×

Virtual private networks distributed across multiple cloud-computing facilities

  • US 9,391,801 B2
  • Filed: 03/12/2014
  • Issued: 07/12/2016
  • Est. Priority Date: 08/13/2013
  • Status: Active Grant
First Claim
Patent Images

1. A cloud-connector subsystem that provides a virtual private cloud operation for creating virtual private clouds distributed across a first and a second cloud-computing facility, the cloud- connector subsystem comprising:

  • cloud-connector nodes associated with each of the first and second cloud-computing facilities; and

    a cloud-connector server that includes one or more processors, one or more memories, one or more data-storage devices, and computer instructions that, when executed on the one or more processors, control the cloud-connector server to provide, in cooperation with the cloud- connector nodes, a virtual-private-cloud-creation operation thatsecurely interconnects a first organization edge appliance associated with a first virtual organization network within the first cloud-computing facility to a second organization edge appliance associated with a second virtual organization network within the second cloud-computing facility using an Internet-protocol-secure tunnel or a secure-socket-layer secure tunnel between the first and second organization edge appliances, each of the first and second organization edge appliances perform the steps of;

    receiving virtual-private-network IP addresses and virtual-private-network configuration information, rules, and policies from the cloud-connector server;

    internally storing the received virtual-private-network IP addresses in routing tables;

    distributing a portion of the virtual-private-network IP addresses and virtual-private-network configuration information, rules, and policies received from the cloud-connector server to additional edge appliances connected to the virtual organization network with which the organization edge appliance is associated; and

    providing a firewall that isolates a sub-network within each respective cloud-computing facility from a network external to each respective cloud-computing facility;

    distributes internal IP virtual-private-network addresses to the first and second cloud-computing facilities for use by two or more virtual-private-cloud members that execute within the first and second cloud-computing facilities to communicate over the virtual private network; and

    configures organization-edge appliances and edge appliances associated with virtual appliances within the first and second cloud-computing facilities to route packets transmitted by the two or more virtual-private-cloud members through the virtual private network.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×