Enterprise Network Architecture for Wireless VPN Tunneling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise networks face challenges in securely managing access to network applications and services, particularly in restricting unauthorized access while allowing limited access to unauthenticated users, especially in large-scale environments with numerous remote sites.

Innovation Solution

The implementation of a centralized enterprise network architecture that includes a central site with a termination device managing a restricted network segment and remote sites with authorized and unauthorized access WLANs, utilizing GRE-over-IP tunneling to segregate and secure communications, with a database mapping wireless communication devices to VLANs and tunnels, allowing only authorized devices to access the restricted network segment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized security policy management is implemented across multiple remote sites, then security control and access restriction are improved, but network infrastructure complexity and deployment difficulty increase

Engineering Contradiction:
Improvesecurity controlVSAvoidnetwork infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network is segmented into virtual LANs (VLANs) that are mapped to specific tunnels, creating distinct security zones. Each remote site is divided into authorized and unauthorized access WLANs, allowing granular security control without increasing overall system complexity. The segmentation enables centralized management of security policies across distributed locations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A centralized database serves as an intermediary between wireless communication devices and the network infrastructure. This database stores mapping information between devices, WLANs, VLANs, and tunnels, automatically routing traffic according to security policies without requiring complex local configuration at each remote site.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If unauthorized users are completely restricted from accessing the enterprise network, then network security is improved, but legitimate guest access requirements are not met

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Different quality of service and access rights are assigned to different WLANs within the same physical network. Authorized access WLANs provide full network access while unauthorized access WLANs provide limited internet-only access. This local differentiation allows simultaneous coexistence of secure internal network access and flexible guest access without compromising overall security.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The network traffic is segmented into different virtual LANs based on user authorization status. Unauthorized users are confined to a separate VLAN that provides internet access but is isolated from the internal enterprise network, while authorized users access a different VLAN with full network privileges.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If IP routing is implemented at each remote site to handle broadcast/multicast communications, then communication functionality is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvecommunication functionalityVSAvoidprocessing overhead
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The centralized database automatically handles broadcast and multicast communication routing by maintaining mapping information between WLANs, VLANs, and tunnels. Remote site devices do not need to perform complex routing decisions; instead, the system self-manages traffic distribution based on pre-configured mappings, reducing processing overhead at remote locations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7961725B2Enterprise network architecture for implementing a virtual private network for wireless users by mapping wireless LANs to IP tunnels
Publication Date: 2011.06.14 EXTREME NETWORKS INC
  • US7961725B2 patent drawing
  • US7961725B2 patent drawing
  • US7961725B2 patent drawing

AI summary

An enterprise network is provided which includes a central site, a network and a remote site communicatively coupled to the central site over the network. The central site includes a first termination device in communication with a restricted network segment including at least one server. The remote site includes an infrastructure device, an authorized access wireless local area network (WLAN), and an unauthorized access WLAN. The infrastructure device comprises a second termination device which communicates with the first termination device over the network. The authorized access WLAN allow communications with the central site via the second termination device over a tunnel coupling the first termination device to the second termination device, whereas the unauthorized access WLAN allows communications with the network via the second termination device.