Optimal data plane security and connectivity for secured connections
Techniques for creating an optimal and secure data plane based on network constraints. The techniques may include establishing an initial networking connection for a data flow between a client device and a resource such that data plane traffic of the data flow is routed through a relay node disposed between the client device and the resource. In some examples, the techniques may include determining, using a Session Traversal Utilities for Network Address Translators (STUN) server, an alternate networking connection for the data flow that bypasses the relay node. Based at least in part on a determination that the alternate networking connection is a more optimal path for the data plane traffic than the initial networking connection, the techniques may include causing the data plane traffic of the data flow to be routed over the alternate networking connection.
1 . A method comprising:
establishing an initial networking connection for a data flow between a client device and a resource such that data plane traffic of the data flow is routed through a relay node disposed between the client device and the resource;
determining, using a Session Traversal Utilities for Network Address Translators (STUN) server, an alternate networking connection for the data flow that bypasses the relay node;
determining that the alternate networking connection is a direct networking connection between the client device and the resource instead of the initial networking connection being the direct network connection;
determining a comparison between performance characteristics of the alternate networking connection and performance characteristics of the initial networking connection;
determining, based at least in part on the comparison and the alternate networking connection being the direct networking connection between the client device and the resource instead of the initial networking connection being the direct network connection, that the alternate networking connection is a more optimal path for the data plane traffic than the initial networking connection; and
based at least in part on the determination that the alternate networking connection is the more optimal path for the data plane traffic than the initial networking connection, causing the data plane traffic of the data flow to be routed over the alternate networking connection.
2 . The method of claim 1 , wherein the alternate networking connection is determined using the STUN server while, simultaneously, the data plane traffic of the data flow is being sent between the client device and the resource via the initial networking connection.
3 . The method of claim 1 , wherein determining the alternate networking connection using the STUN server comprises determining an internet protocol (IP) address and a port associated with a pin-holed flow through one or more networking components or security components disposed between the client device and the resource.
4 . The method of claim 1 , further comprising determining whether a security policy allows for the alternate networking connection to be made between the client device and the resource, and wherein determining the alternate networking connection using the STUN server is based at least in part on a determination that the security policy allows for the alternate networking connection to be made.
5 . The method of claim 1 , further comprising causing the client device to store an indication that the alternate networking connection is the more optimal path for future connections to the resource.
6 . The method of claim 1 , further comprising determining whether an encryption protocol associated with the resource satisfies a security policy, and wherein determining the alternate networking connection using the STUN server is based at least in part on a determination that the encryption protocol satisfies the security policy.
7 . The method of claim 1 , further comprising:
determining that the alternate networking connection between the client device and the resource fails to meet a security policy requirement; and
causing the data plane traffic to flow through a security function associated with the resource when the data plane traffic is routed over the alternate networking connection.
8 . The method of claim 1 , further comprising refraining from causing the data plane traffic of the data flow to be routed over the alternate networking connection based at least in part on determining that the alternate networking connection is a less optimal path than the initial networking connection.
9 . The method of claim 1 , wherein the alternate networking connection is the more optimal path for the data plane traffic that is being sent from the resource to the client device and the initial networking connection is the more optimal path for the data plane traffic that is being sent to the resource from the client device, the method further comprising:
causing the data plane traffic that is being sent from the resource to the client device to be routed over the alternate networking connection; and
causing the data plane traffic that is being sent to the resource from the client device to be routed over the initial networking connection.
10 . The method of claim 1 , wherein determining, based at least in part on the comparison and one or more network conditions, that the alternate networking connection is the more optimal path for the data plane traffic than the initial networking connection is based on at least one of:
an increase in an amount of available bandwidth for the data flow;
a decrease in a cost associated with the data flow;
a decrease in a latency associated with the data flow;
a decrease in an amount of compute associated with sending the data plane traffic; or
achieving a more uniform distribution of resources or resource utilization.
11 . A system comprising:
one or more processors; and
one or more non-transitory computer-readable media storing instructions that, when executed, cause the one or more processors to perform operations comprising:
establishing an initial networking connection for a data flow between a client device and a resource such that data plane traffic of the data flow is routed through a relay node disposed between the client device and the resource;
determining, using a Session Traversal Utilities for Network Address Translators (STUN) server, an alternate networking connection for the data flow between the client device and the resource that bypasses the relay node;
determining that the alternate networking connection is a direct networking connection between the client device and the resource instead of the initial networking connection being the direct network connection;
determining a comparison between performance characteristics of the alternate networking connection and performance characteristics of the initial networking connection;
determining, based at least in part on the comparison and the alternate networking connection being the direct networking connection between the client device and the resource instead of the initial networking connection being the direct network connection, whether the alternate networking connection is a more optimal path for the data plane traffic than the initial networking connection; and
based at least in part on determining that the alternate networking connection is the more optimal path, causing the data plane traffic of the data flow to be routed over the alternate networking connection.
12 . The system of claim 11 , wherein the alternate networking connection is determined using the STUN server while, simultaneously, the data plane traffic of the data flow is being sent between the client device and the resource via the initial networking connection.
13 . The system of claim 11 , wherein determining the alternate networking connection using the STUN server comprises determining an internet protocol (IP) address and a port associated with a pin-holed flow through one or more network security components disposed between the client device and the resource.
14 . The system of claim 11 , the operations further comprising determining whether a security policy allows for the alternate networking connection to be made between the client device and the resource, and wherein determining the alternate networking connection using the STUN server is based at least in part on a determination that the security policy allows for the alternate networking connection to be made.
15 . The system of claim 11 , the operations further comprising determining whether an encryption protocol associated with the resource satisfies a security policy, and wherein determining the alternate networking connection using the STUN server is based at least in part on a determination that the encryption protocol satisfies the security policy.
16 . The system of claim 11 , the operations further comprising:
determining that the alternate networking connection between the client device and the resource fails to meet a security policy requirement; and
causing the data plane traffic to flow through a security function associated with the resource when the data plane traffic is routed over the alternate networking connection.
17 . One or more non-transitory computer-readable media storing instructions that, when executed, cause one or more computing devices to perform operations comprising:
establishing an initial networking connection for a data flow between a client device and a resource such that data plane traffic of the data flow is routed through a relay node disposed between the client device and the resource;
determining, using a Session Traversal Utilities for Network Address Translators (STUN) server, an alternate networking connection for the data flow between the client device and the resource that bypasses the relay node;
determining that the alternate networking connection is a direct networking connection between the client device and the resource instead of the initial networking connection being the direct network connection;
determining a comparison between performance characteristics of the alternate networking connection and performance characteristics of the initial networking connection;
determining, based at least in part on the comparison and the alternate networking connection being the direct networking connection between the client device and the resource instead of the initial networking connection being the direct network connection, whether the alternate networking connection is a more optimal path for the data plane traffic than the initial networking connection; and
based at least in part on determining that the alternate networking connection is the more optimal path, causing the data plane traffic of the data flow to be routed over the alternate networking connection.
18 . The method of claim 1 , wherein the initial networking connection is a Zero Trust Network Access (ZTNA) networking connection, and the alternate networking connection is a first alternate networking connection, the method further comprising:
determining, using the STUN server, a second alternate networking connection for the data flow that bypasses the relay node;
determining that the second alternate networking connection is the more optimal path for the data plane traffic than the ZTNA networking connection, the second alternate networking connection being at least one of a proxied networking connection or a proxy and relay networking connection that passes through a different relay node; and
based at least in part on the determination that the second alternate networking connection is the more optimal path, causing the data plane traffic to be routed over the second alternate networking connection.
19 . The system of claim 11 , wherein the initial networking connection is a Zero Trust Network Access (ZTNA) networking connection, and the alternate networking connection is a first alternate networking connection, the operations further comprising:
determining, using the STUN server, a second alternate networking connection for the data flow that bypasses the relay node;
determining that the second alternate networking connection is the more optimal path for the data plane traffic than the ZTNA networking connection, the second alternate networking connection being at least one of a proxied networking connection or a proxy and relay networking connection that passes through a different relay node; and
based at least in part on the determination that the second alternate networking connection is the more optimal path, causing the data plane traffic to be routed over the second alternate networking connection.
20 . The one or more non-transitory computer-readable media of claim 17 , wherein the initial networking connection is a Zero Trust Network Access (ZTNA) networking connection, and the alternate networking connection is a first alternate networking connection, the operations further comprising:
determining, using the STUN server, a second alternate networking connection for the data flow that bypasses the relay node;
determining that the second alternate networking connection is the more optimal path for the data plane traffic than the ZTNA networking connection, the second alternate networking connection being at least one of a proxied networking connection or a proxy and relay networking connection that passes through a different relay node; and
based at least in part on the determination that the second alternate networking connection is the more optimal path, causing the data plane traffic to be routed over the second alternate networking connection.