SDN Controller Policy Routing for Service Appliance Transparency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional packet steering methods in control-plane based fabric networks, especially with distributed IP anycast gateways, are not scalable and can compromise end-user transparency, which is critical for applications like financial and banking services that require client transaction tracing for compliance.
Innovation Solution
A Software Defined Network (SDN) controller configures Policy Based Routing (PBR) policies to ensure that both request and response traffic traverses a service appliance in a network with a distributed gateway, maintaining client identity throughout transactions by forwarding packets through specific leaf switches, without requiring Source Network Address Translation (SNAT).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional packet steering methods are used in distributed IP anycast gateway networks, then routing control is simplified, but scalability is limited and end-user transparency is compromised
Solution Approach 1:
The patent introduces an SDN controller as an intermediary that mediates between the distributed IP anycast gateways and the service appliances. The controller distributes policy data to gateway devices, enabling them to forward packets through specific leaf switches without requiring the gateways themselves to make complex routing decisions. This intermediary approach maintains end-user transparency while achieving scalability.
Solution Approach 2:
The system dynamically distributes policy data from the SDN controller to gateway devices based on current network conditions and service appliance locations. The policy data is updated and redistributed as needed, allowing the network to adapt to changing conditions while maintaining proper packet steering through service appliances without compromising scalability.
2Loss of information
If service appliances are integrated without SNAT, then end-client transparency is maintained, but packet routing complexity increases in distributed gateway environments
Solution Approach 1:
The patent extracts the routing complexity from the gateway devices and centralizes it in the SDN controller. The controller handles the complex policy distribution and packet steering logic, while gateway devices execute simpler forwarding rules based on received policy data. This extraction reduces device complexity at the gateway level while maintaining end-client transparency.
Solution Approach 2:
Gateway devices are configured to automatically forward packets through service appliances based on policy data they receive from the SDN controller. Once policy data is distributed, the gateway devices autonomously execute the forwarding rules without requiring continuous controller intervention or complex local decision-making logic, reducing operational complexity.
3Ease of operation
If policy data is distributed to gateway devices, then packet steering through service appliances is achieved, but network controller overhead increases
Solution Approach 1:
The SDN controller distributes policy data to gateway devices in advance, before packets need to be steered through service appliances. This preliminary action prepares the gateway devices with the necessary forwarding rules, eliminating the need for real-time controller intervention during packet forwarding and reducing ongoing controller overhead.
Solution Approach 2:
The controller distributes policy data to gateway devices that may not all need it simultaneously, and updates policy data at intervals rather than for every packet. This partial action approach reduces controller processing overhead while still achieving the necessary packet steering automation at the gateway level.
Data Source
AI summary
A network controller for a network implementing a virtual network overlay determines a network gateway via which a service appliance accesses the network. The network controller determines a network gateway via which an application server accesses the network. First policy data is distributed to the network gateway via which the service appliance accesses the network. This first policy data indicates that the network gateway via which the service appliance accesses the network forwards return packets addressed to a client device sent from an application server to the service appliance. Second policy data is distributed to the network gateway via which the application server accesses the network. This second policy data indicates the network gateway via which the application server accesses the network is configured to forward return packets addressed to the client device to the network gateway via which the service appliance accesses the network.


