Tunnel Probe Packet Monitoring for Secure Packet Loss Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing overlay networks face challenges in monitoring packet loss in tunneled communications due to security concerns and bandwidth consumption during communications.
Innovation Solution
The described technology monitors packet loss in tunneled communications by generating probe packets at a network end-point device, periodically transmitting such probe packets through the tunnel to the end-point where a Virtual Forwarding Platform intercepts each probe packet and acknowledges receipt without forwarding it to the customer's virtual machine.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional monitoring methods are used in tunneled communications, then packet loss can be detected, but security concerns arise and bandwidth is consumed
Solution Approach 1:
The monitoring function is segmented from customer communications by using dedicated probe packets with unique flags that are distinct from normal data traffic. This allows separate monitoring channels that do not interfere with customer bandwidth or security
Solution Approach 2:
A Virtual Forwarding Platform acts as an intermediary that intercepts probe packets before they reach customer virtual machines. The VFP acknowledges receipt of probe packets without forwarding them to customers, enabling monitoring while protecting customer systems and bandwidth
2Measurement precision
If probe packets are transmitted through the tunnel, then packet loss is detected, but customer communications may be interfered with
Solution Approach 1:
Different packet types have different handling rules: probe packets with specific flags are intercepted and acknowledged by the VFP without reaching customers, while normal customer traffic flows uninterrupted. This local differentiation ensures monitoring without interference
Solution Approach 2:
The VFP creates a copy of the probe packet processing path that is separate from the customer communication path. Probe packets are acknowledged by the VFP copy rather than being delivered to customers, eliminating interference while maintaining detection capability
Data Source
AI summary
A system generates a probe packet including a probe flag and transmits the probe packet through a network tunnel to a destination computing system. The system receives from the destination computing system through the network tunnel an acknowledgment packet indicating receipt of the probe packet with the probe flag by the destination computing system. The system determines whether the transmitted probe packet and the received acknowledgment packet satisfy a packet loss condition. The system indicates packet loss based on the transmitted probe packet and the received acknowledgment packet satisfying the packet loss condition.


