IP Library Granted Patent US 11,025,477
Granted Patent B2
US 11,025,477 · App. 15/392,649 · Granted Jun 1, 2021

Overlay network ingress edge region selection

Inventors: Ryan Ruel (Cambridge, MA); Fardad Farahmand (Cambridge, MA); Brandon O. Williams (Revere, MA)
Assignee: Akamai Technologies, Inc.
H04L29/06959H04L12/4633H04L29/06612H04L63/0272H04L63/061H04L63/164H04L61/1511H04L61/2514H04L63/0485H04L63/068H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,025,477
App. No.
15/392,649
Granted
Jun 1, 2021
Kind
B2
Abstract

This disclosure relates to enhanced overlay network-based transport of traffic to and from customer branch office locations, facilitated through the use of the Internet-based overlay routing. A method of selecting an ingress edge region of the overlay network begins by mapping a service hostname to an IKEv2 destination of an outer IPsec tunnel associated with a first overlay network edge. An IKEv2 session is established from the first overlay network edge to the customer router. Upon tunnel establishment, a secondary lookup is performed to determine whether the first overlay network edge is an appropriate ingress region. Based on a response to the secondary lookup, a IKEv2 redirect is issued to a second overlay network edge. A new tunnel is then established from the second overlay network edge to the customer router. Thereafter, an additional lookup may also be performed to determine whether the second overlay network edge remains an appropriate ingress region.

Claims (28)

1. A method of selecting an ingress edge region of an Internet-based overlay network, the overlay network having an authoritative domain name service (DNS), comprising:

receiving and mapping a service hostname to an IKEv2 destination of an outer IPsec tunnel associated with a first overlay network edge, the service hostname received at the authoritative DNS from a DNS resolver associated with a customer router;

establishing an IKEv2 session from the first overlay network edge to the customer router;

upon tunnel establishment between the customer router and the first overlay network edge, performing a secondary lookup to determine whether the first overlay network edge is an appropriate ingress region, the secondary lookup initiated to the authoritative DNS by the first overlay network edge;

based on a response to the secondary lookup and a determination by the first overlay network edge that a second overlay network edge region should be established as the ingress edge region, issuing a redirect from the first overlay network edge to a second overlay network edge; and

establishing a new tunnel from the second overlay network edge to the customer router.

2. The method as described in claim 1 wherein the secondary lookup is based on an IP address of the customer router.

3. The method as described in claim 1 further including:

performing an additional lookup to determine whether the second overlay network edge remains an appropriate ingress region, the additional lookup being initiated to the authoritative DNS by the second overlay network edge; and

based on a response to the additional lookup, dropping responses to one or more liveness probes otherwise being received over the new tunnel from the customer router, thereby triggering the customer router to initiate another service hostname lookup.

4. The method as described in claim 1 wherein the redirect is an IKEv2 redirect notify message.

5. The method as described in claim 3 wherein the one or more liveness probes are IP-SLA probes.

6. The method as described in claim 1 wherein the secondary lookup is also performed upon an IKE re-key event.

7. The method as described in claim 1 wherein the first and second overlay network edges are associated with distinct geographic locations.

8. A method of selecting an ingress edge region of an Internet-based overlay network, the overlay network having an authoritative domain name service (DNS), comprising:

receiving and mapping a service hostname to a first destination tunnel associated with a first overlay network edge, the service hostname received at the authoritative DNS from a DNS resolver associated with a customer router;

establishing a tunnel from the first overlay network edge to the customer router;

upon tunnel establishment between the customer router and the first overlay network edge, performing a secondary lookup to determine whether the first overlay network edge is an appropriate ingress region, the secondary lookup initiated to the authoritative DNS by the first overlay network edge;

when based on a response to the secondary lookup received from the authoritative DNS the first overlay network edge determines that it is an appropriate ingress region, using the tunnel to communicate messages between the customer router and the first overlay network edge;

when based on a response to the secondary lookup received from the authoritative DNS the first overlay network edge determines that it is not an appropriate ingress region, issuing a redirect from the first overlay network edge to a second overlay network edge; and

establishing a new tunnel from the second overlay network edge to the customer router.

9. The method as described in claim 8 wherein the session is an IKEv2 session.

10. The method as described in claim 9 wherein the redirect is an IKEv2 redirect notify message.

11. The method as described in claim 8 further including:

performing an additional lookup to determine whether the second overlay network edge remains an appropriate ingress region, the additional lookup being initiated to the authoritative DNS by the second overlay network edge; and

based on a response to the additional lookup, dropping responses to one or more liveness probes otherwise being received over the new tunnel from the customer router, thereby triggering the customer router to initiate another service hostname lookup.

12. The method as described in claim 11 wherein the liveness probes are IP-SLA probes.

13. The method as described in claim 8 wherein the first destination tunnel is an IKEv2 destination of an outer IPsec tunnel associated with the first overlay network edge.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 6, 2017
From: RUEL, RYAN; FARAHMAND, FARDAD; WILLIAMS, BRANDON O.
To: AKAMAI TECHNOLOGIES, INC.
Reel/Frame 040871/0350 →
Continuity (2)
Provisional Application 62273479 · Dec 31, 2015
Related Publication 20170195161A1 · Jul 6, 2017
Cited By (2)
US 12,316,599 US 12,432,183