VRF-Based Network Segmentation Without Separate Subnets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network segmentation methods require a one-to-one mapping between network segments and layer-3 networks, leading to increased overhead, resource usage, and cost, making them impractical for mid-market enterprise deployments that need multiple layer-3 domains without separate IP subnets.

Innovation Solution

Implementing virtual routing functions (VRFs) per logical subnet segment, mapping each to a Virtual Network Identifier (VNI) and Scalable Group Tag (SGT), allowing multiple layer-3 virtual or logical segments without separate IP subnets, and maintaining layer-2 and layer-3 address tables to enable secure policy-based segmentation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional VLAN based segmentation or overlay-based architectures are used, then network segmentation and security are achieved, but increased overhead and resource usage occur

Engineering Contradiction:
Improvenetwork segmentation and securityVSAvoidoverhead and resource usage
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent merges multiple layer-3 virtual networks into a single shared layer-3 domain, allowing multiple VLANs to coexist without requiring separate IP subnets for each segment. This consolidation reduces the overall number of layer-3 domains needed while maintaining segmentation through virtual routing and forwarding instances.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal layer-3 domain that serves multiple network segments simultaneously through the use of virtual routing and forwarding (VRF) instances. Each VRF instance provides isolated routing tables and policies for different segments, enabling one layer-3 domain to fulfill the functions of multiple traditional separate domains.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If one to one mapping of network segment to layer-3 network is implemented, then network segmentation is achieved, but device complexity and cost increase

Engineering Contradiction:
Improvenetwork segmentationVSAvoidmapping complexity and cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the layer-3 domain into multiple virtual routing and forwarding (VRF) instances, each handling a specific network segment. This segmentation allows logical separation of routing tables and policies while physically sharing the same layer-3 domain, reducing the need for multiple physical or separate logical layer-3 networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtualization dimension to the traditional one-to-one mapping model. Instead of mapping each network segment to a separate layer-3 network in physical space, multiple segments are mapped to the same layer-3 domain in virtual space through VRF instances, adding a layer of abstraction that reduces complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If separate layer-3 domains are used for each network segment, then secure segmentation is achieved, but scalability and efficiency decrease

Engineering Contradiction:
Improvesecure segmentationVSAvoidnetwork management efficiency and scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent creates virtual copies of routing and forwarding functionality through VRF instances within a shared layer-3 domain. Each VRF instance maintains its own routing table and policies as a virtual copy, providing isolation and security without requiring separate physical layer-3 domains for each network segment.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12003348B2Micro and macro segmentation in enterprise networks without a per segment layer-3 domain
Publication Date: 2024.06.04 CISCO TECHNOLOGY INC
  • US12003348B2 patent drawing
  • US12003348B2 patent drawing
  • US12003348B2 patent drawing

AI summary

Secure network segmentation using logical subnet segments is described. A single network segment or subnet provided by a third party is mapped into multiple layer-3 virtual or logical segments without requiring separate subnets. This mapping is accomplished by using virtual routing functions (VRFs) per logical subnet segment while retaining a single subnet across the segments. The logical subnet segments interact with the single network segment provided by the third party (ISP). The layer-3 VRF instances are created without the need for separate IP subnet pools per layer-3 segment. Each VRF instance for the various logical subnet segments is mapped to an identifier and tag.