VXLAN Tunneling for Private Network to VPC Connectivity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for connecting a private network to a Virtual Private Cloud (VPC) face limitations such as inability to support layer 2 applications, unbalanced traffic load, and high costs due to the need for multiple gateways, as well as security and performance issues when using public internet connections.
Innovation Solution
The implementation of Virtual Extensible Local Area Network (VXLAN) tunneling technology for secure and scalable network traffic transmission from a cloud data center's edge router to gateway hardware, allowing for efficient layer 2 traffic handling and load balancing across multiple gateway servers, enabling secure and cost-effective access to VPCs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional methods are used to connect private network to VPC, then connection is established, but layer 2 applications cannot be supported and traffic load is unbalanced
Solution Approach 1:
The patent introduces a gateway virtual machine as an intermediary component between the private network and VPC. This gateway VM implements VXLAN tunneling to establish layer 2 connectivity while distributing traffic across multiple physical gateways, thereby supporting layer 2 applications and balancing traffic load simultaneously.
Solution Approach 2:
The patent changes the network tunneling parameter from conventional methods to VXLAN (Virtual Extensible LAN) tunneling. This parameter change enables layer 2 application support and provides mechanisms for load balancing across multiple gateways, resolving both the adaptability and reliability issues.
2Productivity
If multiple gateways are deployed to support multiple users, then connection capacity increases, but system complexity and cost increase
Solution Approach 1:
The gateway virtual machine is designed with multi-functionality, serving multiple users and VPCs simultaneously through VXLAN tunneling. A single physical gateway can host multiple gateway VMs, each handling different user connections, thereby increasing connection capacity without proportionally increasing physical gateway quantity.
Solution Approach 2:
Instead of deploying separate physical gateways for each user, the patent creates virtual copies (gateway VMs) of the gateway function on shared physical hardware. This virtualization approach increases connection capacity while reducing overall system complexity and cost.
3Ease of operation
If public internet connection is used, then accessibility is improved, but security and performance deteriorate
Solution Approach 1:
The patent introduces encrypted VXLAN tunnels as an intermediary communication channel between the private network and VPC. This tunneling mechanism provides secure and high-performance connectivity while maintaining accessibility, effectively replacing vulnerable public internet connections with dedicated encrypted pathways.
Data Source
AI summary
A networking method including receiving, at an edge router of a cloud data center, a virtual private cloud (“VPC”) network communication from a private network via a dedicated physical connection line to the edge router. The VPC network communication is forwarded to a gateway hardware group via a first connection using Virtual Extensible Local Area Network (“VXLAN”) technology. The VPC network communication is then forwarded from the gateway hardware group to VPC of a user of the private network via a second connection using VXLAN technology to access a virtual machine (“VM”).


