Per Session IPSec Tunnel Load Balancing via Virtual SDWAN Interface
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current SDWAN systems lack the ability to effectively steer traffic based on the quality of remote IPSec tunnels, particularly when these tunnels are built on heterogeneous physical links, leading to inefficient load balancing and potential high costs due to prioritization issues.
Innovation Solution
Implementing a dynamic selector for load balancing on a per-session basis between multiple uplinks for IPSec tunnels to a remote SDWAN controller, using a virtual SDWAN interface that monitors network conditions and updates an IPSec phase 2 table to select the optimal uplink for each session, ensuring consistent routing based on real-time performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If SDWAN steers traffic based on local link quality only, then local routing decisions are simple to make, but traffic cannot be optimized based on remote end conditions leading to inefficient load balancing
Solution Approach 1:
The patent implements feedback by having the remote SDWAN controller send quality metrics back to the local SDWAN. The remote controller measures tunnel quality parameters (latency, packet loss, jitter) and transmits this information to the local controller, enabling informed routing decisions that reflect actual remote end conditions without requiring complex local monitoring of remote links.
Solution Approach 2:
The patent uses the remote SDWAN controller as an intermediary that provides quality information about remote links. Instead of the local SDWAN directly monitoring remote link conditions (which it cannot do), the remote controller acts as a mediator that observes and reports on remote link quality, enabling the local controller to make better routing decisions.
2Adaptability or versatility
If SDWAN uses heterogeneous physical links for IPSec tunnels, then network flexibility and adaptability are improved, but cost efficiency deteriorates due to inability to prioritize links based on remote end quality
Solution Approach 1:
The patent implements dynamic link selection where the SDWAN controller continuously receives quality metrics from remote controllers and adjusts routing decisions in real-time. The system dynamically switches between heterogeneous links (broadband, LTE, 5G) based on current quality conditions, optimizing cost efficiency by automatically selecting the most appropriate link for each traffic flow without sacrificing adaptability.
Solution Approach 2:
The patent changes routing parameters (which link to use) based on received quality metrics. When quality metrics indicate poor performance or high cost on a particular link type, the system changes the routing parameter to select an alternative link, thereby optimizing cost efficiency while maintaining the ability to use heterogeneous links when appropriate.
3Loss of information
If SDWAN monitors remote tunnel quality using periodic probes, then some quality information can be obtained, but real-time optimization is prevented due to detection delays
Solution Approach 1:
The patent applies preliminary action by having the remote SDWAN controller continuously monitor and prepare quality metrics before they are needed for routing decisions. The remote controller actively measures tunnel quality parameters and maintains updated quality information ready for immediate transmission to the local controller, eliminating the need for periodic probe delays.
Solution Approach 2:
The patent implements continuous feedback where quality metrics are transmitted from the remote controller to the local controller in near-real-time. This feedback mechanism provides current quality information without the delays inherent in periodic probing, enabling the local controller to make timely routing optimizations based on actual current conditions.
Data Source
AI summary
A first data packet can be forwarded to a virtual SDWAN interface which has multiple IPSec tunnels as members, each of which is disposed over a different uplink, wherein the multiple IPSec tunnels each connect to the remote SDWAN controller. Load balancing of the particular session is performed relative to other sessions by selecting one of the multiple uplinks for transmission to the remote SDWAN controller. Phase 2 of IPSec is set up for the particular session by updating an IPSec phase 2 table with the selected uplink associated with the particular session, to direct subsequent packets of the same session.


