SSL VPN Session Failover IP Stickiness Mechanism
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtual private network (VPN) environments, managing IP address assignments and ensuring seamless session failover while maintaining security is challenging due to issues like IP address changes and security software updates, which can lead to network vulnerabilities during failovers.
Innovation Solution
The implementation of an SSL VPN session failover system that propagates user IP address assignments and endpoint authorization information between appliances, ensuring seamless IIP address stickiness and re-authorizing clients based on policy-driven security evaluations during failover scenarios.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a gateway device assigns IP addresses to VPN users, then network access is enabled, but IP address changes during failover cause communication disruptions
Solution Approach 1:
The standby gateway is pre-configured with all user IP address assignments before failover occurs. When the primary gateway fails, the standby gateway immediately activates with the pre-loaded IP address mapping information, eliminating the need for reassignment and maintaining session continuity without interruption.
Solution Approach 2:
The standby gateway maintains a complete copy of the IP address assignment database from the primary gateway. This copying mechanism ensures that when failover occurs, the standby gateway can immediately provide the same IP address assignments that were previously made by the primary gateway, preserving IP address consistency across the transition.
2Reliability
If a gateway re-authorizes clients during failover, then security is maintained, but session interruption occurs
Solution Approach 1:
Client authorization credentials and security attributes are pre-synchronized to the standby gateway before failover. When the primary gateway fails, the standby gateway can immediately resume authorized sessions without requiring re-authentication, maintaining both security and continuous session operation.
Solution Approach 2:
The system maintains continuous authorization state across gateway failover by preserving authentication credentials and security policy configurations in the standby gateway. This allows the useful action of authorized network access to continue uninterrupted during the gateway transition.
3Adaptability or versatility
If IP addresses are reassigned during failover, then new sessions can be established, but existing communications are disrupted
Solution Approach 1:
The standby gateway copies the complete IP address assignment database from the primary gateway before takeover. This ensures that when the standby gateway becomes active, it can immediately assign the same IP addresses that were previously assigned, maintaining IP address stability for all existing communications while still enabling new session establishment.
Solution Approach 2:
All IP address assignments are pre-configured in the standby gateway before failover occurs. This preliminary configuration ensures that the standby gateway can immediately resume service with the same IP address assignments, preventing any disruption to existing communications while maintaining the ability to establish new sessions.
Data Source
AI summary
The SSL VPN session failover solution of the appliance and/or client agent described herein provides an environment for handling IP address assignment and end point re-authorization upon failover. The appliances may be deployed to provide a session failover environment in which a second appliance is a backup to a first appliance when a failover condition is detected, such as failure in operation of the first appliance. The backup appliance takes over responsibility for SSL VPN sessions provided by the first appliance. In the failover environment, the first appliance propagates SSL VPN session information including user IP address assignment and end point authorization information to the backup appliance. The backup appliance maintains this information. Upon detection of failover of the first appliance, the backup appliance activates the transferred SSL VPN session and maintains the user assigned IP addresses. The backup appliance may also re-authorize the client for the transferred SSL VPN session.


