Dynamic selection of a VPN gateway based on user behavior

Dynamic VPNC gateway selection techniques in SD-WANs address the inefficiencies of static methods by adapting traffic routing based on user behavior and network conditions, enhancing resource utilization and fault tolerance.

DE102021127677B4Active Publication Date: 2025-06-12HEWLETT PACKARD ENTERPRISE DEV LP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
DE102021127677
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-02-09
Filing Date
2021-10-25
Publication Date
2025-06-12
Estimated Expiration
2041-10-25

AI Technical Summary

Technical Problem

Existing SD-WANs have static VPNC gateway selection methods that fail to dynamically adapt to user behavior and network conditions, leading to inefficient resource utilization and increased risk of network failures.

Method used

The implementation of dynamic VPNC gateway selection techniques that monitor user behavior and network conditions in real-time, allowing for adaptive traffic routing and on-demand VRF ID configuration to optimize resource usage and enhance fault tolerance.

Benefits of technology

This approach enables dynamic adaptation of traffic distribution, optimizes resource utilization, improves user experience, and increases network fault tolerance by autonomously adjusting VPNC gateway selection based on user behavior and network performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A procedure that includes: Assigning criticality ranks to users based on one or more factors related to user behaviors; Determining, by a branch gateway (208, 308) comprising a hardware processor (502), whether a primary virtual private network concentrator (VPNC) gateway is healthy, the primary VPNC gateway (306A) being one of a plurality of VPNC gateways (306, 316) across one or more data centers (302), the primary VPNC gateway receiving forwarded traffic from user devices (310), including a first device of a first user and a second device of a second user; Determining, by the branch gateway, whether a service is healthy, the service being provided by a data center from the one or more data centers; and based on a determination that the service is not healthy or a determination that the primary VPNC gateway is not healthy: Determining, by the branch gateway, whether the first user associated with the first device has a non-critical rank, and whether the first device from which the first traffic is received is a new client device that has newly joined a network, based on a determination that the first user has the non-critical rank and the first device is a new client device, dynamically selecting, by the branch gateway, a secondary VPNC gateway (306N) from the plurality of VPNC gateways across the one or more data centers to transmit the first traffic from the first device forwarded by the branch gateway to the secondary VPNC gateway, Determining, by the branch gateway, whether the second user associated with the second device has a critical rank, and whether the second device from which the second traffic is received is a new client device that has newly joined the network, and based on a determination that the second user has the critical rank or the second device is not a new client device, maintaining a selection by the branch gateway of the primary VPNC gateway for transmitting the second traffic from the second device forwarded by the branch gateway to the primary VPNC gateway.
Need to check novelty before this filing date? Find Prior Art

Description

Technical FieldThe present disclosure relates generally to electronic data networks, and more particularly to software-defined networks.US 2020 / 0106687 A1 relates to a computer implemented method for determining the operating states of applications in different data centers and for switching access between the applications.US 10623285 B1 relates to a multimode service for health monitoring.The present invention has for its object to overcome at least partially the disadvantages of the known methods and systems for the dynamic selection of a VPNC gateway.This object is achieved by a method according to independent claim 1, a system according to independent claim 10 and a storage medium according to independent claim 18.Brief Description of the DrawingsThe present disclosure will be described in detail in accordance with one or more different embodiments with reference to the following figures. The figures are for illustrative purposes only and are merely representative or exemplary embodiments. FIG. 1 shows an example of a network configuration that may be implemented for an organization such as a business, an educational agency, a government agency, a healthcare agency, or another organization. FIG. 2 illustrates an example of a software defined wide area network (SD-WAN) system, in accordance with some embodiments. FIG. 3A illustrates an example software defined wide area network (SD-WAN) in which the dynamic VPNC gateway selection techniques (virtual private network concentrators) may be implemented, in accordance with some embodiments. FIG. 3B illustrates an example of employing a dynamic VPN concatenation gateway selection technique to optimize traffic routing to the primary VPN concatenation point and a secondary concatenation point within an SD-WAN, in accordance with some embodiments. FIG. 3C illustrates another example of employing a dynamic VPN concatenation gateway selection technique to optimize traffic routing to the primary VPN concatenation point and a secondary concatenation point within an SD WAN, in accordance with some embodiments. FIG. 3D illustrates another example of using a dynamic VPN concatenation gateway selection technique to optimize traffic routing to the primary VPN concatenation point and a secondary concatenation point within an SD WAN, in accordance with some embodiments. FIG. 4 shows an example of a mechanism for learning traffic routes for users to implement a demand-driven VRF ID configuration that includes aspects of dynamic VPN concatenation gateway selection techniques, in accordance with some embodiments. FIG. 5 is an example of a method for implementing the dynamic VPN concatenation gateway selection techniques, in accordance with some embodiments. FIG. 6 is a block diagram of an example computing component or apparatus for implementing the dynamic VPN concatenation gateway selection techniques, according to an embodiment. FIG. 7 shows an example configuration of a VRF rule implemented via the disclosed on-demand VRF ID configuration, in accordance with some embodiments.The figures are not exhaustive and do not limit the present disclosure to the precise form disclosed.Detailed DescriptionVirtual Private Networks (VPNs) allow users to establish secure, private communication channels over unsecured public networks such as the Internet. These secure, private communication channels are generally referred to as VPN tunnels. Network devices, referred to as VPN concentrators (VPNc), are used to establish and configure these tunnels, authenticate the users, assign the tunnels to the users, ensure delivery of the data flowing through the tunnels, and encrypt and decrypt the data. To facilitate provisioning and management, VPN concentrators are often clustered. The use of VPN concentrator clusters allows efficient network management by, for example, allowing load balancing between the VPN concentrators in the cluster. One problem that arises in this environment is the distribution of VPN tunnels to the VPN concentrators in a cluster.Moreover, the software-defined wide area network (SD-WAN) may play a central role in providing smart connectivity in a distributed topology, for example between branch centers and data centers. A SD WAN is a virtual WAN architecture that allows companies to utilize various combinations of transport services - including MPLS, LTE, and broadband Internet services - to connect users securely to applications.An SD WAN may use a centralized control function to safely and intelligently route the traffic over the WAN. This increases application performance and provides a high user experience that may result in higher enterprise productivity, more agility, and lower cost for the users.In SD-WANs, a secured tunnel may be formed between the branch exchange gateway (BG) and each VPNC throughout the topology. In the SD-WAN, a preference order for forwarding the traffic to each VPNC in a VPNC cluster (also referred to as VPNC priority herein) may be set. For example, within a VPNC cluster in a data center, one VPNC may be referred to as a primary VPNC, another VPNC in the VPNC cluster may be referred to as a secondary VPNC, etc. According to this defined preference for VPNCs in the cluster, the traffic is mostly routed to the primary VPNC. However, there are also cases where the traffic is routed to the secondary VPNC. This preference for VPNCs or VPNC priority can be manually configured in the BG.In existing SD-WANs, the route cost for each destination service may be determined for all learned networks. During operation, in accordance with a conventional VPNC gateway selection approach implemented for the SD-WAN, such as the Dynamic Path Steering (DPS) policy, a VPNC gateway can be selected with minimal cost for the next hop. Because the route cost is determined by the VPNC affinity as configured in the branch gateway or by the cost determined by the PCM of a destination, the traffic is predominantly forwarded to the primary VPNC gateway (e.g., VPNC with the lowest route cost). In other words, the operation of conventional approaches is tuned to route most of the traffic to the primary VPNC for the destination route (only quite in rather flat topologies). Although the resources of the primary VPNC are frequently used in this case, the other VPNCs of the cluster often remain unused for a longer time. Thus, secondary lower priority VPNCs and VPNCs may only become active when the primary VPNC is not available (e.g., non-functional, loss of connectivity, offline) or the service provided by the selected data center fails. Because many VPNCs in a cluster are typically not used, the selection scheme cannot optimize a network topology with multiple VPNC clusters deployed throughout the SD-WAN (e.g., when many resources are available but remain unused). Conventional approaches to selecting VPNC gateways as described above are primarily static, since they are unable to adapt the selective distribution of data traffic to the VPNCs in real time and / or on the basis of the current conditions in the network, in particular the performance of the data centers. Static approaches do not allow users to prioritize, end-to-end services, and adjust traffic to achieve optimized traffic distribution among the different VPNCs. There are some conventional approaches that have some generally customizable aspects. Policy Based Routing (PBR), for example, allows some adaptation with respect to applications or highly selective users, but fails to scale, dynamically adapt, and partition traffic among multiple VPNCs. The systems and techniques presented herein for dynamically selecting VPNC gateways and for on-demand VRF ID configuration provide an improvement over these existing approaches because they function dynamically based on "user recognition". That is, the dynamic VPNC gateway selection techniques make routing decisions based on multiple dynamic and / or user specific factors including: a) behavior of users on the network; and b) state / performance of a target service and / or a VPNC gateway device. These disclosed dynamic VPNC gateway selection techniques not only add an additional level of traffic adaptation and granular traffic / session management, but also achieve some aspects of network fault tolerance and self-healing. Thus, the disclosed dynamic VPNC gateway selection techniques can realize various improvements over the currently existing routing and / or VPNC selection approaches used in SD-WANs (and VPNs), such as optimizing resource usage, improving user experience, and increasing fault tolerance in the network.Before describing embodiments of the disclosed systems and methods in detail, it is useful to describe an example network installation with which these systems and methods could be implemented in various applications. FIG. 1 shows an example of a network configuration 100 that may be implemented for an organization such as a business, an educational agency, a government agency, a healthcare agency, or another organization. This diagram illustrates an example configuration implemented in a multi-user (or at least multiple client devices 110) organization and possibly multiple physical or geographic locations 102, 132, 142. The network configuration 100 may include a primary site 102 that communicates with a network 120. The network configuration 100 may also include one or more remote sites 132, 142 that are in communication with the network 120.The primary site 102 may include a primary network, which may be, for example, an office network, a home network, or other network installation. The primary network 102 may be a private network, e.g., a network that may include security and access controls to restrict access to authorized users of the private network. Authorized users may include, for example, primary site enterprise employees 102, home occupants, business customers, etc.In the example shown, the primary site 102 includes a controller 104 that communicates with the network 120. The controller 104 may provide communication with the network 120 for the primary site 102, although it may not be the only point of communication with the network 120 for the primary site 102. A single controller 104 is shown, although the primary location may include multiple controllers and / or multiple communication points with the network 120. In some embodiments, the controller 104 communicates with the network 120 via a router (not shown). In other embodiments, the controller 104 provides router functions to the devices at the primary site 102.A controller 104 may configure and manage network devices, e.g., at the primary site 102, and may also manage network devices at the remote sites 132, 134. The controller 104 may configure and / or manage switches, routers, access points, and / or client devices connected to a network. The controller 104 may itself be or provide the functionality of an access point.The controller 104 may be in communication with one or more switches 108 and / or wireless access points (APs) 106 a- c. The switches 108 and the wireless APs 106 a- cprovide network connectivity to various client devices 110 a- j. Via a connection to a switch 108 or AP 106a-c, a client device 110a-j may access network resources, including other devices in the network (primary site 102) and network 120.Examples of client devices may include desktop computers, laptops, servers, web servers, authentication servers, authentication authorization accounting (AAA) servers, domain name system (DNS) servers, dynamic host configuration protocol (DHCP) servers, Internet protocol (IP) servers, virtual private network (VPN) servers, network policy servers, mainframes, tablet computers, e-readers, netbook computers, televisions, and similar screens (e.g., smart TVs), content receivers, set-top boxes, Personal Digital Assistants (PDAs), Mobile Phones, Smart Terminals, Silent Terminals, Virtual Terminals, Video game consoles, Virtual Assistants, Internet of Things (IOT) devices, and the like.Included within the primary site 102 is a switch 108 as an example of an access point to the wired client devices 110 i- jconfigured at the primary site 102. The client devices 110 i- jmay connect to the switch 108 and access other devices within the network configuration 100 via the switch 108. The client devices 110 i- jmay also access the network 120 via the switch 108. The client devices 110 i- jmay communicate with the switch 108 via a wired connection 112. In the illustrated example, the switch 108 communicates with the controller 104 via a wired connection 112, although this connection may also be wireless.The wireless APs 106 a- care another example of an access point to the network established at the primary location 102 for client devices 110 a- h. Each of the APs 106 a- cmay be a combination of hardware, software, and / or firmware configured to provide wireless network connectivity to wireless client devices 110 a- h. In the illustrated example, the APs 106 a- cmay be managed and configured by the controller 104. The APs 106 a- ccommunicate with the controller 104 and the network via connections 112, which may be either wired or wireless interfaces.The network configuration 100 may include one or more remote sites 132. A remote location 132 may be located at a different physical or geographic location than the primary location 102. In some cases, the remote location 132 may be at the same geographic location or possibly in the same building as the primary location 102, but does not have a direct connection to the primary location network 102. Instead, remote site 132 may utilize a connection over another network, e.g., network 120. A remote location 132 as shown in FIG. 1 may be, for example, a satellite office, other floor or suite in a building, etc. Remote site 132 may include a gateway device 134 for communication with network 120. A gateway device 134 may be a router, a digital-to-analog modem, a cable modem, a DSL modem, or other network device configured for communication with the network 120. Remote site 132 may also include a switch 138 and / or an AP 136 that communicates with gateway device 134 via either wired or wireless connections. The switch 138 and the AP 136 provide connectivity to the network to various client devices 140 a- d.In various embodiments, remote site 132 may be in direct communication with primary site 102 such that client devices 140 a- dat remote site 132 access the network resources at primary site 102 as though these client devices 140 a- dwere at primary site 102. In such embodiments, remote site 132 is managed by controller 104 at primary site 102, and controller 104 provides the necessary connectivity, security, and accessibility to enable communication of remote site 132 with primary site 102. Once connected to the primary site 102, the remote site 132 may function as part of a private network provided by the primary site 102.In various embodiments, network configuration 100 may include one or more smaller remote locations 142 that include only a gateway device 144 for communicating with network 120 and a wireless AP 146 through which various client devices 150 a- b access network 120. Such a remote location 142 may represent, for example, a single employee's home or a temporary remote office. Remote site 142 may also communicate with primary site 102 such that client devices 150 a- bat remote site 142 access the network resources at primary site 102 as though these client devices 150 a- bwere at primary site 102. Remote site 142 may be managed by controller 104 at primary site 102 to enable this transparency. After connection to the primary site 102, the remote site 142 may function as part of a private network provided by the primary site 102.The network 120 may be a public or private network, such as the Internet or other communication network that enables the connection between the various sites 102, 130-142 as well as access to the servers 160a-b. The network 120 may include third party telecommunications lines such as telephone lines, broadcast coaxial cables, fiber optic cables, satellite communications, cellular communications, and the like. The network 120 may include any number of intermediary network devices, such as switches, routers, gateways, servers, and / or controllers, that are not directly part of the network configuration 100, but facilitate communication between the various parts of the network configuration 100 and between the network configuration 100 and other entities connected to the network. The network 120 may include various content servers 160 a- b. Content servers 160 a- bmay include various providers of downloadable multimedia and / or streaming content, including audio, video, graphics and / or text content, or any combination thereof. Examples of content servers 160 a- bare, for example, web servers, streaming radio and video providers, and cable and satellite television providers. The client devices 110 aj, 140 a- d, 150 a- bmay request and access the multimedia contents provided by the content servers 160 a- b.Various embodiments of the disclosed technology will now be described. FIG. 2 shows an example of a VPN system according to an embodiment. As shown in FIG. 2, the VPN system 200 includes a VPN concentrator cluster 202. The VPN concentrator cluster 202 includes a VPN master 204 and a plurality of VPN concentrators 206 ato 206 n. The VPN master 204 may be implemented in a VPN concentrator 206, as a stand-alone device, or as a combination thereof. In Figure 2, it is desirable to establish VPN tunnels with a plurality of branch exchange gateways 208a-208m over a network 210 such as the Internet. While the embodiment of FIG. 2 is described as constructing VPN tunnels with branch exchange gateways, it should be understood that the disclosed technology can be used to construct VPN tunnels with any network endpoint that supports this function.In the example of FIG. 2, each branch gateway 208 initiates a VPN tunnel by sending a VPN request 214 to the VPN master 204 in the VPN concentrator cluster 202 via a corresponding network connection 212. In response to the VPN requests 214, the VPN master 204 transmits a corresponding network address 216 to each branch gateway 208. Each network address 216 is the network address of one of the VPN concentrators 206 in the VPN concentrator cluster 202. Each network address 216 may be, for example, an Internet Protocol (IP) address.FIG. 3A shows an example of an SD-WAN 300 in which the disclosed dynamic VPNC gateway selection methods may be implemented. Unlike the conventional router-centric WAN architecture, the SD WAN 300 may be designed to fully support applications hosted in local data centers (shown as data centers 302 aand 302 nin FIG. 3A ). In the example, the SD WAN 300 may have a topology that includes multiple branches 315 a, 315 b, and 315 nand multiple data centers 302 aand 302 ncommunicating through the communication network 310. The branch points 315 a- 315 nmay be located at different geographic locations and connected to data centers 302 a- 302 nthat may be remote from the respective locations of the branch points 315 a- 315 n. In the example, each of the branch locations 315 a- 315 nincludes a plurality of client devices 310 jthat can be used by users located proximate (on-site) to the respective branch location 315 a- 315 n. Also, in each of the branch points 315 a- 315 n, one of the branch point gateways (BGs) 308 a- 308 nmay be deployed. Each of the BGs 308 a- 308 nmay serve as an interface for incoming and / or outgoing data traffic for the respective branch points 315 a- 315 n. For example, branch gateway 308 amay interface for uplink traffic from client devices 310 jin branch 315 a, which is routed to communication network 310, and interface for downlink traffic from communication network 310, which is routed to a corresponding client device 310 j.Additionally, FIG. 3A illustrates that each of data centers 302 a- 302 nmay have a cluster of VPNCs and multiple servers deployed thereon. In the example, data center 302a has a first cluster of VPNCs 306a-306n and servers 304a-304n, and data center 302n has a second cluster of VPNCs 316a-316n and servers 314a-314n. In operation, each of the BGs 308 a- 308 nmay tunnel with these VPNCs 306 a- 306 n, 316 a- 316 nvia WAN uplink(s) in one of the data centers 302 a- 302 n. Secured tunnels may be formed between a BG and each VPNC in the respective data center. For example, BG 308 amay establish a secure tunnel with each of the VPNCs 306 a- 306 nin the cluster in data center 302 a. The order of preference of the VPNC (or VPNC priority) may be manually configured on the BGs 308 a- 308 n. To transmit data traffic from data centers 302 a- 302 nvia SD WAN 300 to a destination, an uplink from one of BGs 308 a- 308 nmay be selected based on the dynamic VPNC gateway selection techniques disclosed herein, and packets may be forwarded to a VPNC gateway, referred to as a primary VPNC gateway. The BGs 308 a- 308 nmay store instructions that implement the dynamic VPNC gateway selection techniques. For example, a rule of the dynamic VPNC gateway selection scheme may determine a VPNC gateway from the cluster as a primary VPNC gateway for the respective data center. A primary VPNC may be determined automatically or manually based on various factors (e.g., minimum route cost, preference / prioritization, etc.) and then stored in the BGs 308 a- 308 nto be used for routing the traffic in the SD WAN 300. For example, VPNC 306 amay be selected as a primary VPNC gateway for data center 302 aand VPNC 316 amay be selected as a primary VPNC gateway for data center 302 n. All remaining VPNC gateways in the cluster may be referred to as a secondary VPNC gateway or a low priority VPNC gateway, or may be assigned to different lower priority levels (e.g., priority levels that are lower than the highest priority of the primary VPNC gateway). Generally, a VPNC gateway in the cluster with the highest priority may be referred to as a primary gateway, and one or more VPNC gateways with lower priorities may function as secondary VPNC gateways. In many provisionings, there may be more than two VPNC gateways. For each of the VPNC gateways, its own priority may be calculated and assigned by either the configuration or cost of its path. In the example of FIG. 3A, the VPNC gateway 316 nmay be determined to be a secondary VPNC gateway for the data center 302 n. Note that in data centers with multiple VPNCs, more than one VPNC gateway may be referred to as a secondary VPNC gateway or lower priority VPNC gateway.As already indicated, in some current approaches, forwarding the traffic to a VPNC gateway may depend on the BG's next hop route, which in most scenarios is configured to statically send the traffic to the designated primary VPNC. Conversely, in these current approaches, the selected data center sends the traffic from the primary VPNC. Thus, many existing approaches do not allow for actual use of the use of the other, less preferred VPNCs, which typically become active only when the primary VPNC fails or the service provided by the selected data center fails. In contrast, the disclosed dynamic VPNC gateway selection techniques enable dynamic adaptation of the VPNC gateway selection rule. According to embodiments, the rule(s) for forwarding traffic to a VPNC gateway are not only limited to forwarding to the primary VPNC gateway, but may also be dynamically updated based on additional factors such as the behavior of the user (e.g., new user, critical user, etc.) and the conditions of the target service / device in the data centers (e.g., state of the devices, service state, etc.). For example, the network conditions may be monitored in real-time and recognize that the state of the VPNC gateway 302 a, which is the primary (or super-priority) VPNC gateway for the corresponding data center 302 a, has degraded (although the device is still available / online). Therefore, the dynamic VPNC gateway selection techniques may dynamically adapt so that the traffic is routed to the secondary (or low priority) VPNC gateway for data center 302 a, namely VPNC gateway 306 n. Conversely, the above-mentioned existing approaches would still statically forward the traffic to the VPNC gateway 306a, even if its state is compromised, since it is still the designated primary VPNC gateway and is still online. However, the dynamic VPNC gateway selection techniques may change their function based on the real-time conditions of the network and thereby redirect the data traffic to avoid further use of a primary VPNC gateway while its state is degraded (which may cause additional damage and / or reduced performance on the device). As described above, current approaches rarely fail to a secondary VPNC gateway, and in most cases only when a device / service fails completely. The techniques presented use monitoring and / or tracking the state of a device and the state of a service for the VPNCs as an on-demand fault tolerance. Moreover, the disclosed techniques may dynamically select a VPNC gateway in a manner that enables improvements over current approaches, such as self-healing of the network (e.g., reuse of the primary VPNC gateway as its state improves) and adaptation to potentially improve the quality of network communication and user experience. The dynamic VPNC gateway selection techniques as disclosed herein may provide several advantages including, but not limited to: 1) dynamic behavior support that enables adaptation of the traffic and distribution of the traffic in a manner that optimally utilizes multiple VPNC gateways in the network; 2) performance of the target service / device in selecting the preferred VPNC; and 3) support of fault tolerance or fault safety of the network as needed, other than redundancy fault protection.Moreover, the dynamic VPNC gateway selection techniques may dynamically determine the uplink for a particular user (based on the behavior) to achieve the primary VPNC of the data center and enable the distribution of the data traffic to multiple VPNCs of a data center, which may improve overall efficiency of the system (e.g., distribution / load balancing between multiple VPNC resources). Often, VPNCs are not configured to operate in all active active active mode for BGs, especially because of the requirements for symmetric routing. The disclosed embodiments may address this limitation by autonomously adjusting the selection rules based on the behavior of the users, which offers various improvements over conventional approaches that are manually configured, static, and independent of the users of the traffic, and require periodic maintenance. For example, there may be thousands of users in the branches 315 a- 315 n. As will be described in more detail, the dynamic VPNC gateway selection techniques may observe the behavior of a user to dynamically adapt the selection rules based on at least two major categories of users, including: 1) critical users and 2) new users. The presented techniques avoid implementing thousands of user-specific policies and instead enable user-based adaptation of VPNC selection and traffic routing by using a higher level approach (e.g., without having to create a specific policy for each user) that is more generally based on user categories (depending on their observed behavior) to achieve optimal distributed usage of VPNCs. Generally, traffic for selection of VPNCs may be adjusted in accordance with the multiple level dynamic VPNC gateway selection techniques by considering the criticality (e.g., priority) and / or behavior of the users in forwarding the traffic to the VPNC gateways. This enhanced level of adaptation supported by the disclosed techniques may provide better control and management of traffic to the designated data centers than can be achieved with more traditional approaches. In general, the dynamic VPNC gateway selection techniques as disclosed herein support key functions including, but not limited to: 1) user behavior based on autonomous VPNC and / or data center selection; 2) autonomous VRF ID configuration and / or removal on demand; and 3) performance-based routing of data center services.FIG. 3B shows an example operation of a branch exchange gateway 308 aconfigured with a dynamic VPNC gateway selection component 309 that implements dynamic selection of VPNC gateways in accordance with the disclosed techniques. It should be appreciated that the components and function of the systems shown in FIGS. 3B-3D (e.g., branch points, branch point gateways, VPNC gateways, data centers, etc.) are substantially similar to those described in detail with respect to FIG. 3A. For the sake of brevity, the similar components and functions will not be described in detail again with reference to FIGS. 3A-3B. The dynamic VPNC gateway selection component 309 may be implemented as a hardware and / or software computing component, e.g., a server computer, controller, or other similar computing component capable of processing data. In the example implementation of FIG. 3A, the dynamic VPNC gateway selection component 309 includes a hardware processor and a machine readable storage medium. A hardware processor may be, for example, one or more central processing units (CPUs), semiconductor-based microprocessors, and / or other hardware devices suitable for fetching and executing instructions stored in a machine-readable storage medium. A hardware processor of the dynamic VPNC gateway selection component 309 may fetch, decode, and execute instructions, such as instructions to control processes or operations to dynamically select a VPNC gateway, in accordance with the techniques disclosed herein. Alternatively or additionally to fetching and executing instructions, a hardware processor of the dynamic VPNC gateway selection component 309 may include one or more electronic circuits including electronic components for executing the functionality of one or more instructions, such as a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), or other electronic circuits.As indicated above, the disclosed techniques may provide a user behavior based autonomous VPNC gateway and / or data center selection function. Accordingly, the dynamic VPNC gateway selection component 309 is configured to dynamically monitor and / or track the behavior of users, e.g., users associated with the client devices 310 jin the branch 315 a, in a manner that ultimately enables autonomous VPNC / DC selection. According to embodiments, the dynamic VPNC gateway selection component 309 may assign each user associated with the branch 315 ato a score based on multiple different parameters related to the monitored behavior. These parameters may include, but are not limited to: a) location; b) critical versus non-critical applications bandwidth consumed; c) traffic QOS; d) user reputation; e) user threat / security value; and f) user role. Subsequently, each calculated score is used to determine a criticality rank for the user. In the embodiments, the dynamic VPNC gateway selection component 309 may be programmed to apply a particular algorithm to calculate the user score. The algorithm for calculating the user score will be described in more detail with reference to FIG. 4. Also, in scenarios where a user is associated with a plurality of devices, each device used by a particular user is associated with the same criticality level assigned to the user. Referring to the example of FIG. 3A, the dynamic VPNC gateway selection component 309 has associated the user associated with the client device 310j with a "critical" criticality rank and the user associated with the client device 310k with a "non-critical" criticality rank. In other words, based on its tracked behavior, the user associated with the client device 310 kis less critical than the user associated with the client device 310 j. The client devices 310j and 310j may be ranked according to their criticality, wherein the ranking is based on a score calculated by the user score calculation algorithm. As can be seen, traffic from both client devices 310j, 310k is routed to the VPNC gateway 306 of data center 302a by BG 308a according to the disclosed dynamic VPNC gateway selection techniques, which in this particular example scenario, matches conventional approaches (e.g., all traffic is routed to the primary VPNC).Due to the above-mentioned capabilities of the dynamic VPNC gateway selection component 309, the BG 308a knows the behavior of all users in the system and can thus dynamically and intelligently adjust the traffic forwarding. FIG. 3A is used in particular to illustrate an operating example in which the status quo of the data traffic is maintained. For example, real-time monitoring of network conditions may determine that the state of VPNC gateways 306 a- 306 nor the service provided by data center 302 ais good. Alternatively, in cases where the state of either gateway degrades to below a fixed state or performance threshold, the dynamic VPNC gateway selection component 309 may migrate traffic from new and less critical (e.g., non-critical) clients to a secondary VPNC gateway or data center (or with lower priority). According to embodiments, all currently existing sessions for client devices supported by the data center are maintained. The selection of the VPNC in the BG and the reverse path in the DC is achieved by a dynamic on-demand configuration of the corresponding import / export rules in the VRF ID for the corresponding target prefix. This dynamic system, which takes into account the user behavior and the performance of the target service, not only optimizes resource utilization in the VPNCs, but also reinforces the fault tolerance of the network and provides self-healing of the network.In the example of FIG. 3A, traffic for the selected destination is sent from the BG 308 ato the corresponding primary VPNC gateway 306 a. For all ECMP routes, the data traffic is sent to the same primary VPNC gateway, namely 306a. However, if the state of the primary VPNC gateway 306 aor service falls below a defined state / power threshold, the BG 308 amay dynamically adapt (opposite the dynamic VPNC gateway selection component 309) to send traffic from clients identified 1) as new users and 2) as less critical users to the secondary VPNC gateway 306 n(or with lower priority). In some embodiments, rather than dynamically selecting a VPNC gateway, the techniques dynamically select another data center to which traffic is forwarded.Referring again to the scenario in which the device and service state of the primary VPNC gateway 306 ais good, the BG 308 acontains all current data streams from the client devices 310 jand 310 k, and may only migrate the sessions of new clients that were added to the branch point 315 aand also have been assigned a "non-critical" criticality rank. All new entries from less critical clients in the data path table of the BG 308a may be used to decide forwarding of packets to the secondary VPNC gateway 306n of the data center 302a (or secondary data center) instead of the designated primary VPNC gateway 306a.Referring now to FIG. 3C, another example operation of the BG 308 aconfigured with the dynamic VPNC gateway selection component 309 is illustrated. As mentioned above, an essential feature of the dynamic VPNC gateway selection component 309 is the observation and assessment of the state (resource availability and performance) of VPNC. In other words, the dynamic VPNC gateway selection component 309 is capable of making measurements of the performance of the target service and devices on the network. Current TCP / UDP uplink state checks may be used such that the VPNC gateway selection component 309 is able to monitor (and then measure) the dynamic state / performance of a particular device and service provided by the data center. For example, relevant AMON messages are sent from the VPNC gateways 306 a- 306 nin the data center 302 aand ultimately conveyed to the dynamic VPNC gateway selection to track resource availability on the devices.In particular, in the example of FIG. 3C, it is determined that the state of the primary VPNC gateway 306 ais degraded or otherwise reduced. For example, a significant amount of traffic may be routed to the primary VPNC gateway 306 a(e.g., a large number of client sessions), which results in the device's resources being congested (indicated by a dashed star). As a result, the users of the client devices 310j and 310k that are in ongoing sessions with the destination 304 in the data center 302a may experience a deceleration associated with the effects on the performance and state of the VPNC gateway 306a. However, by monitoring network conditions, the dynamic VPNC gateway selection component 309 may recognize that the resources of the VPNC gateway 306 aare below a defined threshold state or performance as provided by the techniques. The BG 308 amay use this insight to dynamically adapt the secondary VPNC gateway 306 nand then select to receive the forwarded traffic from a new and non-critical (or less critical) client 310 l. In other words, the BG 308a is configured to use the insight about the state of the VPNC gateways in the network, and in particular the primary VPNC gateway 306a. In the example of FIG. 3C, the BG 308 aapplies the disclosed techniques to dynamically select the secondary VPNC gateway 306 nsuch that the user experience is optimized, for example, by adapting to the new client 310 lwhile maintaining the existing sessions of the 310 j, 310 k. Moreover, by implementing the disclosed dynamic VPNC gateway configuration aspects, BG 308 acan optimize the distribution of traffic among the plurality of VPNCs 306 a- 306 nin data center 302 a.FIG. 3D shows another example of operation for the BG 308 awith the dynamic VPNC gateway selection component 309 therein. In addition to evaluating the state of the devices, the dynamic VPNC gateway selection component 309 may also observe and evaluate the state of the service. Accordingly, in the example of FIG. 3D, the dynamic VPNC gateway selection component 309 may determine that the state of the service in the data center 302 ais out of order. For example, BG 308 amay forward the uplink traffic to network 310 to enable currently active sessions with server 304 in data center 302 aand client device 310 jused by a user classified as critical (according to the criticality ranking scheme) and client device 310 j 10 kused by a user classified as less critical (according to the criticality ranking scheme). During communication with data center 302 a, dynamic VPNC gateway selection component 309 may recognize that the service provided by server 304 in data center 302 ais not efficient with respect to the state / power threshold set on component 309. In response to determining that the state of the service in data center 302 ais degraded, dynamic VPNC gateway selection component 309 may dynamically select to send traffic from client device 310 lto primary VPNC gateway 306 oof secondary data center 302 nin place of to data center 302 a,in the same manner as the other currently active sessions. This VPNC gateway 306 omay be defined in a list of the VPNCs configured in the SD-WAN with a lower priority. In some embodiments, the configuration for a VRF ID is performed in the primary VPNC 306o of the secondary data center 302n. The BG 308 amay be commanded by the dynamic VPNC gateway selection component 309 to send traffic for all new and less critical clients, such as the client device 310 l, to that lower priority (or secondary) VPNC gateway 306 obased on the configured VRF ID.According to the disclosed dynamic VPNC selection techniques, a BG may be programmed to first attempt to send the traffic to the primary (higher priority) VPNC gateway of a data center. The primary VPNC may be configured in the CAAS as either the first VPNC for a primary data center or the primary VPNC of another data center having the lowest route cost learned by the dynamic path forwarding via PCM. In either case, a rule for a particular designated route and the corresponding list of VPNCs may be added in the BG along with their cost as next hops. FIG. 4 shows an example of a table 400 that contains the VRF ID, the destination prefix, and the list of next hop gateways. For example, a table 400 may originate from a debug dashboard and displays the routes learned in front of the device. A next hop may be learned by various mechanisms, e.g., by configuration by the user or by calculation of the shortest route by the PCM. Table 400 indicates that two next hops are available to the BG to reach the network "192.168.19.176 / 28". The lowest cost next hop (10) is the VPNC with the mac address "00:1a:1e:03:64:b0" and the higher cost next hop (20) is the VPNC with the mac address "00:1a:1e:03:59:38".FIG. 5 shows a flow diagram of a process 500 for implementing the disclosed dynamic VPNC gateway selection techniques. Moreover, FIG. 5 shows process 500 as a series of executable operations stored on a machine readable storage medium 504 and executed by hardware processors 502, which may be the main processor of a computing component 500. The computing component 500 may be, for example, the dynamic VPNC gateway selection component described at least with reference to FIG. 3B. In operation, the hardware processors 502 perform the operations of the process 500 and thus implement the disclosed techniques.In the example, the process 500 begins with operation 506, where one or more users are ranked. Each user may be connected to one or more client devices in a network, e.g., a laptop computer in a branch point connected to the SD-WAN. Operation 506 may include assigning to the user a score calculated using an algorithm to calculate the user score, and then ranking the user in a corresponding rank based on their respective score. In general terms, the user score computation algorithm takes into account various parameters related to the user's behavior in the network to compute a score indicative of the user's behavior to ultimately assign a ranking to it. These parameters may include, but are not limited to: a) location; b) bandwidth consumed by critical versus non-critical applications; c) quality of service (QOS) of the traffic; d) user's representation; e) user's threat / security value; and f) user role. Each user's score may be calculated by the BG or alternatively calculated from resources in the cloud and then transmitted to the BG. Again, operation 506 may include ranking the users based on the range of their scores. As a result, the BG knows the "behavior" of the individual users based on their ranking. For example, a BG may have a list containing the ranking for each user (and client device) present in the system. In some embodiments, when a single user is associated with multiple devices on the network, e.g., a laptop, a desktop computer, and a tablet computer, each of the multiple devices used by that user is associated with the same criticality level assigned to the user.The user score computation algorithm that may be applied in operation 506 will now be described in detail. As a prerequisite for the algorithm, a location map or floor plan of all employees, appRF data, bandwidth consumption and QoS data of each user, net insight security events are generated. The calculation of the assessment can be carried out in pseudo real time or at regular intervals, as defined, for example, by the administrator. By continuously recalculating (or updating the calculations) the user scores, the disclosed techniques may maintain a "dynamic" aspect with respect to perception of user behavior. In particular, the disclosed techniques generate a dynamic user score. The behavior of a user in a network, such as SD-WAN, is typically not static and may change as the needs and / or functions of the user adapt. For example, a user may be set as a hardware engineer and then change to a software engineering department within the same company. Thus, the type of applications (e.g., bandwidth, QoS, etc.), the permissions, roles, and other behaviors of that user in the enterprise network will change depending on how their professional requirements and functions change. By ensuring that the user score calculation algorithm recalculates the user score at various times, the methods are able to detect these changes in the user's behavior that are reflected in a dynamically changing score. The user score calculation algorithm uses the following factors to determine the score for the user.1. Priority Depending on Location: A high priority location indicates the physical location where critical business tasks are performed. High priority locations (sales team, business leader's office, area of technical support) are identified by the administrator or retrieved from the VisualRf floor plan if available. Users at high priority locations are assigned a high rating. More important resources are more sensitive to network failures, thus keeping the rating high.2. Priority based on bandwidth consumption of critical versus non-critical applications: this is based on the percentage of critical applications and the percentage of bandwidth used by non-critical applications. User assessment is a representation of user behavior when accessing business critical and non-business critical applications. The user rating is a weighted combination of the percentage of bandwidth consumed by critical applications versus non-critical applications. An example of a mathematical representation of the user bandwidth is shown in the following equation:In the above equation, the percentage of bandwidth used by non-critical applications is weighted low. This is because users consuming more bandwidth for non-critical applications are more compromised. An example of a mathematical representation of a user's bandwidth percentage consumption is presented in the following equation:3. Priority based on the QOS of the traffic: This takes into account the QoS flow indicators given by the IP-TOS / DSCP values. A user whose traffic flows mostly in queues with high priority receives a high rating. An example of the mathematical representation of a QoS score for a user is presented in the following equation:The weight may be assigned to different types of service as defined in DSCP RFC 4594. The weights are implementation specific and may be assigned in the algorithm depending on the choice of implementation (e.g., highest weight for Expanded Forwarding, AF 11-AF 43 with subsequent weight, CS 0-CS 7 with relevant weight, default forwarding service with corresponding weight, etc.).4. Priority due to user's representation: The user's representation is calculated based on the contents invoked by the user. The following parameters are also used as input: Input: IP address, time and day of the request and response, Web category, Web representation, file type, content type, used bandwidth Web category / Web representation is calculated by searching for certain known patterns in different fields (such as user agent, IP, domain, etc.) and evaluated by Webroot / Brightcloud to determine the IP representation. If content access for an application is high, but most bytes (bandwidth) are consumed by the sport / purchase category, the user should be less heavily weighted. This can be achieved by assigning a relative weight to each category. This may already be part of the AppRf function. The user reputation may be created based on mathematical formulation or modeling of the above-mentioned factor by machine learning or based on another prior art. An example of a mathematical representation of a representation value for a user is presented in the following equation:where a denotes the total number of impermissible applications that the client accesses,m represents the total number of malware URL requests issued by the client,f denotes the total number of prohibited file attachments and / or MIME types that the client used in emails,i denotes the total number of abnormal breaks detected for the client,d denotes the total number of sensitive data violations detected for the client, andW denotes a weight assigned for the class.5. Priority based on user threat / security assessment: The threat score is calculated based on events relating to a single user (severity, confidence assessment, grade) as well as on inter-event correlation information (e.g., the grade change in different events) from associated devices or networks. The generation of events is typically done by labeling the data flow, which may be based on the following factors: a) rule-based cases, e.g., DGA, detection of HTTP header orderings, BitTorr, etc.; and b) third party data correlation-based cases, e.g., IOC, FireEy. Examples of events are DNS Exfiltration / DNS Dictionary DGA, HTTP Header Misbooking / Disorder, expired SSL certificate / SSL inactive certificate, suspect PDF, Spyware / Malware access to user devices, Hacker tool on the device, etc. An example of a mathematical representation of a security / threat assessment for a user is presented in the equation below:The definitions of other values relating to a user's threat / security are listed below:Maximum Event Score: max (event_score) Is assigned to the user when it encounters at least one or more high severity, high confidence eventsAttack Level Function: # Number of Attack Levels Fulfilled by the User / Total Number of Attack LevelsFeature Recognition Type: # Number of Recognition Types Satisfied by User / Total Number of Recognition TypesOverall rating feature: sum (event_ scores) / max (sum (event_ scores) of all users)6. Priority based on the user role: assigning a score to each role in an organization (e.g., in a business context: CEO=0.8, Senior Vice President=0.6, Guide Level=0.5, etc.). Guest users have the minimum score. Note that different roles may have the same score (e.g., a researcher may have the same score as a developer). This information can be retrieved via an identity and access management product.A. Preprocessing of Factor Scores:All factor scores are normalized by a Z-score or other mathematical variant prior to calculating the score. This helps in the detection of outliers and the comparison between independent features. The Z score can be easily converted to a percentile scale using probability density functions when a range between 0 and 1 is required.μ is the mean value of the basic population,s is the standard deviation of the population.An example of a mathematical representation of a representation value for a user is presented in the following equation:w1,w2,w3,w4,w5,w6,w7 are weights with respect to the respective parameters under the condition of w1+w2+w3+w4+w5+w6+w7 = 1 and 0<w1<1, 0<w2<1, 0<w3<1, 0<w4<1, 0<w5<1, 0<w6<1, 0<w7<1LBeuser=normalized location of the user [0, 1]BBeuser=normalized score based on bandwidth [0, 1] QBeuser=normalized score based on QoS queues [0, 1]RPBeuser=normalized user decryption value [0, 1]TBeuser=normalized threat value [0, 1]RLBeuser=normalized score based on the role [0, 1]The calculation of the score is quite open and versatile. The weighting can be set to 0 if a specific parameter is not to be taken into account in the calculation of the evaluation.As described above, the above-mentioned user score calculation algorithm in operation 506 may be applied to the generated user scores for multiple users of client devices in the network to eventually rank the users. For example, the user scores resulting from the calculations according to the user score calculation algorithm may be stored in an appropriate data structure as shown in Table 1 below and accessed for later use:A. A0,2 * 0,2 + 0,4 * 0,7 + 0,2 * 0,6 + 0,2 * 0,6 + 0,4 * 0,5 + 0,2 * 0,40,84B. B0,2 * 0,1 + 0,4 * 0,6 + 0,2 * 0,4 + 0,2 * 0,5 + 0,4 * 0,3 + 0,2 * 0,20,70C. C0,2 * 0,1 + 0,4 * 0,2 + 0,2 * 0,2 + 0,2 * 0,1 + 0,4 * 0,1 + 0,2 * 0,20,24D. D0,2 * 0,3 + 0,4 * 0,8 + 0,2 * 0,5 + 0,2 * 0,7 + 0,4 * 0,6 + 0,2 * 0,30,92E. E0,2 * 0,1 + 0,4 * 0,1 + 0,2 * 0,1 + 0,2 * 0,1 + 0,4 * 0,1 + 0,2 * 0,10,16Next, process 500 may proceed to operation 508 where a conditional check is performed to determine whether a primary VPNC gateway is okay for a particular data center. As already indicated, the main features of the disclosed dynamic VPNC gateway selection techniques include observing and evaluating the state (e.g., resource availability and performance) of a service and a VPNC gateway device itself. A threshold value for the state or the power can be defined as an indication of the least acceptable measured value of the state of a device and / or service. In other words, if a currently measured (or monitored) state of the primary VPNC gateway is compared to the state / performance threshold and determined to be lower than the threshold, the test at operation 508 may determine that the state of the primary VPNC gateway has degraded to an unacceptable level (e.g., VPNC has slowed to a point that negatively affects client connectivity). The threshold for performance is set such that at the time of reaching the threshold there is sufficient capacity to service all critical users (e.g., higher priority users) currently connected to the network as well as a number of critical users that may be presented to the network in the future. In some embodiments, separate thresholds are used that correspond to the state of the device (or VPNC) and the state of the service, respectively.Alternatively, if it is determined that the currently measured state of the primary VPNC gateway is greater than the state / power threshold, operation 508 has determined that the primary VPNC gateway is okay for the data center (shown as "Yes" in FIG. 5 ). Then, the process 500 continues to check the state of the service. In operation 510, another conditional check is performed to determine if the data center service is okay. According to embodiments, operations 508 and 510 may use uplink state checks implemented in protocol standards such as TCP / UDP or Internet Control Message Protocol (ICMP) as a mechanism for dynamically monitoring the state / performance of a particular device and / or a service provided by the data center. Similar to the previous operation, a currently measured state of the service may be compared to a state / power threshold in operation 510 to determine if the service provided by the data center is okay.If the measured state of the service is greater than the state / power threshold (shown as "Yes" in FIG. 5 ), this indicates that the state of both the device and the service connected to the primary VPNC gateway is acceptable enough to select the primary VPNC gateway for use. After the service is determined to be okay at operation 510, the process 500 may proceed to operation 512 where the primary VPNC gateway is dynamically selected for traffic forwarding for the user.Otherwise, if it is determined that the state of the VPNC gateway (at operation 508) or the state of the service (at operation 510) is below the threshold state / power (shown as "No" in FIG. 5 ), then the process 500 has determined that the power / state is not at an acceptable level for the selection of the primary VPNC gateway and the selection scheme should be adjusted. For example, if the performance of the primary VPNC gateway is significantly degraded, the continued use of the primary VPNC gateway as a standard for receiving all traffic (e.g., additional traffic for new client devices) may further degrade the state of the device and throttle the VPNC in a manner that affects the user experience. Thus, if process 500 determines that the state / performance of either the device (e.g., the primary VPNC gateway) or the service is degraded (e.g., below the state / performance threshold), it enters a portion of the scheme that can dynamically adapt the configuration so that the traffic can be distributed to secondary VPNC gateways (or data centers) to prevent more severe state / performance issues from arising at the primary VPNC gateway.The process 500 continues with the "adaptation" portion of the schema in operation 514, where the operation transitions from the selection of the primary VPNC gateway to potentially migrate the traffic to a secondary VPNC (or data center). In operation 514, a conditional check is performed that determines whether the current traffic is associated with a user that was classified as "less critical" (or not critical) in the previous operation 506. In this case, reference may be made to a stored and / or maintained list of clients and their corresponding evaluations / rankings on a network device.If it is determined in operation 514 that the traffic is associated with a "less critical" client (shown as "Yes" in FIG. 5 ), the process 500 continues with operation 516. In operation 516, an additional conditional check is performed to determine if the traffic is associated with a new client. For example, if the traffic is associated with a client device that newly joined the SD WAN or has no current session, process 500 may identify that device as a new client. If it is determined in operation 516 that the traffic originates from a new client device, this means that adaptation of the selection scheme may be appropriate for that user. Accordingly, process 500 continues to operation 518.Alternatively, process 500 returns to operation 512 if operation 514 determines that the traffic is associated with a critical client (e.g., not associated with a "less critical" client) (shown as "no" in FIG. 5 ) or operation 516 determines that the traffic is not associated with a new client device (shown as "no" in FIG. 5 ). Thus, based on the behavior determined for the respective user, the primary VPNC gateway is selected for forwarding its traffic. In other words, the dynamic VPNC gateway selection techniques do not interfere with the traffic sessions of existing (e.g., no new client) and critical users (e.g., no "less critical" user), thereby allowing them to continue their session with the primary VPNC gateway.However, if the behavior of the user indicates to process 500 that the user is new and "less critical" (e.g., users with a lower user rating and a lower rank than a critical rank), this indicates that 1) the user has just begun sending traffic to the data center; 2) it has no entry in the data path; 3) the user has no existing session that could be interrupted by redirecting his traffic to another VPNC. As a result, dynamically adapting the scheme to send the traffic to a secondary VPNC gateway would not be annoying and would not substantially compromise a new and "less critical" user's experience. Thus, process 500 begins dynamically configuring the VRF ID to select another VPNC gateway (or data center) for that user based on its observed behavior. Operations 514 and 516 may also determine a less critical client where uplink trapping has occurred and whose session must be restarted as a new client.Next, in operation 518, the VRF may be configured at the secondary VPNC gateway. For example, operation 518 may include adding a VRF ID route-destination import and route-destination export configuration for the user identified as a new and less critical user. The VRF is configured at the secondary VPNC gateway for reverse traffic, and the same VRF color tag configuration can be added to the BG. As background, routes with VRF ID may be subscribed to in an overlay network topology. Rules may be added to a VRF on a VPNC gateway and / or the BG, where the rules determine whether to import / export routes of the corresponding VRF ID. In some embodiments, the configuration of the VRF is in Configuration As a Service (CAAS) in operation 518. In some cases, the routes of the configured VRF ID may be learned and known only by the device storing the configuration (e.g., other devices are not informed of the route). Thus, in operation 528, the VRF may be dynamically configured to include a route that sends traffic from a particular new and "less critical" client to the secondary VPNC in a manner that selects the VPNC to provide the best user experience and network security if the state of the primary VPNC gateway is disturbed.Next, in operation 520, based on the configuration in the previous operation 518, the secondary VPNC gateway (or data center) is selected for traffic forwarding. Thereafter, in operation 522, the transmission of the traffic to the selected VPNC gateway may be initiated. For example, following operation 512, in operation 522, forwarding of the traffic to the primary VPNC gateway is emulated. In the scenario in which operation 522 follows operation 520, operation 522 initiates the forwarding of the traffic to the secondary VPNC gateway.FIG. 7 shows an example configuration for a VRF rule 700. FIG. 7 shows an example of a configuration of a VRF rule 700 that may be programmed on the secondary VPNC gateway to define an imported destination route and an exported destination route. The VRF rule 700 is stored on a machine readable storage medium 750. A machine-readable storage medium, such as machine-readable storage medium 750, may be any electronic, magnetic, optical, or other physical storage device that includes or stores executable instructions. For example, the machine readable storage medium 750 may be random access memory (RAM), non-volatile random access memory (NVRAM), electrically erasable programmable read only memory (EEPROM), a storage device, an optical disk, and the like. In some embodiments, the machine readable storage medium 750 may be a non-transitory storage medium, wherein the term "non-transitory" does not include the transitory transmission signals. As described in detail below, the machine readable storage medium 750 may be encoded with executable instructions, for example, instructions represented in the VRF rule 700. A hardware processor may execute instructions of the VRF rule 700 to perform dynamic selection of a VPNC gateway. In some embodiments, the VRF rule 700 is configured dynamically or as needed via the disclosed techniques.FIG. 6 is a block diagram of an example computer system or apparatus 600 in which various of the embodiments described herein may be implemented. The computer system 600 may implement the dynamic VPNC gateway selection techniques as disclosed herein. For example, computer system 600 may be implemented as a dynamic VPNC gateway selection component (shown in FIGS. 3B through 3D ) or as another branch exchange gateway (BG) element for performing the disclosed techniques.As shown, computer system 600 includes a bus 602 or other communication mechanism for communicating information, and one or more hardware processors 604 coupled to bus 602 for processing information. The hardware processor(s) 604 may be, for example, one or more general purpose microprocessors.The computer system 600 also includes a main memory 606, such as random access memory (RAM), a cache, and / or other dynamic storage devices, coupled to the bus 602 for storing information and instructions to be executed by the processor 604. Main memory 606 may also be used to store temporary variables or other intermediate information during execution of instructions to be executed by processor 604. When such instructions are stored in storage media accessible by the processor 604, the computer system 600 becomes a special purpose machine adapted to perform the operations specified in the instructions.The computer system 600 also includes a read only memory (ROM) 608 or other static storage device connected to the bus 602 for storing static information and instructions for the processor 604. A storage device 610, e.g., a magnetic disk, optical disk, or USB stick (flash drive), etc., is provided and connected to the bus 602 to store information and instructions.The computer system 600 may be connected via the bus 602 to a display 612, e.g., a liquid crystal display (LCD) (or touch screen) to display information to a computer user. An input device 614, including alphanumeric and other keys, is coupled to bus 602 for communicating information and command selections to processor 604. Another type of user input device is cursor control 616, such as a mouse, trackball, or cursor direction keys for communicating direction information and command selections to processor 604 and for controlling cursor movement on display 612. In some embodiments, the same directional information and command selections as cursor control may be implemented via receiving touches on a touch screen without cursor.Computer system 600 may include a user interface module for implementing a graphical user interface, which may be stored in a mass storage device as executable software code executed by the computer device(s). This and other modules may include, for example, components such as software components, object oriented software components, class components and task components, processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuitry, data, databases, data structures, tables, arrays, and variables.In general, the term "component", "engine", "system", "database", "data storage", and the like, as used herein, may refer to logic embodied in hardware or firmware, or to a collection of software instructions that may have entry and exit points and are written in a programming language such as Java, C, or C++. A software component may be compiled and linked into an executable program, installed in a dynamic link library, or written in an interpreted programming language such as BASIC, Perl, or Python. It will be appreciated that software components may be invoked from other components or by themselves and / or in response to detected events or interrupts. Software components configured for execution on computers may be provided on a computer readable medium such as a compact disc, digital video disc, epinic flash drive, magnetic disk, or other tangible medium, or as a digital download (and may be originally stored in a compressed or installable format that requires installation, decompression, or decryption prior to execution). Such software code may be partially or completely stored in a memory of the executing computing devices for execution by the computing device. Software instructions may be embedded in firmware such as an EPROM. Moreover, the hardware components may consist of connected logic units such as gates and flip-flops and / or programmable units such as programmable gate arrays or processors.The computer system 600 may implement the techniques described herein using custom hard-wired logic, one or more ASICs or FPGAs, firmware, and / or program logic that, in combination with the computer system, causes or programs the computer system 600 to be a special-purpose machine. According to one embodiment, the techniques described herein are performed by computer system 600 in response to processor(s) 604 executing / executing one or more sequences of one or more instructions contained in main memory 606. Such instructions may be read into main memory 1206 from another storage medium, such as storage device 610. Execution of the sequences of instructions contained in main memory 606 causes processor(s) 604 to perform the process steps described herein. In alternative embodiments, hardwired circuitry may be used in place of or in combination with software instructions.The term "non-transitory media" and similar terms as used herein refer to any media that stores data and / or instructions that cause operation of a machine in a particular manner. Such non-transitory media may include non-transitory media and / or volatile media. The non-volatile media includes, for example, optical or magnetic hard disks, such as storage device 610. Volatile media includes dynamic memory, such as main memory 606. Common forms of non-transitory media include, for example, floppy disks, flexible disks, hard disks, solid state drives, magnetic tapes or other magnetic data storage media, CD-ROMs, other optical data storage media, physical media with patterns of holes, RAM, PROM and EPROM, FLASH-EPROM, NVRAM, other memory chips or cartridges, and their networked versions.Non-transitory media are different from transmission media but may be used in conjunction with them. Transmission media participates in the transmission of information between non-transitory media. Transmission media includes, for example, coaxial cables, copper and fiber optic cables, including the wires making up bus 602. Transmission media can also occur in the form of sound or light waves, as are generated during data communication via radio and infrared.Computer system 600 also includes a communication interface 618 that is connected to bus 602. Network interface 618 establishes a two-way data communication link to one or more network links that are connected to one or more local area networks. The communication interface 618 may be, for example, an Integrated Services Digital Network (ISDN) card, a cable modem, a satellite modem, or a modem to establish a data communication link to a corresponding type of telephone line. As another example, network interface 618 may be a local area network (LAN) card to establish a data communication link to a compatible LAN (or WAN component for communication with a WAN). Wireless connections may also be implemented. In each of these implementations, the network interface 618 sends and receives electrical, electromagnetic, or optical signals that transmit digital data streams having different types of information.A network connection typically allows data communication over one or more networks to other data devices. For example, a network connection may connect over a local area network to a host computer or to data devices operated by an Internet Service Provider (ISP). The ISP, in turn, provides data communication services over the world wide packet data communication network, commonly referred to today as the "Internet.". Both the local area network and the Internet use electrical, electromagnetic or optical signals that transmit digital data streams. The signals over the various networks and the signals on the network connection and over the communication interface 618 that transmit the digital data to and from the computer system 600 are examples of transmission media.Computer system 600 may send messages and receive data including program code via network(s), network connection, and communication interface 618. In the Internet example, a server could transmit a requested code for an application program over the Internet, the ISP, the local area network, and the communication interface 618.The received code may be executed by the processor 604 as it is received and / or stored in the storage device 610 or other non-volatile memory for later execution.Each of the processes, methods, and algorithms described in the preceding paragraphs may be embodied in, and fully or partially automated by, code components executed by one or more computer systems or computer processors having computer hardware. The one or more computer systems or computer processors may also operate to support execution of the respective operations in a cloud computing environment or as a software as a service (SaaS). The processes and algorithms can be partially or fully implemented in application specific circuitry. The various features and methods described above may be used independently or combined in various ways. Various combinations and sub-combinations are intended to fall within the scope of this disclosure, and certain method or process blocks may be omitted in some implementations. The methods and processes described herein are also not limited to a particular order, and the blocks or states associated therewith may be performed in other suitable orders, in parallel, or in other ways. Blocks or states may be added to or removed from the disclosed examples. The execution of certain operations or processes may be distributed among computer systems or computer processors that are not only located on a single machine, but are distributed across a number of machines.A circuit may be implemented in any form of hardware, software, or a combination thereof. For example, one or more processors, controllers, ASICs, PLAs, PALs, CPLDs, FPGAs, logic components, software routines, or other mechanisms may be implemented to form a circuit. In implementation, the various circuits described herein may be implemented as discrete circuits, or the described functions and features may be partially or totally shared among one or more circuits. Although various features or functional elements are individually described or claimed as separate circuits, these features and functions may be shared among one or more common circuits, and such description is not intended to imply or imply that separate circuits are required to implement these features or functions. When a circuit is implemented in whole or in part with software, this software may be implemented to operate on a computer or processing system capable of executing the functionality described with respect to it, such as computer system 600.As used herein, the term "or" may be understood in both the inclusive and exclusive sense. Moreover, the description of resources, operations, or structures in the singular is not to be understood as excluding the plural. Conditional terms such as "may", "could", "could" or "may", unless expressly stated otherwise or otherwise understood in the context, are generally to be understood such that certain embodiments include certain features, elements and / or steps, while other embodiments do not include these.The terms and expressions and their modifications used in this document are not to be understood as limiting, but rather as open-ended, unless expressly stated otherwise. Adjectives such as "conventional", "traditional", "normal", "standard", "known", and terms of similar meaning are not to be understood as limiting the described subject matter to a particular time period or to an available subject matter at a particular time, but should be understood as including conventional, traditional, normal, or standard technologies, which may be available or known now or at any time in the future. The presence of extending words and terms such as "one or more", "at least", "but not limited to", or similar terms in some instances is not to be understood as the narrower case is intended or required when such extending terms are not present.

Claims

A method comprising: assigning criticality ranks to users based on one or more factors related to the behaviors of the users; determining, by a branch exchange gateway (208, 308) comprising a hardware processor (502), whether a primary virtual private network concentrator (VPNC) gateway is okay, wherein the primary VPNC gateway (306A) is one of a plurality of VPNC gateways (306, 316) across one or more data centers (302), wherein the primary VPNC gateway receives forwarded data traffic from devices (310) of the users including a first device of a first user and a second device of a second user; determining, by the branch gateway, whether a service is okay, the service being provided by a data center of the one or more data centers; and based on a determination that the service is not okay or a determination that the primary VPNC gateway is not okay: determining, by the branch gateway, whether the first user associated with the first device has an non-critical rank, and whether the first device from which the first data traffic is received is a new client device newly joined to a network based on a determination that the first user has the non-critical rank and the first device is a new client device, dynamically selecting, by the branch gateway, a secondary VPNC gateway (306N) from the plurality of VPNC gateways across the one or more data centers for transmitting the first traffic from the first device forwarded from the branch gateway to the secondary VPNC gateway, determining, by the branch gateway, whether the second user associated with the second device has a critical rank and whether the second device from which the second traffic is received is a new client device newly joined to the network and based on a determination that the second user has the critical rank or the second device is not a new client device, preserving selection of the primary VPNC gateway by the branch gateway for conveying the second traffic from the second device forwarded from the branch gateway to the primary VPNC gateway.The method of claim 1, wherein determining that the primary VPNC gateway is okay comprises: dynamically measuring a device state associated with the primary VPNC gateway; comparing the measured device state to a state / power threshold; and determining that the measured device state is greater than the state / power threshold.The method of claim 2, wherein the measured device state is associated with at least one of resource availability of the primary VPNC gateway and performance of the primary VPNC gateway.The method of claim 3, wherein dynamically measuring the device state associated with the primary VPNC gateway comprises performing a transmission control protocol (TCP) state check, a user datagram protocol (UDP) state check, or an Internet control message protocol (ICMP) state check for the primary VPNC gateway.The method of claim 1, wherein assigning a rank to a user from the users comprises: calculating a user score for the user, the user score based on the one or more factors related to a behavior of the user; and assigning a critical rank or a non-critical rank to the user based on the user score.The method of claim 5, wherein the one or more factors related to the behavior of the user comprise one or more of: a location of the user, a bandwidth consumed by an application used by the user, a quality of service (QoS) of data traffic associated with the user, a user's representation, a user's threat or security assessment, or a role of the user.The method of claim 5, wherein the user score for the user changes dynamically over time as the one or more factors change with respect to the behavior of the user.The method of claim 1, wherein the data center in which the service is provided is a first data center, the method comprising: based on the determination that the service is not okay and based on the determination that the first user has the non-critical rank and the first device is a new client device, dynamically selecting, by the branch office gateway, the secondary VPNC gateway located in a second data center different from the first data center.The method of claim 1, wherein dynamically selecting the secondary VPNC gateway comprises dynamically configuring a virtual routing and forwarding (VRF) route at the secondary VPNC gateway for first user traffic.A system comprising: a branch gateway (308) having a hardware processor (502) and a non-transitory storage medium (504) including instructions executable on the hardware processor to: assign criticality rules to users based on one or more factors related to behaviors of the users; determining whether a primary virtual private network concentrator (VPNC) gateway is okay, the primary VPNC gateway being one of a plurality of VPNC gateways (306) across one or more data centers, the primary VPNC gateway being for receiving forwarded data traffic from devices of the users including a first device of a first user and a second device of a second user; determining whether a service is okay, the service being provided by one data center from the one or more data centers (302); and based on a determination that the service is not okay or a determination that the primary VPNC gateway is not okay: determining, whether the first user associated with the first device has an non-critical rank and whether the first device from which the first traffic is received is a new client device that has newly joined a network based on a determination that the first user has the non-critical rank and the first device is a new client device, dynamically select a secondary VPNC gateway from the plurality of VPNC gateways across the one or more data centers for communicating the first traffic from the first device that is forwarded from the branch point gateway to the secondary VPNC gateway, the secondary VPNC gateway being different from the primary VPNC gateway, to determine whether the second user is, which is associated with the second device, has a critical rank and whether the second device from which second traffic is received is a new client device newly joined to the network, and based on a determination that the second user has the critical rank or the second device is not a new client device, to obtain a selection of the primary VPNC gateway for communication of the second traffic from the second device, which is forwarded from the branch point gateway to the primary VPNC gateway.The system of claim 10, wherein the instructions are executable on the hardware processor to dynamically monitor the state of each of the plurality of VPNC gateways.The system of claim 11, wherein the instructions are executable on the hardware processor to dynamically determine whether the primary VPNC gateway is okay or not okay based on the monitored condition.The system of claim 10, wherein the data center at which the service is provided is a first data center, and wherein the instructions are executable on the hardware processor to: dynamically select the secondary VPNC gateway located in a second data center different from the first data center based on the determination that the service is not okay and based on the determination that the first user has the non-critical rank and the first device is a new client device.The system of claim 10, wherein the instructions are executable on the hardware processor to: assign a rank to a user of the users based on a user score based on the behavior of the user in the network, the user score calculated based on one or more of a location of the user, a bandwidth consumed by the user for an application, a quality of service (QoS) of the data traffic associated with the user, a representation of the user, a threat or security score of the user, or a role of the user.The system of claim 14, wherein the user score for the user changes dynamically over time as the one or more factors related to the behavior of the user change.The system of claim 10, wherein the data center in which the service is provided is a first data center, and wherein the instructions are executable on the hardware processor to: dynamically select the secondary VPNC gateway located in the first data center based on the determination that the primary VPNC gateway is out of order and based on the determination that the first user has the non-critical rank and the first device is a new client device.The system of claim 12, wherein a state of the primary VPNC gateway is based on a resource availability of the primary VPNC gateway or a performance of the primary VPNC gateway.A non-transitory machine readable storage medium (504) including instructions that, when executed, cause a branch gateway (308) to: assign a rank to a user based on one or more factors related to a behavior of the user, the user being associated with a client device (310), wherein assigning the rank to the user comprises calculating a user score for the user based on the one or more factors related to the behavior of the user and assigning a critical rank or a non-critical rank to the user based on the user score; determining whether a primary virtual private network concentrator (VPNC) gateway is okay, the primary VPNC gateway being one of a plurality of VPNC gateways (306) across one or more data centers (302) of a network to receive forwarded traffic from the user; in response to determining that the primary VPNC gateway is okay, determining whether a service is okay, the service being provided from a destination in a data center of the network; in response to determining that the service is okay, selecting the primary VPNC gateway to receive the forwarded traffic from the user; In response to determining that the service is not okay, or in response to determining that the primary VPNC gateway is not okay, determine whether the user is a non-critical user based on the rank assigned to the user, determine whether the client device associated with the user is a new device on the network in response to determining that the client device was newly added to the network, dynamically select a secondary VPNC gateway from the plurality of VPNC gateways across the one or more data centers to transmit the forwarded data traffic from the user.The non-transitory machine readable storage medium of claim 18, wherein dynamically selecting the secondary VPNC gateway comprises dynamically configuring a virtual routing and forwarding (VRF) ID with a rule to route reverse traffic from the selected secondary VPNC gateway in the data center to the client device associated with the user.

Citation Information

Patent Citations

  • Multi-mode health monitoring service

    US10623285B1

  • Determining operating statuses of applications in different datacenters and switching access between the applications

    US20200106687A1

  • US000010623285B1