IP Library › Granted Patent US 10,841,341
Granted Patent B2
US 10,841,341 · App. 15/453,022 · Granted Nov 17, 2020

Policy-based configuration of internet protocol security for a virtual private network

Inventor: Robert A. May (Vancouver, CA)
Assignee: Fortinet, Inc.
H04L63/205H04L12/4641H04L63/029H04L63/0272H04L63/0281H04L63/0485H04L63/10H04L63/105H04L63/20H04L63/164H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,841,341
App. No.
15/453,022
Granted
Nov 17, 2020
Kind
B2
Abstract

A method for performing policy-based configuration of IPSec for a VPN is provided. According to one embodiment, a request for a VPN connection to be established between a network device and a peer network device is received by the network device from the peer network device. Responsive to receipt of the request, the VPN connection is established by the network device in accordance with a policy associated with the request without requiring manual entry of VPN settings by a network administrator of the network device. The policy includes multiple VPN settings for the VPN connection and is configured by a network administrator of the peer network device via a policy page displayed to the network administrator via a user interface of the peer network device.

Claims (28)

1. A method comprising

receiving, by a network device, from a peer network device a request for a Virtual Private Network (VPN) connection to be established between the network device and the peer network device;

responsive to said receiving, establishing, by the network device, the VPN connection in accordance with a policy associated with the request without requiring manual entry of a plurality of VPN settings by a network administrator of the network device;

wherein the policy includes a plurality of VPN settings for the VPN connection including (i) one or more of (a) a type of VPN authentication, (b) an outgoing VPN interface of the peer network device and (c) a crypto profile and (ii) a type of Internet Protocol Security (IPSec) tunnel to be established between the network device and the peer network device; and

wherein the policy is configured by a network administrator of the peer network device via a policy page displayed to the network administrator via a user interface of the peer network device.

2. The method of claim 1 , further comprising assigning, by the network device, the plurality of VPN settings to a VPN configuration profile.

3. The method of claim 1 , wherein the type of IPSec tunnel to be established comprises a site-to-site tunnel.

4. The method of claim 1 , wherein the type of IPSec tunnel to be established comprises a remote access tunnel.

5. The method of claim 1 , wherein the policy page includes sufficient VPN settings to allow the VPN connection to be established between the network device and the peer network device.

6. The method of claim 1 , further comprising automatically assigning, by the peer network device, default phase-1/phase-2 configuration profiles to the VPN connection.

7. The method of claim 1 , wherein the network device comprises a router or a switch.

8. The method of claim 1 , wherein the network device comprises a firewall security device or a gateway device.

9. The method of claim 1 , wherein the peer network device comprises a router or a switch.

10. The method of claim 1 , wherein the peer network device comprises a firewall security device or a gateway device.

11. A non-transitory computer-readable storage medium embodying a set of instructions, which when executed by one or more processors of a network device, causes the one or more processors to perform a method comprising:

receiving, from a peer network device, a request for a Virtual Private Network (VPN) connection to be established between the network device and the peer network device;

responsive to said receiving, establishing, the VPN connection in accordance with a policy associated with the request without requiring manual entry of a plurality of VPN settings by a network administrator of the network device;

wherein the policy includes a plurality of VPN settings for the VPN connection including (i) one or more of (a) a type of VPN authentication, (b) an outgoing VPN interface of the peer network device and (c) a crypto profile and (ii) a type of Internet Protocol Security (IPSec) tunnel to be established between the network device and the peer network device; and

wherein the policy is configured by a network administrator of the peer network device via a policy page displayed to the network administrator via a user interface of the peer network device.

12. The non-transitory computer-readable storage medium of claim 11 , wherein the method further comprises assigning the plurality of VPN settings to a VPN configuration profile.

13. The non-transitory computer-readable storage medium of claim 11 , wherein the type of IPSec tunnel to be established comprises a site-to-site tunnel.

14. The non-transitory computer-readable storage medium of claim 11 , wherein the type of IPSec tunnel to be established comprises a remote access tunnel.

15. The non-transitory computer-readable storage medium of claim 11 , wherein the policy page includes sufficient VPN settings to allow the VPN connection to be established between the network device and the peer network device.

16. The non-transitory computer-readable storage medium of claim 11 , wherein the method further comprises automatically assigning, by the peer network device, default phase-1/phase-2 configuration profiles to the VPN connection.

17. The non-transitory computer-readable storage medium of claim 11 , wherein the network device comprises a router or a switch.

18. The non-transitory computer-readable storage medium of claim 11 , wherein the network device comprises a firewall security device or a gateway device.

19. The non-transitory computer-readable storage medium of claim 11 , wherein the peer network device comprises a router or a switch.

20. The non-transitory computer-readable storage medium of claim 11 , wherein the peer network device comprises a firewall security device or a gateway device.

Continuity (4)
Continuation 15071977 · Mar 16, 2016
Continuation 14699367 · Apr 29, 2015
Continuation 13461433 · May 1, 2012
Related Publication 20170180428A1 · Jun 22, 2017
Cited By (1)
US 12,289,600