VXLAN Tunnel Server Centralized Switching Across LANs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The overhead of managing multiple VXLAN tunnels across different LANs increases non-linearly, leading to strain on network devices and deteriorating performance, as the number of point-to-point tunnels grows, necessitating a robust technique for configuring and managing VXLAN tunnels from a cloud-based interface.

Innovation Solution

Configuring VXLAN tunnels between a VXLAN tunnel server and access points using VXLAN profiles, forming tunnel groups that enable secure packet exchange, and switching data packets based on VLAN IDs, thereby improving network performance and administration efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If point-to-point VXLAN tunnels are created between multiple access points to extend across different LANs, then connectivity between LANs is improved, but the number of tunnels increases non-linearly causing network device strain and performance deterioration

Engineering Contradiction:
Improveconnectivity between LANsVSAvoidnumber of VXLAN tunnels
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

A central controller is introduced as an intermediary to manage VXLAN tunnel configurations across multiple access points. The controller receives tunnel configuration requests, determines the necessary tunnel topology, and configures tunnels between access points and a gateway device. This centralized management approach replaces the need for numerous point-to-point tunnels with a more efficient tunnel architecture, reducing the non-linear growth of tunnel数量 while maintaining LAN connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If point-to-point VXLAN tunnels are created between multiple access points, then secure communication between different LANs is achieved, but administrative overhead increases non-linearly

Engineering Contradiction:
Improvesecure communicationVSAvoidadministrative overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements automated tunnel configuration and management through a central controller that autonomously determines tunnel topology and configures access points. The controller receives high-level connectivity requirements and automatically translates them into specific tunnel configurations, eliminating the need for manual configuration of each point-to-point tunnel. This self-service approach maintains secure communication while dramatically reducing administrative overhead and time consumption.

Inventive Principle:
Principle #25Self-service

3Reliability

If encryption such as IPSec is applied to data packets in VXLAN tunnels, then security is improved, but processing overhead and network performance are worsened

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines VXLAN encapsulation with IPSec encryption in a unified tunnel architecture. By merging the virtualization layer (VXLAN) with the security layer (IPSec) into an integrated solution managed by a central controller, the system optimizes the configuration of encrypted tunnels. This consolidation allows for efficient resource utilization and reduced processing overhead compared to managing separate encryption tunnels for each point-to-point connection, thereby maintaining security while improving network performance.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20240179028A1Cloud-based virtual extensable local area network (VXLAN) tunnel switching across access points
Publication Date: 2024.05.30 FORTINET INC
  • US20240179028A1 patent drawing
  • US20240179028A1 patent drawing
  • US20240179028A1 patent drawing

AI summary

VXLAN tunnels are configured between a VXLAN tunnel server and each of the plurality of access points using a VXLAN profile. Tunnel groups are formed between the access point and the plurality of access points. Each tunnel group defines interconnections between VXLAN tunnels such that each tunnel in a group is able to exchange packets securely. A data packet is switched between a first VXLAN tunnel coupled to the first access point on the first LAN and a second VXLAN tunnel coupled to the second access point on the second LAN, based on a VLAN ID stored within of the data packet. The data packet is transmitted to the second station through the second access point on the second LAN over the second VXLAN.