IP Library › Granted Patent US 12,647,399
Granted Patent B2
US 12,647,399 · App. 18/612,642 · Granted Jun 2, 2026

Bypassing IKE firewall for cloud-managed IPSec keys in SDWAN fabric

Inventors: Shreekanth Chandranna (Santa Clara, CA); Bhagvan Cheeyandira (Santa Clara, CA); Gopalakrishnan Gunasekaran (Santa Clara, CA)
Assignee: Hewlett Packard Enterprise Development LP
H04L63/029H04L63/0236H04L63/0272H04L63/0435H04L63/061
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,647,399
App. No.
18/612,642
Granted
Jun 2, 2026
Kind
B2
Abstract

Systems and methods are provided for effectuating overlay tunnels between software-defined wide area network (SD-WAN) end-point devices despite the use of IPSec passthrough in one or more network devices, such as modems or routers that exist between the end-point devices. In particular, the Internet Key Exchange (IKE) protocol can be allowed to progress until a modem/router is able to establish an IKE tunnel, after which overlay packets using cloud-managed keys can be allowed to pass through the modem/router. An overlay tunnel may then be established between the end-point devices, and the IKE tunnel can be taken down.

Claims (38)

1 . A method comprising:

detecting, at a first network device between a second network device and a third network device, a key negotiation between the second network device and the third network device;

based on detecting the key negotiation between the second network device and the third network device, creating a firewall session in the first network device between the second and third network devices, wherein a first tunnel is established through the first network device between the second and third network devices using keys from the key negotiation, the first tunnel being compliant with the firewall session;

determining, by the first network device, to allow passage of Internet Protocol Security (IPSec) data packets in the firewall session through the first network device between the second and third network devices;

passing, through the first network device based on the establishment of the first tunnel, the IPSec data packets exchanged between the second and third network devices as part of a hand-shake operation using cloud-managed keys from a cloud-based orchestrator;

passing, through the first network device, a second tunnel established based on the hand-shake operation between the second and third network devices; and

after the establishment of the second tunnel and the cloud-managed keys become active, discarding the keys obtained from the key negotiation and taking down the first tunnel without disrupting encrypted communications between the second and third network devices.

2 . The method of claim 1 , comprising enabling an IPSec passthrough feature at the first network device.

3 . The method of claim 1 , wherein the key negotiation comprises an IPSec key negotiation.

4 . The method of claim 3 , wherein the keys from the key negotiation include IPSec keys, and wherein the first tunnel is established in accordance with the IPSec keys.

5 . The method of claim 4 , wherein the cloud-managed keys from the cloud-based orchestrator are cloud-managed IPSec keys, and wherein the second tunnel is established in accordance with the cloud-managed IPSec keys.

6 . The method of claim 1 , wherein the second tunnel is an overlay tunnel on an underlay network.

7 . The method of claim 1 , wherein the first network device comprises a router, the second network device comprises one of a branch gateway or a virtual private network concentrator operative in a software-defined wide area network (SD-WAN), and the cloud-based orchestrator is a SD-WAN orchestrator.

8 . A first network device comprising:

a hardware processor; and

a non-transitory storage medium storing instructions executable on the hardware processor to:

perform, with a second network device, a key negotiation comprising an exchange of messages that pass through a third network device between the first network device and the second network device;

establish, between the first network device and the second network device, a first tunnel using keys from the key negotiation, the first tunnel passing through the third network device;

receive, at the first network device, cloud-managed keys from a cloud-based orchestrator;

perform a hand-shake operation using the cloud-managed keys between the first network device and the second network device in which Internet Protocol Security (IPSec) data packets are passed in the first tunnel through the third network device, the IPSec data packets for establishing a second tunnel;

establish, between the first network device and the second network device, the second tunnel based on the hand-shake operation; and

after the establishment of the second tunnel and the cloud-managed keys become active, discard the keys obtained from the key negotiation and take down the first tunnel without disrupting encrypted communications between the first and second network devices.

9 . The first network device of claim 8 , wherein the key negotiation comprises an IPSec key negotiation.

10 . The first network device of claim 8 , wherein the first network device comprises a branch gateway or a virtual private network concentrator, and the third network device comprises a router.

11 . The first network device of claim 8 , wherein the IPSec data packets are allowed to pass through the third network device pursuant to an IPSec passthrough feature enabled on the third network device.

12 . The first network device of claim 8 , wherein the keys from the key negotiation are IPSec keys, and wherein the first tunnel is established using the IPSec keys.

13 . The first network device of claim 8 , wherein the second tunnel is an overlay tunnel on an underlay network.

14 . The first network device of claim 8 , wherein the first tunnel established through the third network device between the first and second network devices using keys from the key negotiation is compliant with a firewall session created in the third network device between the first and second network devices.

15 . A non-transitory machine-readable storage medium comprising instructions that upon execution cause a first network device to:

detect, at the first network device between a second network device and a third network device, a key negotiation between the second network device and the third network device;

based on detecting the key negotiation between the second network device and the third network device, create a firewall session in the first network device between the second and third network devices, wherein a first tunnel is established through the first network device between the second and third network devices using keys from the key negotiation, the first tunnel being compliant with the firewall session;

determine to allow passage of Internet Protocol Security (IPSec) data packets in the firewall session through the first network device between the second and third network devices;

pass, through the first network device based on the establishment of the first tunnel, the IPSec data packets exchanged between the second and third network devices as part of a hand-shake operation using cloud-managed keys from a cloud-based orchestrator;

pass, through the first network device, a second tunnel established based on the hand-shake operation between the second and third network devices; and

after the establishment of the second tunnel and the cloud-managed keys become active, discard the keys obtained from the key negotiation and take down the first tunnel without disrupting encrypted communications between the second and third network devices.

16 . The non-transitory machine-readable storage medium of claim 15 , wherein the keys from the key negotiation include IPSec keys, and wherein the first tunnel is established in accordance with the IPSec keys.

17 . The non-transitory machine-readable storage medium of claim 15 , wherein the cloud-managed keys from the cloud-based orchestrator are cloud-managed IPSec keys, and wherein the second tunnel is established in accordance with the cloud-managed IPSec keys.

18 . The non-transitory machine-readable storage medium of claim 15 , wherein the instructions upon execution cause the first network device to make a determination to allow the passage of the IPSec data packets through the first network device in response to the firewall session being created.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2024
From: CHANDRANNA, SHREEKANTH; GUNASEKARAN, GOPALAKRISHNAN; CHEEYANDIRA, BHAGVAN
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 067077/0938 →
Continuity (2)
Continuation 17667987 · Feb 9, 2022
Related Publication 20240236048A1 · Jul 11, 2024
References Cited (29)
US 8639936B2 · Hu et al. · 2014 [cited by applicant]
US 10938717B1 · Sundararajan et al. · 2021 [cited by applicant]
US 11563601B1 · K S · 2023 [cited by examiner]
US 20150188949A1 · Mahaffey et al. · 2015 [cited by applicant]
US 20160080211A1 · Anand et al. · 2016 [cited by applicant]
US 20160080502A1 · Yadav · 2016 [cited by examiner]
US 20190207844A1 · Kodavanty · 2019 [cited by examiner]
US 20200059370A1 · Abraham · 2020 [cited by examiner]
US 20200104161A1 · Kapur et al. · 2020 [cited by applicant]
US 20200177503A1 · Hooda et al. · 2020 [cited by applicant]
US 20200252234A1 · Ramamoorthi · 2020 [cited by examiner]
US 20210011825A1 · Aggarwal · 2021 [cited by examiner]
US 20210185013A1 · Zhang · 2021 [cited by examiner]
US 20210288881A1 · Zhang · 2021 [cited by applicant]
US 20210314385A1 · Pande et al. · 2021 [cited by applicant]
US 20210399920A1 · Sundararajan · 2021 [cited by examiner]
US 20220210005A1 · Keane · 2022 [cited by examiner]
US 20220329459A1 · Sundararajan · 2022 [cited by examiner]
US 20220329477A1 · Chiganmi · 2022 [cited by examiner]
US 20220385498A1 · Janakiraman et al. · 2022 [cited by applicant]
US 20220393981A1 · Solanki · 2022 [cited by examiner]
US 20220394016A1 · Solanki · 2022 [cited by examiner]
US 20230143157A1 · Solanki et al. · 2023 [cited by applicant]
CN 111510316A · 2020 [cited by applicant]
CN 111614796A · 2020 [cited by applicant]
CN 111740893A · 2020 [cited by applicant]
Carrel, D., et al., “IPsec Key Exchange Using A Controller Draft-Carrel-Ipsecme-Controller-Ike,” Network Working Group, vol. 1 Mar. 11, 2019, pp. 21. [cited by applicant]
Marin-Lopez, R., et al., “Software-Defined Networking (SDN)—based IPsec Flow Protection draft-ietf-i2nsf-sdn-ipsec-flow-protection-14,” Internet Draft, Mar. 25, 2021, pp. 80. [cited by applicant]
Qa Cafe, “IPSEC pass through testing,” Jan. 29, 2022, <https://web.archive.Org/web/20220129095539/https://www.qacafe.com/resources/2013-08-28-ipsec-pass-through-testing/>, 2 pages. [cited by applicant]