VRF-Based Network Segmentation Without Separate Subnets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional network segmentation methods require a one-to-one mapping between network segments and layer-3 networks, leading to increased overhead, resource usage, and cost, making them impractical for mid-market enterprise deployments that need multiple layer-3 domains without separate IP subnets.
Innovation Solution
Implementing virtual routing functions (VRFs) per logical subnet segment, mapping each to a Virtual Network Identifier (VNI) and Scalable Group Tag (SGT), allowing multiple layer-3 virtual or logical segments without separate IP subnets, and maintaining layer-2 and layer-3 address tables to enable secure policy-based segmentation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional VLAN based segmentation or overlay-based architectures are used, then network segmentation and security are achieved, but increased overhead and resource usage occur
Solution Approach 1:
The patent merges multiple layer-3 virtual networks into a single shared layer-3 domain, allowing multiple VLANs to coexist without requiring separate IP subnets for each segment. This consolidation reduces the overall number of layer-3 domains needed while maintaining segmentation through virtual routing and forwarding instances.
Solution Approach 2:
The patent creates a universal layer-3 domain that serves multiple network segments simultaneously through the use of virtual routing and forwarding (VRF) instances. Each VRF instance provides isolated routing tables and policies for different segments, enabling one layer-3 domain to fulfill the functions of multiple traditional separate domains.
2Reliability
If one to one mapping of network segment to layer-3 network is implemented, then network segmentation is achieved, but device complexity and cost increase
Solution Approach 1:
The patent segments the layer-3 domain into multiple virtual routing and forwarding (VRF) instances, each handling a specific network segment. This segmentation allows logical separation of routing tables and policies while physically sharing the same layer-3 domain, reducing the need for multiple physical or separate logical layer-3 networks.
Solution Approach 2:
The patent introduces a virtualization dimension to the traditional one-to-one mapping model. Instead of mapping each network segment to a separate layer-3 network in physical space, multiple segments are mapped to the same layer-3 domain in virtual space through VRF instances, adding a layer of abstraction that reduces complexity.
3Reliability
If separate layer-3 domains are used for each network segment, then secure segmentation is achieved, but scalability and efficiency decrease
Solution Approach 1:
The patent creates virtual copies of routing and forwarding functionality through VRF instances within a shared layer-3 domain. Each VRF instance maintains its own routing table and policies as a virtual copy, providing isolation and security without requiring separate physical layer-3 domains for each network segment.
Data Source
AI summary
Secure network segmentation using logical subnet segments is described. A single network segment or subnet provided by a third party is mapped into multiple layer-3 virtual or logical segments without requiring separate subnets. This mapping is accomplished by using virtual routing functions (VRFs) per logical subnet segment while retaining a single subnet across the segments. The logical subnet segments interact with the single network segment provided by the third party (ISP). The layer-3 VRF instances are created without the need for separate IP subnet pools per layer-3 segment. Each VRF instance for the various logical subnet segments is mapped to an identifier and tag.


