SD-WAN Policy Header Packet Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network architectures face delays and bandwidth issues when routing SaaS applications through central data centers, and managing access control and security across multiple segments is complex and prone to human error.
Innovation Solution
A system and method for generating and processing wide area networking packets that include policy information, such as network segment, application, and security information, using a policy configuration to validate and encrypt packets, and manage network traffic centrally across software-defined wide area networks (SD-WANs).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If packets are routed through central data centers, then centralized control is maintained, but additional delay and bandwidth congestion occur
Solution Approach 1:
The patent segments network traffic into different types (SaaS applications, cloud services, traditional enterprise applications) and routes them through different paths. Direct Internet access is provided for SaaS and cloud services, while centralized data center routing is maintained for traditional enterprise applications, thereby reducing delay for time-sensitive traffic while preserving centralized control for other traffic
Solution Approach 2:
An intermediary controller or orchestrator is introduced that maintains centralized policy management and control plane functions while allowing distributed data plane operations. This intermediary enables direct Internet access for appropriate traffic types while maintaining centralized oversight through policy enforcement points at branch offices
2Loss of time
If direct Internet access is implemented, then routing delay is reduced, but access control and security management complexity increases
Solution Approach 1:
Multiple security functions (access control, firewall, intrusion prevention, encryption) are merged into unified security policies that are centrally managed and automatically distributed to branch office devices. This consolidation simplifies management by providing a single source of truth for security configurations while maintaining comprehensive security controls across distributed direct Internet access points
Solution Approach 2:
Security policies, access control rules, and encryption parameters are pre-configured and distributed to branch office devices before direct Internet access is established. This preliminary configuration enables automatic enforcement of security controls without requiring complex real-time decision-making at distributed locations, thereby reducing management complexity while maintaining security
3Reliability
If individual access control is configured at each router, then security is enforced, but configuration complexity and human error increase
Solution Approach 1:
A universal policy management system is implemented that provides multi-functional security controls (access control, firewall, encryption, intrusion prevention) through a single configuration interface. This universal system eliminates the need for separate individual configurations at each router by providing centralized policy templates that automatically adapt to different branch office environments, thereby maintaining security enforcement while dramatically reducing configuration complexity and human error
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
Provided are methods, apparatus, and system for policy based wide area network. A network of network appliances is configured with a policy configuration. Each network appliance is configured to validate each wide area network packet against the policy configuration. The validation can include verifying that the packets meet the SD-WAN network segment requirements and security rules including verifying that the source and destination address of the packet meet the firewall zone requirements. Each wide area network packet contains a policy header that is checked by the sending and receiving network appliance against the policy configuration.