by a provider edge (PE) device, a first virtual extensible local area network (VxLAN) encapsulated packet sent by a network virtualization edge (NVE) device, where the PE device and the NVE device are located in a same data center (DC), and the first VxLAN encapsulated packet includes a first VxLAN network identifier (VNI); parsing, by the PE device, the first VxLAN encapsulated packet to obtain the first VNI; obtaining, according to a correspondence between a VNI and a virtual routing and forwarding (VRF) table, a first VRF table that corresponds to the first VNI; searching, by the PE device, the first VRF table for a route according to a destination Internet Protocol (IP) address of the first VxLAN encapsulated packet; and forwarding the first VxLAN encapsulated packet.