VXLAN Overlay Authentication Using VTEP and VNI Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current VXLAN access authentication methods require cumbersome configuration changes on both the underlay and overlay networks when modifying authentication modes, leading to complex configuration and management.
Innovation Solution
Perform VXLAN access authentication on the overlay network, decoupling the underlay and overlay networks, allowing configuration changes to be made solely on the overlay network, and utilizing a VXLAN tunnel endpoint (VTEP) device for centralized authentication and packet encapsulation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VXLAN access authentication is performed on the underlay network, then authentication can be implemented, but configuration complexity increases when modifying authentication modes
Solution Approach 1:
The patent segments the authentication process from the underlay network to the overlay network. The underlay network handles only packet forwarding, while the overlay network performs authentication. This separation allows independent configuration of authentication modes on the overlay network without affecting underlay network configuration, thereby reducing overall configuration complexity.
Solution Approach 2:
The patent introduces an authentication point device as an intermediary between the control point device and the authentication server. This intermediary operates within the overlay network and handles authentication requests, acting as a mediator that decouples the authentication functionality from the underlay network infrastructure.
2Reliability
If authentication configuration is performed on both underlay and overlay networks, then complete authentication is achieved, but management complexity increases
Solution Approach 1:
The patent extracts the authentication configuration requirements from the underlay network and concentrates them entirely in the overlay network. By taking out the authentication functionality from the underlay network layer and placing it in the overlay network layer, the system achieves complete authentication while simplifying management to a single configuration location.
3Reliability
If VXLAN authentication packets are processed through the underlay network, then authentication requests can be transmitted, but authentication efficiency decreases
Solution Approach 1:
The patent moves the authentication process from the underlay network dimension to the overlay network dimension. By changing the operational dimension from underlay to overlay, authentication packets are processed directly within the VXLAN tunnel without being routed through the underlay network, thereby improving authentication efficiency while maintaining reliable transmission.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A VXLAN access authentication method is disclosed, and may be applied to the field of network communication. The method includes: An authentication point device receives a VXLAN authentication packet, where the VXLAN authentication packet is a VXLAN packet. The VXLAN authentication packet includes a VXLAN header and an authentication request sent by a terminal, the VXLAN header includes a first VNI, and the authentication request includes an authentication credential. The authentication point device obtains permission of the terminal or a second VNI based on the authentication credential. The permission of the terminal corresponds to the second VNI. The authentication point device sends the permission of the terminal or the second VNI to a control point device, where the control point device is a device that encapsulates the authentication request into the VXLAN authentication packet. In this application, VXLAN access authentication is performed on an overlay network, so that configuration complexity can be reduced when a VXLAN access authentication mode is modified or created.