Active Mesh VPC Gateways for Autonomous Cloud Failover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional VPC failover communication schemes in cloud computing platforms require complex failover logic, lead to inefficient resource usage, and cause disruptions due to time-consuming updates of routing tables during communication link failures, especially when both primary and high availability links fail.
Innovation Solution
A load-balanced, full-mesh network architecture is established within a public cloud computing platform, featuring multiple virtual private cloud networks with spoke and transit gateways that maintain active peer-to-peer communication links using IPSec tunnels, allowing autonomous updates and load balancing without relying on intensive monitoring or reprogramming of routing tables, and utilizing secondary tunnels for alternative routing paths when primary links fail.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If active-standby failover scheme is used, then communication reliability is improved, but device complexity increases due to complex failover logic and routing table management
Solution Approach 1:
The network is segmented into multiple active communication links (first link, second link, third link) between gateways, each operating independently. This segmentation eliminates the need for complex failover logic by distributing traffic across multiple paths, where each link can be managed autonomously without centralized control complexity.
Solution Approach 2:
Multiple communication links are established in advance before any failure occurs. The system pre-configures first, second, and third communication links between gateways, so that when a failure occurs, traffic can immediately reroute through pre-established paths without requiring complex real-time failover decisions.
2Reliability
If standby communication link is maintained, then communication reliability is improved, but resource efficiency deteriorates due to idle resource wastage
Solution Approach 1:
The system dynamically adjusts traffic distribution across communication links based on real-time conditions. All links remain active and can carry traffic simultaneously, with the ability to dynamically shift load between links as needed, eliminating the static idle state of standby links while maintaining reliability.
Solution Approach 2:
Multiple communication links continuously carry useful traffic rather than remaining idle. The first, second, and third communication links all actively transmit data between gateways, ensuring that resources are continuously utilized productively while maintaining redundant paths for reliability.
3Reliability
If routing table reprogramming is performed during failover, then communication reliability is improved, but productivity deteriorates due to communication disruptions and time consumption
Solution Approach 1:
Multiple routing paths are pre-configured in the routing tables before any failure occurs. The gateway devices have advance knowledge of alternative paths (first link, second link, third link), eliminating the need for time-consuming routing table reprogramming during failover events.
Solution Approach 2:
Gateway devices autonomously select and switch between communication links based on pre-configured routing information without requiring external controller intervention. This self-service capability allows immediate failover without disruptive reprogramming operations.
Data Source
AI summary
According to one embodiment, a network system features a first virtual private cloud (VPC) network and a second VPC network. The first VPC network includes a first plurality of gateways. Each gateway of the first plurality of gateways is in communications with other gateways of the first plurality of gateways in accordance with a first tunnel protocol. Similarly, a second VPC network includes a second plurality of gateways. Each of the second plurality of gateways is communicatively coupled to the each of the first plurality of gateways in accordance with a second security protocol to provide redundant routing.


