IP Library › Granted Patent US 12,355,659
Granted Patent B2
US 12,355,659 · App. 17/687,821 · Granted Jul 8, 2025

Ultimate regional fallback path for hierarchical SD-WAN

Inventors: Jigar Parekh (Fremont, CA); Satyajit Das (Livermore, CA); Prithvi Sharan (Germantown, MD); Laxmikantha Reddy Ponnuru (San Ramon, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L45/28H04L41/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,355,659
App. No.
17/687,821
Granted
Jul 8, 2025
Kind
B2
Abstract

In one embodiment, a method includes determining, by a network node, that a first plurality of tunnel interfaces resides in a core region of a network and determining, by the network node, that a second plurality of tunnel interfaces resides in an access region of the network. The method also includes configuring, by the network node, a first tunnel interface as a core regional fallback path for the core region of the network and configuring, by the network node, a second tunnel interface as an access regional fallback path for the access region of the network.

Claims (49)

1. A network node comprising one or more processors and one or more computer-readable non-transitory storage media coupled to the one or more processors and including instructions that, when executed by the one or more processors, cause the network node to perform operations comprising:

determining that a first plurality of tunnel interfaces resides in a core region of a network;

determining that a second plurality of tunnel interfaces resides in an access region of the network;

configuring a first tunnel interface as a core regional fallback path for the core region of the network;

configuring a second tunnel interface as an access regional fallback path for the access region of the network;

determining whether to activate the first tunnel interface or the second tunnel interface in response to one or more connectivity losses within the network;

in response to determining that the first plurality of tunnel interfaces loses connectivity to a data plane of the core region of the network, activating, by the network node, the first tunnel interface; and

in response to determining that the second plurality of tunnel interfaces loses connectivity to a data plane of the access region of the network, activating, by the network node, the second tunnel interface, wherein:

the network node is a border router, the border router comprising the first plurality of tunnel interfaces and the second plurality of tunnel interfaces; and

the border router is located at a boundary of the core region and the access region.

2. The network node of claim 1 , wherein a determination to activate the first tunnel interface is independent of a determination to activate the second tunnel interface.

3. The network node of claim 1 , wherein:

the first tunnel interface is connected to a first Internet Protocol Security (IPSec) data plane tunnel that resides in the core region; and

the second tunnel interface is connected to a second IPSec data plane tunnel that resides in the access region.

4. The network node of claim 1 , further comprising using Bidirectional Forwarding Detection (BFD) to determine data plane connectivity within the network.

5. The network node of claim 1 , wherein:

the network is a hierarchical software-defined wide area network (SD-WAN).

6. A method, comprising:

determining, by a network node, that a first plurality of tunnel interfaces resides in a core region of a network;

determining, by the network node, that a second plurality of tunnel interfaces resides in an access region of the network;

configuring, by the network node, a first tunnel interface as a core regional fallback path for the core region of the network;

configuring, by the network node, a second tunnel interface as an access regional fallback path for the access region of the network;

determining whether to activate the first tunnel interface or the second tunnel interface in response to one or more connectivity losses within the network;

in response to determining that the first plurality of tunnel interfaces loses connectivity to a data plane of the core region of the network, activating, by the network node, the first tunnel interface; and

in response to determining that the second plurality of tunnel interfaces loses connectivity to a data plane of the access region of the network, activating, by the network node, the second tunnel interface, wherein:

the network node is a border router, the border router comprising the first plurality of tunnel interfaces and the second plurality of tunnel interfaces; and

the border router is located at a boundary of the core region and the access region.

7. The method of claim 6 , wherein a determination to activate the first tunnel interface is independent of a determination to activate the second tunnel interface.

8. The method of claim 6 , wherein:

the first tunnel interface is connected to a first Internet Protocol Security (IPSec) data plane tunnel that resides in the core region; and

the second tunnel interface is connected to a second IPSec data plane tunnel that resides in the access region.

9. The method of claim 6 , further comprising using, by the network node, Bidirectional Forwarding Detection (BFD) to determine data plane connectivity within the network.

10. The method of claim 6 , wherein:

the network is a hierarchical software-defined wide area network (SD-WAN).

11. One or more computer-readable non-transitory storage media embodying instructions that, when executed by a processor, cause the processor to perform operations comprising:

determining that a first plurality of tunnel interfaces of a border router resides in a core region of a network;

determining that a second plurality of tunnel interfaces of the border router resides in an access region of the network;

configuring a first tunnel interface as a core regional fallback path for the core region of the network;

configuring a second tunnel interface as an access regional fallback path for the access region of the network;

determining whether to activate the first tunnel interface or the second tunnel interface in response to one or more connectivity losses within the network;

in response to determining that the first plurality of tunnel interfaces loses connectivity to a data plane of the core region of the network, activating, by a network node, the first tunnel interface; and

in response to determining that the second plurality of tunnel interfaces loses connectivity to a data plane of the access region of the network, activating, by the network node, the second tunnel interface, wherein:

the network node is a border router, the border router comprising the first plurality of tunnel interfaces and the second plurality of tunnel interfaces; and

the border router is located at a boundary of the core region and the access region.

12. The one or more computer-readable non-transitory storage media of claim 11 , wherein a determination to activate the first tunnel interface is independent of a determination to activate the second tunnel interface.

13. The one or more computer-readable non-transitory storage media of claim 11 , wherein:

the first tunnel interface is connected to a first Internet Protocol Security (IPSec) data plane tunnel that resides in the core region; and

the second tunnel interface is connected to a second IPSec data plane tunnel that resides in the access region.

14. The one or more computer-readable non-transitory storage media of claim 11 , further comprising using Bidirectional Forwarding Detection (BFD) to determine data plane connectivity within the network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2022
From: PAREKH, JIGAR; DAS, SATYAJIT; SHARAN, PRITHVI; PONNURU, LAXMIKANTHA REDDY
To: CISCO TECHNOLOGY, INC.
Reel/Frame 059181/0899 →
Continuity (2)
Provisional Application 63288080 · Dec 10, 2021
Related Publication 20230188460A1 · Jun 15, 2023
References Cited (20)
US 8942085B1 · Pani et al. · 2015 [cited by applicant]
US 20060209682A1 · Filsfils · 2006 [cited by applicant]
US 20160218917A1 · Zhang · 2016 [cited by examiner]
US 20170207996A1 · Lui et al. · 2017 [cited by applicant]
US 20190158605A1 · Markuze · 2019 [cited by examiner]
US 20200076730A1 · Comeras et al. · 2020 [cited by applicant]
US 20200287819A1 · Theogaraj · 2020 [cited by examiner]
US 20200382341A1 · Ore et al. · 2020 [cited by examiner]
US 20200413283A1 · Shen et al. · 2020 [cited by applicant]
US 20210067427A1 · Cidon et al. · 2021 [cited by applicant]
US 20210111991A1 · Vadera · 2021 [cited by examiner]
US 20210152450A1 · Iyer et al. · 2021 [cited by applicant]
US 20220038554A1 · Merwaday · 2022 [cited by examiner]
US 20220103470A1 · Kulkarni · 2022 [cited by examiner]
US 20230059537A1 · Gavand · 2023 [cited by examiner]
US 20230116163A1 · Scholz · 2023 [cited by examiner]
US 20230283661A1 · Hood · 2023 [cited by examiner]
EP 3748923A1 · 2020 [cited by applicant]
FR 2906429A1 · 2008 [cited by applicant]
International Search Report corresponding to PCT/US2022/080472, dated Mar. 1, 2023, 11 pages. [cited by applicant]