IP Library Granted Patent US 11,533,248
Granted Patent B2
US 11,533,248 · App. 17/187,913 · Granted Dec 20, 2022

Method and system of resiliency in cloud-delivered SD-WAN

Inventors: Ajit Ramachandra Mayya (Saratoga, CA); Parag Pritam Thakore (Los Gatos, CA); Stephen Craig Connors (San Jose, CA); Steven Michael Woo (Los Altos, CA); Sunil Mukundan (Chennai, IN); Thomas Harold Speeter (San Martin, CA)
Assignee: NICIRA, INC.
H04L43/55H04L12/2856H04L12/66H04L41/12H04L41/5032H04L43/045H04L43/08H04L43/12H04L45/123H04L45/124H04L45/125H04L45/22H04L45/302H04L45/70H04L47/22H04L47/781H04L61/25H04W76/22H04W76/30H04L12/2854H04L43/087H04L43/0829H04L43/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,533,248
App. No.
17/187,913
Granted
Dec 20, 2022
Kind
B2
Abstract

In one aspect, a computerized method includes the step of providing process monitor in a Gateway. The method includes the step of, with the process monitor, launching a Gateway Daemon (GWD). The GWD runs a GWD process that implements a Network Address Translation (NAT) process. The NAT process includes receiving a set of data packets from one or more Edge devices and forwarding the set of data packets to a public Internet. The method includes the step of receiving another set of data packets from the public Internet and forwarding the other set of data packets to the one or more Edge devices. The method includes the step of launching a Network Address Translation daemon (NATD). The method includes the step of detecting that the GWD process is interrupted; moving the NAT process to the NATD.

Claims (20)

1. A method of performing security services in a software-defined wide area network (SD-WAN) connecting multiple physical sites of an enterprise, the method comprising:

deploying, at a first physical site of the enterprise, an edge device; and

configuring the edge device to forward packets from computers at the first physical site that are addressed to destinations outside of the first physical site to a cloud gateway outside of the first physical site and accessible through the Internet,

the cloud gateway having an associated cloud web security (CWS) service to perform security scanning for packets, which are from the edge device and are addressed to destinations outside of the first physical site, before the packets are forwarded to the destinations of the packets; wherein the cloud gateway forwards packets to the CWS service along a first tunnel for the CWS service to perform the security scanning on the packets before the packets are forwarded to their destinations,

said configuring the edge device comprising (i) configuring the edge device to forward packets to the cloud gateway along a second tunnel through a first link of a first Internet Service Provider (ISP) and (ii) configuring the edge device to dynamically shift to a third tunnel through a second link of a second ISP to forward packets to the cloud gateway.

2. The method of claim 1 , wherein the CWS service performs service insertion for data traffic from the enterprise first network prior to the data traffic being sent to the public Internet.

3. The method of claim 1 , wherein the first tunnel is an IPsec tunnel.

4. The method of claim 1 further comprising configuring the edge device to dynamically select between the second and third tunnels based on measurement metrics repeatedly taken regarding a state of each tunnel, wherein configuring the edge device to dynamically select between the second and third tunnels comprises said configuring the edge to dynamically shift to the third tunnel.

5. The method of claim 1 , wherein the packets are forwarded to their destinations along the Internet.

6. The method of claim 1 , wherein the physical sites, including the first physical site, comprise branch sites of the enterprise.

7. A non-transitory machine readable medium storing a program for performing security services in a software-defined wide area network (SD-WAN) connecting multiple physical sites of an enterprise, the program for execution by at least one processing unit, the program comprising sets of instructions for:

deploying, at a first physical site of the enterprise, an edge device; and

configuring the edge device to forward packets from computers at the first physical site that are addressed to destinations outside of the first physical site to a cloud gateway outside of the first physical site and accessible through the Internet,

the cloud gateway having an associated cloud web security (CWS) service to perform security scanning for packets, which are from the edge device and are addressed to destinations outside of the first physical site, before the packets are forwarded to the destinations of the packets; wherein the cloud gateway forwards packets to the CWS service along a first tunnel for the CWS service to perform the security scanning on the packets before the packets are forwarded to their destinations;

said set of instructions for configuring the edge device comprising sets of instructions for (i) configuring the edge device to forward packets to the cloud gateway along a second tunnel through a first link of a first Internet Service Provider (ISP) and (ii) configuring the edge device to dynamically shift to a third tunnel through a second link of a second ISP to forward packets to the cloud gateway.

8. The non-transitory machine readable medium of claim 7 , wherein the CWS service performs service insertion for data traffic from the enterprise first network prior to the data traffic being sent to the public Internet.

9. The non-transitory machine readable medium of claim 7 , wherein the first tunnel is an IPsec tunnel.

10. The non-transitory machine readable medium of claim 7 , wherein the program further comprises a set of instructions for configuring the edge device to dynamically select between the second and third tunnels based on measurement metrics repeatedly taken regarding a state of each tunnel, wherein the set of instructions for configuring the edge device to dynamically select between the second and third tunnels comprises said set of instructions for configuring the edge to dynamically shift to the third tunnel.

11. The non-transitory machine readable medium of claim 7 , wherein the packets are forwarded to their destinations along the Internet.

12. The non-transitory machine readable medium of claim 7 , wherein the physical sites, including the first physical site, comprise branch sites of the enterprise.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2025
From: VMWARE, LLC
To: VELOCLOUD NETWORKS, LLC
Reel/Frame 072326/0693 →
MERGER Recorded Jan 27, 2025
From: NICIRA, INC.
To: VMWARE LLC
Reel/Frame 070187/0487 →
Continuity (4)
Continuation 16724154 · Dec 20, 2019
Continuation 15701115 · Sep 11, 2017
Provisional Application 62523477 · Jun 22, 2017
Related Publication 20210184952A1 · Jun 17, 2021
Cited By (33)
US 12,218,800 US 12,218,845 US 12,237,990 US 12,250,114 US 12,261,777 US 12,267,364 US 12,316,524 US 12,335,131 US 12,355,655 US 12,368,676 US 12,375,403 US 12,401,544 US 12,425,332 US 12,425,335 US 12,425,347 US 12,425,395 US 12,483,968 US 12,489,672 US 12,506,678 US 12,507,120 US 12,507,148 US 12,507,153 US 12,526,183 US 12,549,465 US 12,563,438 US 12,568,039 US 12,587,468 US 12,603,827 US 12,603,848 US 12,632,330 US 12,652,217 US 12,659,719 US 12,719,782