SD-WAN Orchestrator Hides Virtualization Complexity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing SD-WAN solutions lack efficient integration of network virtualization management and edge security services, leading to suboptimal traffic policing and security application in cloud-based environments.
Innovation Solution
A cloud-native SD-WAN environment that hides network virtualization management user interface components, utilizing a SD-WAN orchestrator to perform network virtualization management operations, and deploying edge security services like L4-7 firewalls and IDS/IPS, with cloud gateways forwarding traffic to managed service nodes for security application.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If network virtualization management components are exposed in SD-WAN environment, then management operations can be performed, but system complexity and security risks increase
Solution Approach 1:
The patent introduces a SD-WAN orchestrator as an intermediary layer between the user interface and the network virtualization management deployment. The orchestrator translates high-level management operations into specific configuration commands, hiding the underlying complexity of network virtualization components while enabling effective management of tenants, network services, and security policies.
2Productivity
If multiple tenants share the same network virtualization management deployment, then resource utilization improves, but traffic policing and security management become more complex
Solution Approach 1:
The patent segments the network virtualization management deployment by introducing tenant-level service routers (T1-SRs) that are specific to each tenant, while sharing provider-level service routers (T0-SRs). This segmentation allows independent traffic policing and security management for each tenant while maintaining efficient resource sharing across the multi-tenant environment.
3Reliability
If security services are deployed at datacenter perimeter, then security control is centralized, but response time to edge threats increases
Solution Approach 1:
The patent extends the security stack from the traditional datacenter perimeter into the cloud edge by deploying security services at PoPs (Points of Presence) geographically distributed around the network. This dimensional shift from centralized to distributed security deployment enables both centralized management through the orchestrator and rapid local response to threats at the network edge.
4Reliability
If active-active high availability configuration is implemented, then service availability improves, but system redundancy and complexity increase
Solution Approach 1:
The patent merges multiple T1-SRs and T0-SRs onto a single physical or virtual service node to provide active-active high availability. By combining multiple logical routing functions on shared hardware, the system achieves redundancy and failover capabilities while reducing the number of physical devices required compared to traditional one-to-one redundancy configurations.
Data Source
AI summary
A software-defined wide area network (SD-WAN) environment that leverages network virtualization management deployment is provided. Edge security services managed by the network virtualization management deployment are made available in the SD-WAN environment. Cloud gateways forward SD-WAN traffic to managed service nodes to apply security services. Network traffic is encapsulated with corresponding metadata to ensure that services can be performed according to the desired policy. Point-to-point tunnels are established between cloud gateways and the managed service nodes to transport the metadata to the managed service nodes using an overlay logical network. Virtual network identifiers (VNIs) in the metadata are used by the managed service nodes to identify tenants/policies. A managed service node receiving a packet uses provider service routers (T0-SR) and tenant service routers (T1-SRs) based on the VNI to apply the prescribed services for the tenant, and the resulting traffic is returned to the cloud gateway that originated the traffic.


