Systems and methods for secured network information transmission
The present application describes systems and methods for secured network information transmission. A network tunnel may be established from a customer premises equipment (CPE) to a routing device at a provider site. The network tunnel may traverse over one or more networks while maintaining a secure path for data. A customer may indicate a chosen configuration for a CPE, and a device at a provider site, a customer device, and/or the CPE itself may automatically, or manually, configure the CPE based on the chosen configuration to allow and/or disallow certain customer network information from being received and/or transmitted through the network tunnel.
1 . A method, comprising:
establishing a network tunnel from a customer premises equipment (CPE) to a virtual router located at a provider site;
providing a configuration interface accessible by a customer device;
providing a key for the network tunnel to the customer device;
receiving, via the configuration interface, one or more selections of customer network information to be communicated over the network tunnel made using the configuration interface on the customer device;
automatically configuring the CPE based at least in part on the one or more selections; and
receiving customer network information from the CPE through the network tunnel at the virtual router based at least in part on the configured CPE and further based at least in part on providing the key.
2 . The method of claim 1 , further comprising:
receiving, at a computing device of the provider site, the one or more selections, wherein the automatically configuring of the CPE is performed by the computing device at the provider site.
3 . The method of claim 1 , wherein the automatically configuring of the CPE is performed by the customer device.
4 . The method of claim 1 , further comprising:
transmitting a query from the virtual router through the network tunnel to the CPE based at least in part on the configured CPE, wherein the receiving customer network information comprises receiving the customer network information from the CPE through the network tunnel at the virtual router based at least in part on the query.
5 . The method of claim 1 , wherein receiving customer network information from the CPE comprises receiving customer network information over a plurality of networks, and wherein the receiving comprises a one-hop communication over the plurality of networks.
6 . The method of claim 1 , wherein receiving customer network information from the CPE comprises receiving customer network information comprising at least one of network packet header information, simple network management protocol (SNMP) information, or interface statistics.
7 . The method of claim 1 , wherein the establishing the network tunnel network further comprises configuring the network tunnel with an internet protocol security (IPSec) framework.
8 . The method of claim 1 , further comprising:
providing the received customer network information from the virtual router to one or more security systems, wherein the one or more security systems comprise at least one of management systems, network packet header information collection systems, or analytics systems.
9 . The method of claim 1 , wherein establishing the network tunnel further comprises determining a first internet protocol (IP) address corresponding to the virtual router, determining a second IP address corresponding to the CPE, and determining a third IP address corresponding to the network tunnel.
10 . The method of claim 1 , further comprising:
configuring a first port of the virtual router to receive a first type of information;
configuring a second port of the virtual router to receive a second type of information; and
dropping received customer network information that is not the first type of information or the second type of information.
11 . A method, comprising:
establishing a network tunnel between a customer premises equipment (CPE) and a virtual router, wherein the virtual router is located at a provider site;
providing a key for the network tunnel to a customer device;
receiving a configuration indication indicating allowed customer network information, disallowed customer network information, or a combination thereof, for communication through the network tunnel; and
receiving at least a portion customer network information from the CPE through the network tunnel based at least in part on the configuration indication and further based at least in part on providing the key.
12 . The method of claim 11 , further comprising:
providing a configuration interface to a customer device;
receiving, at the configuration interface, one or more selections of customer network information to be communicated over the network tunnel made using the configuration interface on the customer device; and
automatically configuring the CPE based at least in part on the one or more selections, wherein receiving the configuration indication is based at least in part on the automatically configuring.
13 . The method of claim 12 , wherein the automatically configuring of the CPE is performed by a computing device at the provider site.
14 . The method of claim 12 , wherein the automatically configuring of the CPE is performed by the customer device.
15 . The method of claim 11 , further comprising:
transmitting a query through the network tunnel to the CPE based at least in part on the configuration indication, wherein receiving the allowed customer network information is based at least in part on the query.
16 . The method of claim 15 , wherein the query comprises a simple network management protocol (SNMP) poll, wherein the allowed customer network information comprises SNMP information, and wherein receiving the allowed customer network information is based at least in part on the SNMP poll.
17 . The method of claim 11 , wherein the configuration indication indicates disallowing simple network management protocol (SNMP) queries to be provided from the provider site, and disallowing SNMP information to be provided from the CPE.
18 . A system, comprising:
a processor; and
a memory operatively connected to the processor and storing instructions that, when executed by the processor, cause the system to perform a method, the method comprising:
establishing a network tunnel from a customer premises equipment (CPE) to a virtual router at a provider site;
providing a configuration interface accessible to a customer device;
providing a key for the network tunnel to the customer device;
receiving, at the configuration interface, one or more selections of customer network information to be communicated over the network tunnel made using the configuration interface on the customer device;
automatically configuring the CPE based at least in part on the one or more selections; and
receiving customer network information from the CPE through the network tunnel at the virtual router based at least in part on the configured CPE and further based at least in part on providing the key.