IP Library Granted Patent US 9,065,802
Granted Patent B2
US 9,065,802 · App. 13/461,433 · Granted Jun 23, 2015

Policy-based configuration of internet protocol security for a virtual private network

Inventor: Robert A. May (Vancouver, CA)
Assignee: Fortinet, Inc.
H04L63/0272H04L63/164H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,065,802
App. No.
13/461,433
Granted
Jun 23, 2015
Kind
B2
Abstract

A method for performing policy-based configuration of Internet Protocol Security (IPSec) for a Virtual Private Network (VPN) is provided. According to one embodiment, a browser-based interface of a network device displays a policy page through which multiple settings may be configured for a VPN connection. The settings include a type of IPSec tunnel to be established between the network device and a peer. One or more parameter values corresponding to one or more of the settings are received and responsive thereto a policy file is created or modified corresponding to the VPN connection. The policy file has contained therein multiple parameter values corresponding to the settings. Establishment of the VPN connection between the network device and the peer is requested based on the parameter values contained within the policy file by sending a notification request, including the policy file, from the network device to the peer.

Claims (50)

1. A method comprising:

displaying, via a browser-based interface of a source network device, a policy page through which a plurality of Virtual Private Network (VPN) settings configured for establishing a VPN connection, the plurality of VPN settings including a type of Internet Protocol Security (IPSec) tunnel to be established between the source network device and a peer network device;

receiving, via the browser-based interface by the source network device, one or more parameter values corresponding to one or more of the plurality of VPN settings;

responsive to said receiving, creating or modifying a policy file corresponding to the VPN connection, the policy file containing therein a plurality of parameter values corresponding to the plurality of VPN settings;

requesting establishment of the VPN connection between the source network device and the peer network device based on the plurality of parameter values contained within the policy file by sending a notification request, including the policy file, from the source network device to the peer network device;

receiving by the source network device an acknowledgement message from the peer network device acknowledging receipt of the notification message;

receiving by the source network device a reply message from the peer network device in response to the notification message; and

displaying information regarding a status of the VPN connection on the policy page.

2. The method of claim 1 , wherein the type of IPSec tunnel to be established comprises a site-to-site tunnel.

3. The method of claim 1 , wherein the policy page includes sufficient VPN settings to allow the VPN connection to be established between the source network device and the peer network device.

4. The method of claim 1 , further comprising assigning default phase-1/phase-2 configuration profiles to the VPN connection.

5. The method of claim 1 , wherein prior to said requesting establishment of a VPN connection, the status indicates configuration of the VPN connection is incomplete.

6. The method of claim 1 , wherein after said requesting establishment of a VPN connection, the status indicates configuration of the VPN connection has been sent.

7. The method of claim 1 , wherein after receipt of the acknowledgement message, the status indicates the VPN connection is waiting for the peer network device to accept.

8. The method of claim 1 , wherein after receipt of the reply message, when the reply message indicates acceptance by the peer network device of the VPN connection, then the status indicates the VPN connection is up.

9. The method of claim 1 , wherein after receipt of the reply message, when the reply message indicates rejection by the peer network device of the VPN connection, then the status indicates the VPN connection has been rejected.

10. The method of claim 1 , wherein the source network device comprises a router, a network switch, a firewall security device or a gateway device.

11. The method of claim 1 , wherein one or more of the notification message, the acknowledgement message and the reply message are exchanged between the source network device and the peer network device via a Secure Socket Layer (SSL) based protocol or via an IPSec protocol based message.

12. A network device comprising

a non-transitory storage device having tangibly embodied therein one or more routines operable to facilitate policy-based configuration of Internet Protocol Security (IPSec) for a Virtual Private Network (VPN) connection; and

one or more processors coupled to the non-transitory storage device and operable to execute the one or more routines, where

the one or more routines cause a policy page to be displayed to a network administrator through which a plurality of VPN settings be configured for establishing the VPN connection, the plurality of VPN settings including a type of IPSec tunnel to be established between the network device and a peer network device;

the one or more routines receiving one or more parameter values corresponding to one or more of the plurality of VPN settings;

responsive to said receiving, the one or more routines creating or modifying a policy file corresponding to the VPN connection, the policy file containing therein a plurality of parameter values corresponding to the plurality of VPN settings;

the one or more routines requesting establishment of the VPN connection between the network device and the peer network device based on the plurality of parameter values contained within the policy file by sending a notification request, including the policy file, from the network device to the peer network device;

the one or more routines receiving by the source network device an acknowledgement message from the peer network device acknowledging receipt of the notification message;

the one or more routines receiving by the source network device a reply message from the peer network device in response to the notification message; and

the one or more routines displaying information regarding a status of the VPN connection on the policy page.

13. The network device of claim 12 , wherein the type of IPSec tunnel to be established comprises a site-to-site tunnel.

14. The network device of claim 12 , wherein the policy page includes sufficient VPN settings to allow the VPN connection to be established between the network device and the peer network device.

15. The network device of claim 12 , further comprising assigning default phase-1/phase-2 configuration profiles to the VPN connection.

16. The network device of claim 12 , wherein the network device comprises a router, a network switch, a firewall security device or a gateway device.

17. A non-transitory computer-readable storage medium tangibly embodying a set of instructions, which when executed by one or more processors of a network device, cause the one or more processors to perform a method for facilitating policy-based configuration of Internet Protocol Security (IPSec) for a Virtual Private Network (VPN) connection, the method comprising:

displaying, via a browser-based interface of the network device, a policy page through which a plurality of VPN settings configured for establishing the VPN connection, the plurality of VPN settings including a type of IPSec tunnel to be established between the network device and a peer network device;

receiving, via the browser-based interface by the network device, one or more parameter values corresponding to one or more of the plurality of VPN settings;

responsive to said receiving, creating or modifying a policy file corresponding to the VPN connection, the policy file containing therein a plurality of parameter values corresponding to the plurality of VPN settings;

requesting establishment of the VPN connection between the network device and the peer network device based on the plurality of parameter values contained within the policy file by sending a notification request, including the policy file, from the network device to the peer network device;

receiving by the network device an acknowledgement message from the peer network device acknowledging receipt of the notification message;

receiving by the network device a reply message from the peer network device in response to the notification message; and

displaying information regarding a status of the VPN connection on the policy page.

18. The computer-readable storage medium of claim 17 , wherein the type of IPSec tunnel to be established comprises a site-to-site tunnel.

19. The computer-readable storage medium of claim 17 , wherein the policy page includes sufficient VPN settings to allow the VPN connection to be established between the network device and the peer network device.

20. The computer-readable storage medium of claim 17 , wherein the method further comprises assigning default phase-1/phase-2 configuration profiles to the VPN connection.

21. The computer-readable storage medium of claim 17 , wherein prior to said requesting establishment of a VPN connection, the status indicates configuration of the VPN connection is incomplete.

22. The computer-readable storage medium of claim 17 , wherein after said requesting establishment of a VPN connection, the status indicates configuration of the VPN connection has been sent.

23. The computer-readable storage medium of claim 17 , wherein after receipt of the acknowledgement message, the status indicates the VPN connection is waiting for the peer network device to accept.

24. The computer-readable storage medium of claim 17 , wherein after receipt of the reply message, when the reply message indicates acceptance by the peer network device of the VPN connection, then the status indicates the VPN connection is up.

25. The computer-readable storage medium of claim 17 , wherein after receipt of the reply message, when the reply message indicates rejection by the peer network device of the VPN connection, then the status indicates the VPN connection has been rejected.

26. The computer-readable storage medium of claim 17 , wherein the network device comprises a router, a network switch, a firewall security device or a gateway device.

27. The computer-readable storage medium of claim 17 , wherein one or more of the notification message, the acknowledgement message and the reply message are exchanged between the network device and the peer network device via a Secure Socket Layer (SSL) based protocol or via an IPSec protocol based message.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2012
From: MAY, ROBERT A.
To: FORTINET, INC.
Reel/Frame 028137/0906 →
Continuity (1)
Related Publication 20130298182A1 · Nov 7, 2013