SD-WAN Edge Discovery Through Firewalls Using a Controller

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In SD-WAN networks, devices with private IP addresses behind firewalls cannot directly establish secure communication due to obscured IP addresses, and temporary firewall disabling or bypass rules pose security risks and administrative challenges.

Innovation Solution

A computer system facilitates secure communication by establishing connections with devices, exchanging IP addresses and ports through firewalls, and providing instructions for tunnel setup without requiring firewall configuration changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If devices with private IP addresses attempt to establish direct communication behind firewalls, then network security is maintained, but device discovery and tunnel establishment fail

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice discovery
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a controller as an intermediary component that mediates between devices with private IP addresses behind firewalls. The controller receives discovery messages from devices, translates them into appropriate formats that can traverse firewalls, and coordinates the establishment of secure tunnels without requiring devices to directly discover each other's private IP addresses.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent moves the discovery process from a direct device-to-device dimension to a controller-mediated dimension. Instead of devices attempting direct peer-to-peer discovery across firewall boundaries, the discovery occurs in a different dimensional space where the controller acts as a gateway, translating and relaying information between devices in separate network zones.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If NAT firewall is temporarily disabled or bypass rules are defined to enable device discovery, then device communication is enabled, but security risks increase and administrative complexity increases

Engineering Contradiction:
Improvedevice communicationVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary actions by having the controller pre-establish translation rules and discovery mechanisms before any communication attempts occur. The controller is pre-configured to recognize device identities, translate addresses appropriately, and set up secure communication channels in advance, eliminating the need for temporary firewall disabling or ad-hoc bypass rule creation.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If NAT firewall is temporarily disabled or bypass rules are defined to enable device discovery, then device communication is enabled, but administrative privileges and configuration complexity increase

Engineering Contradiction:
Improvedevice communicationVSAvoidfirewall configuration
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling devices to autonomously initiate discovery messages and establish communications through the controller without requiring manual firewall configuration or administrative intervention. The controller automatically handles address translation, message routing, and tunnel setup, allowing end devices to service their own communication needs without involving network administrators.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12587507B2Controller-enabled discovery of SD-WAN edge devices
Publication Date: 2026.03.24 RUCKUS IP HOLDINGS LLC
  • US12587507B2 patent drawing
  • US12587507B2 patent drawing
  • US12587507B2 patent drawing

AI summary

During operation, a computer system may establish a connection with an electronic device. Then, the computer system may receive, from a port in a firewall, a packet associated with the electronic device, where the packet includes an IP address of the electronic device. Moreover, the computer system may provide, to the port, a response addressed to the IP address. Next, the computer system may receive an acknowledgment associated with the electronic device that indicates that the response was received. Furthermore, the computer system may provide, addressed to the electronic device, a second IP address of a second electronic device and a second port in a second firewall associated with the second electronic device. Additionally, the computer system may provide, addressed to the second electronic device, the IP address of the electronic device and the port in the firewall.