SD-WAN IPSec Tunnel Multiplexing for VRF Cloud Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies do not effectively segment traffic from routers that rely on IPSec Tunnels, preventing seamless connection to cloud-based networks.
Innovation Solution
Implementing a VRF Router/VRF routing gateway to connect an IPSec-WAN fabric to a VRF segment base routing fabric, using a Software Defined Cloud Interconnect (SDCI) Router to route traffic to cloud services, and employing IPSec tunnel multiplexing and IP-Security Group Tag (IP-SGT) bindings for network segmentation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IPSec Tunnels are used for connectivity, then secure network connection is achieved, but network segmentation capability is lost
Solution Approach 1:
The patent introduces VRF (Virtual Routing and Forwarding) segments that divide the network into isolated virtual routing instances. Each VRF segment can handle traffic independently while maintaining IPSec tunnel connectivity, enabling logical segmentation without compromising the underlying secure tunnel infrastructure.
Solution Approach 2:
The patent employs a VRF router as an intermediary device between IPSec tunnel endpoints and cloud-based services. This intermediary performs VRF routing lookups and segmentations, allowing traffic from IPSec tunnels to be properly routed to appropriate VRF segments while maintaining both security and segmentation capabilities.
2Ease of operation
If traditional IPSec routing is used, then connectivity to remote sites is achieved, but connection to cloud-based networks is prevented
Solution Approach 1:
The patent makes the VRF router multi-functional by enabling it to handle both traditional IPSec tunnel routing to remote sites and routing to cloud-based services. The router performs VRF routing lookups that can direct traffic to either IPSec tunnels or cloud services based on destination, providing universal connectivity capability.
Solution Approach 2:
The patent adds a new dimension to routing by introducing VRF segment-based routing tables alongside traditional routing. This layered routing approach allows traffic to be first routed based on VRF segment membership, then forwarded appropriately to IPSec tunnels or cloud services, enabling multi-dimensional routing decisions.
3Reliability
If network segmentation is implemented, then traffic isolation is achieved, but device compatibility is reduced
Solution Approach 1:
The VRF router acts as an intermediary that implements segmentation logic centrally, allowing legacy IPSec devices without native segmentation support to benefit from traffic isolation. The segmentation is performed at the VRF router level rather than requiring support from endpoint devices, maintaining compatibility while achieving isolation.
Data Source
AI summary
Generally, Software-Defined Wide Area Networks (SD-WAN) generally do not support network segmentation. The concepts disclosed herein connects IPSec SD-WAN fabric to a Virtual Routing and Forwarding (VRF) router and make use of a Software Defined Cloud Interconnect (SDCI) Router to route traffic from IPSec SD-WAN to various cloud services from the SDCI Router in the fabric. The concepts disclosed herein also provides for tunnel multi-plexing that takes incoming and outgoing traffic and maps VPNs to any service VRF associated with the cloud based services.


