Virtual Branch Node Local VNF Manager Port Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtual branch environments, managing hardware platforms and orchestrating virtual network functions (VNFs) across a wide area network (WAN) is challenging due to constrained WAN addressing and the need to preserve IP addresses, while ensuring secure access and efficient routing without increasing the number of subnets or routing entries.
Innovation Solution
A local VNF manager is implemented within the virtual branch node, which establishes a logical local management network, allowing the central orchestrator to access VNFs securely through a WAN interface by using port address translation and network address translation, thereby minimizing the increase in WAN IP addresses and routing entries.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If a central orchestrator directly manages VNFs across multiple branch locations through WAN, then centralized control and orchestration is achieved, but WAN IP address consumption increases and routing complexity grows
Solution Approach 1:
A local VNF manager is introduced as an intermediary component at each branch location. This local manager handles VNF lifecycle operations locally, acting as a mediator between the central orchestrator and VNFs. The local manager maintains a local management network that isolates VNF traffic from WAN routing, thereby enabling centralized control without proportionally increasing WAN IP address consumption or routing complexity.
Solution Approach 2:
The management architecture is segmented into local and central functions. The local VNF manager handles local VNF operations independently, while the central orchestrator provides high-level coordination. This segmentation allows the system to scale without requiring the central orchestrator to directly manage all VNFs, reducing the burden on WAN resources.
2Reliability
If VNFs are deployed with external port mappings for WAN access, then secure access to VNFs is enabled, but routing entries and network complexity increase
Solution Approach 1:
The local VNF manager pre-configures port mappings and network routes locally before VNFs need to be accessed from WAN. This preliminary setup establishes secure access pathways in advance, allowing VNFs to be accessed securely without requiring complex routing configurations to be created dynamically or increasing overall network complexity.
3Reliability
If physical appliances are used in branch locations, then service functions are provided with hardware reliability, but deployment flexibility and speed are reduced
Solution Approach 1:
The patent implements virtualization by creating virtual copies of network functions (VNFs) that run on standard hardware platforms instead of requiring physical appliances. These virtual instances can be deployed through software installation and configuration, enabling rapid deployment without the need for physical hardware shipment, installation, and configuration at each branch location.
Solution Approach 2:
Physical hardware appliances are replaced with virtualized network functions that run on software-defined platforms. This substitution eliminates the mechanical processes of physical device deployment, wiring, and hardware configuration, replacing them with automated software-based deployment mechanisms that significantly increase deployment speed.
Data Source
AI summary
A device is configured to support one or more virtual networking functions at a branch in a network. The device receives from a central control entity a command to deploy a particular virtual networking function, the command including or accompanied by a deployment file that identifies an external port at which the particular virtual networking function is accessed externally at the device. The device maps the external port to an internal port on an internal management network of the device, and stores a portmapping entry for the particular virtual networking function based on the mapping. The device sends to the central control entity a notification containing portmapping information that indicates the internal port to which the external port is mapped.


