Dynamic AI Split Tunneling for Remote Teleworker SaaS Performance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Remote teleworkers often experience degraded quality of experience (QoE) for software-as-a-service (SaaS) applications due to varying routing options, as current methods rely on manual mapping of SLAs between applications and tunnels, which are reactive and prone to SLA failures, leading to inefficient routing decisions.
Innovation Solution
A predictive application-aware routing engine uses path probe data and machine learning models to forecast the best path between end-user sites and online applications, generating dynamic split tunnel policies to optimize routing and reduce SLA failures, thereby enhancing application performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If manual mapping of SLAs between applications and tunnels is used, then configuration simplicity is maintained, but routing accuracy and application performance deteriorate
Solution Approach 1:
The system performs self-service by automatically discovering applications, generating SLAs based on performance measurements, and creating routing policies without manual intervention. The application awareness engine automatically identifies applications and the policy generator automatically creates routing decisions, eliminating the need for manual SLA mapping while maintaining configuration simplicity.
Solution Approach 2:
The system performs preliminary actions by pre-generating SLAs and routing policies based on historical performance data and predictions. The predictive analytics engine forecasts future performance conditions and pre-configures optimal routing paths before performance degradation occurs, enabling proactive rather than reactive routing decisions.
2Device complexity
If reactive routing methods are used, then system simplicity is maintained, but reliability and SLA compliance deteriorate
Solution Approach 1:
The system performs preliminary actions by using predictive analytics to forecast SLA violations before they occur. The predictive analytics engine analyzes historical performance data and current conditions to predict future SLA compliance, allowing the system to proactively adjust routing policies to prevent violations rather than reacting after failures occur.
Solution Approach 2:
The system implements continuous feedback loops where performance monitoring data is constantly collected, analyzed, and used to adjust routing decisions. The performance monitoring component tracks actual SLA compliance and feeds this information back to the policy generator, which dynamically adjusts routing policies to maintain or improve SLA compliance levels.
3Reliability
If dynamic AI-driven routing is implemented, then application performance is improved, but system complexity increases
Solution Approach 1:
The system segments complex routing functions into distinct modular components: application awareness engine for application identification, SLA generation engine for policy creation, predictive analytics engine for forecasting, and performance monitoring component for tracking. This segmentation allows each component to perform its specific function independently, making the overall complex system more manageable and maintainable.
Solution Approach 2:
The system introduces intermediary components that simplify the interaction between complex elements. The policy generator acts as an intermediary that translates predictive analytics outputs into actionable routing policies, while the performance monitoring component serves as an intermediary that converts raw network data into meaningful performance metrics for the SLA compliance evaluation.
Data Source
AI summary
In one embodiment, a device obtains path probe data between one or more end-user sites and an online application. The device makes, based on the path probe data, a prediction as to whether a direct Internet access path or a backhaul path would offer better application performance for the online application. The device generates, based on the prediction, a split tunnel policy for a particular end-user site. The device causes a particular end-user site to connect to the online application in accordance with the split tunnel policy.


