IP Library Granted Patent US 11,575,596
Granted Patent B1
US 11,575,596 · App. 17/723,934 · Granted Feb 7, 2023

Identifying an ingress router of a flow in inter-AS VPN option-C networks with visibility in one AS

Inventors: Vaibhav Lohani (Kharadi, IN); Roopesh Palasdeokar (Dhankawadi, IN)
Assignee: Ciena Corporation
H04L45/38H04L12/4641H04L43/045H04L43/062H04L45/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,575,596
App. No.
17/723,934
Granted
Feb 7, 2023
Kind
B1
Abstract

Systems and methods include detecting whether a monitored network has a unique configuration; responsive to the unique configuration, determining an ingress point for flow samples; and utilizing the determined ingress point for the flow samples to generate a traffic report for the monitored network. The unique configuration is an inter-Autonomous System (AS) option-C Virtual Private Network (VPN) network where control and data planes are asymmetric. The approach provides traffic projection based on the flow samples with the asymmetric flows.

Claims (34)

1. A non-transitory computer-readable medium having instructions stored thereon for programming a processing device to perform steps of:

detecting whether a monitored network has a unique configuration where there are multiple Autonomous Systems (AS) with only partial visibility for the monitored network and where control and data planes are asymmetric where a forwarding path is not the same as a path through which routes are exchanged from an AS that is not visible in the monitored network;

responsive to the unique configuration, determining an ingress point for flow samples; and

utilizing the determined ingress point for the flow samples to generate a traffic report for the monitored network,

wherein the unique configuration is an inter-Autonomous System (AS) option-C Virtual Private Network (VPN) network where control and data planes are asymmetric.

2. The non-transitory computer-readable medium of claim 1 , wherein the detecting is based on originators, including any of Provider Edge (PE) nodes and routing gateways, for some Layer 3 Virtual Private Network (VPN) (L3VPN) routes lacking Virtual routing and forwarding table (VRF) for corresponding services.

3. The non-transitory computer-readable medium of claim 1 , wherein the determining includes following Layer 3 Virtual Private Network (VPN) (L3VPN) traffic in a reverse direction.

4. The non-transitory computer-readable medium of claim 1 , wherein the determining includes searching next-hops of Layer 3 Virtual Private Network (VPN) (L3VPN) routes within local prefixes advertised by protocols used to setup transport tunnels.

5. The non-transitory computer-readable medium of claim 1 , wherein the steps further include

obtaining the flow samples from the monitored network.

6. The non-transitory computer-readable medium of claim 1 , wherein the steps further include

correlating a topology of the monitored network with paths for the flow samples.

7. The non-transitory computer-readable medium of claim 1 , wherein the traffic report is a traffic projection based on the flow samples.

8. A non-transitory computer-readable medium having instructions stored thereon for programming a processing device to perform steps of:

detecting whether a monitored network has a unique configuration where there are multiple Autonomous Systems (AS) with only partial visibility for the monitored network and where control and data planes are asymmetric where a forwarding path is not the same as a path through which routes are exchanged from an AS that is not visible in the monitored network;

responsive to the unique configuration, determining an ingress point for flow samples; and

utilizing the determined ingress point for the flow samples to generate a traffic report for the monitored network,

wherein the detecting is based on some Layer 3 Virtual Private Network (VPN) (L3VPN) traffic entering the monitored network at an Autonomous System Border Router (ASBR).

9. The non-transitory computer-readable medium of claim 8 , wherein the detecting is based on originators, including any of Provider Edge (PE) nodes and routing gateways, for some Layer 3 Virtual Private Network (VPN) (L3VPN) routes lacking Virtual routing and forwarding table (VRF) for corresponding services.

10. The non-transitory computer-readable medium of claim 8 , wherein the determining includes following Layer 3 Virtual Private Network (VPN) (L3VPN) traffic in a reverse direction.

11. The non-transitory computer-readable medium of claim 8 , wherein the determining includes searching next-hops of Layer 3 Virtual Private Network (VPN) (L3VPN) routes within local prefixes advertised by protocols used to setup transport tunnels.

12. The non-transitory computer-readable medium of claim 8 , wherein the steps further include obtaining the flow samples from the monitored network.

13. The non-transitory computer-readable medium of claim 8 , wherein the steps further include correlating a topology of the monitored network with paths for the flow samples.

14. The non-transitory computer-readable medium of claim 8 , wherein the traffic report is a traffic projection based on the flow samples.

15. A non-transitory computer-readable medium having instructions stored thereon for programming a processing device to perform steps of:

detecting whether a monitored network has a unique configuration where there are multiple Autonomous Systems (AS) with only partial visibility for the monitored network and where control and data planes are asymmetric where a forwarding path is not the same as a path through which routes are exchanged from an AS that is not visible in the monitored network;

responsive to the unique configuration, determining an ingress point for flow samples; and

utilizing the determined ingress point for the flow samples to generate a traffic report for the monitored network,

wherein the unique configuration includes some Layer 3 Virtual Private Network (VPN) (L3VPN) routes learned from an adjacent Autonomous System (AS) connected to the monitored network having an originator attribute that points to any of a Provider Edge (PE) node and routing gateway in the monitored network that is wrongly identified.

16. The non-transitory computer-readable medium of claim 15 , wherein the detecting is based on originators, including any of Provider Edge (PE) nodes and routing gateways, for some Layer 3 Virtual Private Network (VPN) (L3VPN) routes lacking Virtual routing and forwarding table (VRF) for corresponding services.

17. The non-transitory computer-readable medium of claim 15 , wherein the determining includes following Layer 3 Virtual Private Network (VPN) (L3VPN) traffic in a reverse direction.

18. The non-transitory computer-readable medium of claim 15 , wherein the determining includes searching next-hops of Layer 3 Virtual Private Network (VPN) (L3VPN) routes within local prefixes advertised by protocols used to setup transport tunnels.

19. The non-transitory computer-readable medium of claim 15 , wherein the steps further include

obtaining the flow samples from the monitored network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 19, 2022
From: LOHANI, VAIBHAV; PALASDEOKAR, ROOPESH
To: CIENA CORPORATION
Reel/Frame 059637/0521 →
Priority Claims (1)
IN 202211012245 · Mar 7, 2022 · national
Cited By (1)
US 12,476,897