Automated VPN Site Detection via BGP Attributes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual configuration of network monitoring tools for Virtual Private Networks (VPNs) is not scalable and becomes difficult to administer for large numbers of VPNs, especially in MPLS-based VPN setups where BGP is used for routing information distribution.

Innovation Solution

A method and computer program product that automatically detect VPN sites by analyzing Border Gateway Protocol (BGP) messages received from Provider Edge (PE) routers, using attributes such as extended community attributes to identify VPN sites, enabling an auto-discovery mechanism for network management systems to synchronize VPN configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual configuration of network monitoring tools is used for VPN sites, then configuration accuracy can be ensured, but scalability deteriorates and administrative burden increases for large numbers of VPNs

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidscalability
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system enables automatic self-configuration of network monitoring tools by having PE routers autonomously generate and distribute BGP messages containing VPN site identification information. The network management system automatically processes these messages and configures monitoring tools without human intervention, allowing the system to serve itself and eliminating manual configuration requirements while maintaining both accuracy and scalability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

PE routers perform preliminary actions by automatically generating BGP messages with VPN site identification attributes before the network management system needs the information. This advance preparation of routing information enables the network management system to automatically detect and configure monitoring tools without waiting for manual input, thus improving both scalability and configuration accuracy

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If manual configuration of network monitoring tools is used for VPN sites, then configuration control can be maintained, but ease of operation deteriorates for large numbers of VPNs

Engineering Contradiction:
Improveadministrative easeVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system replaces complex manual configuration operations with automatic self-service mechanisms where PE routers autonomously generate BGP messages and the network management system automatically processes them to configure monitoring tools. This eliminates the need for administrators to manually configure each VPN site, dramatically improving ease of operation while the standardized BGP protocol framework maintains system manageability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The BGP protocol framework serves multiple functions: it distributes routing information, identifies VPN sites through extended community attributes, and triggers automatic configuration of network monitoring tools. This multi-functionality consolidates what would otherwise require separate manual processes into a single automated mechanism, improving ease of operation without proportionally increasing system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9954761B2Dynamic detection of VPN sites
Publication Date: 2018.04.24 ARBOR NETWORKS INC
  • US9954761B2 patent drawing
  • US9954761B2 patent drawing
  • US9954761B2 patent drawing

AI summary

A method for automatically detecting and configuring Virtual Private Network (VPN) sites is provided. A Border Gateway Protocol (BGP) message is received from a Provider Edge (PE) router. The BGP message includes one or more attributes. The VPN site is identified based on the one or more attributes. Such attributes may include extended community attributes.