Per Session IPSec Tunnel Load Balancing via Virtual SDWAN Interface

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SDWAN systems lack the ability to effectively steer traffic based on the quality of remote IPSec tunnels, particularly when these tunnels are built on heterogeneous physical links, leading to inefficient load balancing and potential high costs due to prioritization issues.

Innovation Solution

Implementing a dynamic selector for load balancing on a per-session basis between multiple uplinks for IPSec tunnels to a remote SDWAN controller, using a virtual SDWAN interface that monitors network conditions and updates an IPSec phase 2 table to select the optimal uplink for each session, ensuring consistent routing based on real-time performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If SDWAN steers traffic based on local link quality only, then local routing decisions are simple to make, but traffic cannot be optimized based on remote end conditions leading to inefficient load balancing

Engineering Contradiction:
Improverouting decision simplicityVSAvoidload balancing efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent implements feedback by having the remote SDWAN controller send quality metrics back to the local SDWAN. The remote controller measures tunnel quality parameters (latency, packet loss, jitter) and transmits this information to the local controller, enabling informed routing decisions that reflect actual remote end conditions without requiring complex local monitoring of remote links.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent uses the remote SDWAN controller as an intermediary that provides quality information about remote links. Instead of the local SDWAN directly monitoring remote link conditions (which it cannot do), the remote controller acts as a mediator that observes and reports on remote link quality, enabling the local controller to make better routing decisions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If SDWAN uses heterogeneous physical links for IPSec tunnels, then network flexibility and adaptability are improved, but cost efficiency deteriorates due to inability to prioritize links based on remote end quality

Engineering Contradiction:
Improvenetwork link flexibilityVSAvoidnetwork cost efficiency
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The patent implements dynamic link selection where the SDWAN controller continuously receives quality metrics from remote controllers and adjusts routing decisions in real-time. The system dynamically switches between heterogeneous links (broadband, LTE, 5G) based on current quality conditions, optimizing cost efficiency by automatically selecting the most appropriate link for each traffic flow without sacrificing adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes routing parameters (which link to use) based on received quality metrics. When quality metrics indicate poor performance or high cost on a particular link type, the system changes the routing parameter to select an alternative link, thereby optimizing cost efficiency while maintaining the ability to use heterogeneous links when appropriate.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If SDWAN monitors remote tunnel quality using periodic probes, then some quality information can be obtained, but real-time optimization is prevented due to detection delays

Engineering Contradiction:
Improvequality information availabilityVSAvoiddetection delay
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having the remote SDWAN controller continuously monitor and prepare quality metrics before they are needed for routing decisions. The remote controller actively measures tunnel quality parameters and maintains updated quality information ready for immediate transmission to the local controller, eliminating the need for periodic probe delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous feedback where quality metrics are transmitted from the remote controller to the local controller in near-real-time. This feedback mechanism provides current quality information without the delays inherent in periodic probing, enabling the local controller to make timely routing optimizations based on actual current conditions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240179565A1Per session link load balancing of ipsec tunnels over multiple uplinks to same ipsec gateway
Publication Date: 2024.05.30 FORTINET INC
  • US20240179565A1 patent drawing
  • US20240179565A1 patent drawing
  • US20240179565A1 patent drawing

AI summary

A first data packet can be forwarded to a virtual SDWAN interface which has multiple IPSec tunnels as members, each of which is disposed over a different uplink, wherein the multiple IPSec tunnels each connect to the remote SDWAN controller. Load balancing of the particular session is performed relative to other sessions by selecting one of the multiple uplinks for transmission to the remote SDWAN controller. Phase 2 of IPSec is set up for the particular session by updating an IPSec phase 2 table with the selected uplink associated with the particular session, to direct subsequent packets of the same session.