Access Point Tunnel Tag Assignment for VLAN Redundancy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network connectivity solutions lack redundancy, leading to VPN downtime and associated productivity losses and inefficiencies when primary VLAN tunnels experience failures.
Innovation Solution
Access points (APs) are designed to detect threshold failures in primary VLAN tunnels and automatically switch to secondary VLAN tunnels by assigning corresponding tunnel tags to DHCP profiles, ensuring continuous VPN connectivity by connecting to backup network controllers in different data centers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single primary VLAN tunnel is used for VPN connectivity, then the network configuration is simple and device complexity is low, but the system lacks redundancy and VPN downtime occurs when the primary tunnel fails
Solution Approach 1:
The system pre-configures both primary and secondary VLAN tunnels before failures occur. The AP establishes backup tunnel connections in advance and assigns tunnel tags to DHCP profiles, so that when the primary tunnel fails, the switch to secondary tunnel can happen immediately without delay for configuration or connection establishment.
Solution Approach 2:
The system uses tunnel tags as parameters to identify different VLAN tunnels. By changing the tunnel tag parameter in DHCP profiles, the system can switch between primary and secondary tunnels. This parameter-based approach allows flexible tunnel selection and switching without complex reconfiguration, resolving the contradiction between reliability and complexity.
2Reliability
If backup VLAN tunnels are configured for redundancy, then VPN connectivity reliability improves, but the device complexity and network configuration overhead increase
Solution Approach 1:
The AP is designed with multi-functionality to handle both primary and secondary tunnel management. It can detect tunnel failures, assign different tunnel tags to DHCP profiles, and switch between tunnels automatically. This universal capability reduces the need for separate dedicated backup systems, maintaining reliability while controlling complexity.
Solution Approach 2:
The system implements automatic failure detection and self-healing through the AP's ability to monitor tunnel health and autonomously switch to backup tunnels. The AP detects when the primary tunnel fails and automatically connects clients to the secondary tunnel without manual intervention, providing reliability while minimizing the operational complexity of managing backup systems.
3Productivity
If automatic tunnel switching is implemented, then VPN downtime is minimized and productivity is maintained, but the system complexity and detection mechanisms increase
Solution Approach 1:
The AP implements feedback mechanisms by continuously monitoring the health of the primary VLAN tunnel. When failure conditions are detected (such as threshold failures), the system automatically triggers the switching process to connect clients to the secondary tunnel. This feedback-based automatic detection and response minimizes VPN downtime and maintains productivity without requiring complex manual detection systems.
4Reliability
If manual intervention is required for tunnel switching, then system complexity is reduced, but VPN downtime increases and productivity is lost
Solution Approach 1:
The system enables self-service automatic tunnel switching through the AP's autonomous failure detection and switching capabilities. When the primary tunnel fails, the AP automatically detects the failure condition and switches clients to the secondary tunnel without requiring manual intervention. This eliminates VPN downtime associated with manual switching while maintaining manageable system complexity through standardized automated procedures.
Data Source
AI summary
An access point, comprising: a processing resource; and a memory resource storing machine-readable instructions to cause the processing resource to: assign a first tunnel tag to a first DHCP profile of a client device, the first tunnel tag identifying a primary VLAN tunnel to a first network controller of a first data center; assign a second tunnel tag to a second DHCP profile of the client device, the second tunnel tag identifying a secondary VLAN tunnel to a second network controller of a second data center; determine whether the primary VLAN tunnel to the first network controller is inactive based on a number of detected access failures; and connect the client device to the secondary VLAN tunnel in response to determining that the primary VLAN tunnel is inactive.


