Virtual private network management
First Claim
1. A method for managing VPN devices, the method comprising the steps of maintaining in a VPN Information Provider (VIP) VPN configurations of VPN devices belonging to a first VPN, providing from the VIP to a first VPN device belonging to the first VPN, VPN configuration of at least one other VPN device belonging to the first VPN, and managing certain aspects of said first VPN device belonging to the first VPN from at least one other management system.
1 Assignment
0 Petitions
Accused Products
Abstract
The invention provides a centralized VPN management of a plurality of VPN sites by means of a VPN Information Provider (VIP). Management of a VPN device is distributed so that at least part of the VPN configuration is centrally managed without giving away control of the firewall rulebase or other critical local configuration used in the VPN device.
-
Citations
29 Claims
-
1. A method for managing VPN devices, the method comprising the steps of
maintaining in a VPN Information Provider (VIP) VPN configurations of VPN devices belonging to a first VPN, providing from the VIP to a first VPN device belonging to the first VPN, VPN configuration of at least one other VPN device belonging to the first VPN, and managing certain aspects of said first VPN device belonging to the first VPN from at least one other management system.
-
11. A method for managing VPN devices, the method comprising the steps of
maintaining in a first VPN Information Provider (VIP) VPN configurations of VPN devices belonging to a first VPN, maintaining in a second VPN Information Provider (VIP) VPN configurations of VPN devices belonging to a second VPN, and providing to a first VPN device belonging to the first and second VPNs, VPN configuration of at least one other VPN device belonging to the first VPN from the first VIP and VPN configuration of at least one other VPN device belonging to the second VPN from the second VIP.
-
21. A method for handling VPN configuration in a VPN device, the method comprising
receiving a packet directed to a destination address in a first VPN, requesting and receiving VPN configuration for a VPN device related to said address from a VPN Information Provider (VIP) administering the first VPN, and using said VPN configuration for establishing a VPN tunnel to said VPN device related to said destination address for reaching said destination address.
-
22. A method for handling VPN configuration in a VPN Information Provider (VIP), the method comprising
maintaining VPN configurations of VPN devices belonging to a first VPN, providing to VPN devices belonging to the first VPN, information about the VPN configurations maintained in the VIP, receiving from a first VPN device belonging to the first VPN, a request for VPN configuration of another VPN device belonging to the first VPN, and sending to said first VPN device belonging to the first VPN, the VPN configuration of the other VPN device as a response to the request.
-
23. An arrangement for managing VPN devices comprising
at least two VPN devices belonging to a first VPN, a VPN Information Provider (VIP) maintaining VPN configurations of VPN devices belonging to the first VPN, at least one other management system managing certain aspects of said VPN devices belonging to the first VPN, while the VPN devices are adapted to receive from the at least one other management system, a first part of configuration, and from the VIP, a second part of configuration, which comprises VPN configuration of at least one other VPN device belonging to the first VPN.
-
25. An arrangement for managing VPN devices comprising
at least two VPN Information Providers (VIP), a first one maintaining VPN configurations of VPN devices belonging to a first VPN and a second one maintaining VPN configurations of VPN devices belonging to a second VPN, and a VPN device belonging to the first and second VPNs and receiving VPN configuration information from the first and second VIPs.
-
26. A VPN device comprising
a mechanism for receiving a packet directed to a destination address in a first VPN, mechanisms for requesting and receiving VPN configuration for a VPN device related to said address from a VPN Information Provider (VIP) administering the first VPN, and a mechanism for using said VPN configuration for establishing a VPN tunnel to said VPN device related to said destination address for reaching said destination address.
-
27. A VPN Information Provider (VIP) comprising
a mechanism for maintaining VPN configurations of VPN devices belonging to a first VPN, a mechanism for providing to VPN devices belonging to the first VPN, information about the VPN configurations maintained in the VIP, a mechanism for receiving from a first VPN device belonging to the first VPN, a request for VPN configuration of another VPN device belonging to the first VPN, and a mechanism for sending to said first VPN device belonging to the first VPN, the VPN configuration of the other VPN device as a response to the request.
-
28. A computer-readable medium, comprising program code which, when executed on a computer device, causes the computer device to provide a VPN device functionality comprising
receiving a packet directed to a destination address in a first VPN, requesting and receiving VPN configuration for a VPN device related to said address from a VPN Information Provider (VIP) administering the first VPN, and using said VPN configuration for establishing a VPN tunnel to said VPN device related to said destination address for reaching said destination address.
-
29. A computer-readable medium, comprising program code which, when executed on a computer device, causes the computer device to provide a VPN Information Provider (VIP) functionality comprising
maintaining VPN configurations of VPN devices belonging to a first VPN, providing to VPN devices belonging to the first VPN, information about the VPN configurations maintained in the VIP, receiving from a first VPN device belonging to the first VPN, a request for VPN configuration of another VPN device belonging to the first VPN, and sending to said first VPN device belonging to the first VPN, the VPN configuration of the other VPN device as a response to the request.
Specification