IP Library › Granted Patent US 12,375,920
Granted Patent B2
US 12,375,920 · App. 18/661,055 · Granted Jul 29, 2025

Systems and methods for distributing SD-WAN policies

Inventors: Stefan Olofsson (Dubai, AE); Ijsbrand Wijnands (Leuven, BE); Hendrikus G. P. Bosch (Aalsmeer, NL); Jeffrey Napper (Delft, NL); Anubhav Gupta (Freemont, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04W12/086H04L63/0272H04L63/20H04W12/37H04L45/64
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,375,920
App. No.
18/661,055
Granted
Jul 29, 2025
Kind
B2
Abstract

In one embodiment, a router includes one or more processors and one or more computer-readable non-transitory storage media coupled to the one or more processors. The one or more computer-readable non-transitory storage media include instructions that, when executed by the one or more processors, cause the router to perform operations including receiving software-defined networking in a wide area network (SD-WAN) policies from a component of an SD-WAN network. The operations also include establishing a session with a mobile device and receiving information associated with the mobile device in response to establishing the session with the mobile device. The operations further include filtering the SD-WAN policies based on the information associated with the mobile device to generate SD-WAN device-specific policies and communicating the SD-WAN device-specific policies to the mobile device.

Claims (77)

1. An apparatus, comprising:

one or more processors; and

one or more computer-readable non-transitory storage media coupled to the one or more processors and comprising instructions that, when executed by the one or more processors, cause the apparatus to perform operations comprising:

receiving software-defined networking in a wide area network (SD-WAN) policies from a component of an SD-WAN network;

establishing a session with a mobile device;

receiving information associated with the mobile device in response to establishing the session with the mobile device, wherein the information associated with the mobile device comprises device posture information comprising a hostname and an identification of an operating system;

filtering the SD-WAN policies based on the information associated with the mobile device to generate SD-WAN device-specific policies; and

communicating the SD-WAN device-specific policies to the mobile device.

2. The apparatus of claim 1 , the operations further comprising:

receiving updated SD-WAN policies from the component of the SD-WAN network;

filtering the updated SD-WAN policies based on the information associated with the mobile device to generate updated SD-WAN device-specific policies; and

communicating the updated SD-WAN device-specific policies to the mobile device.

3. The apparatus of claim 1 , the operations further comprising:

receiving updated information associated with the mobile device;

filtering the SD-WAN policies based on the updated information associated with the mobile device to generate updated SD-WAN device-specific policies; and

communicating the updated SD-WAN device-specific policies to the mobile device.

4. The apparatus of claim 1 , wherein the SD-WAN policies comprise at least one of the following types of policies:

access policies;

segmentation-based policies;

flow classification policies; or

path selection policies.

5. The apparatus of claim 1 , wherein the information associated with the mobile device further comprises security posture information.

6. The apparatus of claim 1 , wherein:

the apparatus is a virtual routing and forwarding (VRF) enterprise Internet Protocol Security (IPsec) gateway; and

the component of the SD-WAN network is a VRF SD-WAN edge router.

7. The apparatus of claim 1 , wherein:

the session between the mobile device and the apparatus is a Virtual Private Network (VPN) session; and

the apparatus is a VRF enterprise Secure Sockets Layer/Transport Layer Security SSL/DTLS gateway.

8. A method, comprising:

receiving software-defined networking in a wide area network (SD-WAN) policies from a component of an SD-WAN network;

establishing a session with a mobile device;

receiving information associated with the mobile device in response to establishing the session with the mobile device, wherein the information associated with the mobile device comprises device posture information comprising a hostname and an identification of an operating system;

filtering the SD-WAN policies based on the information associated with the mobile device to generate SD-WAN device-specific policies; and

communicating the SD-WAN device-specific policies to the mobile device.

9. The method of claim 8 , further comprising:

receiving updated SD-WAN policies from the component of the SD-WAN network;

filtering the updated SD-WAN policies based on the information associated with the mobile device to generate updated SD-WAN device-specific policies; and

communicating the updated SD-WAN device-specific policies to the mobile device.

10. The method of claim 8 , further comprising:

receiving updated information associated with the mobile device;

filtering the SD-WAN policies based on the updated information associated with the mobile device to generate updated SD-WAN device-specific policies; and

communicating the updated SD-WAN device-specific policies to the mobile device.

11. The method of claim 8 , wherein the SD-WAN policies comprise at least one of the following types of policies:

access policies;

segmentation-based policies;

flow classification policies; or

path selection policies.

12. The method of claim 8 , wherein the information associated with the mobile device further comprises security posture information.

13. The method of claim 8 , wherein:

the SD-WAN policies are received by a virtual routing and forwarding (VRF) enterprise Internet Protocol Security (IPsec) gateway; and

the component of the SD-WAN network is a VRF SD-WAN edge router.

14. The method of claim 8 , wherein:

the session is a Virtual Private Network (VPN) session; and

the SD-WAN policies are received by a VRF enterprise Secure Sockets Layer/Transport Layer Security SSL/DTLS gateway.

15. One or more computer-readable non-transitory storage media embodying instructions that, when executed by a processor, cause the processor to perform operations comprising:

receiving software-defined networking in a wide area network (SD-WAN) policies from a component of an SD-WAN network;

establishing a session with a mobile device;

receiving information associated with the mobile device in response to establishing the session with the mobile device, wherein the information associated with the mobile device comprises device posture information comprising a hostname and an identification of an operating system;

filtering the SD-WAN policies based on the information associated with the mobile device to generate SD-WAN device-specific policies; and

communicating the SD-WAN device-specific policies to the mobile device.

16. The one or more computer-readable storage media of claim 15 , the operations further comprising:

receiving updated SD-WAN policies from the component of the SD-WAN network;

filtering the updated SD-WAN policies based on the information associated with the mobile device to generate updated SD-WAN device-specific policies; and

communicating the updated SD-WAN device-specific policies to the mobile device.

17. The one or more computer-readable storage media of claim 15 , the operations further comprising:

receiving updated information associated with the mobile device;

filtering the SD-WAN policies based on the updated information associated with the mobile device to generate updated SD-WAN device-specific policies; and

communicating the updated SD-WAN device-specific policies to the mobile device.

18. The one or more computer-readable storage media of claim 15 , wherein the SD-WAN policies comprise at least one of the following types of policies:

access policies;

segmentation-based policies;

flow classification policies; or

path selection policies.

19. The one or more computer-readable storage media of claim 15 , wherein the information associated with the mobile device further comprises security posture information.

20. The one or more computer-readable storage media of claim 15 , wherein:

the SD-WAN policies are received by a virtual routing and forwarding (VRF) enterprise Internet Protocol Security (IPsec) gateway; and

the component of the SD-WAN network is a VRF SD-WAN edge router.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2024
From: OLOFSSON, STEFAN; WIJNANDS, IJSBRAND; BOSCH, HENDRIKUS G. P.; NAPPER, JEFFREY; GUPTA, ANUBHAV
To: CISCO TECHNOLOGY, INC.
Reel/Frame 067377/0310 →
Continuity (4)
Continuation 17403676 · Aug 16, 2021
Continuation 16574963 · Sep 18, 2019
Provisional Application 62858136 · Jun 6, 2019
Related Publication 20240298180A1 · Sep 5, 2024
References Cited (43)
US 7505397B2 · Lee et al. · 2009 [cited by applicant]
US 7636793B1 · Friedman · 2009 [cited by applicant]
US 8910239B2 · Barton et al. · 2014 [cited by applicant]
US 11129023B2 · Olofsson et al. · 2021 [cited by applicant]
US 11336482B2 · Ramamoorthi et al. · 2022 [cited by applicant]
US 11563601B1 · K S et al. · 2023 [cited by applicant]
US 12052569B2 · Olofsson · 2024 [cited by examiner]
US 20040215978A1 · Okajo et al. · 2004 [cited by applicant]
US 20140109174A1 · Barton et al. · 2014 [cited by applicant]
US 20150109987A1 · Wang et al. · 2015 [cited by applicant]
US 20160330075A1 · Tiwari et al. · 2016 [cited by applicant]
US 20160344635A1 · Lee et al. · 2016 [cited by applicant]
US 20170111233A1 · Kokkula et al. · 2017 [cited by applicant]
US 20170279710A1 · Khan et al. · 2017 [cited by applicant]
US 20190158676A1 · Shaw et al. · 2019 [cited by applicant]
US 20190274070A1 · Hughes et al. · 2019 [cited by applicant]
US 20190334820A1 · Zhao · 2019 [cited by applicant]
US 20200153701A1 · Mohan et al. · 2020 [cited by applicant]
US 20200296007A1 · Finn, II · 2020 [cited by examiner]
US 20200389457A1 · Olofsson et al. · 2020 [cited by applicant]
US 20200389796A1 · Olofsson et al. · 2020 [cited by applicant]
US 20210369309A1 · Olofsson · 2021 [cited by examiner]
CN 107276897A · 2017 [cited by applicant]
CN 108964985A · 2018 [cited by applicant]
CN 109309621A · 2019 [cited by applicant]
CN 109921944A · 2019 [cited by applicant]
JP 2004342072A · 2004 [cited by applicant]
JP 2015153399A · 2015 [cited by applicant]
JP 2018517352A · 2018 [cited by applicant]
WO 2016038611A1 · 2016 [cited by applicant]
Office Action for Korean Application No. 1020227000317, dated Sep. 23, 2024, 14 Pages. [cited by applicant]
Office Action for Indian Application No. 202127056888, dated Mar. 8, 2024, 6 Pages. [cited by applicant]
Chinese Office Action corresponding to Chinese Patent Application No. 202080048762.2, dated Nov. 8, 2022, 18 pages. [cited by applicant]
Cisco: “Cisco SD-WAN Cloud Scale Architecture”, CTI, Published on 2019, Nov. 4, 2020, 216 Pages. [cited by applicant]
Golani K., et al., “Fault Tolerant Traffic Engineering in Software-defined WAN”, 2018 IEEE Symposium on Computers and Communications (ISCC), 6 pages. [cited by applicant]
International Preliminary Report on Patentability for International Application No. PCT/US2020/034781, mailed Dec. 16, 2021, 9 Pages. [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2020/034781, mailed Jul. 27, 2020, 10 pages. [cited by applicant]
“NetScaler SD-WAN 9.2,” Citrix Systems Inc., 2017, 136 Pages. [cited by applicant]
Office Action for Japanese Application No. 2021571811, dated Jun. 15, 2023, 3 Pages. [cited by applicant]
Zhao-Xian X., et al. “Architecture and Research Overview of the Software Defined Wide Area Network”, vol. 42, No. 12, Fire Control & Command Control, (School of Computer and Communication Engineering, Zhengzhou Univ… [cited by applicant]
Office Action for Australian Application No. 2020289026, dated Oct. 17, 2024, 3 Pages. [cited by applicant]
Office Action—Notice of Intention to Grant for Korean Application No. 1020227000317, dated Nov. 28, 2024, 7 Pages. [cited by applicant]
Office Action for Canada Application No. 3142843, dated Mar. 10, 2025, 4 Pages. [cited by applicant]