SD-WAN Control Device Optimizing DNS Query Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional SaaS access methods using SD-WAN techniques are not optimized for actual use scenarios, leading to unexpected latency when accessing a SaaS server from a user terminal, especially in closed networks.
Innovation Solution
A control device connected to multiple networks that dispatches packets received from user terminals, featuring a DNS control unit to manage DNS queries and a routing unit to determine packet destinations based on packet addresses, optimizing DNS query routing and bypassing proxies to improve SaaS access speed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If SD-WAN Local Breakout is implemented to direct SaaS traffic from branch site directly to Internet, then SaaS access speed is improved, but unexpected latency occurs due to non-optimized routing for actual use scenes
Solution Approach 1:
The patent segments the network traffic handling by separating DNS query routing from general data traffic routing. The control device specifically intercepts and routes DNS query packets through an optimized path to Internet DNS servers, while other traffic follows standard routing. This segmentation resolves the contradiction by optimizing the critical DNS resolution path without disrupting overall SD-WAN Local Breakout functionality.
Solution Approach 2:
The control device acts as an intermediary between user terminals and the network, specifically intercepting DNS query packets and redirecting them through an optimized route to Internet DNS servers. This intermediary function allows the system to resolve domain names faster while maintaining the benefits of SD-WAN Local Breakout for actual data traffic, thereby reducing latency without sacrificing access speed.
2Measurement precision
If DNS queries are routed through Internet DNS server instead of internal DNS server, then domain name resolution accuracy is improved, but network traffic increases and latency occurs
Solution Approach 1:
The patent applies local quality by making the DNS query routing path different from general data traffic paths. Specifically, DNS queries are routed locally through the control device to Internet DNS servers for accurate resolution, while the resulting data traffic benefits from Local Breakout by being directed directly to Internet destinations without returning through the corporate network. This localized optimization resolves the contradiction by ensuring accurate domain resolution without causing latency in the actual data access.
Solution Approach 2:
The control device performs preliminary action by intercepting and routing DNS queries before actual data traffic flows. By resolving domain names through Internet DNS servers in advance and caching the results, the system ensures accurate domain name resolution while preventing latency during subsequent data access operations, as the domain resolution is completed beforehand through the optimized path.
3Reliability
If all packets are routed through internal DNS server in closed network, then network security is improved, but SaaS access latency increases
Solution Approach 1:
The patent implements dynamic routing where the control device adapts its behavior based on packet type. For DNS query packets, it dynamically redirects them to Internet DNS servers for fast and accurate resolution. For other traffic, it maintains standard routing through the closed network infrastructure. This dynamic approach resolves the contradiction by selectively applying different routing strategies to different traffic types, ensuring both security and low latency.
Data Source
AI summary
A control device is connected to a plurality of networks, dispatches a packet received from a user terminal to a network among the plurality of networks, and includes a memory and a processor configured to execute receiving a DNS query packet transmitted from the user terminal, and based on a query target of the DNS query packet, dispatching the DNS query packet to a network among the plurality of networks; and receiving a packet, determining a destination of the packet based on a destination address of the packet, and transmitting the packet to the determined destination.


