SD-WAN Edge Discovery Through Firewalls Using a Controller
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In SD-WAN networks, devices with private IP addresses behind firewalls cannot directly establish secure communication due to obscured IP addresses, and temporary firewall disabling or bypass rules pose security risks and administrative challenges.
Innovation Solution
A computer system facilitates secure communication by establishing connections with devices, exchanging IP addresses and ports through firewalls, and providing instructions for tunnel setup without requiring firewall configuration changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If devices with private IP addresses attempt to establish direct communication behind firewalls, then network security is maintained, but device discovery and tunnel establishment fail
Solution Approach 1:
The patent introduces a controller as an intermediary component that mediates between devices with private IP addresses behind firewalls. The controller receives discovery messages from devices, translates them into appropriate formats that can traverse firewalls, and coordinates the establishment of secure tunnels without requiring devices to directly discover each other's private IP addresses.
Solution Approach 2:
The patent moves the discovery process from a direct device-to-device dimension to a controller-mediated dimension. Instead of devices attempting direct peer-to-peer discovery across firewall boundaries, the discovery occurs in a different dimensional space where the controller acts as a gateway, translating and relaying information between devices in separate network zones.
2Ease of operation
If NAT firewall is temporarily disabled or bypass rules are defined to enable device discovery, then device communication is enabled, but security risks increase and administrative complexity increases
Solution Approach 1:
The patent performs preliminary actions by having the controller pre-establish translation rules and discovery mechanisms before any communication attempts occur. The controller is pre-configured to recognize device identities, translate addresses appropriately, and set up secure communication channels in advance, eliminating the need for temporary firewall disabling or ad-hoc bypass rule creation.
3Ease of operation
If NAT firewall is temporarily disabled or bypass rules are defined to enable device discovery, then device communication is enabled, but administrative privileges and configuration complexity increase
Solution Approach 1:
The patent implements self-service by enabling devices to autonomously initiate discovery messages and establish communications through the controller without requiring manual firewall configuration or administrative intervention. The controller automatically handles address translation, message routing, and tunnel setup, allowing end devices to service their own communication needs without involving network administrators.
Data Source
AI summary
During operation, a computer system may establish a connection with an electronic device. Then, the computer system may receive, from a port in a firewall, a packet associated with the electronic device, where the packet includes an IP address of the electronic device. Moreover, the computer system may provide, to the port, a response addressed to the IP address. Next, the computer system may receive an acknowledgment associated with the electronic device that indicates that the response was received. Furthermore, the computer system may provide, addressed to the electronic device, a second IP address of a second electronic device and a second port in a second firewall associated with the second electronic device. Additionally, the computer system may provide, addressed to the second electronic device, the IP address of the electronic device and the port in the firewall.


