Hierarchical-context area network as a virtual private network infrastructure system
Operating a hierarchical-context area network includes a first VPN server obtaining an automatic egress reconfiguration policy associated with a defined scope, wherein the automatic egress reconfiguration policy indicates a defined automatic egress reconfiguration period, receiving, from an end user device associated with the defined scope, via a VPN tunnel between the first VPN server and the end user device, a first protocol data unit addressed to an external device, identifying a second VPN server as a current point of egress for transmitting the first protocol data unit to the external device, receiving, from the end user device, via the VPN tunnel, a second protocol data unit addressed to the external device, and in response to determining that the defined automatic egress reconfiguration period is expired, identifying a third VPN server as the current point of egress for transmitting the second protocol data unit to the external device.
1 . A method comprising:
operating a hierarchical-context area network as a virtual private network infrastructure (VPNI) network of a virtual private network (VPN) system, wherein the hierarchical-context area network includes a hierarchy of VPNI context areas, wherein:
operating the hierarchical-context area network includes:
obtaining, by a first VPN server in the hierarchical-context area network, an automatic egress reconfiguration policy associated with a defined scope;
receiving, by the first VPN server, from an end user device associated with the defined scope, via a VPN tunnel between the first VPN server and the end user device, a first protocol data unit addressed to an external device;
identifying a second VPN server in the hierarchical-context area network as a current point of egress for transmitting the first protocol data unit to the external device, wherein the second VPN server is associated with a first IP address;
receiving, by the first VPN server, from the end user device, via the VPN tunnel, a second protocol data unit addressed to the external device; and
identifying, in accordance with the automatic egress reconfiguration policy, a third VPN server in the hierarchical-context area network as the current point of egress for transmitting the second protocol data unit to the external device, wherein the third VPN server is associated with a second IP address, wherein:
identifying the third VPN server includes identifying the third VPN server in response to determining that a temporal span corresponding to a defined automatic egress reconfiguration period indicated by the automatic egress reconfiguration policy is expired.
2 . The method of claim 1 , wherein operating the hierarchical-context area network includes:
prior to receiving the first protocol data unit, enabling egress reconfiguration for the VPN tunnel.
3 . The method of claim 1 , wherein operating the hierarchical-context area network includes:
in response to identifying the second VPN server as the current point of egress, sending, by the first VPN server, the first protocol data unit, through the hierarchical-context area network, to the second VPN server as the current point of egress;
obtaining, by the second VPN server as the current point of egress, the first protocol data unit; and
transmitting, by the second VPN server as the current point of egress, the first protocol data unit to the external device, via the Internet.
4 . The method of claim 1 , wherein operating the hierarchical-context area network includes:
in response to identifying the third VPN server as the current point of egress, sending, by the first VPN server, the second protocol data unit, through the hierarchical-context area network, to the third VPN server as the current point of egress;
obtaining, by the third VPN server as the current point of egress, the second protocol data unit; and
transmitting, by the third VPN server as the current point of egress, the second protocol data unit to the external device, via the Internet.
5 . The method of claim 1 , wherein operating the hierarchical-context area network includes:
subsequent to identifying the third VPN server as the current point of egress, receiving, by the second VPN server, a third protocol data unit addressed to the second VPN server, from the external device, via the Internet;
in response to receiving the third protocol data unit by the second VPN server, sending, by the second VPN server, to the first VPN server, the third protocol data unit, via the hierarchical-context area network; and
in response to receiving the third protocol data unit by the first VPN server, sending, by the first VPN server, to the end user device, the third protocol data unit, via the VPN tunnel.
6 . The method of claim 2 , wherein enabling egress reconfiguration includes:
enabling egress reconfiguration in response to the first VPN server obtaining an egress reconfiguration request from the end user device via the VPN tunnel.
7 . The method of claim 2 , wherein:
the hierarchical-context area network includes:
a first VPNI context area network (CAN), wherein the first VPNI CAN is a level-one VPNI CAN;
a second VPNI CAN, wherein the second VPNI CAN is a level-two VPNI CAN; and
a third VPNI CAN, wherein the third VPNI CAN is a level-one VPNI CAN, wherein the third VPNI CAN is allocated a shared IP address; and
enabling egress reconfiguration includes the first VPN server identifying the shared IP address as the current point of egress.
8 . The method of claim 7 , wherein operating the hierarchical-context area network includes: enabling automatic egress reconfiguration for the VPN tunnel, wherein enabling automatic egress reconfiguration includes:
enabling automatic egress reconfiguration in response to the first VPN server obtaining a request to enable automatic egress reconfiguration from the end user device via the VPN tunnel.
9 . The method of claim 7 , wherein:
the first VPN server implements an interface to the second VPNI CAN;
the second VPN server implements an interface to the second VPNI CAN; and
the third VPN server implements an interface to the second VPNI CAN.
10 . The method of claim 8 , wherein obtaining the request to enable automatic egress reconfiguration includes:
obtaining the automatic egress reconfiguration policy from the request to enable automatic egress reconfiguration.
11 . The method of claim 9 , wherein:
the first VPN server implements an interface to the first VPNI CAN;
the second VPN server implements an interface to the third VPNI CAN; and
the third VPN server implements an interface to the third VPNI CAN.
12 . The method of claim 9 , wherein:
the first VPN server implements an interface to the first VPNI CAN;
the second VPN server implements an interface to the third VPNI CAN; and
the third VPN server implements an interface to a fourth VPNI CAN, wherein the fourth VPNI CAN is a level-one VPNI CAN.
13 . The method of claim 10 , wherein the automatic egress reconfiguration policy indicates:
an automatic egress reconfiguration pool that includes the second VPN server and the third VPN server.
14 . The method of claim 13 , wherein the automatic egress reconfiguration policy indicates:
an automatic egress reconfiguration pool identification parameter.
15 . The method of claim 14 , wherein the automatic egress reconfiguration pool identification parameter indicates:
a minimum resource availability for inclusion in the automatic egress reconfiguration pool;
a feature implemented by at least one VPN server of the hierarchical-context area network; or
a server type.
16 . The method of claim 14 , wherein enabling automatic egress reconfiguration includes:
including the second VPN server in the automatic egress reconfiguration pool in response to a determination that the second VPN server satisfies the automatic egress reconfiguration pool identification parameter;
including the third VPN server in the automatic egress reconfiguration pool in response to a determination that the third VPN server satisfies the automatic egress reconfiguration pool identification parameter; and
omitting a fourth VPN server from the automatic egress reconfiguration pool in response to a determination that the fourth VPN server is inconsistent with the automatic egress reconfiguration pool identification parameter.
17 . A virtual private network infrastructure (VPNI) system operating a hierarchical-context area network as a VPNI network, wherein the hierarchical-context area network includes a hierarchy of context areas, the VPNI system comprising:
a first virtual private network (VPN) server;
a second VPN server, wherein the second VPN server is associated with a first IP address; and
a third VPN server, wherein the third VPN server is associated with a second IP address, and wherein:
the first VPN server:
obtains an automatic egress reconfiguration policy associated with a defined scope, wherein the automatic egress reconfiguration policy indicates a defined automatic egress reconfiguration period;
receives, from an end user device associated with the defined scope, via a VPN tunnel between the first VPN server and the end user device, a first protocol data unit addressed to an external device;
identifies the second VPN server as a current point of egress for transmitting the first protocol data unit to the external device;
receives, from the end user device, via the VPN tunnel, a second protocol data unit addressed to the external device;
determines that a temporal span corresponding to the defined automatic egress reconfiguration period is expired; and
in response to the determination that the temporal span corresponding to the defined automatic egress reconfiguration period is expired, identifies the third VPN server as the current point of egress for transmitting the second protocol data unit to the external device.
18 . A non-transitory computer-readable storage medium, comprising processor-executable instructions for operating, in response to the instructions, a hierarchical-context area network as a virtual private network infrastructure (VPNI) network, wherein the hierarchical-context area network includes a hierarchy of context areas, wherein operating the hierarchical-context area network includes:
obtaining, by a first VPN server in the hierarchical-context area network, an automatic egress reconfiguration policy associated with a defined scope, wherein the automatic egress reconfiguration policy indicates a defined automatic egress reconfiguration period;
receiving, by the first VPN server, from an end user device associated with the defined scope, via a VPN tunnel between the first VPN server and the end user device, a first protocol data unit addressed to an external device;
identifying a second VPN server in the hierarchical-context area network as a current point of egress for transmitting the first protocol data unit to the external device, wherein the second VPN server is associated with a first IP address;
receiving, by the first VPN server, from the end user device, via the VPN tunnel, a second protocol data unit addressed to the external device; and
in response to determining that a temporal span corresponding to the defined automatic egress reconfiguration period is expired, identifying a third VPN server in the hierarchical-context area network as the current point of egress for transmitting the second protocol data unit to the external device, wherein the third VPN server is associated with a second IP address.
19 . The non-transitory computer-readable storage medium of claim 18 , wherein operating the hierarchical-context area network includes:
subsequent to identifying the third VPN server as the current point of egress, receiving, by the second VPN server, a third protocol data unit addressed to the second VPN server, from the external device, via the Internet;
in response to receiving the third protocol data unit by the second VPN server, sending, by the second VPN server, to the first VPN server, the third protocol data unit, via the hierarchical-context area network; and
in response to receiving the third protocol data unit by the first VPN server, sending, by the first VPN server, to the end user device, the third protocol data unit, via the VPN tunnel.