SDWAN Controller Dynamic Application-Specific VPN Tunnel Setup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network architectures face scalability issues with full-mesh network communication due to resource constraints, high implementation costs, and inefficiencies in managing Virtual Private Network (VPN) tunnels, particularly in Software-Defined Wide Area Networks (SDWAN), where protocols like BGP and ADVPN do not allow for dynamic application-specific VPNs, leading to unnecessary network traffic and difficulty in monitoring service quality.

Innovation Solution

A Software-Defined Wide Area Network (SDWAN) controller dynamically establishes network overlay tunnels between edges within different groups of a network architecture by determining configuration information based on pre-configured rules and pushing VPN and SDWAN configuration to network devices, enabling application-specific links and efficient resource allocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If full-mesh network topology is implemented to enable direct communication between all network devices, then network connectivity and traffic management capability are improved, but device resource consumption increases and implementation cost becomes very high

Engineering Contradiction:
Improvetraffic management capabilityVSAvoiddevice resource consumption
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent segments the network into different groups (e.g., finance group, HR group, IT group) where devices only need to establish connections within their group and with other groups when necessary. This partial mesh approach reduces the total number of required connections compared to a full-mesh topology while still enabling effective traffic management for different application scenarios.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic VPN tunnel establishment where connections are created on-demand based on application requirements rather than static pre-configured connections. The controller dynamically establishes VPN tunnels between edges only when needed for specific application traffic, allowing the network to adapt its connectivity structure dynamically and reduce overall resource consumption.

Inventive Principle:
Principle #15Dynamics

2Manufacturing precision

If manually setting up VPN tunnels is performed to establish network connections, then connection configuration precision is improved, but time consumption increases and operational complexity becomes very high

Engineering Contradiction:
Improveconnection configuration precisionVSAvoidtime consumption
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent implements self-service VPN tunnel establishment where network devices automatically configure their own connections through the controller. When a device needs to establish a VPN tunnel, it sends a request to the controller which automatically determines the configuration parameters and pushes the necessary settings to both ends of the connection, eliminating manual configuration time while maintaining precision.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The controller pre-configures templates and policies for VPN tunnel establishment based on application requirements. When a connection is needed, the controller retrieves the appropriate pre-defined configuration template and applies it automatically, avoiding the need for manual configuration while ensuring precise and consistent setup according to organizational policies.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If BGP and ADVPN protocols are used to create overlay links between edges, then network connectivity is improved, but adaptability to application-specific requirements deteriorates and service quality monitoring becomes difficult

Engineering Contradiction:
Improvenetwork connectivityVSAvoidadaptability to application-specific requirements
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements application-specific VPN tunnels where different quality of service parameters can be assigned to different application traffic types. For example, VoIP traffic can have different tunnel configuration parameters compared to file transfer traffic, allowing each application to receive customized network treatment optimized for its specific requirements while maintaining overall network connectivity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The controller monitors application traffic patterns and service quality metrics, using this feedback information to dynamically adjust VPN tunnel configurations. When service quality degradation is detected or application requirements change, the controller can modify tunnel parameters or establish alternative paths to optimize performance for specific applications.

Inventive Principle:
Principle #23Feedback

4Reliability

If dynamic VPNs are established for specific applications like VoIP, then application-specific service quality is improved, but network traffic volume increases and monitoring complexity increases

Engineering Contradiction:
Improveapplication-specific service qualityVSAvoidnetwork traffic volume
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts and separates different application traffic types into dedicated VPN tunnels, allowing VoIP traffic to be isolated from general data traffic. This extraction enables application-specific quality assurance while the controller intelligently manages traffic routing to minimize overall network traffic volume by only establishing tunnels when specific application traffic is detected.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11329883B2Dynamic establishment of application-specific network tunnels between network devices by an SDWAN controller
Publication Date: 2022.05.10 FORTINET INC
  • US11329883B2 patent drawing
  • US11329883B2 patent drawing
  • US11329883B2 patent drawing

AI summary

Systems and methods for dynamically establishing network overlay tunnels between edges within different groups of a network architecture are provided. According to an embodiment, a Software-Defined Wide Area Network (SDWAN) controller associated with a private network, receives a request to initiate a dynamic Virtual Private Network (VPN) link for a network session between a source edge and a destination edge. The SDWAN controller determines configuration information for each of the source edge and the destination edge, which includes VPN and SDWAN configuration information determined based on pre-configured rules managed by the SDWAN controller for generating the dynamic VPN link between the source edge and the destination edge. The SDWAN controller directs the source edge and the destination edge to set up a VPN overlay tunnel in accordance with the determined configuration information by pushing the determined configuration information to each of the source edge and the destination edge.