VLAN ID-Based VRF Indexing for Network Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional VPN methods in campus networks are overly complex and cumbersome due to the need for multiple VLANs, sub-interfaces, and routing instances, leading to increased computational overhead and provisioning complexity.
Innovation Solution
The method encapsulates VPN traffic using a VLAN ID to identify the virtual route forwarding table, allowing for dynamic association of VLAN-IDs with VRFs, enabling simplified network segmentation and routing decisions across L3 routing entities with a common interface, while maintaining layer 2 segmentation through L2 switching entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple VLANs, sub-interfaces, and routing instances are used for VPN traffic isolation, then traffic segmentation and security are improved, but device complexity and provisioning complexity increase significantly
Solution Approach 1:
The patent merges multiple routing instances and sub-interfaces into a single routing instance and shared interface by using VLAN ID-based virtualization. The single routing instance maintains multiple virtual routing tables indexed by VLAN ID, allowing multiple VPNs to share the same physical and logical interface while maintaining traffic isolation through VLAN tagging and virtual routing table selection.
Solution Approach 2:
The patent makes a single interface and routing instance universal by enabling them to handle multiple VPNs simultaneously through VLAN ID-based identification. The shared interface can receive and forward traffic for multiple different VPNs by examining the VLAN ID in the Ethernet frame and selecting the appropriate virtual routing table, eliminating the need for dedicated interfaces per VPN.
2Reliability
If multiple routing instances and sub-interfaces are deployed for each VPN, then VPN traffic isolation is achieved, but computational overhead increases substantially
Solution Approach 1:
The patent combines multiple routing instance operations into a single routing instance that maintains multiple virtual routing tables. Instead of running separate routing protocols and maintaining separate routing tables for each VPN, the system uses a single routing instance with VLAN ID-based table selection, reducing CPU overhead for routing protocol processing and route table lookups.
Solution Approach 2:
The patent performs preliminary organization of routing information by maintaining multiple virtual routing tables pre-indexed by VLAN ID. This allows the routing system to quickly select the appropriate routing table based on the VLAN ID in the incoming frame without having to process multiple routing instances sequentially, reducing computational overhead during packet forwarding.
3Reliability
If conventional sub-interface assignment to VRF is used for routing, then VPN segmentation is maintained, but the system lacks scalability and requires substantial computing overhead
Solution Approach 1:
The patent inverts the conventional approach by instead of assigning different interfaces to different VRFs, it assigns the same shared interface to multiple VRFs and uses VLAN ID-based identification to select the appropriate VRF. This inversion allows for better scalability as new VPNs can be added by creating new virtual routing tables indexed by new VLAN IDs without requiring new physical or logical interfaces.
Solution Approach 2:
The patent introduces dynamic VLAN ID-based routing table selection that allows the system to adapt to different VPN requirements dynamically. The routing instance can switch between different virtual routing tables based on the VLAN ID in the incoming frame, providing flexible and scalable VPN segmentation that can accommodate changing network requirements without reconfiguring the underlying interface structure.
Data Source
AI summary
A routing mechanism provides network segmentation preservation by route distribution with segment identification, policy distribution for a given VPN segment, and encapsulation/decapsulation for each segment using an Ethernet VLAN_ID, indicative of the VPN segment (subnetwork). Encapsulated segmentation information in a message packet identifies which routing and forwarding table is employed for the next hop. A common routing instance receives the message packets from the common interface, and indexes a corresponding VRF table from the VLAN ID, or segment identifier, indicative of the subnetwork (e.g. segment). In this manner, the routing instance receives the incoming message packet, decapsulates the VLAN ID in the incoming message packet, and indexes the corresponding VRF and policy ID from the VLAN ID, therefore employing a common routing instance over a common subinterface for a plurality of segments (subnetworks) coupled to a particular forwarding device (e.g. VPN router).


