Proxy-ARP Flood in Encapsulation for Inter-EPG Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current software-defined networking (SDN) systems face challenges in managing broadcast, unknown unicast, and multicast traffic within Virtual Local Area Networks (VLANs), leading to potential instability and security risks, particularly when multiple End Point Groups (EPGs) share a Bridge Domain (BD), and they lack support for protocols like ARP, unknown unicast, and IPv6 traffic, hindering service integration and inter-EPG communication.

Innovation Solution

The solution enables Flood in Encapsulation (FIE) for all protocols and implicitly supports proxy-ARP across distributed Clos networks, allowing flexible configuration at both the EPG and BD levels to manage traffic effectively, ensuring communication between EPGs without MAC flaps and enabling service integration by selectively enabling FIE on specific EPGs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Flood in Encapsulation (FIE) is enabled for all protocols across distributed Clos networks, then inter-EPG communication and service integration are improved, but network complexity and potential instability increase

Engineering Contradiction:
Improveinter-EPG communication capabilityVSAvoidnetwork configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a proxy-ARP mechanism as an intermediary layer between EPGs. The spine switch acts as a proxy-ARP server that responds to ARP requests on behalf of remote EPGs, enabling inter-EPG communication without requiring direct FIE configuration between all EPG pairs. This mediator approach simplifies the network configuration while maintaining versatility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the FIE configuration by allowing selective enabling of FIE on specific EPGs rather than globally across the entire network. This granular control approach reduces overall network complexity while still providing inter-EPG communication capability where needed, resolving the contradiction between versatility and complexity.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple EPGs share a Bridge Domain (BD), then service integration and flexibility are improved, but broadcast and unknown unicast traffic management becomes more complex

Engineering Contradiction:
Improveservice integration flexibilityVSAvoidtraffic management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The spine switch serves as a mediator that manages ARP requests and proxy-ARP responses across multiple EPGs sharing a BD. It intercepts ARP requests, determines the target EPG, and responds appropriately without requiring complex local traffic management on leaf switches. This centralizes the complexity in a single point while simplifying individual switch operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a self-service mechanism where the proxy-ARP server automatically responds to ARP requests for remote EPGs without manual intervention. The system autonomously manages the ARP resolution process, reducing the operational complexity of traffic management while maintaining service integration flexibility.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If proxy-ARP is implicitly supported across distributed Clos networks, then inter-VLAN communication is improved, but ARP traffic volume and processing overhead increase

Engineering Contradiction:
Improveinter-VLAN communication easeVSAvoidARP traffic volume
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The patent extracts the ARP processing function from individual leaf switches and consolidates it at the spine switch level. By taking out the proxy-ARP server functionality from distributed switches and centralizing it, the system reduces redundant ARP traffic generation while maintaining ease of inter-VLAN communication. Each leaf switch only needs to forward ARP requests without generating additional proxy responses.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11025536B1Support for flooding in encapsulation and inter-VLAN communication via proxy-ARP
Publication Date: 2021.06.01 CISCO TECHNOLOGY INC
  • US11025536B1 patent drawing
  • US11025536B1 patent drawing
  • US11025536B1 patent drawing

AI summary

A first leaf switch may receive from a first host, a request for a second host that is not known at the first leaf switch. The first host may be within a first End Point Group (EPG) and the second host being within a second EPG. The first EPG and the second EPG may be in a Bridge Domain (BD). Flood in encapsulation may be enabled for the first EPG and for the second EPG. Next, the first leaf switch may flood the request locally in the first EPG and to a spine switch with a VNID of the first EPG. The spine switch may then flood the request to a second leaf switch where the BD is present. The second leaf switch may send a glean request for the second host, receive, in response to sending the glean request, a reply, and learn the second host locally in response to receiving the reply.