Tunnel Encapsulation Header for Application Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In tunnel encapsulated traffic, underlay nodes such as switches and routers lose visibility into application traffic, making application-specific processing, analytics, and policy control difficult without expensive deep packet inspection, which requires hardware upgrades and increased processing time.
Innovation Solution
Appending an encapsulation header with an application identification field to data units, allowing forwarding nodes to identify and prioritize applications without deep packet inspection, using application-specific MAC addresses to enable end-to-end application tracking and analytics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If deep packet inspection is performed on every node in the path to identify applications, then application identification accuracy is improved, but processing time increases and hardware upgrades are required
Solution Approach 1:
The application identification information is inserted into the encapsulation header at the source end (virtual switch or host) before the traffic enters the underlay network. This preliminary action allows underlay nodes to identify applications without performing deep packet inspection, thereby avoiding increased processing time and hardware upgrade requirements while maintaining accurate application identification.
2Measurement precision
If deep packet inspection is performed on every node in the path to identify applications, then application identification accuracy is improved, but device complexity and cost increase due to hardware upgrades
Solution Approach 1:
The application identification function is extracted from the underlay nodes and relocated to the overlay control plane (virtual switch or host). The underlay nodes only need to forward packets based on the application identification information already present in the encapsulation header, eliminating the need for complex deep packet inspection hardware while maintaining accurate application identification.
3Ease of manufacture
If application identification is implemented in underlay nodes without encapsulation header modification, then existing hardware can be used, but underlay nodes cannot identify applications inside tunnels
Solution Approach 1:
The encapsulation header serves as an intermediary structure that carries application identification information from the overlay network through the underlay network. By modifying the encapsulation header to include application identification fields, underlay nodes gain visibility into applications without requiring changes to their core forwarding hardware, thus maintaining hardware compatibility while enabling application identification.
Data Source
AI summary
In some embodiments a method includes receiving, at a first network device, a data unit to be sent to second network device via a tunnel, the data unit associated with an application. The method includes appending, to the data unit, an encapsulation header that includes a first portion configured such that the second network device is configured to forward the data unit based on the second portion of the encapsulation header that is configured to identify the application. The method includes sending, from the first network device to the second network device via a first portion of the tunnel, the data unit such that the second network device appends the encapsulation header to the data unit prior to forwarding the data unit via a second portion of the tunnel.


