US2019342346A1PendingUtilityA1

Creating and using remote device management attribute rule data store

Assignee: NICIRA INCPriority: Aug 28, 2015Filed: Jul 20, 2019Published: Nov 7, 2019
Est. expiryAug 28, 2035(~9.1 yrs left)· nominal 20-yr term from priority
H04W 12/08H04L 12/4641H04L 63/105H04L 61/256H04L 63/029H04L 63/0272H04L 63/08H04L 63/0263H04W 76/12H04L 61/2585H04L 67/1097H04L 69/22H04L 63/0236H04L 67/1004G06F 16/9024H04L 63/20H04L 41/5045H04L 61/2571H04L 61/2591
66
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Some embodiments provide novel methods for processing remote-device data messages in a network based on data-message attributes from a remote device management (RDM) system. For instance, the method of some embodiments identifies a set of RDM attributes associated with a data message, and then performs one or more service operations based on identified RDM attribute set.

Claims

exact text as granted — not AI-modified
1 - 21 . (canceled) 
     
     
         22 . A method for processing remote-device data messages entering a network, the method comprising:
 receiving a data message sent by the remote device;   identifying a set of remote device management (RDM) attributes associated with the received data message; and   based on the RDM attribute set, forwarding the data message to a particular network element within the network via a tunnel and inserting the identified RDM attribute set in a header of the tunnel;   said inserted RDM attribute set in the tunnel header for identifying a service operation to perform on the data message at a set of one or more network elements within the network.   
     
     
         23 . The method of  claim 22 , wherein receiving the remote device data message comprises receiving the data message sent by the remote device through a tunnel that connects the remote device to the network. 
     
     
         24 . The method of  claim 22 , wherein the particular network element is a device that performs a middlebox service operation on the forwarded data message based on the identified RDM attribute set. 
     
     
         25 . The method of  claim 24 , wherein the device performs the middlebox service operation by using the inserted RDM attribute set to identify a service rule that specifies the service operation to perform on the forwarded data message. 
     
     
         26 . The method of  claim 22 , wherein the particular network element executes a middlebox service node that performs a middlebox service operation on the forwarded data message based on the identified RDM attribute set. 
     
     
         27 . The method of  claim 26 , wherein the middlebox service operation comprises one of a firewall operation, a load balancing operation, a logical network segmentation operation, and a destination network address translation operation on the data message based on the inserted RDM attribute set. 
     
     
         28 . The method of  claim 27  further comprising performing, at a VPN gateway, a load balancing operation to select the particular network element from a plurality of service network elements that perform the service operation,
 wherein the VPN gateway forwards data messages to at least two different service network elements along at least two different tunnels. 
 
     
     
         29 . The method of  claim 22 , wherein the tunnel is a first tunnel, the method further comprising:
 receiving, at a virtual private network (VPN) gateway, the data message sent by the remote device through a second tunnel that connects the remote device to the network;   intercepting the data message from an egress path of the VPN gateway as the VPN gateway forwards the data message to a destination within the network; and   encapsulating the data message with a tunnel header for the first tunnel to forward the intercepted data message along the first tunnel to the particular node.   
     
     
         30 . The method of  claim 22 , wherein
 the tunnel is a first tunnel,   the method further comprises receiving, at a virtual private network (VPN) gateway, the data message sent by the remote device through a second tunnel that connects the remote device to the network, and   the particular network element and the VPN gateway operate on two different physical devices.   
     
     
         31 . The method of  claim 22 , wherein the tunnel is a first tunnel, the method program further comprising:
 receiving, at a virtual private network (VPN) gateway, the data message sent by the remote device through a second tunnel that connects the remote device to the network; and   receiving at least a subset of the RDM attribute set in a header of the second tunnel.   
     
     
         32 . The method of  claim 22 , wherein the tunnel is a first tunnel, the program further comprising:
 at a virtual private network (VPN) gateway, receiving the data message sent by the remote device through a second tunnel that connects the remote device to the network;   receiving at least a subset of the RDM attribute set from an RDM server that the VPN gateway uses to authenticate a request from the remote device to establish a VPN session through the second tunnel.   
     
     
         33 . The method of  claim 32 , wherein receiving the RDM attribute subset comprises receiving the RDM attribute subset as part of an authentication approval from the RDM server. 
     
     
         34 . The method of  claim 32  further comprising receiving an authentication approval from the RDM server, wherein receiving the RDM attribute subset comprises receiving the RDM attribute subset in a communication from the RDM server that is separate from the authentication approval. 
     
     
         35 . The method of  claim 22 , wherein the set of network element comprises the particular network element. 
     
     
         36 . A non-transitory machine readable medium storing a program for processing remote-device data messages entering a network, the program comprising sets of instructions for:
 receiving a data message sent by the remote device;   identifying a set of remote device management (RDM) attributes associated with the received data message; and   based on the RDM attribute set, forwarding the data message to a particular network element within the network via a tunnel and inserting the identified RDM attribute set in a header of the tunnel;   said inserted RDM attribute set in the tunnel header for identifying a service operation to perform on the data message at a set of one or more network elements within the network.   
     
     
         37 . The non-transitory machine readable medium of  claim 36 , wherein the set of instructions for receiving the remote device data message comprises a set of instructions for receiving the data message sent by the remote device through a tunnel that connects the remote device to the network. 
     
     
         38 . The non-transitory machine readable medium of  claim 36 , wherein the particular network element is a device that performs a middlebox service operation on the forwarded data message based on the identified RDM attribute set. 
     
     
         39 . The non-transitory machine readable medium of  claim 38 , wherein the device performs the middlebox service operation by using the inserted RDM attribute set to identify a service rule that specifies the service operation to perform on the forwarded data message. 
     
     
         40 . The non-transitory machine readable medium of  claim 36 , wherein the particular network element executes a middlebox service node that performs a middlebox service operation on the forwarded data message based on the identified RDM attribute set. 
     
     
         41 . The non-transitory machine readable medium of  claim 40 , wherein the middlebox service operation comprises one of a firewall operation, a load balancing operation, a logical network segmentation operation, and a destination network address translation operation on the data message based on the inserted RDM attribute set.

Join the waitlist — get patent alerts

Track US2019342346A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.