IP Library Granted Patent US 11,870,639
Granted Patent B2
US 11,870,639 · App. 17/961,456 · Granted Jan 9, 2024

Dynamic path selection and data flow forwarding

Inventors: Kumar Ramachandran (Fremont, CA); Venkataraman Anand (San Ramon, CA); Navneet Yadav (Cupertino, CA); Arivu Ramasamy (San Jose, CA); Aaron Edwards (Sunnyvale, CA); Gopal Reddy (Fremont, CA)
Assignee: Palo Alto Networks, Inc.
H04L41/0668G06F16/285G06F16/955G06F17/18H04L12/4633H04L12/4641H04L41/12H04L41/14H04L43/04H04L43/062H04L43/065H04L43/0817H04L43/0864H04L43/0876H04L45/02H04L45/125H04L45/28H04L45/302H04L45/306H04L45/38H04L47/125H04L47/22H04L47/24H04L47/32H04L47/781H04L47/825H04L63/061H04L67/141H04L67/52H04L67/63H04L69/40H04L43/0811H04L43/10H04L45/22H04L61/2503H04L61/4511H04L61/4523H04W84/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,870,639
App. No.
17/961,456
Granted
Jan 9, 2024
Kind
B2
Abstract

Various techniques for dynamic path selection and data flow forwarding are disclosed. For example, various systems, processes, and computer program products for dynamic path selection and data flow forwarding are disclosed for providing dynamic path selection and data flow forwarding that can facilitate preserving/enforcing symmetry in data flows as disclosed with respect to various embodiments.

Claims (56)

1. A system, comprising:

a processor configured to:

monitor, by a networked branch device, a plurality of network data flows of a selected application from an associated originating interface to an associated destination;

determine for a monitored network data flow of the plurality of network data flows of the selected application, by the networked branch device, a corresponding first path over which to forward the monitored network data flow to the associated destination, independent of a previous path of the monitored network data flow to the associated destination;

transmit for the monitored network data flow of the selected application, by the networked branch device, the monitored network data flow over the determined corresponding first path;

receive for the monitored network data flow of the selected application, by the networked branch device, a corresponding return data flow from the associated destination to the networked branch device;

determine for the monitored network data flow of the selected application, a corresponding second path on which the return data flow is received from the associated destination, wherein the determined corresponding second path is different from the determined corresponding first path; and

move for the monitored network data flow of the selected application, by the networked branch device, a portion of the network data flow transmitted in a forward direction to the determined corresponding second path, wherein the forward direction of the network data flow is from the associated originating interface to the associated destination;

wherein for the monitored network data flow of the selected application, all packets following an initial packet of the network data flow in the forward direction on the determined corresponding second path are forwarded on the same second path as that initial packet in order to prevent flow asymmetry between the forward and the return network data flows; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the processor is further configured to store, in a flow table, the first path at a Layer 4 (L4) level.

3. The system of claim 1 , wherein the processor is further configured to apply time-based application domain classification.

4. The system of claim 1 , wherein determining the first path and the second path comprises network mapping.

5. The system of claim 1 , wherein the processor is further configured to model an application session.

6. The system of claim 1 , wherein the processor is further configured to enforce a hold down period after moving the forward direction of the monitored network data flow before another move of the monitored network data flow.

7. The system of claim 1 , wherein the processor is further configured to move the monitored network data flow of the selected application in the event that the determined corresponding second path no longer meets a network requirement for the selected application.

8. The system of claim 1 , wherein the processor is further configured to:

move the monitored network data flow of the selected application in the event that the determined corresponding second path no longer meets a network requirement for the selected application; and

employ a hold down period after moving the monitored network data flow of the selected application before another move of the monitored network data flow.

9. The system of claim 1 , wherein a network requirement for the selected application is based on at least one of a bandwidth availability, a latency metric, or a quality of service profile.

10. A method, comprising:

monitoring, by a networked branch device, a plurality of network data flows of a selected application from an associated originating interface to an associated destination;

determining for a monitored network data flow of the plurality of network data flows of the selected application, by the networked branch device, a corresponding first path over which to forward the monitored network data flow to the associated destination, independent of a previous path of the monitored network data flow to the associated destination;

transmitting for the monitored network data flow of the selected application, by the networked branch device, the monitored network data flow over the determined corresponding first path;

receiving for the monitored network data flow of the selected application, by the networked branch device, a corresponding return data flow from the associated destination to the networked branch device;

determining for the monitored network data flow of the selected application, a corresponding second path on which the return data flow is received from the associated destination, wherein the determined corresponding second path is different from the determined corresponding first path; and

moving for the monitored network data flow of the selected application, by the networked branch device, a portion of the network data flow transmitted in a forward direction to the determined corresponding second path, wherein the forward direction of the network data flow is from the associated originating interface to the associated destination; and

wherein for the monitored network data flow of the selected application, all packets following an initial packet of the network data flow in the forward direction on the determined corresponding second path are forwarded on the same second path as that initial packet in order to prevent flow asymmetry between the forward and the return network data flows.

11. The method of claim 10 , further comprising storing, in a flow table, the first path at a Layer 4 (L4) level.

12. The method of claim 10 , wherein determining the first path comprises applying time-based application domain classification.

13. The method of claim 10 , wherein determining the first path and the second path comprises network mapping.

14. The method of claim 10 , further comprising modeling an application session.

15. The method of claim 10 , further comprising enforcing a hold down period after moving the forward direction of the monitored network data flow before another move of the monitored network data flow.

16. The method of claim 10 , further comprising moving the monitored network data flow of the selected application in the event that the determined corresponding second path no longer meets a network requirement for the selected application.

17. The method of claim 10 , further comprising:

moving the monitored network data flow of the selected application in the event that the determined corresponding second path no longer meets a network requirement for the selected application; and

employing a hold down period after moving the monitored network data flow of the selected application before another move of the monitored network data flow.

18. The method of claim 10 , wherein the network requirement for the selected application is based on at least one of a bandwidth availability, a latency metric, or a quality of service profile.

19. A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

monitoring, by a networked branch device, a plurality of network data flows of a selected application from an associated originating interface to an associated destination;

determining for a monitored network data flow of the plurality of network data flows of the selected application, by the networked branch device, a corresponding first path over which to forward the monitored network data flow to the associated destination, independent of a previous path of the monitored network data flow to the associated destination;

transmitting for the monitored network data flow of the selected application, by the networked branch device, the monitored network data flow over the determined corresponding first path;

receiving for the monitored network data flow of the selected application, by the networked branch device, a corresponding return data flow from the associated destination to the networked branch device;

determining for the monitored network data flow of the selected application, a corresponding second path on which the return data flow is received from the associated destination, wherein the determined corresponding second path is different from the determined corresponding first path; and

moving for the monitored network data flow of the selected application, by the networked branch device, a portion of the network data flow transmitted in a forward direction to the determined corresponding second path, wherein the forward direction of the network data flow is from the associated originating interface to the associated destination; and

wherein for the monitored network data flow of the selected application, all packets following an initial packet of the network data flow in the forward direction on the determined corresponding second path are forwarded on the same second path as that initial packet in order to prevent flow asymmetry between the forward and the return network data flows.

20. The computer program product of claim 19 , further comprising computer instructions for storing, in a flow table, the first path at a Layer 4 (L4) level.

21. The computer program product of claim 19 , wherein determining the first path comprises applying time-based application domain classification.

22. The computer program product of claim 19 , wherein determining the first path and the second path comprises network mapping.

23. The computer program product of claim 19 , further comprising computer instructions for modeling an application session.

24. The computer program product of claim 19 , further comprising computer instructions for enforcing a hold down period after moving the forward direction of the monitored network data flow before another move of the monitored network data flow.

25. The computer program product of claim 19 , further comprising computer instructions for moving the monitored network data flow of the selected application in the event that the determined corresponding second path no longer meets the network requirement for the selected application.

26. The computer program product of claim 19 , further comprising computer instructions for:

moving the monitored network data flow of the selected application in the event that the determined corresponding second path no longer meets the network requirement for the selected application; and

employing a hold down period after moving the monitored network data flow of the selected application before another move of the monitored network data flow.

27. The computer program product of claim 19 , wherein the network requirement for the selected application is based on at least one of a bandwidth availability, a latency metric, or a quality of service profile.

Continuity (5)
Continuation 17738897 · May 6, 2022
Continuation 17343893 · Jun 10, 2021
Continuation 14856314 · Sep 16, 2015
Provisional Application 62051293 · Sep 16, 2014
Related Publication 20230093190A1 · Mar 23, 2023