VPN Path Identification via Intermediary Routing Database
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In service provider networks, identifying the path and determining the ultimate destination of VPN packets is challenging due to non-unique unroutable IP addresses, making it difficult for network operators to trace issues, perform capacity planning, and identify affected customers, especially when retrieving traffic information from numerous PE routers is expensive and performance-intensive.
Innovation Solution
A system and method that uses a map of route target identifiers to customer names, peers with PE routers to obtain BGP-VPN information, monitors IGP messages, and retrieves NET FLOW information to identify ingress and egress routers, links, and nodes used by individual customers without directly retrieving traffic information from PE routers, even if the ingress router is unknown.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traffic information is retrieved from PE routers to identify VPN packet paths, then path identification accuracy is improved, but network performance is degraded and operational costs increase
Solution Approach 1:
The patent introduces an intermediary system that collects routing information from PE routers and stores it in a database. This intermediary approach allows path identification without continuously querying PE routers for traffic information, thereby maintaining network performance while enabling accurate path tracking through stored routing data and topology information.
Solution Approach 2:
The system performs preliminary actions by collecting and storing routing information, topology data, and customer mapping information in advance. This pre-collected data enables path identification without real-time disruption to network operations, resolving the contradiction between measurement accuracy and network performance.
2Loss of information
If traffic information is retrieved from multiple PE routers to identify customer usage, then measurement capability is improved, but operational complexity and cost increase
Solution Approach 1:
The patent merges multiple data sources including routing information from PE routers, topology data, and customer mapping information into a unified database system. This consolidation allows comprehensive customer usage analysis through a single system rather than managing multiple separate data collection mechanisms, reducing operational complexity while maintaining information completeness.
Solution Approach 2:
The system creates a copy of routing and topology information in a database, separate from the actual network infrastructure. This database copy enables extensive analysis and customer usage tracking without modifying or adding complexity to the operational network devices themselves.
3Difficulty of detecting and measuring
If routing information is collected from all PE routers to enable path tracing, then troubleshooting capability is improved, but system resource consumption increases
Solution Approach 1:
The patent extracts only the necessary routing information, topology data, and customer mapping information from PE routers and stores it in a database. This extraction approach enables comprehensive path tracing and troubleshooting capabilities while minimizing the resources required for ongoing data collection, as the extracted data can be queried without continuous network disruption or additional resource consumption.
Data Source
AI summary
A system and method collects information for VPN traffic from non edge routers that are coupled to edge routers and identifies the path the traffic took and the customer corresponding to the VPN. The system and method also identifies the ingress router coupled to the non edge router from which the traffic was collected. The system and method may assign identifiers to route targets.


