Distributed internet access in an overlay fabric using combined local and remote extranet policies

    公开(公告)号:US10735217B2

    公开(公告)日:2020-08-04

    申请号:US16368006

    申请日:2019-03-28

    Abstract: The present technology provides a system, method, and computer-readable medium directed to dynamic implementation and management of multi-provider internet access featuring multiple access points across a multi-site overlay network fabric. An aspect of the technology is directed to the implementation of a common fabric-wide Virtual Network (VN) with a unique Internet Instance Identifier (Internet IID) that is dedicated to internet access traffic. Default access routes from multiple service providers (SP) are leaked into the VN with the Internet IID at exit points of the fabric using local Extranet policies. Internet-bound traffic generated from any point within the overlay fabric network is then redirected into the Internet IID, using remote Extranet policies. Internet-bound traffic, once in the Internet IID, follows the SP default access route(s) towards the exit points where SP specific access policies may be applied to the traffic which is then forwarded to the corresponding SP network.

    DISTRIBUTED INTERNET ACCESS IN AN OVERLAY FABRIC USING COMBINED LOCAL AND REMOTE EXTRANET POLICIES

    公开(公告)号:US20200162282A1

    公开(公告)日:2020-05-21

    申请号:US16368006

    申请日:2019-03-28

    Abstract: The present technology provides a system, method, and computer-readable medium directed to dynamic implementation and management of multi-provider internet access featuring multiple access points across a multi-site overlay network fabric. An aspect of the technology is directed to the implementation of a common fabric-wide Virtual Network (VN) with a unique Internet Instance Identifier (Internet IID) that is dedicated to internet access traffic. Default access routes from multiple service providers (SP) are leaked into the VN with the Internet IID at exit points of the fabric using local Extranet policies. Internet-bound traffic generated from any point within the overlay fabric network is then redirected into the Internet IID, using remote Extranet policies. Internet-bound traffic, once in the Internet IID, follows the SP default access route(s) towards the exit points where SP specific access policies may be applied to the traffic which is then forwarded to the corresponding SP network.

    SYSTEM AND METHOD OF FAST ROAMING IN AN ENTERPRISE FABRIC NETWORK

    公开(公告)号:US20210185517A1

    公开(公告)日:2021-06-17

    申请号:US17170982

    申请日:2021-02-09

    Abstract: A system and method for fast roaming in one or more enterprise fabric network. The fast roaming involves correlation operations performed in one or more databases managed by control plane of the fabric network to update routing locator entries associated with L2-VNID and L3-VNID in one or more databases when a client moves from behind a first switch to behind a second switch. In some embodiments, the control plane finds the L3-VNID from the L2-VNID. The L3-VNID is used to search for all IP addresses corresponding to a client-MAC. At least new routing locator value that is used in the routing locator entries is provided to the first switch, the second switch, and border nodes associated with the fabric network.

    Stateful LISP subscription for overlapping subnetworks

    公开(公告)号:US10560421B2

    公开(公告)日:2020-02-11

    申请号:US15607248

    申请日:2017-05-26

    Abstract: A Location/Identifier Separation Protocol (LISP) mapping server, including: a network interface for communicating with a LISP-enabled network; a mapping database; a subscription database; and an overlapping subscription publication engine (OSPE) to: receive a first mapping of a first subnetwork to a first routing locator (RLOC); add the first mapping to the mapping database; receive from a first ingress tunnel router (ITR) a subscription request for an endpoint identifier (EID) within the first subnetwork; add to a first subscription entry for the first subnetwork in the subscription database a subscription for the first ITR; receive a second mapping of a second subnetwork to a second RLOC, wherein the second subnetwork overlaps the first subnetwork; add the second mapping to the mapping database; and copy at least part of the first subscription entry to a second subscription entry for the second subnetwork.

    Horizontal Scaling of Fabric Networks
    16.
    发明申请

    公开(公告)号:US20190132209A1

    公开(公告)日:2019-05-02

    申请号:US15912839

    申请日:2018-03-06

    Abstract: A method for establishing a partitioned fabric network is described. The method includes establishing a fabric network including a plurality of border nodes to couple the fabric network to one or more external data networks and a plurality of edge nodes to couple to the fabric network to one or more hosts. The method further includes defining a plurality of partitions of the fabric network. The method further includes registering each of the plurality of partitions with a corresponding one of the plurality of border nodes and with each of the plurality of edge nodes.

    Network device mobility
    17.
    发明授权

    公开(公告)号:US09647923B2

    公开(公告)日:2017-05-09

    申请号:US14011356

    申请日:2013-08-27

    CPC classification number: H04L45/02

    Abstract: According to one example embodiment, an EID-NOTIFY packet is defined for use with the Location/Identifier Separation Protocol (LISP). A first-hop network element may send EID-NOTIFY responsive to decoding a data packet from a previously undetected host on its subnetwork. A site network element may receive EID-NOTIFY, and send a MAP-REGISTER message to a mapping system. EID-NOTIFY may have substantially the same format as MAP-NOTIFY. This may enable the site network element to be removed more than one hop from the subnetwork.

    NETWORK DEVICE MOBILITY
    18.
    发明申请
    NETWORK DEVICE MOBILITY 有权
    网络设备移动性

    公开(公告)号:US20140301387A1

    公开(公告)日:2014-10-09

    申请号:US14011356

    申请日:2013-08-27

    CPC classification number: H04L45/02

    Abstract: According to one example embodiment, an EID-NOTIFY packet is defined for use with the Location/Identifier Separation Protocol (LISP). A first-hop network element may send EID-NOTIFY responsive to decoding a data packet from a previously undetected host on its subnetwork. A site network element may receive EID-NOTIFY, and send a MAP-REGISTER message to a mapping system. EID-NOTIFY may have substantially the same format as MAP-NOTIFY. This may enable the site network element to be removed more than one hop from the subnetwork.

    Abstract translation: 根据一个示例实施例,EID-NOTIFY分组被定义为与位置/标识符分离协议(LISP)一起使用。 第一跳网络元件可以响应于从其子网上以前未检测到的主机解码数据分组而发送EID-NOTIFY。 站点网元可以接收EID-NOTIFY,并向映射系统发送MAP-REGISTER消息。 EID-NOTIFY可能具有与MAP-NOTIFY基本相同的格式。 这可以使站点网络元素从子网中移除多于一个跳。

Patent Agency Ranking