IP Library Granted Patent US 10,187,321
Granted Patent B2
US 10,187,321 · App. 15/058,447 · Granted Jan 22, 2019

Dynamic VPN policy model with encryption and traffic engineering resolution

Inventors: Fabio R. Maino (Palo Alto, CA); Horia Miclea (Epalinges, CH); John Evans (Somerset, GB); Brian Eliot Weis (San Jose, CA); Vina Ermagan (Marina Del Rey, CA)
Assignee: Cisco Technology, Inc.
H04L47/781H04L41/5025H04L43/0882H04L45/64H04L41/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,187,321
App. No.
15/058,447
Granted
Jan 22, 2019
Kind
B2
Abstract

High-level network policies that represent a virtual private network (VPN) as a high-level policy model are received. The VPN is to provide secure connectivity between connection sites of the VPN based on the high-level network policies. The high-level network policies are translated into low-level device configuration information represented in a network overlay and used for configuring a network underlay that provides the connections sites to the VPN. The network underlay is configured with the device configuration information so that the network underlay implements the VPN in accordance with the high-level policies. It is determined whether the network underlay is operating to direct traffic flows between the connection sites in compliance with the high-level network policies. If it is determined that the network underlay is not operating in compliance, the network underlay is reconfigured with new low-level device configuration information so that the network underlay operates in compliance.

Claims (87)

1. A method performed at a network controller, comprising:

receiving network policies that represent a virtual private network (VPN) as a policy model, the VPN providing secure connectivity between connection sites based on the network policies, wherein the network policies include a connectivity policy specifying that a first connection site is to communicate securely both over a secure physical link without encryption and over an unsecure physical link with encryption, and include an encryption policy that governs encryption of network traffic between the connection sites according to the connectivity policy;

translating the network policies into device configuration information represented in a network overlay and used for configuring a network underlay that provides connectivity for the connection sites to the VPN, wherein the translating includes translating the encryption policy into encryption algorithms to be used by the first connection site for encrypting traffic sent from the first connection site over the unsecure physical link;

configuring the network underlay with the device configuration information so that the network underlay implements the VPN in accordance with the network policies, and so that the first connection site is configured, based on the device configuration information, to communicate securely both over the secure physical link without encryption and over the unsecure physical link with encryption;

determining whether the network underlay is operating to direct traffic flows between the connection sites in compliance with the network policies; and

if it is determined that the unsecure physical link has failed such that the first connection site is not operating in compliance with the network policies, reconfiguring the network underlay including reconfiguring the first connection site with new device configuration information so that the first connection site communicates only over the secure physical link without encryption until a new unsecure physical link is configured for use in the connection sites in compliance with the network policies.

2. The method of claim 1 , wherein:

the receiving includes receiving a network requirement for one of the network policies and an indication of a measurable attribute that indicates whether the network underlay is operating in compliance with the network requirement; and

the method further comprises, while the network underlay is operating to direct traffic flows for the VPN:

collecting attribute measurements from the network underlay; and

comparing the attribute measurements to the network requirement.

3. The method of claim 2 , wherein:

if it is determined that the network underlay is not operating in compliance based on the comparing, the reconfiguring includes reconfiguring the network underlay with the new device configuration information.

4. The method of claim 3 , wherein:

the network requirement includes a requirement that link bandwidth usage at a given one of the connection sites is not to exceed a predetermined fraction of a maximum link capacity available at the given connection site, and the measurable attribute includes link bandwidth usage;

the collecting includes collecting link bandwidth usage measurements from the given connection site;

the comparing includes comparing the link bandwidth usage measurements to the predetermined fraction of the maximum link capacity; and

if the comparing indicates that the link bandwidth usage measurements exceed the predetermined fraction of the maximum link capacity, the reconfiguring includes reconfiguring the given connection site to increase the maximum link capacity.

5. The method of claim 1 , wherein:

the connectivity policy further defines which of the connection sites are to be connected with each other via the VPN; and

the translating includes:

translating the connectivity policy into forwarding states to be used by each connection site to implement traffic forwarding in the network underlay according to the connectivity policy; and

translating the encryption policy into encryption algorithms to be used by the connection sites for encrypting traffic sent from the connection sites; and

the configuring includes pushing the forwarding states and the encryption algorithms to the connection sites.

6. The method of claim 5 , wherein the connection sites each include a respective edge network device configured to permit respective customer premises equipment to communicate with the network underlay.

7. The method of claim 5 , wherein:

the receiving further includes receiving a logical topology policy that defines a logical topology by which the connection sites are to be connected with each other; and

the translating further includes translating the logical topology policy into the forwarding states so that the forwarding states implement traffic forwarding in the network underlay in accordance with the logical topology policy.

8. The method of claim 5 , wherein:

the receiving further includes receiving a traffic engineering policy and a service insertion policy; and

the translating further includes translating the connectivity policy into the one or more forwarding states so that the forwarding states implement traffic forwarding in the network underlay in accordance with the traffic engineering policy and the service insertion policy.

9. The method of claim 5 , wherein:

the receiving further includes receiving a set of inter-site connectivity contracts that collectively represent the connectivity policy and the encryption policy, each contract specifying for a given connection site connections with other connection sites to which the given connection site is to be connected and whether traffic between the given connection site and the other connection sites is to be encrypted.

10. An apparatus comprising:

a network interface unit configured to communicate with network devices in a network underlay and customer premises equipment; and

a processor connected with the network interface and configured to:

receive network policies that represent a virtual private network (VPN) as a policy model, the VPN providing secure connectivity between connection sites based on the network policies, wherein the network policies include a connectivity policy specifying that a first connection site is to communicate securely both over a secure physical link without encryption and over an unsecure physical link with encryption, and include an encryption policy that governs encryption of network traffic between the connection sites according to the connectivity policy;

translate the network policies into device configuration information represented in a network overlay and used for configuring the network underlay so as to provide connectivity for the connection sites to the VPN, wherein the processor is configured to translate the encryption policy into encryption algorithms to be used by the first connection site for encrypting traffic sent from the first connection site over the unsecure physical link;

configure the network underlay with the device configuration information so that the network underlay implements the VPN in accordance with the network policies, and so that the first connection site is configured, based on the device configuration information, to communicate securely both over the secure physical link without encryption and over the unsecure physical link with encryption;

determine whether the network underlay is operating to direct traffic flows between the connection sites in compliance with the network policies; and

if it is determined that the unsecure physical link has failed such that the first connection site is not operating in compliance with the network policies, reconfigure the network underlay including the first connection site with new device configuration information so that the first connection site communicates only over the secure physical link without encryption until a new unsecure physical link is configured for use in the connection sites in compliance with the network policies.

11. The apparatus of claim 10 , wherein the processor is configured to:

receive a network requirement for one of the network policies and an indication of a measurable attribute that indicates whether the network underlay is operating in compliance with the network requirement; and

while the network underlay is operating to direct traffic flows for the VPN:

collect attribute measurements from the network underlay; and

compare the attribute measurements to the network requirement.

12. The apparatus of claim 11 , wherein the processor is configured to:

if it is determined that the network underlay is not operating in compliance based on the comparing, reconfigure the network underlay with the new device configuration information.

13. The apparatus of claim 12 , wherein the network requirement includes a requirement that link bandwidth usage at a given one of the connection sites is not to exceed a predetermined fraction of a maximum link capacity available at the given connection site, and the measurable attribute includes link bandwidth usage, and wherein the processor is configured to:

collect link bandwidth usage measurements from the given connection site;

compare the link bandwidth usage measurements to the predetermined fraction of the maximum link capacity; and

if the comparing indicates that the link bandwidth usage measurements exceed the predetermined fraction of the maximum link capacity, reconfigure the given connection site to increase the maximum link capacity.

14. The apparatus of claim 10 , wherein the connectivity policy further defines which of the connection sites are to be connected with each other via the VPN; and

the processor is configured to:

translate the connectivity policy into forwarding states to be used by each connection site to implement traffic forwarding in the network underlay according to the connectivity policy;

translate the encryption policy into encryption algorithms to be used by the connection sites for encrypting traffic sent from the connection sites; and

push the forwarding states and the encryption algorithms to the connection sites.

15. The apparatus of claim 14 , wherein processor is configured to:

receive a logical topology policy that defines a logical topology by which the connection sites are to be connected with each other; and

translate the logical topology policy into the forwarding states so that the forwarding states implement traffic forwarding in the network underlay in accordance with the logical topology policy.

16. A non-transitory computer readable storage media encoded with instructions that, when executed by a processor, cause the processor to:

receive network policies that represent a virtual private network (VPN) as a policy model, the VPN providing secure connectivity between connection sites based on the network policies, wherein the network policies include a connectivity policy specifying that a first connection site is to communicate securely both over a secure physical link without encryption and over an unsecure physical link with encryption, and include an encryption policy that governs encryption of network traffic between the connection sites according to the connectivity policy;

translate the network policies into device configuration information represented in a network overlay and used for configuring a network underlay that provides connectivity for the connection sites to the VPN, wherein the instructions that cause the processor to translate include instructions for translating the encryption policy into encryption algorithms to be used by the first connection site for encrypting traffic sent from the first connection site over the unsecure physical link;

configure the network underlay with the device configuration information so that the network underlay implements the VPN in accordance with the network policies, and so that the first connection site is configured, based on the device configuration information, to communicate securely both over the secure physical link without encryption and over the unsecure physical link with encryption;

determine whether the network underlay is operating to direct traffic flows between the connection sites in compliance with the network policies; and

if it is determined that the unsecure physical link has failed such that the first connection site is not operating in compliance with the network policies, reconfiguring the network underlay including reconfiguring the first connection site with new device configuration information so that the first connection site communicates only over the secure physical link without encryption until a new unsecure physical link is configured for use in the connection sites in compliance with the network policies.

17. The computer readable storage media of claim 16 , wherein the instructions cause the processor to:

receive a network requirement for one of the network policies and an indication of a measurable attribute that indicates whether the network underlay is operating in compliance with the network requirement; and

while the network underlay is operating to direct traffic flows for the VPN:

collect attribute measurements from the network underlay; and

compare the attribute measurements to the network requirement.

18. The computer readable storage media of claim 17 , wherein the instructions cause the processor to:

if it is determined that the network underlay is not operating in compliance based on the comparing, reconfigure the network underlay with the new device configuration information.

19. The computer readable storage media of claim 18 , wherein the network requirement includes a requirement that link bandwidth usage at a given one of the connection sites is not to exceed a predetermined fraction of a maximum link capacity available at the given connection site, and the measurable attribute includes link bandwidth usage, and

wherein the instructions cause the processor to:

collect link bandwidth usage measurements from the given connection site;

compare the link bandwidth usage measurements to the predetermined fraction of the maximum link capacity; and

if the comparing indicates that the link bandwidth usage measurements exceed the predetermined fraction of the maximum link capacity, reconfigure the given connection site to increase the maximum link capacity.

20. The computer readable storage media of claim 16 , wherein:

the connectivity policy further defines which of the connection sites are to be connected with each other via the VPN; and

the instructions cause the processor to:

translate the connectivity policy into forwarding states to be used by each connection site to implement traffic forwarding in the network underlay according to the connectivity policy;

translate the encryption policy into encryption algorithms to be used by the connection sites for encrypting traffic sent from the connection sites; and

push the forwarding states and the encryption algorithms to the connection sites.

21. The computer readable storage media of claim 20 , wherein the instructions cause the processor to:

receive a logical topology policy that defines a logical topology by which the connection sites are to be connected with each other; and

translate the logical topology policy into the forwarding states so that the forwarding states implement traffic forwarding in the network underlay in accordance with the logical topology policy.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2016
From: MAINO, FABIO R.; MICLEA, HORIA; EVANS, JOHN; WEIS, BRIAN ELIOT; ERMAGAN, VINA
To: CISCO TECHNOLOGY, INC.
Reel/Frame 037871/0082 →
Continuity (2)
Provisional Application 62207137 · Aug 19, 2015
Related Publication 20170054758A1 · Feb 23, 2017
Cited By (1)
US 12,309,122