SGT Mapping Reassociation Across Third-Party WAN Borders
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network fabrics face challenges in enforcing security group tags (SGTs) across non-SGT-capable network media, leading to scalability issues and compromised security policies when interconnecting external sites, as SGTs are lost during transmission over third-party networks without inline propagation capabilities.
Innovation Solution
Implementing a policy service control plane that manages SGT mappings through a subscription and publication mechanism, enabling on-demand distribution and reapplication of SGTs at border devices using a centralized control plane, allowing SGT mappings to be learned and cached at ingress borders for accurate policy enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SGTs are propagated inline over network media, then security policy enforcement is improved, but compatibility with third-party WAN networks is lost
Solution Approach 1:
The patent introduces a control plane as an intermediary system that manages SGT mappings between network fabric edges. This control plane decouples the data plane from direct SGT propagation requirements, allowing third-party WAN networks to forward packets without inline SGT capability while maintaining security policy enforcement through centralized mapping management.
2Adaptability or versatility
If SGTs are lost during transmission over third-party networks, then network scalability is improved, but security policy accuracy deteriorates
Solution Approach 1:
The control plane performs preliminary actions by pre-establishing and maintaining SGT mappings before packets traverse third-party networks. When packets arrive at the egress border, the control plane has already resolved the correct SGT mappings, enabling accurate policy enforcement without requiring SGT propagation through the WAN.
Solution Approach 2:
The system implements feedback mechanisms where the control plane receives packet information from ingress borders, resolves SGT mappings, and provides feedback to egress borders. This feedback loop ensures that even though SGTs are not propagated over WAN, the correct mappings are dynamically determined and applied at each border.
3Adaptability or versatility
If intermediate policy application points are selected, then compatibility with third-party networks is maintained, but network device scalability is compromised
Solution Approach 1:
The patent segments the policy enforcement function into two parts: (1) SGT mapping resolution handled by the control plane, and (2) packet forwarding handled by border devices. This segmentation allows third-party networks to be compatible while preventing intermediate policy application points from becoming scalability bottlenecks, as the control plane centralizes the complex mapping resolution function.
Data Source
AI summary
Techniques for propagating security group tag mapping between external interconnected sites that are not capable of carrying the SGT mappings. A system is disclosed that includes operations of subscribing at a first border of a first site, by a control plane, a first SGT mapping associated with a first data packet at the first site for storing the SGT mapping of the first data packet at the control plane. Then transmitting, the first data packet from the first border of the first site to a second border of the second site without attaching the first SGT mapping with the first data packet. Further, in response to a determination by the control plane that the first data packet has lost the associated first SGT mapping at the second border, identifying the SGT mapping with the first data packet at the second border to be re-associated with the first data packet.


