IP Library › Granted Patent US 9,313,183
Granted Patent B2
US 9,313,183 · App. 14/699,367 · Granted Apr 12, 2016

Policy-based configuration of internet protocol security for a virtual private network

Inventor: Robert A. May (Vancouver, CA)
Assignee: Fortinet, Inc.
H04L63/0485H04L12/4641H04L63/0272H04L63/10H04L63/20H04L63/164H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,313,183
App. No.
14/699,367
Granted
Apr 12, 2016
Kind
B2
Abstract

A method for performing policy-based configuration of Internet Protocol Security (IPSec) for a Virtual Private Network (VPN) is provided. According to one embodiment, a policy page through which a policy, including multiple VPN settings for establishing a VPN connection, may be viewed and configured is displayed via a user interface of a source network device. The VPN settings include a type of IPSec tunnel to be established between the source network device and a peer network device. A selection regarding the type of IPSec tunnel to be used for the VPN connection is received via the user interface. The source network device requests the VPN connection be established between the source network device and the peer network device in accordance with the policy by sending a notification request to the peer network device. The notification requests includes parameter values associated with the VPN settings.

Claims (10)

1. A network device comprising

a non-transitory storage device having embodied therein one or more routines operable to facilitate policy-based configuration of Internet Protocol Security (IPSec) for a Virtual Private Network (VPN) connection; and

one or more processors coupled to the non-transitory storage device and operable to execute the one or more routines, where

the one or more routines cause a policy page to be displayed to a network administrator via a user interface of the network device through which a policy, including a plurality of VPN settings for establishing the VPN connection, is viewed and configured, the plurality of VPN settings including a type of IPSec tunnel to be established between the network device and a peer network device;

the one or more routines receiving, via the user interface, a selection regarding the type of IPSec tunnel to be used for the VPN connection; and

the one or more routines requesting the VPN connection be established between the network device and the peer network device in accordance with the policy by sending a notification request, including parameter values associated with the plurality of VPN settings, from the network device to the peer network device.

2. The network device of claim 1 , wherein the type of IPSec tunnel to be established comprises a site-to-site tunnel.

3. The network device of claim 1 , wherein the policy page includes sufficient VPN settings to allow the VPN connection to be established between the network device and the peer network device.

4. The network device of claim 1 , further comprising assigning default phase-1/phase-2 configuration profiles to the VPN connection.

5. The network device of claim 1 , wherein the network device comprises a router, a network switch, a firewall security device or a gateway device.

Continuity (2)
Continuation 13461433 · May 1, 2012
Related Publication 20150244691A1 · Aug 27, 2015