Load balancing client connections across servers of a trust network
View Patent ↗In some examples, a proxy system establishes a client-side secure network tunnel between the proxy system and a client device, and establishes a plurality of server-side secure connections between the proxy system and respective servers of a trust network. The proxy system load balances a plurality of connections of the client device in the client-side secure network tunnel across the servers of the trust network through respective server-side secure connections of the plurality of server-side secure connections.
1 . A non-transitory machine-readable storage medium comprising instructions that upon execution cause a proxy system to:
establish a client-side secure network tunnel according to a tunneling protocol between the proxy system and a network device, the client-side secure network tunnel comprising client connections of requesters connected to the network device;
establish a plurality of server-side secure connections between the proxy system and respective servers of a trust network, wherein one or more target endpoints are accessible to the requesters through the network device and the servers; and
load balance, by the proxy system, the client connections of the requesters in the client-side secure network tunnel across the servers of the trust network through respective server-side secure connections of the plurality of server-side secure connections, the load balancing comprising transferring a first client connection of the client connections in the client-side secure network tunnel from a first server-side secure connection of the plurality of server-side secure connections to a second server-side secure connection of the plurality of server-side secure connections.
2 . The non-transitory machine-readable storage medium of claim 1 , wherein the plurality of server-side secure connections between the proxy system and the respective servers of the trust network comprise a plurality of server-side secure network tunnels between the proxy system and the respective servers of the trust network.
3 . The non-transitory machine-readable storage medium of claim 1 , wherein the client connections in the client-side secure network tunnel comprise Transmission Control Protocol (TCP) connections.
4 . The non-transitory machine-readable storage medium of claim 1 , wherein the load balancing of the client connections of the requesters across the servers of the trust network is according to a dynamic load balancing process based on conditions of the servers of the trust network.
5 . The non-transitory machine-readable storage medium of claim 4 , wherein the conditions of the servers of the trust network comprise an issue impacting a performance of a server of the servers.
6 . The non-transitory machine-readable storage medium of claim 5 , wherein the conditions of the servers of the trust network comprise an update of a server of the servers.
7 . The non-transitory machine-readable storage medium of claim 4 , wherein the dynamic load balancing process creates a new server-side secure connection to another server of the trust network based on the conditions of the servers.
8 . The non-transitory machine-readable storage medium of claim 4 , wherein the dynamic load balancing process terminates a server-side secure connection of the plurality of server-side secure connections based on the conditions of the servers.
9 . The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the proxy system to:
detect an unavailability of a first server of the servers of the trust network; and
based on detecting the unavailability of the first server, transfer a subset of client connections of the requesters established through the first server-side secure connection to the second server-side secure connection.
10 . The non-transitory machine-readable storage medium of claim 9 , wherein the unavailability of the first server is based on a fault of the first server, a fault of a link to the first server, the first server being overburdened, or an update being performed at the first server.
11 . The non-transitory machine-readable storage medium of claim 9 , wherein the transfer of the subset of client connections of the requesters from the first server-side secure connection to the second server-side secure connection is performed without re-establishing the client-side secure network tunnel.
12 . The non-transitory machine-readable storage medium of claim 1 , wherein the requesters comprise an electronic device or a virtual computing entity.
13 . The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the proxy system to:
inspect a data packet received from the network device, the data packet including a client identifier; and
query a routing table for a destination based on the client identifier,
wherein the load balancing is based on updating the routing table.
14 . The non-transitory machine-readable storage medium of claim 1 , wherein the plurality of server-side secure connections comprise server-side secure network tunnels including a first server-side secure network tunnel and a second server-side secure network tunnel, and the instructions upon execution cause the proxy system to:
establish a third server-side secure network tunnel between the proxy system and a further server in the trust network; and
terminate the second server-side secure network tunnel in response to determining that the third server-side secure network tunnel is operational.
15 . The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the proxy system to:
maintain counters for the respective server-side secure connections;
increment a first counter for the first server-side secure connection in response to data packets being directed by the proxy system through the first server-side secure connection;
increment a second counter for the second server-side secure connection in response to data packets being directed by the proxy system through the second server-side secure connection; and
determine whether a difference between a first count of the first counter and a second count of the second counter exceeds a threshold,
wherein the transferring of the first client connection from the first server-side secure connection to the second server-side secure connection is based on the difference exceeding the threshold.
16 . The non-transitory machine-readable storage medium of claim 1 , wherein the client-side secure network tunnel is established according to an Internet Protocol Security (IPSec) protocol.
17 . A method comprising:
establishing, by a proxy system comprising a hardware processor, a client-side secure network tunnel according to a tunneling protocol between the proxy system and a network device, the client-side secure network tunnel comprising client connections of requesters connected to the network device;
establishing, by the proxy system, a plurality of server-side secure connections between the proxy system and respective servers of a trust network, wherein one or more target endpoints are accessible to the requesters through the network device and the servers; and
load balancing, by the proxy system, the client connections of the requesters in the client-side secure network tunnel across the servers of the trust network through respective server-side secure connections of the plurality of server-side secure connections, the load balancing comprising updating a routing table at the network device that transfers traffic of a first client connection of the client connections in the client-side secure network tunnel from a first server-side secure connection of the plurality of server-side secure connections to a second server-side secure connection of the plurality of server-side secure connections.
18 . The method of claim 17 , comprising:
maintaining, by the proxy system, counters for the respective server-side secure connections;
incrementing, by the proxy system, a first counter for the first server-side secure connection in response to data packets being directed by the proxy system through the first server-side secure connection;
incrementing, by the proxy system, a second counter for the second server-side secure connection in response to data packets being directed by the proxy system through the second server-side secure connection; and
determining, by the proxy system, whether a difference between a first count of the first counter and a second count of the second counter exceeds a threshold,
wherein the transferring of the traffic of the first client connection from the first server-side secure connection to the second server-side secure connection is based on the difference exceeding the threshold.
19 . A proxy system comprising:
a processor; and
a non-transitory storage medium storing instructions executable on the processor to:
establish a client-side secure network tunnel according to a tunneling protocol between the proxy system and a client device, the client-side secure network tunnel comprising client connections of requesters connected to the client device;
establish a plurality of server-side secure connections between the proxy system and destination servers in a trust network, wherein one or more target endpoints are accessible to the requesters through the client device and the destination servers;
receive information of conditions of the destination servers in the trust network; and
based on the conditions of the destination servers, load balance, by the proxy system, the client connections of the requesters in the client-side secure network tunnel across the destination servers of the trust network through respective server-side secure connections of the plurality of server-side secure connections, the load balancing comprising transferring a first client connection of the client connections in the client-side secure network tunnel from a first server-side secure connection to a second server-side secure connection.
20 . The proxy system of claim 19 , wherein the load balancing comprises:
adding a further server-side secure connection to another destination server of the trust network based on the conditions of the destination servers, or
terminating a server-side secure connection to a destination server based on a condition of the destination server.