Segmentation Server for NAT Workload Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enforcing segmentation policies and monitoring traffic flows in segmented network environments becomes challenging when workloads operate in different address spaces and IP addresses are subject to modification via network address translation, especially in container environments.

Innovation Solution

A segmentation server discovers network configurations, generates management instructions for firewalls to enforce segmentation policies, and monitors traffic flows, discarding inconsistent information to maintain security and update policies based on observed communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If distributed firewalls use IP addresses to identify workloads for enforcing segmentation policies, then policy enforcement and traffic monitoring can be implemented, but visibility and enforcement become challenging when workloads operate in different address spaces and IP addresses are modified via network address translation

Engineering Contradiction:
Improvesegmentation policy enforcement reliabilityVSAvoidtraffic flow visibility difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a segmentation server as an intermediary that mediates between the firewalls and the segmentation policy. The server discovers network configurations, identifies NAT translations, and generates appropriate management instructions that account for address space differences. This intermediary resolves the visibility problem by translating firewall observations into meaningful traffic flow information that reflects actual workload communications despite NAT modifications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes the parameters used for traffic identification based on network configuration. When NAT is detected, the system switches from using workload IP addresses directly to using a combination of firewall ID, translated IP addresses, and port information. This parameter adaptation allows consistent traffic monitoring and policy enforcement across different address spaces.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If the system generates asymmetric management instructions for workloads in different address spaces, then accurate traffic flow monitoring is achieved, but the complexity of generating and managing these instructions increases

Engineering Contradiction:
Improvetraffic flow identification precisionVSAvoidmanagement instruction generation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The segmentation server performs preliminary actions by discovering the network configuration and identifying NAT translations before generating management instructions. By pre-processing the network topology information and storing it for reference, the system avoids complex real-time calculations when creating firewall rules, thereby reducing the operational complexity while maintaining precise traffic identification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service by automatically discovering network configurations, detecting NAT translations, and generating appropriate asymmetric management instructions without manual intervention. The segmentation server autonomously adapts to different network topologies and workloads, reducing the operational burden on administrators while maintaining high precision in traffic flow identification.

Inventive Principle:
Principle #25Self-service

3Reliability

If the segmentation server discovers and monitors network configurations including NAT translations, then accurate policy enforcement is maintained across address spaces, but the complexity of network configuration discovery and monitoring increases

Engineering Contradiction:
Improvesegmentation policy enforcement reliabilityVSAvoidnetwork configuration discovery complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements feedback mechanisms where firewalls report observed traffic flows to the segmentation server, and the server uses this information to refine its understanding of network configurations and NAT translations. This feedback loop allows the system to automatically adapt to network changes and maintain accurate policy enforcement without requiring complex manual configuration discovery processes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11095611B2Traffic visibility and segmentation policy enforcement for workloads in different address spaces
Publication Date: 2021.08.17 ILLUMIO INC
  • US11095611B2 patent drawing
  • US11095611B2 patent drawing
  • US11095611B2 patent drawing

AI summary

A segmentation server generates and distributes management instructions for enforcing a segmentation policy. The segmentation server discovers a network configuration of workloads including an identification of workloads that are behind network address translation modules. The segmentation server generates management instructions for enforcing the rules in a manner dependent on the detected network configuration. Furthermore, the segmentation server monitors traffic flows and generates a traffic flow graph in a manner dependent on the detected network configuration.