IP Library Granted Patent US 7,882,558
Granted Patent B1
US 7,882,558 · App. 11/542,680 · Granted Feb 1, 2011

Tunnel designation system for virtual private networks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,882,558
App. No.
11/542,680
Granted
Feb 1, 2011
Kind
B1
Abstract

A system and method are provided to couple tunnel servers to tunnel clients executing host applications for use in a virtual private network (VPN) environment. A receiver receives requests from host applications executing on the tunnel clients. The requests are addressed to the tunnel coupling system to establish a VPN tunnel. A processor processes the requests and an indication of loads on the tunnel servers to establish the VPN tunnels by designating at least one of the tunnel servers to each requested tunnel. A tunnel traffic distributor distributes tunnel traffic to the tunnel servers based at least part on the designations. In additional aspects, an evaluation processor evaluates the tunnel traffic before the tunnel traffic distributor distributes the tunnel traffic to the tunnel servers. For example, the evaluation performed by the evaluation processor includes at least performing security functions on the tunnel traffic. In yet another aspect, the request processor establishes the VPN tunnel by, in part, associating each VPN tunnel with characteristics of tunnel traffic for that VPN tunnel, and the tunnel traffic distributor operates in part based on the associations, without involvement of the host applications.

Claims (21)

1. A tunnel designator to couple tunnel servers to tunnel clients executing host applications for use in a virtual private network (VPN) environment, comprising:

(a) a receiver that receives tunnel traffic from host applications executing on the tunnel clients, the tunnel traffic comprising traffic related to existing VPN tunnels and requests to establish a VPN tunnel;

(b) a processor that processes the requests, the processor also maintaining an indication of loads on the tunnel servers, the processor operative to establish

the VPN tunnels by designating at least one of the tunnel servers to each of the requests; and

(c) a tunnel traffic distributor that distributes the tunnel traffic related to existing VPN tunnels to the tunnel servers based at least part on the designations.

2. The tunnel designator of claim 1 , further comprising:

an evaluation processor that evaluates the tunnel traffic before the traffic distributor distributes the tunnel traffic to the tunnel servers.

3. The tunnel designator of claim 2 , wherein the evaluation performed by the evaluation processor includes at least performing security functions on the tunnel traffic.

4. The tunnel designator of claim 1 , wherein:

the processor establishes the VPN tunnel with characteristics of tunnel traffic for that VPN tunnel; and

the tunnel traffic distributor operates in part based on the associations, without involvement of the host applications.

5. A method of connecting a plurality of tunnel clients to a plurality of tunnel servers using a tunnel designator, the method comprising:

using said tunnel designator to receive tunnel traffic of one or more of said tunnel clients, said tunnel traffic comprising traffic related to existing VPN tunnels;

identifying in said tunnel traffic, a request from one of said tunnel clients;

determining if said request is a valid request from one of said tunnel clients;

determining if said request is for a new tunnel,

and if so:

(a) opening a new tunnel to a selected one of said tunnel servers; and

(b) modifying an address map to include information associating said selected one of said tunnel servers to said request;

if not:

(b) using said address map to route said request to a mapped tunnel server.

Assignments (13)
SECURITY INTEREST Recorded Jul 6, 2022
From: WATCHGUARD TECHNOLOGIES, INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 060406/0682 →
SECURITY INTEREST Recorded Jul 6, 2022
From: WATCHGUARD TECHNOLOGIES, INC.
To: GOLDMAN SACHS SPECIALTY LENDING GROUP, L.P., AS COLLATERAL AGENT
Reel/Frame 060406/0720 →
RELEASE OF SECURITY INTEREST Recorded Jul 6, 2022
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: WATCHGUARD TECHNOLOGIES, INC.
Reel/Frame 060406/0751 →
RELEASE OF SECURITY INTEREST Recorded Jun 1, 2020
From: GOLDMAN SACHS SPECIALTY LENDING GROUP, L.P.
To: WATCHGUARD TECHNOLOGIES, INC.
Reel/Frame 052801/0422 →
SECURITY INTEREST Recorded Jun 1, 2020
From: WATCHGUARD TECHNOLOGIES, INC.
To: GOLDMAN SACHS BANK USA
Reel/Frame 052801/0668 →
CHANGE OF ADDRESS FOR ASSIGNEE Recorded Aug 28, 2019
From: GOLDMAN SACHS SPECIALTY LENDING GROUP. L.P.
To: GOLDMAN SACHS SPECIALTY LENDING GROUP. L.P.
Reel/Frame 050195/0673 →
RELEASE OF SECURITY INTEREST Recorded Jun 30, 2015
From: BANK OF MONTREAL, AS ADMINISTRATIVE AGENT
To: WATCHGUARD TECHNOLOGIES, INC.
Reel/Frame 035995/0466 →
SECURITY INTEREST Recorded Jun 30, 2015
From: WATCHGUARD TECHNOLOGIES, INC.
To: GOLDMAN SACHS SPECIALTY LENDING GROUP, L.P., AS COLLATERAL AGENT
Reel/Frame 036038/0455 →
RELEASE OF SECURITY INTEREST Recorded Jul 2, 2012
From: SILICON VALLEY BANK
To: WATCHGUARD TECHNOLOGIES, INC.; GLADIATOR CORPORATION
Reel/Frame 028477/0268 →
SECURITY AGREEMENT Recorded Jul 2, 2012
From: WATCHGUARD TECHNOLOGIES, INC.
To: BANK OF MONTREAL, AS ADMINISTRATIVE AGENT
Reel/Frame 028488/0917 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2010
From: LIN, YEEJANG JAMES
To: RAPIDSTREAM, INC.
Reel/Frame 025503/0340 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2010
From: RAPIDSTREAM INC.
To: WATCHGUARD TECHNOLOGIES, INC.
Reel/Frame 025503/0347 →
SECURITY AGREEMENT Recorded Aug 13, 2009
From: WATCHGUARD TECHNOLOGIES, INC.; GLADIATOR CORPORATION
To: SILICON VALLEY BANK
Reel/Frame 023098/0771 →