IP Library › Granted Patent US 12,335,093
Granted Patent B2
US 12,335,093 · App. 18/620,459 · Granted Jun 17, 2025

Orchestrated reconnect for client-unaware rolling of network nodes

Inventors: Pankaj Chitrigi Ganesh (Arlington, MA); Kyle Andrew Donald Mestery (Woodbury, MN); Danxiang Li (Arlington, MA); Rahim Lalani (Vancouver, CA); Andrzej Konrad Kielbasinski (Grafton, MA)
Assignee: Cisco Technology, Inc.
H04L41/082H04L12/4675H04L45/22H04L67/1031H04L67/563
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,335,093
App. No.
18/620,459
Granted
Jun 17, 2025
Kind
B2
Abstract

Techniques for the transparent rolling of nodes in a cloud-delivered headend service without disrupting client traffic or making users aware of the various nodes in the system being rolled are described herein. The techniques may include receiving an indication that a first node of a network is to be rolled. Based at least in part on the indication, new connection requests may not be sent to the first intermediate node. Additionally, a client device having an existing connection through the first node may be identified. In some examples, a request may be sent to the client device to prompt the client device to establish a new connection. After determining that the new connection has been established such that the new connection flows through a second node of the network, the first node may be rolled.

Claims (55)

1. A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

determining to refrain from servicing virtual private network (VPN) connection requests through a first intermediate node to reach termination nodes of a cloud-based VPN headend service;

sending, to a client device that has an existing VPN connection with a first termination node that passes through the first intermediate node, an indication to cause the client device to establish a new VPN connection without terminating the existing VPN connection;

causing the new VPN connection to be established between the client device and the first termination node or a second termination node through a second intermediate node; and

subsequent to the client device establishing the new VPN connection through the second intermediate node, removing the first intermediate node from service.

2. The system of claim 1 , wherein the indication to cause the client device to establish the new VPN connection includes at least one of a hostname or an internet protocol (IP) address that is associated with the second intermediate node.

3. The system of claim 1 , wherein:

the indication to establish the new VPN connection is sent to each client device of multiple client devices that have existing connections passing through the first intermediate node, and

removing the first intermediate node from service is based at least in part on determining that each one of the multiple client devices have established new connections through other intermediate nodes that are different from the first intermediate node.

4. The system of claim 1 , the operations further comprising at least one of:

updating the first intermediate node with a new version of software while the first intermediate node is removed from service; or

deploying the second intermediate node to replace the first intermediate node based at least in part on the first intermediate node being removed from service.

5. The system of claim 4 , wherein the first intermediate node is at least one of a load balancer node, a proxy node, or a headend node of the cloud-based VPN headend service.

6. The system of claim 1 , wherein the first intermediate node is associated with a first datacenter and the second intermediate node is associated with a second datacenter, the second datacenter located in a different geographical location than the first datacenter.

7. The system of claim 1 , the operations further comprising:

receiving, at a proxy node of the cloud-based VPN headend service, a connection request from the client device, the connection request indicating a request for the new VPN connection; and

based at least in part on the first intermediate node being removed from service, sending, from the proxy node, the connection request to the second intermediate node.

8. A method comprising:

determining to refrain from servicing virtual private network (VPN) connection requests through a first intermediate node to reach termination nodes of a cloud-based VPN headend service;

sending, to a client device that has an existing VPN connection with a first termination node that passes through the first intermediate node, an indication to cause the client device to establish a new VPN connection without terminating the existing VPN connection;

causing the new VPN connection to be established between the client device and the first termination node or a second termination node through a second intermediate node; and

subsequent to the client device establishing the new VPN connection through the second intermediate node, removing the first intermediate node from service.

9. The method of claim 8 , wherein the indication to cause the client device to establish the new VPN connection includes at least one of a hostname or an internet protocol (IP) address that is associated with the second intermediate node.

10. The method of claim 8 , wherein:

the indication to establish the new VPN connection is sent to each client device of multiple client devices that have existing connections passing through the first intermediate node, and

removing the first intermediate node from service is based at least in part on determining that each one of the multiple client devices have established new connections through other intermediate nodes that are different from the first intermediate node.

11. The method of claim 8 , further comprising at least one of:

updating the first intermediate node with a new version of software while the first intermediate node is removed from service; or

deploying the second intermediate node to replace the first intermediate node based at least in part on the first intermediate node being removed from service.

12. The method of claim 11 , wherein the first intermediate node is at least one of a load balancer node, a proxy node, or a headend node of the cloud-based VPN headend service.

13. The method of claim 8 , wherein the first intermediate node is associated with a first datacenter and the second intermediate node is associated with a second datacenter, the second datacenter located in a different geographical location than the first datacenter.

14. The method of claim 8 , further comprising:

receiving, at a proxy node of the cloud-based VPN headend service, a connection request from the client device, the connection request indicating a request for the new VPN connection; and

based at least in part on the first intermediate node being removed from service, sending, from the proxy node, the connection request to the second intermediate node.

15. One or more non-transitory computer-readable media storing computer executable instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

determining to refrain from servicing virtual private network (VPN) connection requests through a first intermediate node to reach termination nodes of a cloud-based VPN headend service;

sending, to a client device that has an existing VPN connection with a first termination node that passes through the first intermediate node, an indication to cause the client device to establish a new VPN connection without terminating the existing VPN connection;

causing the new VPN connection to be established between the client device and the first termination node or a second termination node through a second intermediate node; and

subsequent to the client device establishing the new VPN connection through the second intermediate node, removing the first intermediate node from service.

16. The one or more non-transitory computer-readable media of claim 15 , wherein the indication to cause the client device to establish the new VPN connection includes at least one of a hostname or an internet protocol (IP) address that is associated with the second intermediate node.

17. The one or more non-transitory computer-readable media of claim 15 , wherein:

the indication to establish the new VPN connection is sent to each client device of multiple client devices that have existing connections passing through the first intermediate node, and

removing the first intermediate node from service is based at least in part on determining that each one of the multiple client devices have established new connections through other intermediate nodes that are different from the first intermediate node.

18. The one or more non-transitory computer-readable media of claim 15 , the operations further comprising at least one of:

updating the first intermediate node with a new version of software while the first intermediate node is removed from service; or

deploying the second intermediate node to replace the first intermediate node based at least in part on the first intermediate node being removed from service.

19. The one or more non-transitory computer-readable media of claim 18 , wherein the first intermediate node is at least one of a load balancer node, a proxy node, or a headend node of the cloud-based VPN headend service.

20. The one or more non-transitory computer-readable media of claim 15 , wherein the first intermediate node is associated with a first datacenter and the second intermediate node is associated with a second datacenter, the second datacenter located in a different geographical location than the first datacenter.

21. The system of claim 1 , the operations further comprising:

modifying a configuration of a load balancer disposed between client devices and termination nodes to cause the load balancer to refrain from sending new VPN connections to the first intermediate node; and

routing, by the load balancer, the new VPN connection to the second intermediate node based at least in part on configuration being modified.

22. The system of claim 1 , wherein:

sending the indication to cause the client device to establish the new VPN connection comprises sending, by the first termination node, a reconnect request to the client device, wherein the reconnect request causing the client device to establish the new VPN connection.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2024
From: CHITRIGI GANESH, PANKAJ; MESTERY, KYLE ANDREW DONALD; LI, DANXIANG; LALANI, RAHIM; KIELBASINSKI, ANDRZEJ KONRAD
To: CISCO TECHNOLOGY, INC.
Reel/Frame 066939/0232 →
Continuity (2)
Continuation 17462781 · Aug 31, 2021
Related Publication 20240243971A1 · Jul 18, 2024
References Cited (24)
US 7673048B1 · O'Toole, Jr. · 2010 [cited by examiner]
US 7885184B2 · George et al. · 2011 [cited by applicant]
US 9253123B1 · Podge · 2016 [cited by applicant]
US 10257167B1 · Matthews et al. · 2019 [cited by applicant]
US 20040049573A1 · Olmstead · 2004 [cited by applicant]
US 20060235972A1 · Asnis · 2006 [cited by applicant]
US 20080046995A1 · Satterlee et al. · 2008 [cited by applicant]
US 20080056272A1 · Batta · 2008 [cited by applicant]
US 20090037367A1 · Wein · 2009 [cited by applicant]
US 20140189132A1 · Suganthi et al. · 2014 [cited by applicant]
US 20140372504A1 · Ben Dror et al. · 2014 [cited by applicant]
US 20150372982A1 · Herle et al. · 2015 [cited by applicant]
US 20160212098A1 · Roch · 2016 [cited by examiner]
US 20170171156A1 · Schultz · 2017 [cited by applicant]
US 20190034210A1 · Palladino · 2019 [cited by applicant]
US 20190075083A1 · Mayya et al. · 2019 [cited by applicant]
US 20210136040A1 · Mestery et al. · 2021 [cited by applicant]
US 20210194986A1 · Shribman et al. · 2021 [cited by applicant]
US 20220094751A1 · Szczesniak et al. · 2022 [cited by applicant]
WO WO2006004461A1 · 2006 [cited by applicant]
PCT Search Report and Written Opinion mailed Nov. 16, 2022 for PCT Application No. PCT/US22/41054, 28 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/462,781, mailed on Sep. 29, 2023, Ganesh, “Orchestrated Reconnect for Client-Unaware Rolling of Network Nodes”, 11 Pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/462,781, mailed on Nov. 28, 2022, Ganesh, “Orchestrated Reconnect for Client-Unaware Rolling of Network Nodes”, 6 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/462,781, mailed on Jun. 14, 2023, Inventor #1 Pankaj Chitrigi Ganesh, “Orchestrated Reconnect for Client-Unaware Rolling of Network Nodes,” 6 pages. [cited by applicant]