Firewall Policy-Based Tunnel Mapping for IPsec Gateway Throughput
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Route-based VPNs face performance issues such as limited throughput and CPU balancing problems due to overloaded CPUs while others remain underutilized, especially when traffic exceeds VPN tunnel capacity.
Innovation Solution
A method for transmitting data messages via secure tunnels using a gateway device that matches messages to firewall rules mapping to specific secure tunnels, encapsulates them with a security parameter index (SPI), and forwards them through a virtual tunnel interface (VTI), leveraging Internet Protocol Security (IPsec) for encryption and authentication across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If route-based VPN is used to support dynamic routing protocols and enable dynamic modification of protected traffic definitions, then scalability and adaptability are improved, but throughput is limited and CPU balancing issues occur
Solution Approach 1:
The patent segments the single VPN tunnel into multiple parallel tunnels. Each tunnel is assigned to handle specific traffic flows based on routing protocols, thereby distributing the traffic load and increasing overall throughput while maintaining dynamic adaptability through policy-based routing rules.
Solution Approach 2:
The patent introduces an additional dimension of parallelism by creating multiple VPN tunnels instead of using a single tunnel. This dimensional expansion allows simultaneous handling of multiple traffic streams, thereby increasing throughput without compromising the dynamic routing capabilities.
2Device complexity
If a single VPN tunnel is used to transmit protected traffic, then configuration is simplified, but throughput is limited and packets are dropped when traffic exceeds tunnel capacity
Solution Approach 1:
The patent divides the single tunnel capacity into multiple parallel tunnels, each capable of handling a portion of the traffic. This segmentation increases the aggregate throughput capacity while the configuration remains manageable through automated policy-based setup.
Solution Approach 2:
The patent creates multiple tunnels that collectively serve the universal function of transmitting protected traffic. Each tunnel is multi-functional in that it can handle different types of traffic flows based on routing policies, thereby increasing overall system capacity without proportionally increasing configuration complexity.
3Device complexity
If traffic is directed to a single VPN tunnel, then routing is simplified, but CPU becomes overloaded while other CPUs remain underutilized
Solution Approach 1:
The patent segments the CPU processing load by assigning different traffic flows to different tunnels, which are then distributed across multiple CPUs. This segmentation balances the processing load across available CPUs, preventing any single CPU from becoming overloaded while maintaining simplified routing through policy-based allocation.
Solution Approach 2:
The patent introduces routing policies as intermediaries that mediate between incoming traffic and the underlying tunnel/CPU resources. These policies automatically distribute traffic across multiple tunnels and CPUs based on predefined rules, thereby simplifying the routing operation while achieving balanced CPU utilization without manual intervention.
Data Source
AI summary
Some embodiments of the invention provide a method for transmitting data messages via secure tunnels in a network. The method is performed at a gateway device. The method determines that a data message received at the gateway device should be sent via a secure interface of the gateway device. The method matches the data message to a firewall rule that maps to a particular secure tunnel used by the secure interface, with multiple different firewall rules mapping to multiple different secure tunnels used by the secure interface. The method encapsulates the data message with a header that comprises an indicator value specifying the particular secure tunnel and forwards the encapsulated data message to a destination interface.


