SSL VPN Session Failover IP Stickiness Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtual private network (VPN) environments, managing IP address assignments and ensuring seamless session failover while maintaining security is challenging due to issues like IP address changes and security software updates, which can lead to network vulnerabilities during failovers.

Innovation Solution

The implementation of an SSL VPN session failover system that propagates user IP address assignments and endpoint authorization information between appliances, ensuring seamless IIP address stickiness and re-authorizing clients based on policy-driven security evaluations during failover scenarios.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a gateway device assigns IP addresses to VPN users, then network access is enabled, but IP address changes during failover cause communication disruptions

Engineering Contradiction:
Improvesession continuityVSAvoidIP address consistency
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The standby gateway is pre-configured with all user IP address assignments before failover occurs. When the primary gateway fails, the standby gateway immediately activates with the pre-loaded IP address mapping information, eliminating the need for reassignment and maintaining session continuity without interruption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The standby gateway maintains a complete copy of the IP address assignment database from the primary gateway. This copying mechanism ensures that when failover occurs, the standby gateway can immediately provide the same IP address assignments that were previously made by the primary gateway, preserving IP address consistency across the transition.

Inventive Principle:
Principle #26Copying

2Reliability

If a gateway re-authorizes clients during failover, then security is maintained, but session interruption occurs

Engineering Contradiction:
ImprovesecurityVSAvoidsession duration
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

Client authorization credentials and security attributes are pre-synchronized to the standby gateway before failover. When the primary gateway fails, the standby gateway can immediately resume authorized sessions without requiring re-authentication, maintaining both security and continuous session operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuous authorization state across gateway failover by preserving authentication credentials and security policy configurations in the standby gateway. This allows the useful action of authorized network access to continue uninterrupted during the gateway transition.

Inventive Principle:
Principle #20Continuity of useful action

3Adaptability or versatility

If IP addresses are reassigned during failover, then new sessions can be established, but existing communications are disrupted

Engineering Contradiction:
Improvesession establishmentVSAvoidIP address stability
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The standby gateway copies the complete IP address assignment database from the primary gateway before takeover. This ensures that when the standby gateway becomes active, it can immediately assign the same IP addresses that were previously assigned, maintaining IP address stability for all existing communications while still enabling new session establishment.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

All IP address assignments are pre-configured in the standby gateway before failover occurs. This preliminary configuration ensures that the standby gateway can immediately resume service with the same IP address assignments, preventing any disruption to existing communications while maintaining the ability to establish new sessions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9009327B2Systems and methods for providing IIP address stickiness in an SSL VPN session failover environment
Publication Date: 2015.04.14 CITRIX SYSTEMS INC
  • US9009327B2 patent drawing
  • US9009327B2 patent drawing
  • US9009327B2 patent drawing

AI summary

The SSL VPN session failover solution of the appliance and/or client agent described herein provides an environment for handling IP address assignment and end point re-authorization upon failover. The appliances may be deployed to provide a session failover environment in which a second appliance is a backup to a first appliance when a failover condition is detected, such as failure in operation of the first appliance. The backup appliance takes over responsibility for SSL VPN sessions provided by the first appliance. In the failover environment, the first appliance propagates SSL VPN session information including user IP address assignment and end point authorization information to the backup appliance. The backup appliance maintains this information. Upon detection of failover of the first appliance, the backup appliance activates the transferred SSL VPN session and maintains the user assigned IP addresses. The backup appliance may also re-authorize the client for the transferred SSL VPN session.