Virtual Routers for Multi-Cloud VRF Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The integration of on-premises networks with public cloud networks is hindered by the lack of uniformity in policy management, configuration parameters, and routing models, leading to difficulties in maintaining isolation and segregation of network paths across multi-cloud fabrics, particularly due to restrictions imposed by public cloud providers and the loss of VRF information during data packet transmission.
Innovation Solution
The solution involves spinning up gateways to manage VPCs with overlapping subnets, running virtual routers that preserve VRF information using network overlays like VxLAN, and employing sink VRFs for source-IP based VRF selection to ensure seamless connectivity and segregation across multi-cloud interconnects.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If public cloud gateways are used to manage VPCs with overlapping subnets, then connectivity between cloud and on-premises networks is enabled, but VRF information is lost during data packet transmission
Solution Approach 1:
The patent introduces virtual routers as intermediary devices between public cloud gateways and on-premises networks. These virtual routers run network overlays (VxLAN) that encapsulate original VRF information within tunnel packets, allowing VRF segmentation to be preserved end-to-end even when passing through cloud gateways that don't natively support VRF. The virtual router acts as a mediator that translates between gateway routing and VRF routing domains.
Solution Approach 2:
The patent adds a new dimensional layer by implementing network overlays (VxLAN tunnels) that create a virtual networking dimension above the physical gateway infrastructure. This overlay dimension carries VRF information that would otherwise be lost at the gateway layer, enabling VRF segmentation to extend into the cloud environment through an additional networking dimension.
2Reliability
If multiple VRF routing tables are implemented to maintain isolation and segmentation, then network security and scalability are improved, but device complexity and configuration difficulty increase
Solution Approach 1:
The patent makes virtual routers multi-functional by enabling them to perform both gateway functions (routing to cloud networks) and VRF routing functions (maintaining segmentation). A single virtual router can handle multiple VRF routing tables simultaneously while also providing overlay tunneling capabilities, consolidating what would otherwise require separate dedicated devices for each function.
Solution Approach 2:
The patent merges gateway functionality and VRF routing functionality into unified virtual router instances. Instead of requiring separate physical gateways and VRF routers, the virtual router combines both roles, reducing device complexity while maintaining network isolation through software-based multi-functionality.
3Reliability
If network overlays like VxLAN are used to preserve VRF information, then VRF segregation is maintained across cloud interconnects, but device complexity and overhead increase
Solution Approach 1:
The patent implements self-service by enabling virtual routers to automatically discover and establish VxLAN overlay tunnels with other virtual routers based on VRF routing table information. The system autonomously configures overlay parameters and maintains tunnel state without requiring manual intervention, reducing the operational complexity of overlay deployment while preserving VRF segregation.
Data Source
AI summary
Techniques for maintaining isolation and segregation for network paths through multi-cloud fabrics using VRF technologies. The techniques include running virtual routers in a cloud network that connect the cloud network to an on-premises network using a network overlay that preserves VRF information in data packets. Further, the virtual routers connect to individual gateways in the cloud network using tunnels, and each individual gateway is connected to multiple VPCs without overlapping subnets. The virtual routers may assign a sink VRF to each gateway connection that can be used to perform source-IP based VRF selection by mapping source IP addresses in each tunnel connection to appropriate VRFs for the source IP addresses. In this way, virtual routers may use sink VRFs to translate into the VRF information for data packets from the VPCs via source-IP based lookup, and use the corresponding VRF route table to determine next hops for data packets.


