Invention Grant
- Patent Title: Multi-hop WAN MACsec over IP
-
Application No.: US15077052Application Date: 2016-03-22
-
Publication No.: US09967372B2Publication Date: 2018-05-08
- Inventor: Kuralvanan Arangasamy , Brian Eliot Weis , Rakesh Chopra , Hugo J. W. Vliegen
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Edell, Shapiro & Finnan, LLC
- Main IPC: H04L12/741
- IPC: H04L12/741 ; H04L29/06 ; H04L12/28 ; H04L12/46

Abstract:
In an egress processing method, an egress frame is received. The egress frame includes an outer Ethernet frame, an Internet Protocol (IP) header, a layer 3 (L3) encapsulation identifying a layer 2 (L2)-over-L3 tunnel protocol, and an inner Ethernet frame with a payload. The outer Ethernet frame, the IP header, and the inner Ethernet frame, and the L3 encapsulation are parsed. Based on results of the parsing, a media access control security (MACsec) policy that defines how to protect the inner Ethernet frame is determined, and the inner Ethernet frame is protected according to the MACsec policy, while leaving unprotected the outer Ethernet frame, the IP header, and the L3 encapsulation, to produce a partly protected output egress frame. The partly protected output egress frame is transmitted to the peer network device over a public wide area network.
Public/Granted literature
- US20170104850A1 MULTI-HOP WAN MACSEC OVER IP Public/Granted day:2017-04-13
Information query