SDN Controller Policy Routing for Service Appliance Transparency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional packet steering methods in control-plane based fabric networks, especially with distributed IP anycast gateways, are not scalable and can compromise end-user transparency, which is critical for applications like financial and banking services that require client transaction tracing for compliance.

Innovation Solution

A Software Defined Network (SDN) controller configures Policy Based Routing (PBR) policies to ensure that both request and response traffic traverses a service appliance in a network with a distributed gateway, maintaining client identity throughout transactions by forwarding packets through specific leaf switches, without requiring Source Network Address Translation (SNAT).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional packet steering methods are used in distributed IP anycast gateway networks, then routing control is simplified, but scalability is limited and end-user transparency is compromised

Engineering Contradiction:
ImprovescalabilityVSAvoidend-user transparency
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent introduces an SDN controller as an intermediary that mediates between the distributed IP anycast gateways and the service appliances. The controller distributes policy data to gateway devices, enabling them to forward packets through specific leaf switches without requiring the gateways themselves to make complex routing decisions. This intermediary approach maintains end-user transparency while achieving scalability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically distributes policy data from the SDN controller to gateway devices based on current network conditions and service appliance locations. The policy data is updated and redistributed as needed, allowing the network to adapt to changing conditions while maintaining proper packet steering through service appliances without compromising scalability.

Inventive Principle:
Principle #15Dynamics

2Loss of information

If service appliances are integrated without SNAT, then end-client transparency is maintained, but packet routing complexity increases in distributed gateway environments

Engineering Contradiction:
Improveend-client transparencyVSAvoidpacket routing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent extracts the routing complexity from the gateway devices and centralizes it in the SDN controller. The controller handles the complex policy distribution and packet steering logic, while gateway devices execute simpler forwarding rules based on received policy data. This extraction reduces device complexity at the gateway level while maintaining end-client transparency.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Gateway devices are configured to automatically forward packets through service appliances based on policy data they receive from the SDN controller. Once policy data is distributed, the gateway devices autonomously execute the forwarding rules without requiring continuous controller intervention or complex local decision-making logic, reducing operational complexity.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If policy data is distributed to gateway devices, then packet steering through service appliances is achieved, but network controller overhead increases

Engineering Contradiction:
Improvepacket steering automationVSAvoidnetwork controller overhead
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The SDN controller distributes policy data to gateway devices in advance, before packets need to be steered through service appliances. This preliminary action prepares the gateway devices with the necessary forwarding rules, eliminating the need for real-time controller intervention during packet forwarding and reducing ongoing controller overhead.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The controller distributes policy data to gateway devices that may not all need it simultaneously, and updates policy data at intervals rather than for every packet. This partial action approach reduces controller processing overhead while still achieving the necessary packet steering automation at the gateway level.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10623505B2Integrating service appliances without source network address translation in networks with logical overlays
Publication Date: 2020.04.14 CISCO TECHNOLOGY INC
  • US10623505B2 patent drawing
  • US10623505B2 patent drawing
  • US10623505B2 patent drawing

AI summary

A network controller for a network implementing a virtual network overlay determines a network gateway via which a service appliance accesses the network. The network controller determines a network gateway via which an application server accesses the network. First policy data is distributed to the network gateway via which the service appliance accesses the network. This first policy data indicates that the network gateway via which the service appliance accesses the network forwards return packets addressed to a client device sent from an application server to the service appliance. Second policy data is distributed to the network gateway via which the application server accesses the network. This second policy data indicates the network gateway via which the application server accesses the network is configured to forward return packets addressed to the client device to the network gateway via which the service appliance accesses the network.