SD-WAN Edge Traffic Steering Across Hybrid Underlay Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current SD-WAN technologies struggle with unpredictable flow paths, especially when unsecured networks like the Internet are part of the underlay, leading to increased latency and security risks, and existing traffic steering methods are ineffective for mixed administrative control environments.
Innovation Solution
Implementing a method for SD-WAN Traffic Engineering (TE) that includes edge discovery processes, secure connection establishment, and packet encapsulation using GENEVE headers to steer traffic flows through optimized SD-WAN paths, even in hybrid networks with mixed underlay types.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If unsecured networks like the Internet are used in the underlay, then network flexibility and cost-effectiveness are improved, but latency increases and security risks worsen
Solution Approach 1:
The network is segmented into secured and unsecured segments. Secured segments use encrypted tunnels for critical traffic, while unsecured segments handle non-critical traffic. This allows the system to leverage the flexibility of unsecured networks for cost-effective routing while maintaining security for sensitive data flows through dedicated encrypted paths.
Solution Approach 2:
An intermediary security layer is introduced between the unsecured network and the data traffic. This intermediary layer provides encryption and authentication mechanisms that allow unsecured networks to be used for transport while maintaining security guarantees for the actual data communication.
2Adaptability or versatility
If unsecured networks are used in the underlay, then network flexibility is improved, but latency increases
Solution Approach 1:
Different quality characteristics are applied locally to different network segments. Critical traffic receives prioritized handling with lower latency through secured segments, while non-critical traffic utilizes unsecured segments for flexibility. This local differentiation allows the system to optimize latency where needed without sacrificing overall network flexibility.
Solution Approach 2:
The network dynamically adjusts traffic routing based on real-time conditions. When latency is critical, traffic is steered through secured segments with guaranteed paths. When flexibility is prioritized, traffic utilizes unsecured segments. This dynamic adaptation allows the system to optimize performance based on instantaneous network state.
3Device complexity
If existing traffic steering methods are used, then implementation simplicity is maintained, but effectiveness in hybrid networks with mixed administrative control deteriorates
Solution Approach 1:
The traffic steering mechanism is designed to be universal across different network types and administrative domains. It can handle secured and unsecured networks, single-domain and multi-domain scenarios, and various administrative control models through a unified approach. This multi-functionality enables the system to adapt to hybrid networks without requiring separate steering mechanisms for each scenario.
Solution Approach 2:
The system changes key parameters such as encryption status, administrative domain, and policy requirements to adapt traffic steering behavior. By dynamically adjusting these parameters based on the network environment, the system maintains simplicity in implementation while achieving effectiveness in complex hybrid scenarios.
4Reliability
If secure overlay tunnels are established, then security is improved, but processing demands at transit nodes increase
Solution Approach 1:
The security processing functions are extracted from the transit nodes and consolidated at the edge nodes. Transit nodes only handle forwarding operations, while security-related encryption and decryption are performed at edge nodes where the traffic originates and terminates. This extraction significantly reduces the processing burden on transit nodes while maintaining security.
Solution Approach 2:
An intermediary security architecture is introduced where security functions are centralized at edge nodes rather than being distributed at every transit node. This intermediary approach allows secure tunnel establishment without imposing heavy processing demands on intermediate transit infrastructure.
Data Source
AI summary
A method implemented by a first edge node of a software-defined wide area network (SD-WAN) for steering traffic over an SD-WAN path. The first edge node receives, on a control plane, first gateway (GW) properties of a first adjacent SD-WAN gateway of a second edge node of the SD-WAN, wherein the first edge node is an authorized peer of the second edge node, and the first adjacent SD-WAN gateway satisfies a first policy of the second edge node. The first edge node generates, based on the first GW properties, a data packet containing header information for steering the data packet to the second edge node over an SD-WAN path comprising the first adjacent SD-WAN gateway. The first edge node transmits, on a data plane, the data packet to a next hop along the SD-WAN path as indicated by an outer Internet Protocol (IP) destination address of the data packet.


