SDWAN Controller Automates VPN Tunnels via Group Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Full-mesh network communication among network devices within an organization is not scalable due to resource constraints and is costly to implement, with manual VPN setup being time-consuming and error-prone.
Innovation Solution
A Software-Defined Wide Area Network (SDWAN) controller automatically configures Virtual Private Network (VPN) links based on group and role settings of network devices, using Internet Protocol Security (IPsec) configuration to establish full-mesh communication by designating hubs and edges within groups and between groups.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If full-mesh network communication is implemented among all network devices, then network connectivity and communication capability are improved, but resource consumption and implementation cost increase significantly
Solution Approach 1:
The patent segments the full-mesh network into multiple groups, where each group forms a complete mesh among its members. Devices in different groups communicate through gateway devices rather than establishing direct connections. This segmentation reduces the total number of VPN tunnels required while maintaining full-mesh communication capability within each group, thereby reducing resource consumption.
Solution Approach 2:
Gateway devices serve as intermediaries between different groups. Instead of every device in every group establishing direct VPN tunnels with all devices in all groups, the gateway devices mediate inter-group communication. This intermediary approach significantly reduces the number of required connections while maintaining full connectivity across the entire network.
2Reliability
If robust resources are implemented to support multiple VPN tunnels simultaneously, then network communication capability is improved, but implementation cost increases
Solution Approach 1:
By segmenting the network into groups with localized full-mesh connections, the patent reduces the total number of VPN tunnels each device must support. This segmentation allows devices to maintain reliable communication within their group without requiring robust resources to support connections to all devices in the entire network, thereby reducing implementation cost.
Solution Approach 2:
The patent applies local quality by implementing full-mesh connectivity locally within each group rather than globally across all devices. Each group maintains high reliability through complete mesh connectivity among its members, while inter-group communication relies on gateway devices. This localized approach ensures communication reliability where needed while reducing overall resource requirements and implementation cost.
3Ease of operation
If manual VPN setup is performed, then configuration control is improved, but time consumption and error rate increase
Solution Approach 1:
The patent implements self-service by enabling devices to automatically configure and establish VPN tunnels based on pre-defined group memberships and policies. The system autonomously determines which devices should connect to form full-mesh groups and automatically establishes the necessary tunnels, eliminating the need for manual configuration while maintaining configuration control through centralized group definitions.
Solution Approach 2:
The patent applies preliminary action by pre-defining group memberships and communication policies before the actual network setup. Devices are assigned to groups in advance, and the system automatically uses these pre-defined configurations to establish VPN tunnels. This preliminary configuration approach maintains control over the network architecture while dramatically reducing setup time and eliminating manual configuration errors.
Data Source
AI summary
Systems and methods are described for automatically building up a VPN to facilitate full-mesh communication within a private network of an organization based on group and role settings of participating network devices. According to one embodiment, configuration information, including a group setting, indicating a group with which the particular network device is associated, and a role setting, specifying a role of the particular network device within the group as either a hub or an edge, is received by an SDWAN controller associated with the private network for each network device of the private network. Based on the configuration information, IPsec configuration information is determined for establishment of VPN links between a hub of each group and one or more edges of the group. Full-mesh communication among the groups is enabled by causing the hubs to set up IPsec tunnels between each pair of hubs based on the IPsec configuration information.


