IP Library Granted Patent US 9,407,504
Granted Patent B1
US 9,407,504 · App. 14/156,324 · Granted Aug 2, 2016

Virtual links for network appliances

Inventors: Marco Di Benedetto (Santa Clara, CA); Pierluigi Rolando (San Jose, CA); Thomas Vincent Flynn (Santa Clara, CA)
Assignee: Cisco Technology, Inc.
H04L41/0853
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,407,504
App. No.
14/156,324
Granted
Aug 2, 2016
Kind
B1
Abstract

Creating virtual links is disclosed, including: determining a first network appliance to configure to communicate with a second network appliance using a virtual link, wherein the virtual link comprises a layer three overlay point-to-point data link; and determining the second network appliance to configure to communicate with the first network appliance using the virtual link.

Claims (46)

1. A system, comprising:

a processor configured to:

determine a first network appliance to configure to communicate with a second network appliance using a virtual link, wherein the virtual link comprises a layer three overlay point-to-point data link;

configure an inner interface of the first network appliance to receive data from the first network appliance to be sent via the virtual link;

encapsulate the received data by adding a virtual link-related tunnel header for each data packet;

configure an outer interface of the first network appliance to send the encapsulated data via the virtual link;

determine the second network appliance to configure to communicate with the first network appliance using the virtual link;

configure an outer interface of the second network appliance to receive the encapsulated data sent from the first network appliance via the virtual link;

decapsulate the received data by removing the virtual-link related tunnel header from each received data packet; and

configure an inner interface of the first network appliance to send the decapsulated data to the second network appliance; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the first network appliance is configured to perform a first network service and the second network appliance is configured to perform a second network service.

3. The system of claim 1 , wherein the first network appliance is provisioned on a first device, wherein the processor is further configured to migrate the first network appliance to a second device, wherein the virtual link is maintained between the first network appliance and the second network appliance after the migration.

4. The system of claim 1 , wherein the virtual link is provisioned for the first network appliance and the second network appliance by a managing entity.

5. The system of claim 1 , wherein a configuration associated with the virtual link is not modifiable by an administrator associated with the first network appliance and the second network appliance.

6. The system of claim 1 , wherein the virtual link comprises the point-to-point data link between the outer interface of the first network appliance and the outer interface of the second network appliance.

7. The system of claim 1 , wherein the inner interface on the first network appliance is associated with a first Internet Protocol (IP) address assigned by a provisioning administrator and the outer interface on the first network appliance is associated with a second IP address configured by an administrator of the first network appliance.

8. A method, comprising:

determining a first network appliance to configure to communicate with a second network appliance using a virtual link, wherein the virtual link comprises a layer three overlay point-to-point data link;

configuring an inner interface of the first network appliance to receive data from the first network appliance to be sent via the virtual link;

encapsulating the received data by adding a virtual link-related tunnel header for each data packet;

configuring an outer interface of the first network appliance to send the encapsulated data via the virtual link;

determining the second network appliance to configure to communicate with the first network appliance using the virtual link;

configuring an outer interface of the second network appliance to receive the encapsulated data sent from the first network appliance via the virtual link;

decapsulating the received data by removing the virtual-link related tunnel header from each received data packet; and

configuring an inner interface of the first network appliance to send the decapsulated data to the second network appliance.

9. The method of claim 8 , wherein the first network appliance is configured to perform a first network service and the second network appliance is configured to perform a second network service.

10. The method of claim 8 , wherein the first network appliance is provisioned on a first device and further comprising migrating the first network appliance to a second device, wherein the virtual link is maintained between the first network appliance and the second network appliance after the migration.

11. The method of claim 8 , wherein the virtual link is provisioned for the first network appliance and the second network appliance by a managing entity.

12. The method of claim 8 , wherein a configuration associated with the virtual link is not modifiable by an administrator associated with the first network appliance and the second network appliance.

13. The method of claim 8 , wherein the virtual link comprises the point-to-point data link between the outer interface of the first network appliance and the outer interface of the second network appliance.

14. The method of claim 8 , wherein the inner interface on the first network appliance is associated with a first Internet Protocol (IP) address assigned by a provisioning administrator and the outer interface on the first network appliance is associated with a second IP address configured by an administrator of the first network appliance.

15. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

determining a first network appliance to configure to communicate with a second network appliance using a virtual link, wherein the virtual link comprises a layer three overlay point-to-point data link;

configuring an inner interface of the first network appliance to receive data from the first network appliance to be sent via the virtual link;

encapsulating the received data by adding a virtual link-related tunnel header for each data packet;

configuring an outer interface of the first network appliance to send the encapsulated data via the virtual link;

determining the second network appliance to configure to communicate with the first network appliance using the virtual link

configuring an outer interface of the second network appliance to receive the encapsulated data sent from the first network appliance via the virtual link;

decapsulating the received data by removing the virtual-link related tunnel header from each received data packet; and

configuring an inner interface of the first network appliance to send the decapsulated data to the second network appliance.

16. The computer program product of claim 15 , wherein the first network appliance is configured to perform a first network service and the second network appliance is configured to perform a second network service.

17. The computer program product of claim 15 , wherein the first network appliance is provisioned on a first device and further comprising migrating the first network appliance to a second device, wherein the virtual link is maintained between the first network appliance and the second network appliance after the migration.

18. The computer program product of claim 15 , wherein the virtual link is provisioned for the first network appliance and the second network appliance by a managing entity.

19. The computer program product of claim 15 , wherein a configuration associated with the virtual link is not modifiable by an administrator associated with the first network appliance and the second network appliance.

20. The computer program product of claim 15 , wherein the virtual link comprises the point-to-point data link between the outer interface of the first network appliance and the outer interface of the second network appliance.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 9, 2015
From: EMBRANE LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 036768/0136 →
CHANGE OF NAME Recorded Oct 9, 2015
From: EMBRANE, INC.
To: EMBRANE LLC
Reel/Frame 036829/0462 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2014
From: DI BENEDETTO, MARCO; ROLANDO, PIERLUIGI; FLYNN, THOMAS VINCENT
To: EMBRANE, INC.
Reel/Frame 032305/0463 →