IP Library › Granted Patent US 11,818,096
Granted Patent B2
US 11,818,096 · App. 17/084,453 · Granted Nov 14, 2023

Enforcement of inter-segment traffic policies by network fabric control plane

Inventors: Prakash C. Jain (Fremont, CA); Sanjay Kumar Hooda (Pleasanton, CA); Satish Kumar Kondalam (Milpitas, CA); Vikram Vikas Pendharkar (San Jose, CA); Anoop Vetteth (Fremont, CA); Solomon T Lucas (Sunnyvale, CA)
Assignee: Cisco Technology, Inc.
H04L63/0227H04L47/825H04L2212/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,818,096
App. No.
17/084,453
Granted
Nov 14, 2023
Kind
B2
Abstract

This disclosure describes techniques to operate a control plane in a network fabric. The techniques include determining a stateless rule corresponding to communication between a first segment of the network fabric and a second segment of the network fabric. The techniques further include configuring the control plane to enforce the stateless rule.

Claims (59)

1. A method of operating a control plane in a network fabric, comprising:

receiving, at the control plane that enforces network policy on communications in the network fabric, a stateless rule corresponding to communication between a first virtual forwarding and routing (VRF) segment of the network fabric and a second VRF segment of the network fabric;

receiving first network layer prefixes associated with first subscriber devices in the first VRF segment and second network layer prefixes associated with second subscriber devices in the second VRF segment;

adding, to a site registration table of the control plane, the first network layer prefixes associated with the first VRF segment, and the second network layer prefixes associated with the second VRF segment; and

receiving a packet sent from a first subscriber device of the first VRF, the packet having a source address that is included in the first network layer prefixes and a destination address included in the second network layer prefixes; and

determining, using the stateless rule, the source address, and the destination address, that the packet is allowed to be communicated from the first VRF and to the second VRF.

2. The method of claim 1 , further comprising:

at least one of configuring a firewall service to not enforce the stateless rule or configuring the firewall service to enforce at least one of the stateless rule or a stateful rule in coordination with the control plane.

3. The method of claim 1 , further comprising:

configuring the control plane with the stateless rule as at least a portion of an extranet policy.

4. The method of claim 1 , wherein:

the network fabric is of a Locator ID Separation Protocol (LISP) type; and

the control plane includes at least a Map-Server/Map-Resolver (MSMR).

5. The method of claim 1 , wherein:

the network fabric is of a BGP EVPN type; and

the control plane includes at least a centralized route reflector.

6. The method of claim 1 , further comprising:

determining an overlap between the source address associated with the first VRF segment and the destination address associated with the second VRF segment; and

enabling communication between the first VRF segment and the second VRF segment based at least in part on the overlap.

7. The method of claim 1 , further comprising:

by the control plane, receiving a message from a service router that is coupled for communication to a firewall service, the message resulting at least in part from a firewall advertisement from the firewall service to attract communication between the first VRF segment of the network fabric and the second VRF segment of the network fabric; and

configuring the control plane to enforce the stateless rule includes configuring the control plane to allow the communication between the first VRF segment of the network fabric and the second VRF segment of the network fabric, in accordance with the message.

8. The method of claim 7 , wherein:

the firewall advertisement includes an indication of a specific prefix, to attract inter-VRF segment communication from at least one subscriber associated with the specific prefix.

9. The method of claim 7 , wherein:

the firewall advertisement includes an indication of any prefix, to attract inter-VRF segment communication from at least one subscriber associated with any prefix.

10. A method of operating a control plane in a network fabric, comprising:

receiving, at the control plane that enforces network policy on communications in the network fabric, a policy corresponding to communication between a first virtual forwarding and routing (VRF) segment of the network fabric and a second VRF segment of the network fabric;

receiving first network layer prefixes associated with first subscriber devices in the first VRF segment and second network layer prefixes associated with second subscriber devices in the second VRF segment;

receiving a message originating in a first VRF segment of the network fabric and destined for a second VRF segment of the network fabric, the message having a source address and a destination address; and

applying the policy, and using the source address and the destination address, to determine whether to allow the message to be provided to the second VRF segment.

11. The method of claim 10 , further comprising:

configuring the control plane with the policy.

12. The method of claim 10 , wherein the policy includes an indication of the first VRF segment and an indication of the second VRF segment.

13. A control plane, comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations of:

receiving, at the control plane that enforces network policy on communications in a network fabric, a stateless rule corresponding to communication between a first virtual forwarding and routing (VRF) segment of the network fabric and a second VRF segment of the network fabric;

receiving first network layer prefixes associated with first subscriber devices in the first VRF segment and second network layer prefixes associated with second subscriber devices in the second VRF segment;

adding, to a site registration table of the control plane, the first network layer prefixes associated with the first VRF segment, and the second network layer prefixes associated with the second VRF segment; and

receiving a packet sent from a first subscriber device of the first VRF, the packet having a source address that is included in the first network layer prefixes and a destination address included in the second network layer prefixes; and

determining, using the stateless rule, the source address, and the destination address, that the packet is allowed to be communicated from the first VRF and to the second VRF.

14. The control plane of claim 13 , the operations further comprising:

at least one of configuring a firewall service to not enforce the stateless rule or configuring the firewall service to enforce at least one of the stateless rule or a stateful rule in coordination with the control plane.

15. The control plane of claim 13 , the operations further comprising:

configuring the control plane with the stateless rule as at least a portion of an extranet policy.

16. The control plane of claim 13 , wherein:

the network fabric is a Locator ID Separation Protocol (LISP) network fabric; and

the control plane comprises at least a Map-Server/Map-Resolver (MSMR).

17. The control plane of claim 13 , further comprising:

determining an overlap between the source address associated with the first VRF segment and the destination address associated with the second VRF segment; and

enabling communication between the first VRF segment and the second VRF segment based at least in part on the overlap.

18. The control plane of claim 13 , the operations further comprising:

by the control plane, receiving a message from a service router that is coupled for communication to a firewall service, the message resulting at least in part from a firewall advertisement from the firewall service to attract communication between the first VRF segment of the network fabric and the VRF second segment of the network fabric; and

configuring the control plane to enforce the stateless rule includes configuring the control plane to allow the communication between the first VRF segment of the network fabric and the second VRF segment of the network fabric, in accordance with the message.

19. The control plane of claim 18 , wherein:

the firewall advertisement includes an indication of a specific prefix, to attract inter-VRF segment communication from at least one subscriber associated with the specific prefix.

20. The control plane of claim 18 , wherein:

the firewall advertisement includes an indication of any prefix, to attract inter-VRF segment communication from at least one subscriber associated with any prefix.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2020
From: JAIN, PRAKASH C; HOODA, SANJAY KUMAR; KONDALAM, SATISH KUMAR; PENDHARKAR, VIKRAM VIKAS; VETTETH, ANOOP; LUCAS, SOLOMON T
To: CISCO TECHNOLOGY, INC.
Reel/Frame 054226/0724 →
Continuity (1)
Related Publication 20220141181A1 · May 5, 2022
Cited By (61)
US 12,192,026 US 12,200,038 US 12,200,083 US 12,200,084 US 12,218,776 US 12,218,777 US 12,229,210 US 12,231,253 US 12,231,519 US 12,244,560 US 12,250,089 US 12,250,090 US 12,261,712 US 12,277,187 US 12,277,188 US 12,277,189 US 12,278,878 US 12,278,880 US 12,284,069 US 12,289,383 US 12,294,481 US 12,301,401 US 12,309,123 US 12,309,241 US 12,323,287 US 12,323,500 US 12,323,501 US 12,332,960 US 12,341,860 US 12,355,855 US 12,368,789 US 12,375,582 US 12,411,902 US 12,413,648 US 12,425,492 US 12,438,956 US 12,445,511 US 12,457,273 US 12,483,635 US 12,517,972 US 12,524,490 US 12,524,491 US 12,536,243 US 12,542,764 US 12,549,645 US 12,563,130 US 12,587,429 US 12,587,430 US 12,587,579 US 12,603,809 US 12,652,330 US 12,659,218 US 12,671,750 US 12,706,984 US 12,719,734 US 12,719,735 US 12,719,945 US 12,724,840 US 12,726,551 US 12,739,296 US 12,744,828