METHODS AND SYSTEMS FOR APPLICATION AND POLICY BASED NETWORK TRAFFIC ISOLATION AND DATA TRANSFER
Various techniques for dynamic path selection and data flow forwarding are disclosed. For example, various systems, processes, and computer program products for dynamic path selection and data flow forwarding are disclosed for providing dynamic path selection and data flow forwarding that can facilitate preserving/enforcing symmetry in data flows as disclosed with respect to various embodiments.
1 . A system, comprising:
a processor configured to:
monitor, by a networked branch device, a plurality of network data flows of a selected application from an associated originating interface to an associated destination;
determine a network requirement for the selected application;
determine for each monitored network data flow of the selected application, by the networked branch device, a corresponding first path over which to forward the monitored network data flow to the associated destination, independent of a previous path of the monitored network data flow to the associated destination;
transmit for each monitored network data flow of the selected application, by the networked branch device, the monitored network data flow over the determined corresponding first path;
receive for each monitored network data flow of the selected application, by the networked branch device, a corresponding return data flow from the associated destination to the networked branch device;
determine for each monitored network data flow of the selected application, a corresponding second path on which the return data flow is received from the associated destination, wherein the determined corresponding second path is different from the determined corresponding first path; and
move for each monitored network data flow of the selected application, by the networked branch device, a portion of the network data flow transmitted in a forward direction to the determined corresponding second path, wherein the forward direction of the network data flow is from the associated originating interface to the associated destination, and wherein the determined corresponding second path meets the network requirement for the selected application;
wherein for each monitored network data flow of the selected application, all packets following an initial packet of the network data flow in the forward direction on the determined corresponding second path are forwarded on the same second path as that initial packet in order to prevent flow asymmetry between the forward and the return network data flows; and
a memory coupled to the processor and configured to provide the processor with instructions.