SGT Mapping Reassociation Across Third-Party WAN Borders

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network fabrics face challenges in enforcing security group tags (SGTs) across non-SGT-capable network media, leading to scalability issues and compromised security policies when interconnecting external sites, as SGTs are lost during transmission over third-party networks without inline propagation capabilities.

Innovation Solution

Implementing a policy service control plane that manages SGT mappings through a subscription and publication mechanism, enabling on-demand distribution and reapplication of SGTs at border devices using a centralized control plane, allowing SGT mappings to be learned and cached at ingress borders for accurate policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SGTs are propagated inline over network media, then security policy enforcement is improved, but compatibility with third-party WAN networks is lost

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidcompatibility with third-party WAN networks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a control plane as an intermediary system that manages SGT mappings between network fabric edges. This control plane decouples the data plane from direct SGT propagation requirements, allowing third-party WAN networks to forward packets without inline SGT capability while maintaining security policy enforcement through centralized mapping management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If SGTs are lost during transmission over third-party networks, then network scalability is improved, but security policy accuracy deteriorates

Engineering Contradiction:
Improvenetwork scalabilityVSAvoidsecurity policy accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The control plane performs preliminary actions by pre-establishing and maintaining SGT mappings before packets traverse third-party networks. When packets arrive at the egress border, the control plane has already resolved the correct SGT mappings, enabling accurate policy enforcement without requiring SGT propagation through the WAN.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the control plane receives packet information from ingress borders, resolves SGT mappings, and provides feedback to egress borders. This feedback loop ensures that even though SGTs are not propagated over WAN, the correct mappings are dynamically determined and applied at each border.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If intermediate policy application points are selected, then compatibility with third-party networks is maintained, but network device scalability is compromised

Engineering Contradiction:
Improvecompatibility with third-party networksVSAvoidnetwork device scalability
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the policy enforcement function into two parts: (1) SGT mapping resolution handled by the control plane, and (2) packet forwarding handled by border devices. This segmentation allows third-party networks to be compatible while preventing intermediate policy application points from becoming scalability bottlenecks, as the control plane centralizes the complex mapping resolution function.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12574381B2Scalable source security group tag (SGT) propagation over third-party WAN networks
Publication Date: 2026.03.10 CISCO TECHNOLOGY INC
  • US12574381B2 patent drawing
  • US12574381B2 patent drawing
  • US12574381B2 patent drawing

AI summary

Techniques for propagating security group tag mapping between external interconnected sites that are not capable of carrying the SGT mappings. A system is disclosed that includes operations of subscribing at a first border of a first site, by a control plane, a first SGT mapping associated with a first data packet at the first site for storing the SGT mapping of the first data packet at the control plane. Then transmitting, the first data packet from the first border of the first site to a second border of the second site without attaching the first SGT mapping with the first data packet. Further, in response to a determination by the control plane that the first data packet has lost the associated first SGT mapping at the second border, identifying the SGT mapping with the first data packet at the second border to be re-associated with the first data packet.