IP Library › Granted Patent US 11,805,103
Granted Patent B2
US 11,805,103 · App. 17/235,034 · Granted Oct 31, 2023

Dynamic selection of tunnel endpoints

Inventors: Sasindran Devaraj (Bangalore, IN); Vijayakumar Subramanian (Bangalore, IN); Vinodh Kumar Velur Sukumarran (Bangalore, IN)
Assignee: Hewlett Packard Enterprise Development LP
H04L63/029H04L63/0236H04L63/0876H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,805,103
App. No.
17/235,034
Granted
Oct 31, 2023
Kind
B2
Abstract

Examples of dynamically selecting tunnel endpoints are described. In an example, a request for authenticating a client device connected to an edge device via a wired link is received. The request includes information indicative of a port of the edge device at which the client device is connected and a type of the client device. Based on at least one of the port, the type, resource availability of a plurality of network devices, and location of the plurality of network devices, a network device is identified as a tunnel endpoint. A message indicative of a successful authentication of the client device is sent to the edge device. The message includes a network address of the network device identified as the tunnel endpoint.

Claims (62)

1. A method for selecting a tunnel endpoint in a network, comprising:

receiving, by a network manager, a request for authenticating generated by a client device connected to an edge device via a link, wherein the request includes information indicative of a type of the client device, and wherein the network manager comprises a remote server comprising authentication capabilities;

identifying, by the network manager, based on the type of the client device, resource availability of a plurality of network devices, and location of the plurality of network devices, a network device, from the plurality of network devices, as a tunnel endpoint for terminating a network tunnel from the edge device to the network device by:

determining, based on the request, the type of the client device;

identifying, based on the type of the client device, a destination server to which the client device is to connect;

identifying a first network device, from the plurality of network devices, located in a site identical to that of the destination server;

determining resource availability of a first network device based on processor consumption, memory consumption, and a number of client devices connected to the first network device; and

in response to determining that the first network device is available to accept a connection from the client device based on the resource availability of the first network device, identifying the first network device as the tunnel endpoint; and

sending, by the network manager to the edge device, a message indicative of a successful authentication of the client device responsive to the request for authenticating, wherein the message includes a network address of the first network device identified as the tunnel endpoint.

2. The method of claim 1 , further comprising, determining, by the network manager, a role for the client device, wherein the role is indicative of permissions of the client device to access applications and services hosted by the network device.

3. The method of claim 2 , wherein the message includes a vendor specific attribute (VSA) indicative of the role of the client device.

4. The method of claim 1 , wherein identifying the network device as the tunnel endpoint further comprises:

identifying, based on the request, a port of the edge device at which the client device is connected, wherein the request further includes information indicative of the port of the edge device at which the client device is connected;

determining, based on a predefined mapping, whether the port is mapped to a second network device from the plurality of network devices; and

in response to determining that the port is mapped to the second network device, identifying the second network device as the tunnel endpoint.

5. The method of claim 1 , wherein identifying the network device as the tunnel endpoint further comprises:

in response to determining that the first network device is unavailable to accept a connection from the client device, identifying a third network device, from the plurality of network devices, located in a site closest to that of the destination server; and

in response to determining that the third network device is available to accept a connection from the client device, identifying the third network device as the tunnel endpoint.

6. The method of claim 1 , wherein in response to one of a failure being encountered in terminating the network tunnel in the network device and the network device being unreachable, configuring the edge device to terminate the network tunnel from the edge device to a predefined network device.

7. The method of claim 1 , wherein the message includes a VSA indicative of the network address of the network device identified as the tunnel endpoint.

8. The method of claim 1 , wherein the network tunnel is a Generic Routing Encapsulation (GRE) tunnel.

9. The method of claim 1 , wherein the remote server is a Remote Authentication Dial-In User Service (RADIUS) authentication server.

10. The method of claim 1 , wherein the network manager includes a cloud-based network manager.

11. A network manager comprising:

a remote server comprising authentication capabilities, the remote server comprising:

a processor; and

a memory coupled to the processor, the memory storing instructions executed by the processor to:

receive a request for authenticating generated by a client device connected to an edge device via a link, wherein the request includes information indicative of a-a type of the client device;

identify, based on the type of the client device, resource availability of a plurality of network devices, and location of the plurality of network devices, a network device, from the plurality of network devices, as a tunnel endpoint for terminating a network tunnel from the edge device to the network device by:

determining, based on the request, the type of the client device;

identifying, based on the type of the client device, a destination server to which the client device is to connect;

identifying a first network device, from the plurality of network devices, located in a site identical to that of the destination server;

determining resource availability of the first network device based on processor consumption, memory consumption, and a number of client devices connected to the first network device; and

in response to determining that the first network device is available to accept a connection from the client device based on the resource availability of the first network device, identifying the first network device as the tunnel endpoint; and

send, to the edge device, a message indicative of a successful authentication of the client device responsive to the request for authenticating, wherein the message includes a network address of the first network device identified as the tunnel endpoint.

12. The network manager of claim 11 , wherein the processor is further to:

determine a role for the client device, wherein the role is indicative of permissions of the client device to access applications and services hosted by the network device.

13. The network manager of claim 12 , wherein the message includes a vendor specific attribute (VSA) indicative of the role of the client device.

14. The network manager of claim 11 , wherein identifying the network device as the tunnel endpoint further comprises:

identifying, based on the request, a port of the edge device at which the client device is connected, wherein the request further includes information indicative of the port of the edge device at which the client device is connected;

determining, based on a predefined mapping, whether the port is mapped to a second network device from the plurality of network devices; and

in response to determining that the port is mapped to the second network device, identifying the second network device as the tunnel endpoint.

15. The network manager of claim 11 , wherein identifying the network device as the tunnel endpoint further comprises:

in response to determining that the first network device is unavailable to accept a connection from the client device, identifying a third network device, from the plurality of network devices, located in a site closest to that of the destination server; and

in response to determining that the third network device is available to accept a connection from the client device, identifying the third network device as the tunnel endpoint.

16. The network manager of claim 11 , wherein in response to one of a failure being encountered in terminating the network tunnel in the network device and the network device being unreachable, configuring the edge device to terminate the network tunnel from the edge device to a predefined network device.

17. A non-transitory computer-readable medium comprising computer-readable instructions, the computer-readable instructions when executed by a processor, cause the processor to:

receive, by a remote server comprising authentication capabilities, a request for authenticating generated by a client device connected to an edge device via a link, wherein the request includes information indicative of a type of the client device;

identify, based on the type of the client device, resource availability of a plurality of network devices, and location of the plurality of network devices, a network device, from the plurality of network devices, as a tunnel endpoint for terminating a network tunnel from the edge device to the network device by:

determining, based on the request, the type of the client device;

identifying, based on the type of the client device, a destination server to which the client device is to connect;

identifying a first network device, from the plurality of network devices, located in a site identical to that of the destination server;

determining resource availability of the first network device based on processor consumption, memory consumption, and a number of client devices connected to the first network device; and

in response to determining that the first network device is available to accept a connection from the client device based on the resource availability of the first network device, identifying the first network device as the tunnel endpoint; and

send, to the edge device, a message indicative of a successful authentication of the client device responsive to the request for authenticating, wherein the message includes a network address of the first network device identified as the tunnel endpoint.

18. The non-transitory computer-readable medium of claim 17 , wherein the instructions further cause the processor to:

determine a role for the client device, wherein the role is indicative of permissions of the client device to access applications and services hosted by the network device.

19. The non-transitory computer-readable medium of claim 18 , wherein the message includes a vendor specific attribute (VSA) indicative of the role of the client device.

20. The non-transitory computer-readable medium of claim 17 , wherein identifying the network device as the tunnel endpoint further comprises:

identifying, based on the request, a port of the edge device at which the client device is connected, wherein the request further includes information indicative of the port of the edge device at which the client device is connected;

determining, based on a predefined mapping, whether the port is mapped to a second network device from the plurality of network devices; and

in response to determining that the port is mapped to the second network device, identifying the second network device as the tunnel endpoint.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2021
From: DEVARAJ, SASINDRAN; SUBRAMANIAN, VIJAYAKUMAR; SUKUMARRAN, VINODH KUMAR VELUR
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 057600/0329 →
Continuity (1)
Related Publication 20220182359A1 · Jun 9, 2022