IP Library Granted Patent US 8,868,745
Granted Patent B1
US 8,868,745 · App. 10/744,529 · Granted Oct 21, 2014

Method and system for providing configurable route table limits in a service provider for managing VPN resource usage

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,868,745
App. No.
10/744,529
Granted
Oct 21, 2014
Kind
B1
Abstract

A number of route tables are stored in a server at the edge of a service provider network, and are used to connect a set of customer sites to VPNs provided by the service provider. The forwarding entries in the route tables describe how packets conveyed over associated VPNs are to be forwarded between the service provider network and customer equipment systems. The disclosed system provides a configuration process for the route table including a route count limit as a parameter. The route count limit parameter provided through the configuration process is associated with the route table, and may be stored at the provider edge system, as well as at each other packet forwarding device within the network infrastructure of the service provider. Each forwarding device in the service provider infrastructure stores the route count limit, and further operates to keep track of the current number of routes inserted into the route table. Once the route table reaches the route count limit associated with it, new route requests can be either rejected, or accepted, based on a predetermined policy configuration. If new route requests are accepted, then the number of routes exceeding the route count limit is taken into account when charging the associated customer for service.

Claims (64)

1. A method for managing resources associated with a virtual private network, comprising:

receiving a request for a new route across said virtual private network, said request for said new route generated in response to assignment of an address to a client device, wherein said request for said new route includes at least an address prefix;

comparing said address prefix in said request for said new route to a value of a prefix field in at least one route limit policy rule;

in response to said address prefix in said request for said new route matching a value of said prefix field in said route limit policy rule, obtaining a route count limit from said route limit policy rule;

determining a current route count for said virtual private network by determining a current number of forwarding entries in a route table associated with said virtual private network and stored in a provider edge device;

accepting said request for said new route in the event that adding said requested route to said current route count would not violate said route limit policy rule;

rejecting said request for said new route in the event that adding said requested route to said current route count would violate said route limit policy rule;

maintaining a rejected route request list of requested routes that were previously rejected;

detecting a change in said route count limit; and

accepting at least one of said previously rejected routes in said rejected route request list responsive to said change in said route count limit causing said current route count to go below said route count limit.

2. The method of claim 1 , wherein said route limit policy rule indicates that route requests beyond said route count limit are to be rejected, and wherein said rejecting said request for said new route comprises rejecting said request for a new route in the event that said current route count for said virtual private network is at least as high as said route count limit.

3. The method of claim 1 , wherein said route limit policy rule indicates that route requests beyond said route count limit are to be accepted, and wherein said accepting said request for said new route comprises accepting said request for a new route in the event that said current route count for said virtual private network is at least as high as said route count limit and incrementing a count of accepted route requests beyond said route count limit.

4. The method of claim 3 , wherein said accepting said request for said new route further comprises adding a new forwarding entry to said route table associated with said virtual private network.

5. The method of claim 3 , further comprising determining a customer charge for a customer associated with said virtual private network responsive, at least in part, to said count of accepted route requests beyond said route count limit.

6. The method of claim 1 , wherein said route limit policy rule includes a route count alarm threshold, and wherein said accepting said request for said new route further comprises:

determining a new current route count for said virtual private network after said new route is added;

comparing said new current route count with said route count alarm threshold; and

generating an alarm in the event that said new current route count is at least as high as said route count alarm threshold.

7. The method of claim 6 , wherein said alarm comprises an electronic message presented to a user through a graphical user interface.

8. The method of claim 1 , wherein said route limit policy rule includes a range of time, and further comprising:

determining a current time;

comparing said current time with said range of time; and

wherein said accepting said request for said new route and said rejecting said request for said new route are responsive to said comparing said current time with said range of time.

9. The method of claim 1 , wherein said route limit policy rule includes a first range of time and a second range of time, and further comprising:

determining a current time;

comparing said current time to said first range of time;

comparing, in the event that said current time is not within said first range of time, said current time with said second range of time; and

wherein said accepting said request for said new route and said rejecting said request for said new route are responsive to said comparing said current time with said second range of time.

10. The method of claim 1 , wherein said route limit policy rule in a given provider edge system reflects one of a plurality of local policies applicable to different respective ones of a plurality of provider edge systems in said virtual private network.

11. The method of claim 1 , wherein said value of said prefix field indicates that any requested prefix will match said value of said prefix field.

12. A system for managing resources associated with a virtual private network, comprising:

at least one processor and at least one memory;

at least one route table associated with said virtual private network and stored in said memory;

a rejected route request list stored in said memory;

program code stored in said memory, said program code for execution on said processor and including:

policy processing program code operable to obtain at least one route limit policy rule for said virtual private network, wherein said route limit policy rule includes a route count limit and a prefix field, and wherein said policy processing program code is further operable to store said route limit policy rule in association with said virtual private network;

request processing program code operable to

receive a request for a new route associated with said virtual private network, said request for said new route generated in response to assignment of an address to a client device, wherein said request for said new route includes at least an address prefix,

compare said address prefix in said request for said new route to a value of said prefix field in said route limit policy rule,

in response to said address prefix in said prefix in said request for said new route matching a value of said prefix field in said route limit policy rule, obtain said route count limit from said route limit policy rule,

determine a current route count for said virtual private network by determining a current number of forwarding entries in said route table associated with said virtual private network,

accept said request for said new route by adding a new entry to said route table in the event that adding said requested route to said current route count would not violate said route limit policy rule,

reject said request for said new route in the event that adding said requested route to said current route count would violate said route limit policy rule,

store requested routes that were previously rejected in said rejected route request list,

detect a change in said route count limit, and

accept at least one of said previously rejected routes stored in said rejected route request list responsive to said change in said route count limit causing said current route count to go below said route count limit.

13. The system of claim 12 , wherein said route limit policy rule indicates that route requests beyond said route count limit are to be rejected, and wherein said request processing program code is further operable to reject said request for said new route in the event that said current route count for said virtual private network is at least as high as said route count limit.

14. The system of claim 12 , wherein said route limit policy rule indicates that route requests beyond said route count limit are to be accepted, and wherein said request processing program code is further operable to accept said request for said new route in the event that said current route count for said virtual private network is at least as high as said route count limit, and to increment a count of accepted route requests beyond said route count limit.

15. The system of claim 14 , further comprising program code operable to determine a customer charge for a customer associated with said virtual private network responsive, at least in part, to said count of accepted route requests beyond said route count limit.

16. The system of claim 12 , wherein said route limit policy rule includes a route count alarm threshold, and wherein said request processing program code further comprises:

time determining program code operable to determine a new current route count for said virtual private network after said new route is added;

comparison program code operable to compare said new current route count with said route count alarm threshold; and

alarm generation program code operable to generate an alarm in the event that said new current route count is at least as high as said route count alarm threshold.

17. The system of claim 16 , wherein said alarm comprises an electronic message presented to a user through a graphical user interface.

18. The system of claim 12 , wherein said route limit policy rule includes a range of time, said program code further comprising:

time determining program code operable to determine a current time;

comparison program code operable to compare said current time with said range of time; and

wherein said request processing program code is responsive to said means for comparing said current time with said range of time.

19. The system of claim 12 , wherein said route limit policy rule includes a first range of time and a second range of time, and said program code further comprising:

time determining program code operable to determine a current time;

comparison program code operable to compare said current time to said first range of time, and to compare, in the event that said current time is not within said first range of time, said current time with said second range of time; and

wherein said request processing program code is responsive to said comparison program code.

20. The system of claim 12 , wherein said route limit policy rule in a given provider edge system reflects one of a plurality of local policies applicable to different respective ones of a plurality of provider edge systems in said virtual private network.

21. The system of claim 12 , wherein said value of said prefix field indicates that any requested prefix will match said value of said prefix field.

Assignments (18)
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
RELEASE OF SECURITY INTEREST Recorded Jan 11, 2018
From: CITICORP USA, INC.
To: AVAYA, INC.; SIERRA HOLDINGS CORP.
Reel/Frame 045045/0564 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 023892/0500 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.
Reel/Frame 044891/0564 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 029608/0256 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 044891/0801 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 025863/0535 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST, NA
To: AVAYA INC.
Reel/Frame 044892/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 030083/0639 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 045012/0666 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →