Internet protocol security tunnel rebalancer
Techniques are described for managing secure connections (e.g., tunnels) between different endpoints using a pod of servers. Instead of computing devices connecting to a single server at a service IP address, the connections are spread among the different servers in the pod that can be reached using a public IP address.
1 . A method to manage secure connections, the method comprising:
monitoring, using one or more processors, available computing resources of computing devices within a pod; wherein the computing devices within the pod are associated with one or more public Internet Protocol (IP) addresses that are the same for individual ones of the computing devices within the pod;
receiving, using the one or more processors, a packet addressed to a tunnel endpoint associated with a tunnel;
determining, using the one or more processors, a computing device within the pod that is assigned to perform processing associated with the packet;
determining, based on the monitoring, to process the packet using the computing device; and
causing the computing device within the pod to process the packet.
2 . The method of claim 1 , wherein the packet is receivable by any one of the computing devices within the pod.
3 . The method of claim 1 , wherein determining the computing device within the pod that is assigned to perform processing associated with the packet is based, at least in part, on available resources of the computing device.
4 . The method of claim 1 , wherein determining the computing device within the pod that is assigned to perform processing associated with the packet, includes determining that the computing device manages the tunnel associated with the packet.
5 . The method of claim 4 , wherein determining the computing device within the pod that is assigned to perform processing associated with the packet, includes accessing data that identifies the tunnels managed by each of the computing devices within the pod.
6 . The method of claim 1 , wherein causing the computing device within the pod to process the packet comprises forwarding the packet to a service IP address that is unique to the computing device.
7 . The method of claim 6 , wherein forwarding the packet to the computing device includes generating an encapsulated packet at a first computing device that received the packet and forwarding the encapsulated packet to the service IP address.
8 . The method of claim 1 , further comprising causing the tunnel endpoint to be moved from the computing device to a second computing device within the pod based on the monitoring.
9 . A system to manage secure connections, the system comprising:
a pod that includes computing devices, wherein the computing devices of the pod are associated with one or more public Internet Protocol (IP) addresses and perform processing associated with a plurality of tunnels;
one or more processors; and
non-transitory computer-readable medium storing a set of instructions, the set of instructions when executed by the one or more processors cause processing to be performed comprising:
monitoring available computing resources of the computing devices within the pod;
receiving a packet addressed to a tunnel endpoint associated with a tunnel of the plurality of tunnels;
determining a computing device within the pod that is assigned to perform processing associated with the packet;
determining, based on the monitoring, to process the packet using the computing device; and
causing the computing device within the pod to process the packet.
10 . The system of claim 9 , wherein the packet is receivable by any one of the computing devices within the pod.
11 . The system of claim 9 , wherein determining the computing device within the pod that is assigned to perform processing associated with the packet is based, at least in part, on available resources of the computing device.
12 . The system of claim 9 , wherein determining the computing device within the pod that is assigned to perform processing associated with the packet, includes determining that the computing device manages the tunnel associated with the packet.
13 . The system of claim 12 , wherein determining the computing device within the pod that is assigned to perform processing associated with the packet, includes accessing data that identifies the tunnels managed by each of the computing devices within the pod.
14 . The system of claim 9 , wherein causing the computing device within the pod to process the packet comprises forwarding the packet to a service IP address that is unique to the computing device.
15 . The system of claim 14 , wherein forwarding the packet to the computing device includes generating an encapsulated packet at a first computing device that received the packet and forwarding the encapsulated packet to the service IP address.
16 . The system of claim 9 , further comprising causing the tunnel endpoint to be moved from the computing device to a second computing device within the pod based on the moni.
17 . A non-transitory computer-readable medium comprising instructions that when executed, cause one or more processors to perform operations including:
monitoring available computing resources of computing devices within a pod; wherein each of the computing devices within the pod are reachable using one or more public Internet Protocol (IP) addresses;
receiving a packet addressed to a tunnel endpoint associated with a tunnel;
determining a computing device within a pod that is assigned to perform processing associated with the packet;
determining, based on the monitoring, to process the packet using the computing device; and
causing the computing device within the pod to process the packet.
18 . The non-transitory computer-readable medium of claim 17 , wherein determining the computing device within the pod that is assigned to perform processing associated with the packet is based, at least in part, on available resources of the computing device.
19 . The non-transitory computer-readable medium of claim 17 , wherein causing the computing device within the pod to process the packet comprises forwarding the packet to a service IP address that is unique to the computing device.
20 . The non-transitory computer-readable medium of claim 19 , wherein forwarding the packet to the computing device includes generating an encapsulated packet at a first computing device that received the packet and forwarding the encapsulated packet to the service IP address.