-
公开(公告)号:US20240146565A1
公开(公告)日:2024-05-02
申请号:US17979255
申请日:2022-11-02
Applicant: Cisco Technology, Inc.
Inventor: Ajeet Pal Singh Gill , Balaji Sundararajan , Srilatha Tangirala , Nithin Bangalore Raju , Ravi Kiran Chintallapudi , Pradeepan Kannawadi , Ganesh Devendrachar
Abstract: Techniques for virtualizing tenant transport interfaces configured to implement per-tenant network routing attribute differentiation in each tenant overlay of a multisite wide area network (WAN) and share the virtual transport interfaces between multi-tenant edge (MTE) devices providing transport services to tenant devices based on a defined tenant tier model. A Software-Defined Networking (SDN) controller may receive a physical transport interface and/or a device type associated with a tenant device. The SDN controller may determine a virtual transport interface for the tenant device based on a tier associated with the tenant. MTE device(s) may utilize the physical transport interface to establish sessions with other MTE device(s) in the WAN. The virtual transport interface may be utilized by MTE devices to implement and/or enforce network routing attributes when forwarding network traffic associated with the tenant via the sessions established between the MTE devices through the WAN.
-
公开(公告)号:US20230188502A1
公开(公告)日:2023-06-15
申请号:US17709922
申请日:2022-03-31
Applicant: Cisco Technology, Inc.
Inventor: Samir Thoria , Ajeet Pal Singh Gill , Srilatha Tangirala , Balaji Sundararajan , Nithin Bangalore Raju , Vivek Agarwal
CPC classification number: H04L63/0272 , H04L12/4641 , H04L45/74
Abstract: In one embodiment, a method includes identifying, by a router, a first tenant. The first tenant is associated with a first tenant virtual private network (VPN). The method also includes determining, by the router, a mapping of the first tenant VPN to a first device VPN and generating, by the router, a first label representing the first device VPN. The method further includes adding, by the router, the first label to a first network packet and communicating, by the router, the first network packet with the first label to a controller.
-
公开(公告)号:US20220326995A1
公开(公告)日:2022-10-13
申请号:US17390187
申请日:2021-07-30
Applicant: Cisco Technology, Inc.
Inventor: Xiaohu Wang , Ajeet Pal Singh Gill , Srilatha Tangirala , Nithin Bangalore Raju , Prabahar Radhakrishnan , Vivek Agarwal , Balaji Sundararajan
Abstract: A method for allocating resources of a virtual controller is disclosed. The method comprises: allocating resources of a virtual controller to a first tenant, wherein the first tenant is allocated a first tenant quantity of guaranteed resources of the virtual controller and a second tenant is allocated a second tenant quantity of guaranteed resources of the virtual controller; determining that resources requested by the first tenant are greater than the first tenant quantity of guaranteed resources; determining that the virtual controller has unutilized resources sufficient to at least partially provide additional resources beyond the first tenant quantity of guaranteed resources to the first tenant; and temporarily provisioning the additional resources to the first tenant, wherein the additional resources are greater than the first tenant quantity of guaranteed resources.
-
公开(公告)号:US12132660B2
公开(公告)日:2024-10-29
申请号:US17718775
申请日:2022-04-12
Applicant: Cisco Technology, Inc.
Inventor: Balaji Sundararajan , Srilatha Tangirala , Ajeet Pal Singh Gill , Vivek Agarwal , Nithin Bangalore Raju
Abstract: According to certain embodiments, a method by a network device includes receiving a handshake message for a traffic flow from a Software-Defined Wide-Area Network (SDWAN) and determining, from a traffic policy, whether the traffic flow should be symmetrical. In response to determining from the traffic policy that the traffic flow should be symmetrical, the method further includes performing a flow lookup on the traffic flow to determine if the network device originated the traffic flow. In response to determining that the network device did not originate the traffic flow, the method further includes determining a second network device that originated the traffic flow and sending the handshake message for the traffic flow to the second network device in order to maintain symmetry for the traffic flow.
-
15.
公开(公告)号:US20240333689A1
公开(公告)日:2024-10-03
申请号:US18128824
申请日:2023-03-30
Applicant: Cisco Technology, Inc.
Inventor: Pritam Baruah , Balaji Sundararajan , Nithin Bangalore Raju , Srilatha Tangirala , Ramakumara Kariyappa
IPC: H04L9/40
CPC classification number: H04L63/0281 , H04L63/0236 , H04L63/20
Abstract: Techniques for utilizing a network gateway provisioned in a software-defined network to verify service readiness of one or more security service(s) of a service chain prior to redirecting network traffic along a given data-path to the security service(s). The gateway may be configured to open a specific port on a network device hosting a security service to transmit network policies and/or test network traffic to the security service. The network gateway may host a virtual source and/or a virtual destination and cause the virtual source to send test network traffic through the security service via the port and to the virtual destination. The gateway may then utilize the received test network traffic to determine whether a given security service satisfies a threshold health and/or functionality measurement. Once it is determined that the security service satisfies the thresholds, the gateway may cause network traffic to be redirected to the security service.
-
公开(公告)号:US20240267325A1
公开(公告)日:2024-08-08
申请号:US18604972
申请日:2024-03-14
Applicant: Cisco Technology, Inc.
Inventor: Balaji Sundararajan , Ramakumara Kariyappa , Nithin Bangalore Raju , Bhairav Dutia , Vivek Agarwal , Satish Mahadevan , Ankur Bhargava
IPC: H04L45/586 , H04L45/748 , H04L61/5061
CPC classification number: H04L45/586 , H04L45/748 , H04L61/5061
Abstract: Symmetric networking techniques disclosed herein can be applied by gateway routers in cloud networks. The techniques can ensure that both outbound traffic received at a cloud from a branch device and return traffic directed from the cloud back to the branch device are processed by a same gateway router. The gateway router can use network address translation to insert IP addresses from an inside pool and an outside pool assigned to the router.
-
公开(公告)号:US20230188476A1
公开(公告)日:2023-06-15
申请号:US18166786
申请日:2023-02-09
Applicant: Cisco Technology, Inc.
Inventor: Srilatha Tangirala , Nithin Bangalore Raju , Ananya Raval , Prabahar Radhakrishnan , Vivek Agarwal , Balaji Sundararajan
CPC classification number: H04L47/805 , H04L47/825 , H04L45/64 , H04L47/762 , H04L45/02 , H04L47/781
Abstract: Route exchange in a plurality of network controller appliances on a per-tenant basis is disclosed. In one aspect, a method includes receiving, from a network management system and at a first network controller appliance, a designation of at least two tenants to be hosted on the first network controller appliance, the first network controller appliance being one of a plurality of network controller appliances in a SD-WAN; sending, from the first network controller appliance to other network controller appliances of the plurality of network controller appliances, a tenant list query message to obtain a corresponding tenant list of each of the other network controller appliances; and receiving a corresponding response from each of the other network controller appliances indicating the corresponding tenant list of each of the other network controller appliances, the corresponding response being used to update the tenant list on the first network controller appliance.
-
公开(公告)号:US20220329540A1
公开(公告)日:2022-10-13
申请号:US17389003
申请日:2021-07-29
Applicant: Cisco Technology, Inc.
Inventor: Srilatha Tangirala , Nithin Bangalore Raju , Ananya Raval , Prabahar Radhakrishnan , Vivek Agarwal , Balaji Sundararajan
IPC: H04L12/927 , H04L12/911 , H04L12/923 , H04L12/751 , H04L12/715
Abstract: Route exchange in a plurality of network controller appliances on a per-tenant basis is disclosed. In one aspect, a method includes receiving, from a network management system and at a first network controller appliance, a designation of at least two tenants to be hosted on the first network controller appliance, the first network controller appliance being one of a plurality of network controller appliances in a SD-WAN; sending, from the first network controller appliance to other network controller appliances of the plurality of network controller appliances, a tenant list query message to obtain a corresponding tenant list of each of the other network controller appliances; and receiving a corresponding response from each of the other network controller appliances indicating the corresponding tenant list of each of the other network controller appliances, the corresponding response being used to update the tenant list on the first network controller appliance.
-
-
-
-
-
-
-