IP Library Granted Patent US 11,575,560
Granted Patent B2
US 11,575,560 · App. 17/738,897 · Granted Feb 7, 2023

Dynamic path selection and data flow forwarding

Inventors: Kumar Ramachandran (Fremont, CA); Venkataraman Anand (San Ramon, CA); Navneet Yadav (Cupertino, CA); Arivu Ramasamy (San Jose, CA); Aaron Edwards (Sunnyvale, CA); Gopal Reddy (Fremont, CA)
Assignee: Palo Alto Networks, Inc.
H04L41/0668G06F16/285G06F16/955G06F17/18H04L12/4633H04L12/4641H04L41/12H04L41/14H04L43/04H04L43/062H04L43/065H04L43/0817H04L43/0864H04L43/0876H04L45/02H04L45/125H04L45/28H04L45/302H04L45/306H04L45/38H04L47/125H04L47/22H04L47/24H04L47/32H04L47/781H04L47/825H04L63/061H04L67/141H04L67/52H04L67/63H04L69/40H04L43/0811H04L43/10H04L45/22H04L61/2503H04L61/4511H04L61/4523H04W84/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,575,560
App. No.
17/738,897
Granted
Feb 7, 2023
Kind
B2
Abstract

Various techniques for dynamic path selection and data flow forwarding are disclosed. For example, various systems, processes, and computer program products for dynamic path selection and data flow forwarding are disclosed for providing dynamic path selection and data flow forwarding that can facilitate preserving/enforcing symmetry in data flows as disclosed with respect to various embodiments.

Claims (47)

1. A system, comprising:

a processor configured to:

monitor, by a networked branch device, a plurality of network data flows of a selected application from an associated originating interface to an associated destination;

determine for each monitored network data flow of the selected application, by the networked branch device, a corresponding first path over which to forward the monitored network data flow to the associated destination, irrespective of a previous path of the monitored network data flow to the associated destination;

transmit for each monitored network data flow of the selected application, by the networked branch device, the monitored network data flow over the determined corresponding first path;

receive for each monitored network data flow of the selected application, by the networked branch device, a corresponding return data flow from the associated destination to the networked branch device;

determine for each monitored network data flow of the selected application, a corresponding second path on which the return data flow is received from the associated destination, wherein the determined corresponding second path is different from the determined corresponding first path, and wherein the determined corresponding first path comprises a plurality of hub devices;

determine, by a hub device in the determined corresponding second path, a hub device interface on which the hub device received the return data flow; and

move for each monitored network data flow of the selected application, by the networked branch device, a forward direction of the network data flow, wherein the forward direction of the network data flow is from the associated originating interface to the associated destination, to the determined corresponding second path, wherein the forward direction of the network data flow is routed through the determined hub device interface;

wherein for each monitored network data flow of the selected application, all packets following an initial packet of the network data flow in the forward direction on the determined corresponding second path are forwarded on the same second path as that initial packet in order to prevent flow asymmetry between the forward and the return network data flows; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the processor is further configured to store, in a flow table, the first paths at a Layer 4 (L4) level.

3. The system of claim 1 , wherein the processor is further configured to apply time-based application domain classification.

4. The system of claim 1 , wherein determining a first path and a second path comprises network mapping.

5. The system of claim 1 , wherein the processor is further configured to model an application session.

6. The system of claim 1 , wherein the processor is further configured to store, by the hub device, the determined hub device interface.

7. The system of claim 1 , wherein the processor is further configured to store, by the hub device, the determined hub device interface, wherein storing the determined hub device interface comprises updating a flow table in the hub device.

8. A method, comprising:

monitoring, by a networked branch device, a plurality of network data flows of a selected application from an associated originating interface to an associated destination;

determining for each monitored network data flow of the selected application, by the networked branch device, a corresponding first path over which to forward the monitored network data flow to the associated destination, irrespective of a previous path of the monitored network data flow to the associated destination;

transmitting for each monitored network data flow of the selected application, by the networked branch device, the monitored network data flow over the determined corresponding first path;

receiving for each monitored network data flow of the selected application, by the networked branch device, a corresponding return data flow from the associated destination to the networked branch device;

determining for each monitored network data flow of the selected application, a corresponding second path on which the return data flow is received from the associated destination, wherein the determined corresponding second path is different from the determined corresponding first path, and wherein the determined corresponding first path comprises a plurality of hub devices;

determining, by a hub device in the determined corresponding second path, a hub device interface on which the hub device received the return data flow; and

moving for each monitored network data flow of the selected application, by the networked branch device, a forward direction of the network data flow, wherein the forward direction of the network data flow is from the associated originating interface to the associated destination, to the determined corresponding second path, wherein the forward direction of the network data flow is routed through the determined hub device interface;

wherein for each monitored network data flow of the selected application, all packets following an initial packet of the network data flow in the forward direction on the determined corresponding second path are forwarded on the same second path as that initial packet in order to prevent flow asymmetry between the forward and the return network data flows.

9. The method of claim 8 , further comprising storing, in a flow table, the first paths at a Layer 4 (L4) level.

10. The method of claim 8 , wherein determining a first path comprises applying time-based application domain classification.

11. The method of claim 8 , wherein determining a first path and a second path comprises network mapping.

12. The method of claim 8 , further comprising modeling an application session.

13. The method of claim 8 , further comprising storing, by the hub device, the determined hub device interface.

14. The method of claim 8 , further comprising storing, by the hub device, the determined hub device interface, wherein storing the determined hub device interface comprises updating a flow table in the hub device.

15. A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

monitoring, by a networked branch device, a plurality of network data flows of a selected application from an associated originating interface to an associated destination;

determining for each monitored network data flow of the selected application, by the networked branch device, a corresponding first path over which to forward the monitored network data flow to the associated destination, irrespective of a previous path of the monitored network data flow to the associated destination;

transmitting for each monitored network data flow of the selected application, by the networked branch device, the monitored network data flow over the determined corresponding first path;

receiving for each monitored network data flow of the selected application, by the networked branch device, a corresponding return data flow from the associated destination to the networked branch device;

determining for each monitored network data flow of the selected application, a corresponding second path on which the return data flow is received from the associated destination, wherein the determined corresponding second path is different from the determined corresponding first path, and wherein the determined corresponding first path comprises a plurality of hub devices;

determining, by a hub device in the determined corresponding second path, a hub device interface on which the hub device received the return data flow; and

moving for each monitored network data flow of the selected application, by the networked branch device, a forward direction of the network data flow, wherein the forward direction of the network data flow is from the associated originating interface to the associated destination, to the determined corresponding second path, wherein the forward direction of the network data flow is routed through the determined hub device interface;

wherein for each monitored network data flow of the selected application, all packets following an initial packet of the network data flow in the forward direction on the determined corresponding second path are forwarded on the same second path as that initial packet in order to prevent flow asymmetry between the forward and the return network data flows.

16. The computer program product of claim 15 , further comprising computer instructions for storing, in a flow table, the first paths at a Layer 4 (L4) level.

17. The computer program product of claim 15 , wherein determining a first path comprises applying time-based application domain classification.

18. The computer program product of claim 15 , wherein determining a first path and a second path comprises network mapping.

19. The computer program product of claim 15 , further comprising computer instructions for modeling an application session.

20. The computer program product of claim 15 , further comprising computer instructions for storing, by the hub device, the determined hub device interface.

21. The computer program product of claim 15 , further comprising computer instructions for storing, by the hub device, the determined hub device interface, wherein storing the determined hub device interface comprises updating a flow table in the hub device.

Continuity (4)
Continuation 17343893 · Jun 10, 2021
Continuation 14856314 · Sep 16, 2015
Provisional Application 62051293 · Sep 16, 2014
Related Publication 20220263708A1 · Aug 18, 2022
Cited By (2)
US 12,255,794 US 12,363,035