IP Library Granted Patent US 7,961,725
Granted Patent B2
US 7,961,725 · App. 11/831,315 · Granted Jun 14, 2011

Enterprise network architecture for implementing a virtual private network for wireless users by mapping wireless LANs to IP tunnels

Assignee: Symbol Technologies, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,961,725
App. No.
11/831,315
Granted
Jun 14, 2011
Kind
B2
Abstract

An enterprise network is provided which includes a central site, a network and a remote site communicatively coupled to the central site over the network. The central site includes a first termination device in communication with a restricted network segment including at least one server. The remote site includes an infrastructure device, an authorized access wireless local area network (WLAN), and an unauthorized access WLAN. The infrastructure device comprises a second termination device which communicates with the first termination device over the network. The authorized access WLAN allow communications with the central site via the second termination device over a tunnel coupling the first termination device to the second termination device, whereas the unauthorized access WLAN allows communications with the network via the second termination device.

Claims (32)

1. A method for communicating a data packet from a wireless communication device to an entity in a restricted network segment of a central site in an enterprise network, comprising:

storing, at a wireless switch that is coupled to a plurality of access ports and being located at a remote site in the enterprise network, a wireless communication device database (WCDD) comprising: a list of wireless communication devices associated with the wireless switch indexed by respective MAC addresses of each wireless communication device, respective addresses of each wireless communication device, a WLAN which each wireless communication device is associated with, a mapping table of WLANs-to-VLANs, and a mapping table of WLANs-to-tunnels;

receiving, at the wireless switch, the data packet from a wireless communication device via an access port coupled to the wireless switch;

determining, at the wireless switch based on the data packet, whether the wireless communication device is associated with one of:

an unauthorized access WLAN; and

an authorized access WLAN that is mapped to a Generic Routing Encapsulation (GRE) tunnel implemented over the IP network and that is designed to allow communications with an IP router at the central site via the wireless switch over the GRE tunnel, wherein the GRE tunnel extends an IP subnet from the central site to the authorized access WLAN.

2. A method according to claim 1 , wherein the step of determining, at the wireless switch based on the data packet, whether the wireless communication device is associated with one of: an authorized access WLAN and an unauthorized access WLAN, comprises:

determining the source MAC address of the data packet; and

determining, at the wireless switch based on the source MAC address of the data packet and information stored in the WCDD, whether a WLAN that the wireless communication device is associated with is an authorized access WLAN that is mapped to a Generic Routing Encapsulation (GRE) tunnel.

3. A method according to claim 2 , when the wireless switch determines that the WLAN that the wireless communication device is associated with is an authorized access WLAN that is mapped to a Generic Routing Encapsulation (GRE) tunnel, further comprising:

removing, at the wireless switch, a layer 2 (L2) header from the data packet to generate a layer 3 data packet;

encapsulating, at the wireless switch, the layer 3 (L3) data packet with a GRE header and an outer IP header to generate a GRE-over-IP packet; and

tunneling, from the wireless switch, the GRE-over-IP packet over the open network via the GRE tunnel to the IP router.

4. A method according to claim 3 , further comprising:

decapsulating, at the IP router, the GRE-over-IP packet by removing the outer IP header and the GRE header to generate the layer 3 (L3) data packet; and

transmitting, from the IP router, the layer 3 (L3) data packet to an entity in the restricted network segment located at the central site.

5. A method according to claim 1 , when the wireless switch determines that the WLAN that the wireless communication device is associated with is an unauthorized access WLAN, further comprising:

transmitting, from the wireless switch, via an access port coupled to the wireless switch, the data packet to a destination on an IP network.

6. A method for communicating a Layer 3 data packet from an entity in a restricted network segment of a central site in an enterprise network to an authorized wireless communication device at a remote site in the enterprise network, the method comprising:

receiving, at an IP router, the Layer 3 data packet from an entity in the restricted network segment;

removing, at the IP router, a layer 2 (L2) header from the Layer 3 data packet;

encapsulating, at the IP router, the Layer 3 data packet with a GRE header and an outer IP header to generate a GRE-over-IP packet;

transmitting, from the IP router, the GRE-over-IP packet over a Generic Routing Encapsulation (GRE) tunnel that couples the IP router to a wireless switch having an access port coupled thereto;

receiving, at the wireless switch, the GRE-over-IP packet; and

decapsulating, at the wireless switch, the GRE-over-IP packet by removing the outer IP header and the GRE header to generate an inner data packet; and

storing, at the wireless switch, a wireless communication device database (WCDD) comprising: a list of wireless communication devices associated with the wireless switch indexed by respective MAC addresses of each wireless communication device, respective addresses of each wireless communication device, a WLAN which each wireless communication device is associated with, a mapping table of WLANs-to-VLANs, and a mapping table of WLANs-to-tunnels.

7. A method according to claim 6 , further comprising:

determining, at the wireless switch, whether the inner data packet is destined for a wireless communication device associated with an authorized access WLAN that is mapped to a tunnel based on a destination address of the inner data packet and information stored in the WCDD.

8. A method according to claim 7 , further comprising:

when the inner data packet is destined for a wireless communication device associated with an authorized access WLAN that is mapped to a tunnel,

encapsulating the inner data packet into a data frame having a MAC address associated with the destination wireless communication device; and

transmitting the data frame over-the-air (OTA) to the destination wireless communication device via an access port coupled to the wireless switch.

Assignments (13)
RELEASE OF PATENT AND TRADEMARK SECURITY INTEREST AT REEL/FRAME NO. 46050/0546 Recorded Jul 30, 2026
From: BANK OF MONTREAL, AS AGENT
To: EXTREME NETWORKS, INC.
Reel/Frame 076081/0088 →
SECURITY INTEREST Recorded Jul 29, 2026
From: EXTREME NETWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 076078/0590 →
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2016
From: SYMBOL TECHNOLOGIES, LLC
To: EXTREME NETWORKS, INC.
Reel/Frame 040579/0410 →
AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2016
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 040521/0762 →
RELEASE OF SECURITY INTEREST Recorded Aug 17, 2015
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 036371/0738 →
CHANGE OF NAME Recorded Jul 8, 2015
From: SYMBOL TECHNOLOGIES, INC.
To: SYMBOL TECHNOLOGIES, LLC
Reel/Frame 036083/0640 →
SECURITY AGREEMENT Recorded Oct 31, 2014
From: ZIH CORP.; LASER BAND, LLC; ZEBRA ENTERPRISE SOLUTIONS CORP.; SYMBOL TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC. AS THE COLLATERAL AGENT
Reel/Frame 034114/0270 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 8, 2007
From: NAGARAJAN, RAMAKRISHNAN; BORKAR, UDAYAN
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 019666/0808 →
Continuity (1)
Related Publication 20090034431A1 · Feb 5, 2009