SD-WAN Policy Mapping for SASE Security Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The integration of SD-WAN constructs with SASE security policies is complicated due to the lack of unified policy definition across SD-WAN and security cloud providers, requiring excessive coordination and manual intervention to implement or update security policies, as security administrators are unaware of SD-WAN network constructs like VPNs and IP addresses.
Innovation Solution
A method for automatically integrating SD-WAN constructs into SASE security policies by using security policy labels known to both security cloud providers and SD-WAN fabric controllers, allowing the SD-WAN controller to map network constructs to security policies, enhance them, and deploy them to network edges, without requiring manual input of segmentation details.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual coordination between security administrators and network administrators is used to implement security policies, then security policies can be implemented with awareness of SD-WAN constructs, but the process becomes complicated and time-consuming
Solution Approach 1:
The patent introduces an intermediary system that automatically maps SD-WAN constructs (VPNs, IP addresses, subnets) to security policy parameters. This intermediary translates network constructs into security policy language, eliminating the need for manual coordination while maintaining accuracy. The system acts as a bridge between SD-WAN network operations and security policy management.
Solution Approach 2:
The system enables security policies to be automatically enriched by pulling SD-WAN construct information directly from the SD-WAN controller. The security policy management system serves itself by automatically obtaining and mapping network construct data without requiring manual intervention from administrators, thus reducing coordination time while maintaining reliability.
2Reliability
If security administrators are made aware of SD-WAN network constructs, then security policies can be accurately configured, but the operational complexity increases
Solution Approach 1:
The patent introduces an intermediary system that automatically maps SD-WAN constructs (VPNs, IP addresses, subnets) to security policy parameters. This intermediary translates network constructs into security policy language, eliminating the need for manual coordination while maintaining accuracy. The system acts as a bridge between SD-WAN network operations and security policy management.
Solution Approach 2:
The system creates automated mappings and translations of SD-WAN construct information into security policy parameters. Instead of requiring administrators to understand and manually enter complex network construct details, the system automatically copies and transforms the necessary information, reducing operational complexity while maintaining configuration accuracy.
3Ease of operation
If automated mapping of SD-WAN constructs to security policies is implemented, then operational complexity is reduced, but integration complexity between systems increases
Solution Approach 1:
The patent introduces an intermediary system that automatically maps SD-WAN constructs (VPNs, IP addresses, subnets) to security policy parameters. This intermediary translates network constructs into security policy language, eliminating the need for manual coordination while maintaining accuracy. The system acts as a bridge between SD-WAN network operations and security policy management.
Solution Approach 2:
The system implements a universal mapping framework that can handle multiple SD-WAN constructs (VPNs, IP addresses, subnets) and translate them into various security policy parameters. This multi-functional approach consolidates multiple integration tasks into a single automated process, reducing operational complexity while managing integration complexity through a unified interface.
Data Source
AI summary
Techniques for automatically integrating SD-WAN constructs to security policies are described. The techniques may include defining, by a security cloud provider, a security policy for an entity, the entity represented by a VPN security policy label and the security policy absent source and destination CIDR IP addresses. The security cloud provider notifies an SD-WAN controller of the security policy. The SD-WAN controller maps the VPN security policy label to an IP address pool and a VPN ID. The SD-WAN controller generates an enhanced security policy by automatically adding source and destination CIDR IP addresses to the security policy. The SD-WAN controller deploys the enhanced security policy to an SD-WAN branch router and generates a VPN segment between the SD-WAN branch router and the security cloud provider to establish a common secure internet gateway tunnel for the IP address pool.


