IP Library › Granted Patent US 11,552,824
Granted Patent B2
US 11,552,824 · App. 17/391,790 · Granted Jan 10, 2023

Label based policy enforcement

Inventors: Saumya Dikshit (Bangalore, IN); Vinayak Joshi (Bangalore, IN)
Assignee: Hewlett Packard Enterprise Development LP
H04L12/4641H04L45/50H04L45/64H04L2212/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,552,824
App. No.
17/391,790
Granted
Jan 10, 2023
Kind
B2
Abstract

Examples disclosed herein relate to a method comprising receiving a data packet originating from a first device and intended for a second device, wherein the first device and the first access device belong to a first branch of a Wide Area Network (WAN) using a MPLS overlay and the second device belongs to a second branch of the WAN. The method includes encapsulating the data packet in VXLAN including a VXLAN label identifying a role type and transmitting the data packet to a first core device. The method includes determining an MPLS label corresponding to the role type and transmitting the data packet over the MPLS overlay to a second core device belonging to the second branch of the WAN. The method includes translating the MPLS label into the VXLAN label and transmitting the data packet including the VXLAN label to a second access device for an enforcement action.

Claims (39)

1. A method comprising:

receiving, by a first access device, a data packet originating from a first device and intended for a second device, wherein the first device and the first access device belong to a first branch of a Wide Area Network (WAN) using a MPLS overlay and the second device belongs to a second branch of the WAN;

encapsulating, by the first access device, the data packet in VXLAN including a VXLAN label identifying a role type of the first device and the second device;

transmitting, by the first access device, the data packet to a first core device, wherein the first core device belongs to the first branch of the WAN;

determining, by the first core device, an MPLS label corresponding to the role type;

transmitting, by the first core device, the data packet over the MPLS overlay to a second core device belonging to the second branch of the WAN, the data packet including the MPLS label;

translating, by the second core device, the MPLS label into the VXLAN label; and

transmitting, by the second core device, the data packet including the VXLAN label to a second access device for an enforcement action of the role type, the second access device belonging to the second branch.

2. The method of claim 1 wherein the first core device and the first access device are connected via a first VXLAN overlay tunnel mesh on the first branch of the WAN and the second core device and the second access device are connected via a second VXLAN overlay tunnel mesh on the second branch.

3. The method of claim 1 comprising:

removing, by the first core device, VXLAN information including the VXLAN label from the data packet.

4. The method of claim 1 wherein the enforcement action is discarding a packet intended for the second device and the role type of the first device does not have permission to transmit data packets to the role type of the second device.

5. The method of claim 1 comprising:

decapsulating, by the first core device, the data packet in VXLAN and

placing, by the first core device, an MPLS label corresponding to the VXLAN tag on the packet.

6. The method of claim 1 wherein the first device and the second device are on different IP subnets.

7. The method of claim 1 wherein the MPLS label is placed on a predetermined location of a label stack on the data packet.

8. A system comprising:

a packet receiver to receive, via an MPLS overlay, at a first core device, a data packet from a second core device, the data packet originating from a first device and intended for a second device, wherein the first device and the first core device belong to a first branch of a Wide Area Network (WAN) using a MPLS overlay and the second device and the second core device belong to a second branch of the WAN;

a label translator to translate, by the first core device, an MPLS label identifying a role type of the first device and the second device into a VXLAN label, the MPLS label added to the data backet by the second core device; and

a packet transmitter to transmit, by the first core device, the data packet including the VXLAN label to a first access device for an enforcement action of the role type, the first access device belonging to the first branch.

9. The system of claim 8 wherein the first core device and the first access device are connected via a first VXLAN overlay tunnel mesh on the first branch of the WAN and the second core device and a second access device are connected via a second VXLAN overlay tunnel mesh on the second branch.

10. The system of claim 8 wherein the enforcement action is discarding a packet intended for the second device and the role type of the first device does not have permission to transmit data packets to the role type of the second device.

11. The system of claim 8 wherein the first device and the second device are on different IP subnets.

12. The system of claim 8 wherein the MPLS label is placed on a predetermined location of a label stack on the data packet.

13. The system of claim 8 wherein the VXLAN information including the VXLAN label from the data packet has been removed by the second core device.

14. A non-transitory machine-readable storage medium encoded with instructions, the instructions executable by a processor of a system to cause the system to:

receive, by a first core device, a data packet originating from a first device and intended for a second device, wherein the first device and the first core device belong to a first branch of a Wide Area Network (WAN) using a MPLS overlay and the second device belongs to a second branch of the WAN;

decapsulate, by the first core device, the data packet encapsulated in VXLAN by a first access device, the data packet including a VXLAN label identifying a role type of the first device and the second device, wherein the first access device belongs to the first branch of the WAN;

determine, by the first core device, an MPLS label corresponding to the role type and

transmit, by the first core device, the data packet, including the MPLS label, over the MPLS overlay to a second core device for translation into the VXLAN label and enforcement of the role type, the second core device belonging to the second branch of the WAN.

15. The non-transitory machine-readable storage medium of claim 14 wherein the first core device and the second access device are connected via a first VXLAN overlay tunnel mesh on the first branch of the WAN and the second core device and the second access device are connected via a second VXLAN overlay tunnel mesh on the second branch.

16. The non-transitory machine-readable storage medium of claim 15 , the instructions executable by a processor of a system to cause the system to:

remove, by the first core device, VXLAN information including the VXLAN label from the data packet.

17. The non-transitory machine-readable storage medium of claim 14 wherein the enforcement action is discarding a packet intended for the second device and the role type of the first device does not have permission to transmit data packets to the role type of the second device.

18. The non-transitory machine-readable storage medium of claim 15 , the instructions executable by a processor of a system to cause the system to:

decapsulate, by the first core device, the VXLAN and places an MPLS label corresponding to the VXLAN tag on the packet.

19. The non-transitory machine-readable storage medium of claim 14 wherein the first device and the second device are on different IP subnets.

20. The non-transitory machine-readable storage medium of claim 14 wherein the MPLS label is placed on a predetermined location of a label stack on the data packet.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2021
From: DIKSHIT, SAUMYA; JOSHI, VINAYAK
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 057346/0152 →
Priority Claims (1)
IN 202141019140 · Apr 26, 2021 · national
Continuity (1)
Related Publication 20220345330A1 · Oct 27, 2022