Unified L2/L3 Cloud Gateway for Centralized Policy and ARP Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The separation of Layer 2 (L2) and Layer 3 (L3) gateways in networking systems leads to inconvenient policy changes, scaling challenges, and increased risk of conflicts due to the need to manage policies across different devices from different vendors, along with issues like ARP flooding and complex inter-tenant communication.
Innovation Solution
Integrating L2 and L3 functionalities into a Service Node that includes a centralized gateway (CGW) and service gateway (SGW), allowing for centralized policy management and ARP suppression through a well-hierarchy structure and EVPN control plane, enabling efficient routing and traffic management across virtual machines.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If L2 and L3 gateways are separated into different devices, then each device can be optimized for its specific function, but policy management becomes complex and scaling becomes challenging
Solution Approach 1:
The patent combines L2 gateway and L3 gateway functionalities into a unified gateway device. This integration allows centralized policy management for both L2 and L3 functions in a single device, eliminating the complexity of managing policies across multiple separate devices while maintaining functional optimization through modular architecture.
Solution Approach 2:
The unified gateway device is designed to perform multiple functions including L2 switching, L3 routing, and policy management in a single platform. This multi-functional approach reduces the number of devices needed and simplifies overall network architecture while maintaining specialized functionality through software-based service chains.
2Ease of operation
If L2 and L3 policies are managed on separate devices, then each device can be independently configured, but conflicts between L2 and L3 policies are more likely to occur
Solution Approach 1:
By merging L2 and L3 policy management into a single unified device, the patent enables centralized coordination of policies. The unified gateway can detect and resolve conflicts between L2 and L3 policies before they propagate through the network, reducing the risk of policy conflicts while maintaining independent configuration capabilities through virtualization and service chains.
3Reliability
If separate L2 and L3 gateway devices are used, then vendor specialization can be maintained, but ARP flooding issues occur and scaling becomes difficult
Solution Approach 1:
The unified gateway device acts as an intermediary that consolidates ARP processing for both L2 and L3 functions. By centralizing ARP handling in a single device, the patent prevents ARP flooding between separate L2 and L3 gateways while maintaining vendor specialization through the choice of unified gateway hardware and software platform.
4Device complexity
If L2 and L3 functionalities are integrated in a Service Node, then policy management is simplified and scaling is easier, but the device must handle both L2 and L3 capabilities simultaneously
Solution Approach 1:
The unified gateway device segments L2 and L3 functionalities into separate service chains that can be independently configured and managed. This segmentation allows the device to handle both L2 and L3 capabilities simultaneously while maintaining simplified policy management through centralized control, as each service chain can be optimized for its specific function.
Solution Approach 2:
The patent implements dynamic service chains that can be flexibly configured and adjusted based on network requirements. The unified gateway can dynamically allocate resources and switch between L2 and L3 processing modes as needed, enabling the device to handle dual capabilities while maintaining adaptability to changing network conditions and requirements.
Data Source
AI summary
Disclosed herein are systems, methods, and computer-readable media for managing Layer 2 (L2) and Layer 3 (L3) policies. Traffic is routed from a first VM to a first CGW within a Service Node, where the Service Node can include a centralized policy for both L2 functions and L3 functions, and the first CGW can integrate both L2 gateways and L3 gateways. Based on a floating IP address of the packet, the traffic is routed within the Service Node, the traffic being routed by an access BD from an ingress BD-VIF to an egress BD-VIF. The traffic is then routed from a second CGW that integrates both L2 gateways and L3 gateways to the destination VM.


