VXLAN Gateway De-encapsulation for Packet Visibility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Legacy Inter-Networking Elements (INEs) lack visibility into original packets within virtual overlay network traffic due to encapsulation, preventing them from implementing sophisticated network security and services.
Innovation Solution
A system with an interface and processor logic that communicates with a virtual overlay network gateway, capable of de-encapsulating packets, performing services on them, and re-encapsulating or sending them without encapsulation based on destination network type, allowing for advanced routing and security applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If packets are encapsulated with overlay headers in virtual overlay networks, then location transparency and virtual network connectivity are achieved, but visibility of original packets is lost preventing security inspection and service implementation
Solution Approach 1:
The patent introduces VXLAN gateway devices as intermediary elements between virtual overlay networks and legacy infrastructure. These gateways perform de-encapsulation of VXLAN packets to expose inner packets for security inspection and service processing, then re-encapsulate them for forwarding. This intermediary mechanism resolves the contradiction by temporarily removing encapsulation for processing while maintaining it for network transparency.
Solution Approach 2:
The patent segments the network processing function into distinct components: VXLAN gateways handle encapsulation/decapsulation, overlay network devices handle security inspection and service processing of inner packets, and legacy infrastructure handles standard packet forwarding. This segmentation allows each component to operate in its optimal domain, resolving the visibility problem without compromising virtual network functionality.
2Productivity
If legacy Inter-Networking Elements process encapsulated VXLAN packets, then network infrastructure utilization is maintained, but sophisticated security and services cannot be implemented due to lack of packet visibility
Solution Approach 1:
The VXLAN gateway acts as a mediator that translates between the encapsulated VXLAN format and the original packet format. It receives encapsulated packets from the virtual network, de-encapsulates them for processing by legacy infrastructure with enhanced capabilities, and re-encapsulates them for return to the virtual network. This enables legacy infrastructure to process both types of packets while gaining security and service capabilities.
Solution Approach 2:
The patent creates a universal processing architecture where the overlay network device can handle both encapsulated VXLAN packets and standard packets. By implementing both VXLAN termination and standard packet processing functions in the same infrastructure, the system achieves multi-functionality that resolves the contradiction between infrastructure utilization and security capabilities.
3Loss of information
If VXLAN gateways terminate and de-encapsulate packets, then visibility for security inspection is achieved, but additional processing steps increase device complexity
Solution Approach 1:
The patent merges the VXLAN gateway functionality with the overlay network device into a single integrated component. This combination eliminates the need for separate termination and inspection devices, reducing overall system complexity while maintaining full packet visibility for security inspection and service processing.
Data Source
AI summary
In one embodiment, a method includes receiving network traffic, determining whether packets have an overlay header, terminating a tunnel and de-encapsulating inner packets of packets having an overlay header, performing services on the inner packets in response to a determination that services are to be performed on the inner packets, originating a tunnel, encapsulating a first packet of the serviced inner packets with an overlay header, and switching the encapsulated serviced inner packets to a destination address in a virtual network in response to determining that the first packet is to be switched to the destination address in the virtual network, and switching a second packet of the serviced inner packets to a destination address in a non-virtual network without encapsulating the serviced inner packets with the overlay header in response to a determination that the second packet is to be switched to the destination address in the non-virtual network.


