Tunnel designation system for virtual private networks
First Claim
1. A tunnel designator to couple tunnel servers to tunnel clients executing host applications for use in a virtual private network (VPN) environment, comprising:
- (a) a receiver that receives tunnel traffic from host applications executing on the tunnel clients, the tunnel traffic comprising traffic related to existing VPN tunnels and requests to establish a VPN tunnel;
(b) a processor that processes the requests, the processor also maintaining an indication of loads on the tunnel servers, the processor operative to establishthe VPN tunnels by designating at least one of the tunnel servers to each of the requests; and
(c) a tunnel traffic distributor that distributes the tunnel traffic related to existing VPN tunnels to the tunnel servers based at least part on the designations.
13 Assignments
0 Petitions
Accused Products
Abstract
A system and method are provided to couple tunnel servers to tunnel clients executing host applications for use in a virtual private network (VPN) environment. A receiver receives requests from host applications executing on the tunnel clients. The requests are addressed to the tunnel coupling system to establish a VPN tunnel. A processor processes the requests and an indication of loads on the tunnel servers to establish the VPN tunnels by designating at least one of the tunnel servers to each requested tunnel. A tunnel traffic distributor distributes tunnel traffic to the tunnel servers based at least part on the designations. In additional aspects, an evaluation processor evaluates the tunnel traffic before the tunnel traffic distributor distributes the tunnel traffic to the tunnel servers. For example, the evaluation performed by the evaluation processor includes at least performing security functions on the tunnel traffic. In yet another aspect, the request processor establishes the VPN tunnel by, in part, associating each VPN tunnel with characteristics of tunnel traffic for that VPN tunnel, and the tunnel traffic distributor operates in part based on the associations, without involvement of the host applications.
29 Citations
5 Claims
-
1. A tunnel designator to couple tunnel servers to tunnel clients executing host applications for use in a virtual private network (VPN) environment, comprising:
-
(a) a receiver that receives tunnel traffic from host applications executing on the tunnel clients, the tunnel traffic comprising traffic related to existing VPN tunnels and requests to establish a VPN tunnel; (b) a processor that processes the requests, the processor also maintaining an indication of loads on the tunnel servers, the processor operative to establish the VPN tunnels by designating at least one of the tunnel servers to each of the requests; and (c) a tunnel traffic distributor that distributes the tunnel traffic related to existing VPN tunnels to the tunnel servers based at least part on the designations. - View Dependent Claims (2, 3, 4)
-
-
5. A method of connecting a plurality of tunnel clients to a plurality of tunnel servers using a tunnel designator, the method comprising:
-
using said tunnel designator to receive tunnel traffic of one or more of said tunnel clients, said tunnel traffic comprising traffic related to existing VPN tunnels; identifying in said tunnel traffic, a request from one of said tunnel clients; determining if said request is a valid request from one of said tunnel clients; determining if said request is for a new tunnel, and if so; (a) opening a new tunnel to a selected one of said tunnel servers; and (b) modifying an address map to include information associating said selected one of said tunnel servers to said request; if not; (b) using said address map to route said request to a mapped tunnel server.
-
Specification