SD-WAN Policy Mapping for SASE Security Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of SD-WAN constructs with SASE security policies is complicated due to the lack of unified policy definition across SD-WAN and security cloud providers, requiring excessive coordination and manual intervention to implement or update security policies, as security administrators are unaware of SD-WAN network constructs like VPNs and IP addresses.

Innovation Solution

A method for automatically integrating SD-WAN constructs into SASE security policies by using security policy labels known to both security cloud providers and SD-WAN fabric controllers, allowing the SD-WAN controller to map network constructs to security policies, enhance them, and deploy them to network edges, without requiring manual input of segmentation details.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual coordination between security administrators and network administrators is used to implement security policies, then security policies can be implemented with awareness of SD-WAN constructs, but the process becomes complicated and time-consuming

Engineering Contradiction:
Improvesecurity policy implementation accuracyVSAvoidpolicy coordination time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces an intermediary system that automatically maps SD-WAN constructs (VPNs, IP addresses, subnets) to security policy parameters. This intermediary translates network constructs into security policy language, eliminating the need for manual coordination while maintaining accuracy. The system acts as a bridge between SD-WAN network operations and security policy management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables security policies to be automatically enriched by pulling SD-WAN construct information directly from the SD-WAN controller. The security policy management system serves itself by automatically obtaining and mapping network construct data without requiring manual intervention from administrators, thus reducing coordination time while maintaining reliability.

Inventive Principle:
Principle #25Self-service

2Reliability

If security administrators are made aware of SD-WAN network constructs, then security policies can be accurately configured, but the operational complexity increases

Engineering Contradiction:
Improvesecurity policy configuration accuracyVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system that automatically maps SD-WAN constructs (VPNs, IP addresses, subnets) to security policy parameters. This intermediary translates network constructs into security policy language, eliminating the need for manual coordination while maintaining accuracy. The system acts as a bridge between SD-WAN network operations and security policy management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates automated mappings and translations of SD-WAN construct information into security policy parameters. Instead of requiring administrators to understand and manually enter complex network construct details, the system automatically copies and transforms the necessary information, reducing operational complexity while maintaining configuration accuracy.

Inventive Principle:
Principle #26Copying

3Ease of operation

If automated mapping of SD-WAN constructs to security policies is implemented, then operational complexity is reduced, but integration complexity between systems increases

Engineering Contradiction:
Improvesecurity policy management easeVSAvoidsystem integration complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system that automatically maps SD-WAN constructs (VPNs, IP addresses, subnets) to security policy parameters. This intermediary translates network constructs into security policy language, eliminating the need for manual coordination while maintaining accuracy. The system acts as a bridge between SD-WAN network operations and security policy management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a universal mapping framework that can handle multiple SD-WAN constructs (VPNs, IP addresses, subnets) and translate them into various security policy parameters. This multi-functional approach consolidates multiple integration tasks into a single automated process, reducing operational complexity while managing integration complexity through a unified interface.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260046316A1Integrating sd-wan constructs with SASE security policies
Publication Date: 2026.02.12 CISCO TECHNOLOGY INC
  • US20260046316A1 patent drawing
  • US20260046316A1 patent drawing
  • US20260046316A1 patent drawing

AI summary

Techniques for automatically integrating SD-WAN constructs to security policies are described. The techniques may include defining, by a security cloud provider, a security policy for an entity, the entity represented by a VPN security policy label and the security policy absent source and destination CIDR IP addresses. The security cloud provider notifies an SD-WAN controller of the security policy. The SD-WAN controller maps the VPN security policy label to an IP address pool and a VPN ID. The SD-WAN controller generates an enhanced security policy by automatically adding source and destination CIDR IP addresses to the security policy. The SD-WAN controller deploys the enhanced security policy to an SD-WAN branch router and generates a VPN segment between the SD-WAN branch router and the security cloud provider to establish a common secure internet gateway tunnel for the IP address pool.