Dynamic Split Tunneling via DNS Interception
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional Virtual Private Network (VPN) split tunneling methods are cumbersome and require large, complex rules for routing traffic to specific data centers, making them inefficient for modern cloud-based services that need to route traffic based on application services rather than traditional routes.
Innovation Solution
Implementing dynamic split tunneling logic that uses Fully Qualified Domain Names (FQDNs) to route traffic securely to multiple data centers, with a VPN client intercepting and modifying DNS requests and responses to use dummy IP addresses for sub-domains, allowing traffic to be routed through the appropriate tunnels without user-driven authentication, enabling efficient and secure access to application services across multiple networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional split tunneling methods are used to route traffic to specific data centers, then traffic routing capability is provided, but the system becomes cumbersome with very large split include/exclude VPN rules
Solution Approach 1:
The patent changes the routing parameter from traditional IP-based include/exclude rules to application service-based routing. Instead of managing large lists of IP addresses and subnets, the system routes traffic based on application services identified through DNS interception and FQDN matching, dramatically reducing rule complexity while maintaining routing capability.
Solution Approach 2:
The patent introduces an intermediary mechanism between DNS resolution and traffic routing. The VPN client intercepts DNS requests, modifies them to include FQDN information, and uses this intermediate layer to determine routing decisions, eliminating the need for complex traditional split tunneling rules.
2Reliability
If traditional VPN tunnels all traffic, then secure access is provided, but efficiency is reduced due to unnecessary encryption and routing of non-service traffic
Solution Approach 1:
The patent segments traffic routing by application service rather than applying a blanket tunnel to all traffic. Each application service can be routed through appropriate VPN tunnels based on its specific requirements, providing security where needed while allowing efficient direct routing for services that don't require tunneling.
Solution Approach 2:
The patent implements dynamic routing decisions based on real-time DNS interception and FQDN matching. The system dynamically determines which traffic should be tunneled and which should use direct routes, adapting to application service requirements rather than using static all-or-nothing tunneling.
3Productivity
If split tunneling is implemented to allow access to certain network segments, then routing efficiency is improved, but user-driven authentication becomes cumbersome
Solution Approach 1:
The patent implements self-service authentication through automatic FQDN-based routing. The VPN client automatically intercepts DNS requests, determines the appropriate tunnel based on FQDN matching, and routes traffic without requiring user intervention or manual authentication decisions, making the process transparent to the user.
Solution Approach 2:
The patent performs preliminary DNS interception and FQDN matching before traffic routing decisions are made. By resolving service names and matching FQDNs in advance, the system prepares routing information beforehand, enabling efficient automatic authentication and routing without user-driven processes.
Data Source
AI summary
One embodiment provides selectively routing Domain Name System (DNS) request for sub-domains associated with a first network through a tunnel associated with the first network via the interface. DNS requests for sub-domains associated with a second network are selectively routed through a tunnel associated with the second network via the interface. Embodiments include replacing the destination address for DNS requests for sub-domains associated with the second network to match an address of a DNS server associated with the second network. Data representative of DNS requests for sub-domains associated with the second network is stored. Embodiments forward the DNS requests for sub-domains associated with the second network with the address of the DNS server associated with the second network.


