Dynamic VPN Routing With Hub-Based IPSEC Endpoint Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Dynamic VPN solutions like Cisco DMVPN and Fortinet ADVPN face limitations in adapting to changing link quality at remote sites due to reliance on local information, leading to decreased effectiveness and efficiency.
Innovation Solution
A system and method for global visibility of VPN conditions that integrates information from both local and remote sites by using a hub to select IPSEC endpoints based on link quality metrics, enabling dynamic VPN routing with updated link quality information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If dynamic VPN solutions rely on local information for routing decisions, then device complexity is reduced and ease of operation is improved, but adaptability to changing link quality deteriorates
Solution Approach 1:
The patent introduces a central controller as an intermediary that collects link quality metrics from multiple sites and makes centralized routing decisions. This mediator aggregates information from distributed sources and coordinates IPSEC endpoint selections across the network, enabling global visibility without requiring complex distributed algorithms at each device.
Solution Approach 2:
The system implements continuous feedback loops where link quality metrics are constantly monitored, reported to the central controller, and used to dynamically adjust routing decisions. This feedback mechanism enables the system to adapt to changing conditions in real-time, with the controller receiving updates on link quality and responding by selecting optimal IPSEC endpoints.
2Loss of information
If dynamic VPN solutions use local information only, then information processing simplicity is maintained, but loss of information about remote link quality increases
Solution Approach 1:
The patent merges information collection from multiple distributed sites into a centralized view at the controller. By combining link quality data from all sites through the central controller, the system achieves complete information awareness without requiring each device to independently gather and process information from everywhere in the network.
3Reliability
If IPSEC endpoints are selected without considering link quality, then ease of operation is improved and device complexity is reduced, but network performance and reliability deteriorate
Solution Approach 1:
The system dynamically changes routing parameters (IPSEC endpoint selections) based on measured link quality metrics. Instead of using static routing configurations, the controller adjusts routing parameters in response to changing network conditions, optimizing reliability while maintaining operational simplicity through automated parameter adjustment.
Data Source
AI summary
A local spoke is configured with a hub that serves at least one remote spoke equipped with a plurality of IPSEC endpoint interfaces for routing traffic according to a routing table of the hub. A first routing path is received to the at least one remote spoke for dynamic VPN with a first IPSEC endpoint selected by the hub based on a Reply message without consideration of first link quality of the remote spoke relative to other available links. In another embodiment, an ADVPN shortcut is established. Data packets are then transmitted using a second routing path for dynamic VPN with a second IPSEC endpoint. A new ADVPN shortcut is established for more optimal routing, based on updated link quality metrics discovered during a health check. The existing ADVPN shortcut is then allowed to expire.


