Dynamic selection of a VPNC gateway based on user behavior

    公开(公告)号:US11929988B2

    公开(公告)日:2024-03-12

    申请号:US17171963

    申请日:2021-02-09

    Abstract: Systems and methods are provided for dynamic virtual private network concentrators (VPNC) gateway selection and on-demand VRF-ID configuration. A dynamic VPNC gateway selection component can dynamically route to a particular VPNC gateway based on multiple user-specific factors, including: a) behavior of users on the network; and b) performance of a destination service/device. A dynamic VPNC gateway selection component can rank a user based on one or more factors relating to the behavior of the user. Also, the dynamic VPNC gateway selection component can determine whether a VPNC gateway at a data center is healthy, and whether a destination service at the data center is healthy. The dynamic VPNC gateway selection component can dynamically select a VPNC gateway from a plurality of VPNC gateways at the data center for communicating forwarded traffic from the user based on the user's ranking if either the VPNC gateway or the service are unhealthy.

    SELECTIVE FORMATION AND MAINTENANCE OF TUNNELS WITHIN A MESH TOPOLOGY

    公开(公告)号:US20230136635A1

    公开(公告)日:2023-05-04

    申请号:US17515125

    申请日:2021-10-29

    Abstract: Systems and methods are provided for clustering network devices into cohorts. Next, the systems may determine a subset of the network devices between which tunnels are created, based on any of amounts of available memory, jitter, latency, packet loss, and average round trip time. The selective determination may include, determining to create a first tunnel between a first network device of the first cohort and a second network device within the first cohort, and a second tunnel between the first network device and a third network device within the second cohort, and determining not to create tunnels between first remaining network devices of the first cohort and the second set of network devices of the second cohort. The systems provision the tunnel and the second tunnel to transmit data.

    SHORT-TERM LEASE ALLOCATION FOR NETWORK ADDRESS CONFLICT REDUCTION IN DHCP FAILOVER DEPLOYMENTS

    公开(公告)号:US20210400015A1

    公开(公告)日:2021-12-23

    申请号:US17282911

    申请日:2019-01-17

    Abstract: Systems and methods are provided for monitoring a connection state between a primary DHCP server and a secondary DHCP server, determining that a connection between the primary DHCP server and the secondary DHCP server has not been established within a first timeframe, establishing a partner-down operation state at one or more of the primary DHCP server and secondary DHCP server, and, during an established partner-down operation state, issuing/allocating short-term network address leases from one of the primary DHCP servers or secondary DHCP servers. Short-term network leases of the present disclosure may have a duration of between 1 second and 5 minutes.

    ADAPTIVE ROUTING OF BRANCH TRAFFIC IN SOFTWARE-DEFINED WIDE AREA NETWORK (SDWAN) DEPLOYMENTS

    公开(公告)号:US20200287976A1

    公开(公告)日:2020-09-10

    申请号:US16294388

    申请日:2019-03-06

    Abstract: A method including selecting, with a network orchestrator, a first virtual internet gateway (VIG) as a primary VIG for a branch gateway, is provided. The method includes selecting a second VIG as a secondary VIG for the branch gateway. The method includes monitoring roundtrip times for multiple packets between the primary VIG and the branch gateway, and between the secondary VIG and the branch gateway, and determining a first forecast roundtrip time associated with the connection between the primary VIG and branch gateway, as well as determining a second forecast roundtrip time associated with the connection between the secondary VIG and the branch gateway. The method includes selecting a new primary VIG based on the first forecast roundtrip time and the second forecast roundtrip time, and further based on a skew of active branches between the primary VIG and the secondary VIG.

    INTERNET PROTOCOL SECURITY MESSAGES FOR SUBNETWORKS

    公开(公告)号:US20190334866A1

    公开(公告)日:2019-10-31

    申请号:US16183947

    申请日:2018-11-08

    Abstract: An end controller, comprising: a processing resource; and a memory resource storing machine-readable instructions to cause the processing resource to: receive, using internet protocol security (IPSec) messages, a plurality of subnetworks that form a route to a branch device via a branch gateway; transfer the plurality of subnetworks to a layer-2-layer-3 module; transfer the plurality of subnetworks to an open shortest path first (OSPF) module; and publish the plurality of subnetworks that form the route to the branch device to a core router using OSPF link state advertisements (LSAs).

Patent Agency Ranking