Dynamic path selection of VPN endpoint

    公开(公告)号:US12113773B2

    公开(公告)日:2024-10-08

    申请号:US17570364

    申请日:2022-01-06

    Applicant: VMware LLC

    CPC classification number: H04L63/0272 H04L12/4641 H04L63/0428 H04L45/24

    Abstract: Some embodiments provide a method that identifies multiple paths between a first site and a second site. A security association (SA) is established for transmitting encrypted payload from the first site to the second site in a virtual private network (VPN) session. The method selects a path based on metrics that are obtained for the paths. The selected path is defined by a first endpoint address of the first site and a second endpoint address of the second site. The method sends a message from the first site to the second site to update the SA to switch from using an original path to using the selected path. The message indicates the first and second endpoint addresses. The method transmits a packet including a payload that is encrypted according to the updated SA.

    Logical switch level load balancing of L2VPN traffic

    公开(公告)号:US12231407B2

    公开(公告)日:2025-02-18

    申请号:US17564274

    申请日:2021-12-29

    Applicant: VMware LLC

    Abstract: The disclosure provides an approach for logical switch level load balancing of Layer 2 virtual private network (L2VPN) traffic. A method of securing communications with a peer gateway generally includes establishing, at a virtual tunnel interface of a local gateway, a plurality of security tunnels with the peer gateway. Each of the plurality of security tunnels is associated with a different set of one or more layer 2 segments and with one or more security associations (SAs) with the peer gateway. The method generally includes receiving a packet, at the local gateway, via a first L2 segment. The method generally includes selecting one of the plurality of security tunnels and an SA associated with the selected security tunnel based on the L2 segment via which the packet was received. The method generally includes encrypting and encapsulating the packet based on the selected security tunnel and SA.

Patent Agency Ranking