US2019268263A1PendingUtilityA1

Flow cache based mechanism of packet redirection in multiple border routers for application awareness

Assignee: CISCO TECH INCPriority: Aug 29, 2014Filed: Mar 4, 2019Published: Aug 29, 2019
Est. expiryAug 29, 2034(~8.1 yrs left)· nominal 20-yr term from priority
H04L 45/04H04L 47/2441H04L 47/2475H04L 45/38H04L 45/20
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Techniques whereby a LAN-side border router observes all packets of an application flow from both directions so that the application recognition performed on the LAN-side border router functions properly. A border router may implement flags in a flow cache to indicate whether the border router is the LAN-side border router and/or a WAN-side border router for an application flow. As packets are received at a border router at either the LAN interface or WAN interface, the flags associated with packet's application flows are examined to determine if the border router is the LAN-side border router for the application flow. If so, then application recognition and routing control may be performed. If not, the packet may be redirected to another border router that may be the LAN-side border router or the WAN-side border router for the application flow to insure that border router observes the packet.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 classifying a packet received at a first border router as corresponding to a first application flow of a plurality of application flows;   determining whether the packet of the first application flow is to be forwarded to a second border router based on an attribute of the first application flow maintained in a flow cache; and   in response to determining that the packet of the first application flow is to be forwarded to the second border router:   redirecting the packet to the second border router over a first tunnel interface; and   sending the packet out of the second border router to a destination.   
     
     
         2 . The method of  claim 1 , wherein the packet is received at a Local Area Network (LAN) interface, the method further comprising setting the attribute to indicate that the first border router is a border router associated with the LAN interface for the application flow. 
     
     
         3 . The method of  claim 1 , wherein the packet is received at a Wide Area Interface (WAN) of the first border router, the method further comprising:
 setting a second attribute to indicate that the first border router is a border router associated with the WAN interface for the application flow;   determining if the attribute indicates that the first border router is the border router associated with a LAN interface for the application flow; and   forwarding the packet to a LAN if the first border router is determined to be the border router associated with the LAN interface.   
     
     
         4 . The method of  claim 3 , further comprising redirecting the packet to a second border router that is associated with the LAN interface if the first border router is not to be the border router associated with the LAN interface. 
     
     
         5 . The method of  claim 1 , wherein if the packet is received at the first tunnel interface of the first border router, the method further comprising:
 setting the attribute to indicate that the first border router is not the border router associated with a LAN interface for the application flow; and   forwarding the packet to a WAN interface of the first border router.   
     
     
         6 . The method of  claim 1 , wherein if the packet is received at a second tunnel interface of the first border router, the method further comprising:
 setting a second attribute to indicate that the first border router is not a border router associated with a WAN interface for the application flow;   determining if the attribute indicates that the first border router is the border router associated with a LAN interface for the application flow; and   forwarding the packet to a LAN.   
     
     
         7 . The method of  claim 1 , further comprising:
 receiving a subsequent packet associated with the packet at the first border router;   determining that the subsequent packet is associated with an application flow in the flow cache of the first border router;   determining that the first border router is the border router associated with a LAN interface; and   forwarding the subsequent packet to the LAN.   
     
     
         8 . The method of  claim 7 , further comprising:
 receiving the subsequent packet associated with the packet at the second border router;   determining that the subsequent packet is not associated with an application flow in a flow cache of the second border router; and   forwarding the subsequent packet to the first border router.   
     
     
         9 . The method of  claim 1 , further comprising establishing a shortcut tunnel for the application flow between the first border router and a downstream border router, the shortcut tunnel bypassing a circular ordered list of tunnels between plural border routers. 
     
     
         10 . The method of  claim 9 , further comprising examining a Time to Live (TTL) field in a packet header field associated with the circular ordered list of tunnels to determine packet redirection. 
     
     
         11 . The method of  claim 10 , further comprising decrementing the TTL field each time the packet passes through border routers associated with the circular ordered list of tunnels. 
     
     
         12 . The method of  claim 11 , further comprising determining if the TTL field is a predetermined value, and if so, forwarding the packet to a LAN. 
     
     
         13 . An apparatus, comprising:
 a network interface unit configured to enable communications over a LAN interface, a WAN interface, a first tunnel interface and a second tunnel interface; and   a processor coupled to the network interface unit, and configured to:
 classify a packet received at a first border router as corresponding to a first application flow of a plurality of application flows; 
 determine whether the packet of the first application flow is to be forwarded to a second border router based on an attribute of the first application flow maintained in a flow cache; and 
 in response to determining that the packet of the first application flow is to be forwarded to the second border router: 
 redirect the packet to the second border router over a first tunnel interface; and 
 send the packet out of the second border router to a destination. 
   
     
     
         14 . The apparatus of  claim 13 , wherein when a packet is received at the LAN interface of the apparatus, the processor is further configure to set the attribute to indicate that the apparatus is a border router associated with the LAN interface for the application flow. 
     
     
         15 . The apparatus of  claim 13 , wherein when a packet is received at the WAN interface of the apparatus, the processor is further configured to:
 set a second attribute to indicate that the apparatus is a border router associated with the WAN interface for the application flow;   determine if the attribute indicates that apparatus is the border router associated with the LAN interface for the application flow; and   forward the packet to a LAN over the network interface unit if the apparatus is determined to be the border router associated with a LAN interface.   
     
     
         16 . The apparatus of  claim 15 , the processor is further configured to redirect the packet to a second apparatus that is associated with the LAN interface over the network interface unit if the apparatus is not to be the border router associated with the LAN interface. 
     
     
         17 . The apparatus of  claim 13 , wherein if the packet is received at the first tunnel interface of the apparatus, the processor is further configured to:
 set the attribute to indicate that the apparatus is not the border router associated with the LAN interface for the application flow; and   forward the packet to a WAN interface.   
     
     
         18 . The apparatus of  claim 13 , wherein if the packet is received at the second tunnel interface of the apparatus, the processor is further configured to:
 set the second attribute to indicate that the apparatus is not a border router associated with a WAN interface for the application flow;   determine if the attribute indicates that the apparatus is the border router associated with a LAN interface for the application flow; and   forward the packet to a LAN over the LAN interface.   
     
     
         19 . The apparatus of  claim 13 , the processor further configure to:
 receive a subsequent packet associated with the packet at the apparatus;   determine that the subsequent packet is associated with an application flow in the flow cache of the apparatus;   determine that the apparatus is the border router associated with a LAN interface; and   forward the subsequent packet to the LAN over the LAN interface.   
     
     
         20 . One or more computer readable storage media encoded with software comprising computer executable instructions and when the software is executed operable to:
 classify a packet received at a first interface of a first border router as corresponding to a first application flow of a plurality of application flows;   determine whether the packet of the first application flow is to be forwarded to a second border router based on an attribute of the first application flow maintained in a routing control table; and   in response to determining that the packet of the first application flow is to be forwarded to the second border router:   redirect the packet to the second border router over a first tunnel interface; and   send the packet out of a second interface of the second border router.

Join the waitlist — get patent alerts

Track US2019268263A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.