Branch Controller UDP Ping for SD-WAN Application Health Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In SD-WAN environments, existing VPN connections lack programmability to configure networks based on the health and availability of applications, limiting the ability to reroute traffic effectively in response to performance issues or failures, leading to potential downtime and suboptimal application performance.
Innovation Solution
The implementation of a modified UDP ping mechanism that transmits through VPN connections to gather information on network characteristics and application statuses, allowing the branch site controller to switch traffic to alternative core sites based on performance metrics, ensuring continuous and high-quality service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VPN connections are established to multiple core sites for redundancy, then network reliability is improved, but the ability to dynamically switch traffic based on application health status deteriorates due to lack of programmability
Solution Approach 1:
The system implements a feedback mechanism where the branch controller continuously monitors application health status from core sites and uses this information to dynamically adjust traffic routing. The controller receives health status updates and automatically switches traffic away from sites with unhealthy applications, creating a closed-loop control system that adapts to changing conditions.
Solution Approach 2:
The branch controller autonomously performs health status monitoring and traffic switching decisions without requiring manual intervention. The system self-manages the routing configuration by evaluating application health metrics and automatically reconfiguring VPN traffic paths when degradation is detected, enabling the network to self-heal and adapt.
2Device complexity
If traditional VPN gateways are used without application health monitoring, then device complexity is reduced, but network performance and availability deteriorate due to inability to detect and respond to application failures
Solution Approach 1:
The patent introduces an intermediary application health monitoring mechanism that sits between the VPN gateway and the core sites. This intermediary component collects application health status information and provides it to the branch controller, enabling intelligent routing decisions without significantly increasing gateway complexity. The intermediary acts as a mediator that bridges the gap between simple gateway infrastructure and sophisticated traffic management needs.
Solution Approach 2:
The system performs preliminary health status checks and monitoring before traffic routing decisions are made. By continuously assessing application health in advance and maintaining readiness to switch routes, the system proactively prevents performance degradation rather than reacting after failures occur, thereby improving application availability without requiring complex real-time decision-making at the gateway.
3Ease of operation
If manual configuration and monitoring of VPN connections is used, then ease of operation is maintained, but productivity and response time to failures deteriorate
Solution Approach 1:
The branch controller automatically performs health status monitoring, evaluation, and traffic switching operations without requiring manual configuration or intervention. The system self-configures routing paths based on real-time application health data, eliminating the time-consuming manual processes while maintaining operational simplicity through automated decision-making algorithms.
Solution Approach 2:
The system implements automated feedback-driven routing where the branch controller continuously receives health status information and automatically adjusts traffic routing in response. This feedback loop enables rapid response to application failures and performance degradation, dramatically improving productivity and switch response time compared to manual monitoring and configuration approaches.
Data Source
AI summary
A computer-implemented method includes requesting, using a branch controller, an operating status of at least one application of a first plurality of applications executing in a first core site using a first User Datagram Protocol (UDP) ping, the first UDP ping being transmitted to a first network controller included in the first core site through a first VPN connection between the branch controller and the first core site; and receiving, using the branch controller, the operating status of the at least one application of the first plurality of applications using the first UDP ping received through the first VPN connection.


