SDWAN Controller Automates VPN Tunnels via Group Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Full-mesh network communication among network devices within an organization is not scalable due to resource constraints and is costly to implement, with manual VPN setup being time-consuming and error-prone.

Innovation Solution

A Software-Defined Wide Area Network (SDWAN) controller automatically configures Virtual Private Network (VPN) links based on group and role settings of network devices, using Internet Protocol Security (IPsec) configuration to establish full-mesh communication by designating hubs and edges within groups and between groups.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If full-mesh network communication is implemented among all network devices, then network connectivity and communication capability are improved, but resource consumption and implementation cost increase significantly

Engineering Contradiction:
Improvenetwork connectivityVSAvoidresource consumption
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the full-mesh network into multiple groups, where each group forms a complete mesh among its members. Devices in different groups communicate through gateway devices rather than establishing direct connections. This segmentation reduces the total number of VPN tunnels required while maintaining full-mesh communication capability within each group, thereby reducing resource consumption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Gateway devices serve as intermediaries between different groups. Instead of every device in every group establishing direct VPN tunnels with all devices in all groups, the gateway devices mediate inter-group communication. This intermediary approach significantly reduces the number of required connections while maintaining full connectivity across the entire network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If robust resources are implemented to support multiple VPN tunnels simultaneously, then network communication capability is improved, but implementation cost increases

Engineering Contradiction:
Improvenetwork communication capabilityVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

By segmenting the network into groups with localized full-mesh connections, the patent reduces the total number of VPN tunnels each device must support. This segmentation allows devices to maintain reliable communication within their group without requiring robust resources to support connections to all devices in the entire network, thereby reducing implementation cost.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by implementing full-mesh connectivity locally within each group rather than globally across all devices. Each group maintains high reliability through complete mesh connectivity among its members, while inter-group communication relies on gateway devices. This localized approach ensures communication reliability where needed while reducing overall resource requirements and implementation cost.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If manual VPN setup is performed, then configuration control is improved, but time consumption and error rate increase

Engineering Contradiction:
Improveconfiguration controlVSAvoidsetup efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent implements self-service by enabling devices to automatically configure and establish VPN tunnels based on pre-defined group memberships and policies. The system autonomously determines which devices should connect to form full-mesh groups and automatically establishes the necessary tunnels, eliminating the need for manual configuration while maintaining configuration control through centralized group definitions.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-defining group memberships and communication policies before the actual network setup. Devices are assigned to groups in advance, and the system automatically uses these pre-defined configurations to establish VPN tunnels. This preliminary configuration approach maintains control over the network architecture while dramatically reducing setup time and eliminating manual configuration errors.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11546303B2Automatic establishment of network tunnels by an SDWAN controller based on group and role assignments of network devices
Publication Date: 2023.01.03 FORTINET INC
  • US11546303B2 patent drawing
  • US11546303B2 patent drawing
  • US11546303B2 patent drawing

AI summary

Systems and methods are described for automatically building up a VPN to facilitate full-mesh communication within a private network of an organization based on group and role settings of participating network devices. According to one embodiment, configuration information, including a group setting, indicating a group with which the particular network device is associated, and a role setting, specifying a role of the particular network device within the group as either a hub or an edge, is received by an SDWAN controller associated with the private network for each network device of the private network. Based on the configuration information, IPsec configuration information is determined for establishment of VPN links between a hub of each group and one or more edges of the group. Full-mesh communication among the groups is enabled by causing the hubs to set up IPsec tunnels between each pair of hubs based on the IPsec configuration information.