SD-WAN Cloud Gateway Tenant Isolation via VNI Metadata

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Software-Defined Wide Area Network (SD-WAN) solutions lack efficient integration of network virtualization management and edge security services, particularly in cloud-based Secure Access Service Edge (SASE) environments, where multiple tenants share a single network virtualization management deployment, leading to complexity in traffic policing and security service application.

Innovation Solution

A cloud-native SD-WAN environment that hides network virtualization management user interface components, utilizing a SD-WAN orchestrator to perform operations like provisioning and configuring network services, with edge security services such as firewalls and IDS/IPS, and implementing stateful active-active high availability to ensure continuous security and traffic management across multiple tenants.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single network virtualization management deployment is shared by multiple tenants in a cloud-based SASE environment, then resource utilization and scalability are improved, but traffic policing complexity and security service application difficulty increase

Engineering Contradiction:
Improvemulti-tenant scalabilityVSAvoidtraffic policing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the shared network virtualization management deployment by introducing tenant service routers (T1-SRs) that are dedicated to specific tenants. Each T1-SR handles traffic policing and security service application for its assigned tenant, thereby dividing the complex multi-tenant management into smaller, isolated units. This segmentation maintains multi-tenant scalability while reducing the complexity of traffic policing by confining it to individual tenant contexts rather than managing all tenants simultaneously.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If network virtualization management user interface components are exposed in a cloud-native SD-WAN environment, then operational flexibility and configurability are improved, but system security and management overhead increase

Engineering Contradiction:
Improveoperational flexibilityVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the user interface components from the core network virtualization management deployment and places them in a separate SD-WAN orchestrator. This extraction allows the orchestrator to provide operational flexibility and configurability through its interface while the core management deployment remains secure and isolated. The orchestrator acts as an intermediary that handles user interactions without exposing the core system to potential security risks or management overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If active-active high availability configuration is implemented for managed service nodes, then service continuity and fault tolerance are improved, but synchronization complexity and resource requirements increase

Engineering Contradiction:
Improveservice continuityVSAvoidsynchronization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the state synchronization functionality into the managed service nodes themselves, allowing them to automatically share and synchronize traffic policing states with their peer nodes in the active-active configuration. This merging approach enables service continuity and fault tolerance by ensuring that if one node fails, the other node already possesses the necessary state information to take over seamlessly. The synchronization complexity is managed through integrated state sharing mechanisms rather than external coordination systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11375005B1High availability solutions for a secure access service edge application
Publication Date: 2022.06.28 VELOCLOUD NETWORKS LLC
  • US11375005B1 patent drawing
  • US11375005B1 patent drawing
  • US11375005B1 patent drawing

AI summary

A software-defined wide area network (SD-WAN) environment that leverages network virtualization management deployment is provided. Edge security services managed by the network virtualization management deployment are made available in the SD-WAN environment. Cloud gateways forward SD-WAN traffic to managed service nodes to apply security services. Network traffic is encapsulated with corresponding metadata to ensure that services can be performed according to the desired policy. Point-to-point tunnels are established between cloud gateways and the managed service nodes to transport the metadata to the managed service nodes using an overlay logical network. Virtual network identifiers (VNIs) in the metadata are used by the managed service nodes to identify tenants/policies. A managed service node receiving a packet uses provider service routers (T0-SR) and tenant service routers (T1-SRs) based on the VNI to apply the prescribed services for the tenant, and the resulting traffic is returned to the cloud gateway that originated the traffic.