Firewall Policy-Based Tunnel Mapping for IPsec Gateway Throughput

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Route-based VPNs face performance issues such as limited throughput and CPU balancing problems due to overloaded CPUs while others remain underutilized, especially when traffic exceeds VPN tunnel capacity.

Innovation Solution

A method for transmitting data messages via secure tunnels using a gateway device that matches messages to firewall rules mapping to specific secure tunnels, encapsulates them with a security parameter index (SPI), and forwards them through a virtual tunnel interface (VTI), leveraging Internet Protocol Security (IPsec) for encryption and authentication across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If route-based VPN is used to support dynamic routing protocols and enable dynamic modification of protected traffic definitions, then scalability and adaptability are improved, but throughput is limited and CPU balancing issues occur

Engineering Contradiction:
Improvedynamic modification of protected traffic definitionsVSAvoidthroughput
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent segments the single VPN tunnel into multiple parallel tunnels. Each tunnel is assigned to handle specific traffic flows based on routing protocols, thereby distributing the traffic load and increasing overall throughput while maintaining dynamic adaptability through policy-based routing rules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an additional dimension of parallelism by creating multiple VPN tunnels instead of using a single tunnel. This dimensional expansion allows simultaneous handling of multiple traffic streams, thereby increasing throughput without compromising the dynamic routing capabilities.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If a single VPN tunnel is used to transmit protected traffic, then configuration is simplified, but throughput is limited and packets are dropped when traffic exceeds tunnel capacity

Engineering Contradiction:
ImproveVPN configurationVSAvoidthroughput
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent divides the single tunnel capacity into multiple parallel tunnels, each capable of handling a portion of the traffic. This segmentation increases the aggregate throughput capacity while the configuration remains manageable through automated policy-based setup.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates multiple tunnels that collectively serve the universal function of transmitting protected traffic. Each tunnel is multi-functional in that it can handle different types of traffic flows based on routing policies, thereby increasing overall system capacity without proportionally increasing configuration complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Device complexity

If traffic is directed to a single VPN tunnel, then routing is simplified, but CPU becomes overloaded while other CPUs remain underutilized

Engineering Contradiction:
ImproveroutingVSAvoidCPU balancing
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The patent segments the CPU processing load by assigning different traffic flows to different tunnels, which are then distributed across multiple CPUs. This segmentation balances the processing load across available CPUs, preventing any single CPU from becoming overloaded while maintaining simplified routing through policy-based allocation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces routing policies as intermediaries that mediate between incoming traffic and the underlying tunnel/CPU resources. These policies automatically distribute traffic across multiple tunnels and CPUs based on predefined rules, thereby simplifying the routing operation while achieving balanced CPU utilization without manual intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11956213B2Using firewall policies to map data messages to secure tunnels
Publication Date: 2024.04.09 VMWARE INC
  • US11956213B2 patent drawing
  • US11956213B2 patent drawing
  • US11956213B2 patent drawing

AI summary

Some embodiments of the invention provide a method for transmitting data messages via secure tunnels in a network. The method is performed at a gateway device. The method determines that a data message received at the gateway device should be sent via a secure interface of the gateway device. The method matches the data message to a firewall rule that maps to a particular secure tunnel used by the secure interface, with multiple different firewall rules mapping to multiple different secure tunnels used by the secure interface. The method encapsulates the data message with a header that comprises an indicator value specifying the particular secure tunnel and forwards the encapsulated data message to a destination interface.