IP Library Granted Patent US 7,647,422
Granted Patent B2
US 7,647,422 · App. 10/222,531 · Granted Jan 12, 2010

VPN failure recovery

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,647,422
App. No.
10/222,531
Granted
Jan 12, 2010
Kind
B2
Abstract

An approach to rapid failover of a communication path between computers that are linked by redundant virtual links in a virtual private network (VPN) features detection of communication link and device failures through an active monitoring approach and re-routing of communication through a redundant link of the VPN when a failure is detected.

Claims (38)

1. A method for providing remote access to a server system over a data network comprising:

maintaining a plurality of communication paths through the data network between each of one or more client systems and the server system,

each path being associated with one of a plurality of gateway devices coupled between the data network and the server system, wherein each path is maintained as an active transport layer session;

for each of the client systems, the paths between said client system and the server system being associated with different of the gateway devices;

routing communication between a first of the client systems and the server system over a first of the communication paths passing through a first of the gateway devices;

monitoring communications associated with the first gateway device; and

re-routing the communication between the first client system and the server system to a second of the communication paths through a second of the gateway devices, before a transport layer timeout, in the event of a communication failure associated with the first gateway device.

2. The method of claim 1 wherein maintaining the communication paths includes maintaining paths through geographically distributed of the gateway devices, and coupling said geographically distributed gateway devices through a trusted data network.

3. The method of claim 1 wherein maintaining the communication paths includes maintaining a separate virtual communication link between each of the client systems and multiple of the gateway devices.

4. The method of claim 3 wherein at least some of the client systems include a client computer coupled to an access device, and wherein maintaining a virtual link between said client systems and the gateway devices includes maintaining virtual links between the access devices and the gateway devices.

5. The method of claim 3 wherein maintaining each of the virtual links includes maintaining a communication tunnel between the client system and the gateway device coupled by said link.

6. The method of claim 5 wherein maintaining the communication tunnels includes maintaining a PPTP tunnel.

7. The method of claim 5 wherein maintaining the communication tunnels includes maintaining a L2TP tunnel.

8. The method of claim 5 wherein maintaining the communication tunnels includes maintaining a IPSec tunnel.

9. The method of claim 8 wherein maintaining the IPSec tunnel includes passing network layer communication through said tunnel.

10. The method of claim 9 wherein passing network layer communication through the tunnel includes passing network layer communication in a Point-to-Point Protocol (PPP) session and passing the PPP session through the tunnel.

11. The method of claim 1 wherein routing communication between the client system and the server system includes transmitting data from the client system over the data network to a first network addressed of the first gateway device.

12. The method of claim 11 wherein re-routing the communication includes transmitting data from the client system over the data network to a network address of the second gateway device, said address of the second gateway address being different than the address of the first gateway device.

13. The method of claim 1 wherein monitoring communication associated with the first gateway device includes monitoring communication characteristics between the first gateway device and one or more devices of the server system.

14. The method of claim 13 wherein monitoring communication characteristics between the first gateway device and the one or more devices includes polling said devices from the first gateway device and detecting responses at the first gateway device from said devices.

15. The method of claim 14 wherein polling the devices includes transmitting ICMP echo requests.

16. The method of claim 1 wherein monitoring communication associated with the first gateway device includes monitoring communication characteristics between the first gateway device and the data network.

17. The method of claim 16 wherein monitoring communication characteristics between the first gateway device and the data network includes monitoring a device coupled between the first gateway device and the data network.

18. The method of claim 16 wherein monitoring communication characteristics between the first gateway device and the data network includes monitoring communication characteristics between the first gateway device and a network Point of Presence (POP) of the data network.

19. The method of claim 1 wherein monitoring communication associated with the first gateway device includes monitoring communication characteristics between the first gateway device and one or more devices accessible over the data network.

20. The method of claim 19 wherein monitoring communication characteristics between the first gateway device and one or more devices accessible over the data network includes monitoring communication characteristics between the gateway device and the client system.

21. The method of claim 19 wherein monitoring communication characteristics between the first gateway device and the one or more devices includes transmitting heartbeat messages from the first gateway device to said devices and detecting responses at the first gateway device from said devices.

22. The method of claim 21 wherein transmitting heartbeat messages includes transmitting ICMP echo requests.

23. The method of claim 21 wherein transmitting heartbeat messages includes transmitting LCP echo requests.

24. The method of claim 1 wherein re-routing the communication includes terminating the communication paths passing through the first gateway device.

25. The method of claim 1 wherein re-routing the communication includes updating routing data to indicate the second gateway device provides a path between the first client system and the server system.

26. The method of claim 25 wherein updating the routing data includes passing routing data from the second gateway device to the first client system.

27. The method of claim 25 wherein updating the routing data includes passing routing data from the second gateway device to one or more devices of the server system.

28. The method of claim 27 wherein passing the routing data to the one or more devices of the server system includes passing said data to routers of said system.

29. The method of claim 27 wherein passing the routing data to the one or more devices of the server system includes passing said data to host computers of said system.

30. A communication system comprising:

a plurality of gateway devices, each programmed to maintain a communication path between each of one or more client systems and the server system;

the gateway devices being programmed to route communication between a first of the client systems and the server system over a first of the communication paths passing through a first of the gateway devices, communication associated with the first gateway device being monitored, and to re-route the communication between the first client system and the server to a second of the communication paths via an active transport layer session through a second of the gateway devices, before a transport layer timeout, in the event of a communication failure associated with the first gateway device.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Oct 26, 2020
From: JEFFERIES FINANCE LLC
To: RPX CORPORATION
Reel/Frame 054486/0422 →
PATENT SECURITY AGREEMENT Recorded Oct 23, 2020
From: RPX CLEARINGHOUSE LLC; RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 054198/0029 →
PATENT SECURITY AGREEMENT Recorded Oct 23, 2020
From: RPX CLEARINGHOUSE LLC; RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 054244/0566 →
SECURITY INTEREST Recorded Jun 29, 2018
From: RPX CORPORATION
To: JEFFERIES FINANCE LLC
Reel/Frame 046486/0433 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2017
From: EXTREME NETWORKS, INC.
To: RPX CORPORATION
Reel/Frame 044087/0334 →
RELEASE OF SECURITY INTEREST Recorded Sep 29, 2017
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 043747/0694 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2015
From: ENTERASYS NETWORKS, INC.
To: EXTREME NETWORKS, INC.
Reel/Frame 036538/0011 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2015
From: ENTERASYS NETWORKS, INC.
To: EXTREME NETWORKS, INC.
Reel/Frame 036467/0566 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS AT REEL/FRAME NO. 25339/0875 Recorded Nov 1, 2013
From: WELLS FARGO TRUST CORPORATION LIMITED
To: ENTERASYS NETWORKS INC.
Reel/Frame 031558/0677 →
GRANT OF SECURITY INTEREST IN U.S. PATENTS Recorded Nov 10, 2010
From: ENTERASYS NETWORKS INC.
To: WELLS FARGO TRUST CORPORATION LIMITED, AS SECURITY AGENT
Reel/Frame 025339/0875 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2002
From: SINGH, INDERPREET; MCCANN, BENJAMIN
To: ENTERASYS NETWORKS, INC.
Reel/Frame 013209/0662 →