Proxy-ARP Flood in Encapsulation for Inter-EPG Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current software-defined networking (SDN) systems face challenges in managing broadcast, unknown unicast, and multicast traffic within Virtual Local Area Networks (VLANs), leading to potential instability and security risks, particularly when multiple End Point Groups (EPGs) share a Bridge Domain (BD), and they lack support for protocols like ARP, unknown unicast, and IPv6 traffic, hindering service integration and inter-EPG communication.
Innovation Solution
The solution enables Flood in Encapsulation (FIE) for all protocols and implicitly supports proxy-ARP across distributed Clos networks, allowing flexible configuration at both the EPG and BD levels to manage traffic effectively, ensuring communication between EPGs without MAC flaps and enabling service integration by selectively enabling FIE on specific EPGs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If Flood in Encapsulation (FIE) is enabled for all protocols across distributed Clos networks, then inter-EPG communication and service integration are improved, but network complexity and potential instability increase
Solution Approach 1:
The patent introduces a proxy-ARP mechanism as an intermediary layer between EPGs. The spine switch acts as a proxy-ARP server that responds to ARP requests on behalf of remote EPGs, enabling inter-EPG communication without requiring direct FIE configuration between all EPG pairs. This mediator approach simplifies the network configuration while maintaining versatility.
Solution Approach 2:
The patent segments the FIE configuration by allowing selective enabling of FIE on specific EPGs rather than globally across the entire network. This granular control approach reduces overall network complexity while still providing inter-EPG communication capability where needed, resolving the contradiction between versatility and complexity.
2Adaptability or versatility
If multiple EPGs share a Bridge Domain (BD), then service integration and flexibility are improved, but broadcast and unknown unicast traffic management becomes more complex
Solution Approach 1:
The spine switch serves as a mediator that manages ARP requests and proxy-ARP responses across multiple EPGs sharing a BD. It intercepts ARP requests, determines the target EPG, and responds appropriately without requiring complex local traffic management on leaf switches. This centralizes the complexity in a single point while simplifying individual switch operations.
Solution Approach 2:
The patent implements a self-service mechanism where the proxy-ARP server automatically responds to ARP requests for remote EPGs without manual intervention. The system autonomously manages the ARP resolution process, reducing the operational complexity of traffic management while maintaining service integration flexibility.
3Ease of operation
If proxy-ARP is implicitly supported across distributed Clos networks, then inter-VLAN communication is improved, but ARP traffic volume and processing overhead increase
Solution Approach 1:
The patent extracts the ARP processing function from individual leaf switches and consolidates it at the spine switch level. By taking out the proxy-ARP server functionality from distributed switches and centralizing it, the system reduces redundant ARP traffic generation while maintaining ease of inter-VLAN communication. Each leaf switch only needs to forward ARP requests without generating additional proxy responses.
Data Source
AI summary
A first leaf switch may receive from a first host, a request for a second host that is not known at the first leaf switch. The first host may be within a first End Point Group (EPG) and the second host being within a second EPG. The first EPG and the second EPG may be in a Bridge Domain (BD). Flood in encapsulation may be enabled for the first EPG and for the second EPG. Next, the first leaf switch may flood the request locally in the first EPG and to a spine switch with a VNID of the first EPG. The spine switch may then flood the request to a second leaf switch where the BD is present. The second leaf switch may send a glean request for the second host, receive, in response to sending the glean request, a reply, and learn the second host locally in response to receiving the reply.


