US2005138204A1PendingUtilityA1

Virtual private network having automatic reachability updating

Priority: Jun 10, 1999Filed: Nov 8, 2004Published: Jun 23, 2005
Est. expiryJun 10, 2019(expired)· nominal 20-yr term from priority
H04L 45/00H04L 45/22H04L 41/0894H04L 41/40H04L 61/4523H04L 63/20H04L 63/0272H04L 63/164H04L 63/061H04L 47/20H04L 63/0442H04L 69/40H04L 41/0233H04L 69/329H04L 12/4641H04L 63/0227H04L 47/41H04L 63/1425H04L 67/1095H04L 41/22H04L 45/586H04L 47/2441H04L 63/08H04L 63/0263Y02D30/50
43
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A unified policy management system for an organization including a central policy server and remotely situated policy enforcers. A central database and policy enforcer databases storing policy settings are configured as LDAP databases adhering to a hierarchical object oriented structure. Such structure allows the policy settings to be defined in an intuitive and extensible fashion. Changes in the policy settings made at the central policy server are automatically transferred to the policy enforcers for updating their respective databases. Each policy enforcer collects and transmits health and status information in a predefined log format and transmits it to the policy server for efficient monitoring by the policy server. For further efficiencies, the policy enforcement functionalities of the policy enforcers are effectively partitioned so as to be readily implemented in hardware. The system also provides for dynamically routed VPNs where VPN membership lists are automatically created and shared with the member policy enforcers. Updates to such membership lists are also automatically transferred to remote VPN clients. The system further provides for fine grain access control of the traffic in the VPN by allowing definition of firewall rules within the VPN. In addition, policy server and policy enforcers may be configured for high availability by maintaining a backup unit in addition to a primary unit. The backup unit become active upon failure of the primary unit.

Claims

exact text as granted — not AI-modified
1 . A computer network comprising: 
 a first edge device coupled to a first private network, the first edge device configured to create a first table with information of member networks reachable through the first edge device, the first table being stored in a first database;    a second edge device coupled to a second private network, the second edge device configured to create a second table with information of member networks reachable through the second edge device, the second table being stored in a second database;    wherein, the first and second edge devices enable secure communication between the first and second private networks, and the first edge device shares the first table with the second edge device and the second edge device shares the second table with the first edge device.    
   
   
       2 . The computer network of  claim 1 , wherein the first edge device includes logic for: 
 receiving a new route information;    storing the new route information in the first database; and    transmitting a portion of the new route information to the second edge device.    
   
   
       3 . The computer network of  claim 2 , wherein the portion of the new route information is a route name.  
   
   
       4 . The computer network of  claim 2 , wherein the second edge device includes logic for: 
 receiving the portion of the new route information;    accessing the first database based on the portion of the new route information;    retrieving the new route information from the first database; and    storing the retrieved route information in the second database.    
   
   
       5 . The computer network of  claim 1 , wherein communication between the first and second networks is managed according to a security policy associated with the networks.  
   
   
       6 . The computer network of  claim 5 , wherein the security policy is defined for a security group providing a hierarchical organization of the group, the group including member networks, users allowed to access the member networks, and a rule controlling access to the member networks.  
   
   
       7 . The computer network of  claim 6 , wherein each member network has full connectivity with all other member networks and the security policy defined for the security policy group is automatically configured for each connection.  
   
   
       8 . The computer network of  claim 6 , wherein the security policy provides encryption of traffic among the member networks and the rule is a firewall rule providing access control of the encrypted traffic among the member networks.  
   
   
       9 . In a computer network including a first edge device coupled to a first private network and a second edge device coupled to a second private network, the first and second edge devices enabling secure communication between the first and second private networks, a method for gathering membership information comprising: 
 creating a first table with information of member networks reachable through the first edge device,    storing the first table in a first database;    creating a second table with information of member networks reachable through the second edge device;    storing the second table in a second database;    sharing the first table with the second edge device; and    sharing the second table with the first edge device.    
   
   
       10 . The method of  claim 9  further comprising: 
 receiving a new route information;    storing the new route information in the first database; and    transmitting a portion of the new route information to the second edge device.    
   
   
       11 . The method of  claim 10 , wherein the portion of the new route information is a route name.  
   
   
       12 . The method of  claim 10  further comprising: 
 receiving the portion of the new route information;    accessing the first database based on the portion of the new route information;    retrieving the new route information from the first database; and    storing the retrieved route information in the second database.    
   
   
       13 . The method of  claim 9 , wherein communication between the first and second networks is managed according to a security policy associated with the networks.  
   
   
       14 . The method of  claim 13  further comprising defining the security policy for a security policy group, the group providing a hierarchical organization of the group including member networks, users allowed to access the member networks, and a rule controlling access to the member networks.  
   
   
       15 . The method of  claim 14 , wherein each member network has full connectivity with all other member networks and the security policy defined for the security policy group is automatically configured for each connection.  
   
   
       16 . The method of  claim 14 , wherein the security policy provides encryption of traffic among the member networks and the rule is a firewall rule providing access control of the encrypted traffic among the member networks.

Join the waitlist — get patent alerts

Track US2005138204A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.