Fault tolerant virtual private network endpoint node

    公开(公告)号:US11025483B1

    公开(公告)日:2021-06-01

    申请号:US15277929

    申请日:2016-09-27

    Inventor: Omer Hashmi

    Abstract: A provider network includes a service that creates fault tolerant virtual private network (VPN) endpoint nodes. Each such VPN endpoint node is created as a plurality of virtual machines executing on host computers. Each of the virtual machines is configured from a common machine image that includes software capable of causing the respective virtual machine to configure a secure communication tunnel such as an IPSec tunnel. One of the virtual machines, however, is operated in an active mode to actively configure the tunnel and send and receive encrypted traffic over the tunnel, while another virtual machine is configured to operate in a standby mode. The standby mode VPN endpoint virtual machine can be quickly transitioned to the active mode to take over the role of configuring and exchanging encrypted packets over the tunnel should the active mode VPN endpoint experience a failure.

    Virtual private gateway for encrypted communication over dedicated physical link

    公开(公告)号:US10560431B1

    公开(公告)日:2020-02-11

    申请号:US15369626

    申请日:2016-12-05

    Abstract: A request to establish an encrypted VPN connection between a network external to a provider network connected to the provider network via a dedicated direct physical link and a set of resources of the provider network is received. A new isolated virtual network (IVN) is established to implement an encryption virtual private gateway to be used for the connection. One or more protocol processing engines (PPEs) are instantiated within the IVN, address information of the one or more PPEs is exchanged with the external network and a respective encrypted VPN tunnel is configured between each of the PPEs and the external network. Routing information pertaining to the set of resources is provided to the external network via at least one of the encrypted VPN tunnels, enabling routing of customer data to the set of resources within the provider network from the external network via an encrypted VPN tunnel implemented over a dedicated direct physical link between the external network and the provider network.

Patent Agency Ranking