Abstract
Proposed herein is a stateless mechanism for disambiguating overlapping private Internet Protocol version 4 (IPv4) traffic from multiple tenants by synthesizing Internet Protocol version 6 (IPv6) addresses that encode both tenant or virtual routing and forwarding (VRF) identity and the original IPv4 source address. Shared downstream gateways, including virtual private network (VPN), zero trust network access (ZTNA), Internet Protocol Security (IPsec), and cloud gateways, can receive native IPv6 traffic with globally unique source addresses without modification to understand tenants, VRFs, or overlay networks. Because the mapping is algorithmically reversible from the IPv6 address itself, return traffic can be translated back to the correct tenant without per-flow network address translation (NAT) state. The mechanism therefore supports active-active scaling and simple failover.
Creative Commons License

This work is licensed under a Creative Commons Attribution 4.0 License.
Recommended Citation
Garg, Rashmi; Tollet, Jerome; Ganne, Benoit; Kainikara, Anil Kumar; and de Kerhor, Arthur, "MULTI-TENANT TRAFFIC DISAMBIGUATION WITH TENANT-INDEXED IPV6 ADDRESSES", Technical Disclosure Commons, ()
https://www.tdcommons.org/dpubs_series/11791