Tier-1 Router NAT and Firewall Offloading for Gateway Bottlenecks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Edge gateways in data centers experience performance degradation and bottlenecks due to excessive network address translation (NAT) and firewall processing, particularly for traffic within the data center, leading to congestion.

Innovation Solution

Offload NAT and firewall functionality from edge gateways to tenant gateways within the data center by synchronizing NAT tables and firewall rules, allowing these functions to be performed at the tenant gateways for intra-data center traffic, thereby reducing the load on the edge gateway.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If edge gateway performs NAT and firewall processing for all traffic, then security and address translation are ensured, but gateway performance degrades and bottlenecks occur

Engineering Contradiction:
ImproveNAT and firewall functionalityVSAvoidgateway performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the NAT and firewall processing functions from the edge gateway and distributes them to multiple tenant gateways. Each tenant gateway maintains local NAT tables and firewall rules, allowing independent processing of traffic for its respective tenants. This segmentation eliminates the bottleneck at the edge gateway while maintaining security and address translation capabilities across the data center network.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If edge gateway processes all intra-data center traffic, then centralized control is maintained, but traffic flow efficiency decreases due to congestion

Engineering Contradiction:
Improvecentralized controlVSAvoidtraffic flow efficiency
Core Design Contradiction:
Ease of operationVSSpeed

Solution Approach 1:

The patent introduces a hierarchical dimension to the gateway architecture, distributing processing functions across multiple levels (edge gateway and tenant gateways). This dimensional change allows traffic to be processed at the nearest appropriate gateway level rather than all traffic being funneled through the edge gateway, significantly improving traffic flow efficiency while maintaining centralized policy control through the control plane.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Productivity

If NAT tables and firewall rules are synchronized to tenant gateways, then processing load is distributed, but system complexity increases

Engineering Contradiction:
Improveprocessing load distributionVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the control plane continuously monitors and synchronizes NAT tables and firewall rules to the appropriate tenant gateways. This automated feedback loop manages the complexity of distributed state synchronization, ensuring consistency across the system without requiring manual configuration or complex coordination protocols, thereby enabling load distribution while keeping system complexity manageable.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12413527B2Offloading network address translation and firewall rules to tier-1 routers for gateway optimization
Publication Date: 2025.09.09 VMWARE INC
  • US12413527B2 patent drawing
  • US12413527B2 patent drawing
  • US12413527B2 patent drawing

AI summary

The disclosure provides an approach for gateway optimization. Embodiments include receiving, at a first gateway associated with a first tenant within a data center, a packet directed to a first public network address of an endpoint associated with a second tenant within the data center. Embodiments include performing, by the first gateway, network address translation (NAT) to translate the first public network address to a private network address of the endpoint. Embodiments include forwarding, by the first gateway, the packet to an edge gateway of the data center. Embodiments include forwarding, by the edge gateway, the packet to a second gateway associated with the second tenant within the data center without sending the packet to a public interface of the edge gateway. Embodiments include forwarding, by the second gateway, the packet to the endpoint.