VXLAN Gateway De-encapsulation for Packet Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy Inter-Networking Elements (INEs) lack visibility into original packets within virtual overlay network traffic due to encapsulation, preventing them from implementing sophisticated network security and services.

Innovation Solution

A system with an interface and processor logic that communicates with a virtual overlay network gateway, capable of de-encapsulating packets, performing services on them, and re-encapsulating or sending them without encapsulation based on destination network type, allowing for advanced routing and security applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If packets are encapsulated with overlay headers in virtual overlay networks, then location transparency and virtual network connectivity are achieved, but visibility of original packets is lost preventing security inspection and service implementation

Engineering Contradiction:
Improvevirtual network connectivityVSAvoidpacket visibility
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent introduces VXLAN gateway devices as intermediary elements between virtual overlay networks and legacy infrastructure. These gateways perform de-encapsulation of VXLAN packets to expose inner packets for security inspection and service processing, then re-encapsulate them for forwarding. This intermediary mechanism resolves the contradiction by temporarily removing encapsulation for processing while maintaining it for network transparency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network processing function into distinct components: VXLAN gateways handle encapsulation/decapsulation, overlay network devices handle security inspection and service processing of inner packets, and legacy infrastructure handles standard packet forwarding. This segmentation allows each component to operate in its optimal domain, resolving the visibility problem without compromising virtual network functionality.

Inventive Principle:
Principle #1Segmentation

2Productivity

If legacy Inter-Networking Elements process encapsulated VXLAN packets, then network infrastructure utilization is maintained, but sophisticated security and services cannot be implemented due to lack of packet visibility

Engineering Contradiction:
Improvenetwork infrastructure utilizationVSAvoidsecurity and service capabilities
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The VXLAN gateway acts as a mediator that translates between the encapsulated VXLAN format and the original packet format. It receives encapsulated packets from the virtual network, de-encapsulates them for processing by legacy infrastructure with enhanced capabilities, and re-encapsulates them for return to the virtual network. This enables legacy infrastructure to process both types of packets while gaining security and service capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal processing architecture where the overlay network device can handle both encapsulated VXLAN packets and standard packets. By implementing both VXLAN termination and standard packet processing functions in the same infrastructure, the system achieves multi-functionality that resolves the contradiction between infrastructure utilization and security capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If VXLAN gateways terminate and de-encapsulate packets, then visibility for security inspection is achieved, but additional processing steps increase device complexity

Engineering Contradiction:
Improvepacket visibilityVSAvoidprocessing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent merges the VXLAN gateway functionality with the overlay network device into a single integrated component. This combination eliminates the need for separate termination and inspection devices, reducing overall system complexity while maintaining full packet visibility for security inspection and service processing.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9699277B2Providing services to virtual overlay network traffic
Publication Date: 2017.07.04 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9699277B2 patent drawing
  • US9699277B2 patent drawing
  • US9699277B2 patent drawing

AI summary

In one embodiment, a method includes receiving network traffic, determining whether packets have an overlay header, terminating a tunnel and de-encapsulating inner packets of packets having an overlay header, performing services on the inner packets in response to a determination that services are to be performed on the inner packets, originating a tunnel, encapsulating a first packet of the serviced inner packets with an overlay header, and switching the encapsulated serviced inner packets to a destination address in a virtual network in response to determining that the first packet is to be switched to the destination address in the virtual network, and switching a second packet of the serviced inner packets to a destination address in a non-virtual network without encapsulating the serviced inner packets with the overlay header in response to a determination that the second packet is to be switched to the destination address in the non-virtual network.