Method and system of establishing a virtual private network in a cloud service for branch networking
First Claim
1. A computerized system useful for implementing a virtual private network (VPN), the system comprising:
- an edge device that automatically establishes an Internet Protocol Security (IPsec) tunnel alongside an unsecure Multipath Protocol (MP) tunnel with a gateway device in a public cloud in preparation for a transmission of a secure traffic communication, wherein the edge device has a list of local subnets, and wherein the edge device sends the list of local subnets to the gateway device during an initial MP tunnel establishment handshake message exchange between the edge device and the gateway device, wherein each local subnet includes an indication of whether the local subnet is reachable over the VPN;
the gateway device automatically establishing the IP sec tunnel alongside the unsecure MP tunnel with the edge device; and
an orchestrator module operating on an enterprise datacenter server that receives a toggle-the-VPN command and enables the VPN on the orchestrator module, and wherein the orchestrator module informs the edge device that the list of local subnets is accessible over the VPN, causing the edge device to update the gateway device with a new list of local subnets of the edge device that are accessible over the VPN.
4 Assignments
0 Petitions
Accused Products
Abstract
In one aspect, a computerized system useful for implementing a virtual private network (VPN) including an edge device that automatically establishes an Internet Protocol Security (IPsec) tunnel alongside an unsecure Multipath Protocol (MP) tunnel with a gateway device in preparation for a transmission of a secure traffic communication. The edge device has a list of local subnets. The edge device sends the list of local subnets to the gateway during an initial MP tunnel establishment handshake message exchange between the edge device and the gateway device. Each subnet includes an indication of whether the subnet is reachable over the VPN. A gateway device that automatically establishes the IPsec tunnel alongside the unsecure MP tunnel with the edge device. An enterprise datacenter server that comprises an orchestrator module that receives a toggle the VPN command and enables the VPN on the orchestrator. The orchestrator informs the edge device the list of subnets is accessible over the VPN causing the edge device to update the gateway device with a new list of subnets of the edge device that accessible over the VPN.
128 Citations
20 Claims
-
1. A computerized system useful for implementing a virtual private network (VPN), the system comprising:
-
an edge device that automatically establishes an Internet Protocol Security (IPsec) tunnel alongside an unsecure Multipath Protocol (MP) tunnel with a gateway device in a public cloud in preparation for a transmission of a secure traffic communication, wherein the edge device has a list of local subnets, and wherein the edge device sends the list of local subnets to the gateway device during an initial MP tunnel establishment handshake message exchange between the edge device and the gateway device, wherein each local subnet includes an indication of whether the local subnet is reachable over the VPN; the gateway device automatically establishing the IP sec tunnel alongside the unsecure MP tunnel with the edge device; and an orchestrator module operating on an enterprise datacenter server that receives a toggle-the-VPN command and enables the VPN on the orchestrator module, and wherein the orchestrator module informs the edge device that the list of local subnets is accessible over the VPN, causing the edge device to update the gateway device with a new list of local subnets of the edge device that are accessible over the VPN. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A method for an edge device for implementing a virtual private network (VPN), the method comprising:
-
establishing an unsecure Multipath Protocol (MP) tunnel with a gateway device in a public cloud, wherein establishing the MP tunnel comprises an establishment handshake message exchange comprising sending a list of local subnets of the edge device to the gateway device, wherein each local subnet includes an indication of whether the local subnet is reachable over the VPN; automatically establishing an Internet Protocol Security (IPsec) tunnel with the gateway device alongside the MP tunnel in preparation for a transmission of a secure traffic communication; receiving an update that the list of local subnets is accessible over the VPN from an orchestrator module executing on an enterprise datacenter, wherein the orchestrator module sends the update in response to receiving a toggle-the-VPN command, and in response to the toggle-the-VPN command the orchestrator module also enables the VPN on the orchestrator module; and transmitting to the gateway device a new list of local subnets of the edge device that are accessible over the VPN. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18, 19, 20)
-
Specification