Technique for using OER with an ECT solution for multi-homed spoke-to-spoke sites
First Claim
1. A method for dynamically creating and utilizing a plurality of multi-homed Virtual Private Network (VPN) tunnels from a client node of a spoke network to a peer client node of a peer spoke network in a computer network, the method comprising:
- establishing one or more spoke-to-hub tunnels from the client node to an enterprise network;
dynamically establishing a plurality of spoke-to-spoke tunnels from the client node to the peer client node;
for each of a plurality of reachable address prefixes, designating a first of the plurality of spoke-to-spoke tunnels as a primary spoke-to-spoke tunnel for a respective prefix;
for each of the plurality of reachable address prefixes, designating remaining tunnels of the plurality of spoke-to-spoke tunnels as secondary spoke-to-spoke tunnels for the respective prefix;
monitoring quality of the plurality of spoke-to-spoke tunnels for the plurality of prefixes; and
dynamically re-designating one of the secondary spoke-to-spoke tunnels as the primary spoke-to-spoke tunnel for a particular prefix of the plurality of prefixes based on the quality of the plurality of spoke-to-spoke tunnels for the particular prefix.
1 Assignment
0 Petitions
Accused Products
Abstract
A technique dynamically creates and utilizes a plurality of multi-homed Virtual Private Network (VPN) tunnels from a client node of one spoke network to a client node of another spoke network in a computer network. According to the technique, a VPN client node, e.g., a “spoke,” creates at least one VPN tunnel with an enterprise network, e.g., a “hub.” Once the spoke-to-hub tunnel is established, the spoke may dynamically create a plurality of VPN tunnels with a peer spoke network, e.g., a “peer spoke.” The spoke designates (e.g., for a prefix) one of the tunnels as a primary tunnel and the other tunnels as secondary tunnels, and monitors the quality (e.g., loss, delay, reachability, etc.) of all of the dynamic tunnels, such as, e.g., by an Optimized Edge Routing (OER) process. The spoke may then dynamically re-designate any one of the secondary tunnels as the primary tunnel for a prefix based on the quality of the tunnels to the peer spoke. Notably, the spoke may also dynamically load balance traffic to the peer spoke among the primary and secondary tunnels based on the quality of those tunnels.
92 Citations
21 Claims
-
1. A method for dynamically creating and utilizing a plurality of multi-homed Virtual Private Network (VPN) tunnels from a client node of a spoke network to a peer client node of a peer spoke network in a computer network, the method comprising:
-
establishing one or more spoke-to-hub tunnels from the client node to an enterprise network; dynamically establishing a plurality of spoke-to-spoke tunnels from the client node to the peer client node; for each of a plurality of reachable address prefixes, designating a first of the plurality of spoke-to-spoke tunnels as a primary spoke-to-spoke tunnel for a respective prefix; for each of the plurality of reachable address prefixes, designating remaining tunnels of the plurality of spoke-to-spoke tunnels as secondary spoke-to-spoke tunnels for the respective prefix; monitoring quality of the plurality of spoke-to-spoke tunnels for the plurality of prefixes; and dynamically re-designating one of the secondary spoke-to-spoke tunnels as the primary spoke-to-spoke tunnel for a particular prefix of the plurality of prefixes based on the quality of the plurality of spoke-to-spoke tunnels for the particular prefix. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A system for dynamically utilizing a plurality of multi-homed Virtual Private Network (VPN) spoke-to-spoke tunnels, the system comprising:
-
an enterprise network; a spoke network; a peer spoke network; a client node in the spoke network; and a spoke router between the client node and the peer spoke network, the spoke router having A) an enterprise class teleworker (ECT) solution process adapted to i) establish one or more spoke-to-hub tunnels from the client node to the enterprise network, ii) dynamically establish a plurality of spoke-to-spoke tunnels from the client node to the peer client node, iii) for each of a plurality of reachable address prefixes, designate a first of the plurality of spoke-to-spoke tunnels as a primary spoke-to-spoke tunnel for a respective prefix, iv) for each of the plurality of reachable address prefixes, designate remaining tunnels of the plurality of spoke-to-spoke tunnels as secondary spoke-to-spoke tunnels for the respective prefix; and B) an optimized edge routing (OER) process adapted to i) monitor quality of the plurality of spoke-to-spoke tunnels for the plurality of prefixes, and ii) dynamically re-designate one of the secondary spoke-to-spoke tunnels as the primary spoke-to-spoke tunnel for a particular prefix of the plurality of prefixes based on the quality of the plurality of spoke-to-spoke tunnels for the particular prefix. - View Dependent Claims (9, 10, 11, 12)
-
-
13. A node for use with dynamically creating and utilizing a plurality of multi-homed Virtual Private Network (VPN) tunnels from a client node of a spoke network to a peer client node of a peer spoke network in a computer network, the node comprising:
-
one or more network interfaces to communicate with the client node and the peer client node; a processor coupled to the one or more network interfaces and adapted to execute software processes; and a memory adapted to store A) an enterprise class teleworker (ECT) solution process executable by the processor, the ECT solution process configured to i) establish one or more spoke-to-hub tunnels from the client node to the enterprise network, ii) dynamically establish a plurality of spoke-to-spoke tunnels from the client node to the peer client node, iii) for each of a plurality of reachable address prefixes, designate a first of the plurality of spoke-to-spoke tunnels as a primary spoke-to-spoke tunnel for a respective prefix, iv) for each of the plurality of reachable address prefixes, designate remaining tunnels of the plurality of spoke-to-spoke tunnels as secondary spoke-to-spoke tunnels for the respective prefix; and B) an optimized edge routing (OER) process executable by the processor, the OER process configured to i) monitor quality of the plurality of spoke-to-spoke tunnels for the plurality of prefixes, and ii) dynamically re-designate one of the secondary spoke-to-spoke tunnels as the primary spoke-to-spoke tunnel for a particular prefix of the plurality of prefixes based on the quality of the plurality of spoke-to-spoke tunnels for the particular prefix. - View Dependent Claims (14, 15, 16, 17)
-
-
18. An apparatus for dynamically creating and utilizing a plurality of multi-homed Virtual Private Network (VPN) tunnels from a client node of a spoke network to a peer client node of a peer spoke network in a computer network, the apparatus comprising:
-
means for establishing one or more spoke-to-hub tunnels from the client node to an enterprise network; means for dynamically establishing a plurality of spoke-to-spoke tunnels from the client node to the peer client node; means for designating a first of the plurality of spoke-to-spoke tunnels as a primary spoke-to-spoke tunnel for each of a plurality of reachable address prefixes; means for designating remaining tunnels of the plurality of spoke-to-spoke tunnels as secondary spoke-to-spoke tunnels for each of the plurality of reachable address prefixes; means for monitoring quality of the plurality of spoke-to-spoke tunnels for the plurality of prefixes; and means for dynamically re-designating one of the secondary spoke-to-spoke tunnels as the primary spoke-to-spoke tunnel for a particular prefix of the plurality of prefixes based on the quality of the plurality of spoke-to-spoke tunnels for the particular prefix. - View Dependent Claims (19)
-
-
20. A non-transitory computer readable storage medium storing executable program instructions for dynamically creating and utilizing a plurality of multi-homed Virtual Private Network (VPN) tunnels from a client node of a spoke network to a peer client node of a peer spoke network in a computer network, the executable program instructions comprising program instructions for:
-
establishing one or more spoke-to-hub tunnels from the client node to an enterprise network; dynamically establishing a plurality of spoke-to-spoke tunnels from the client node to the peer client node; for each of a plurality of reachable address prefixes, designating a first of the plurality of spoke-to-spoke tunnels as a primary spoke-to-spoke tunnel for a respective prefix; for each of the plurality of reachable address prefixes, designating remaining tunnels of the plurality of spoke-to-spoke tunnels as secondary spoke-to-spoke tunnels for the respective prefix; monitoring quality of the plurality of spoke-to-spoke tunnels for the plurality of prefixes; and dynamically re-designating one of the secondary spoke-to-spoke tunnels as the primary spoke-to-spoke tunnel for a particular prefix of the plurality of prefixes based on the quality of the plurality of spoke-to-spoke tunnels for the particular prefix. - View Dependent Claims (21)
-
Specification