WO2025019331A1 - Integrating sd-wan constructs with security policies - Google Patents
Integrating sd-wan constructs with security policies Download PDFInfo
- Publication number
- WO2025019331A1 WO2025019331A1 PCT/US2024/037828 US2024037828W WO2025019331A1 WO 2025019331 A1 WO2025019331 A1 WO 2025019331A1 US 2024037828 W US2024037828 W US 2024037828W WO 2025019331 A1 WO2025019331 A1 WO 2025019331A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- security
- security policy
- wan
- vpn
- wan controller
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/20—Network architectures or network communication protocols for network security for managing network security; network security policies in general
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/28—Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
- H04L12/46—Interconnection of networks
- H04L12/4633—Interconnection of networks using encapsulation techniques, e.g. tunneling
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/28—Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
- H04L12/46—Interconnection of networks
- H04L12/4641—Virtual LANs, VLANs, e.g. virtual private networks [VPN]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/08—Configuration management of networks or network elements
- H04L41/0803—Configuration setting
- H04L41/0806—Configuration setting for initial configuration or provisioning, e.g. plug-and-play
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/08—Configuration management of networks or network elements
- H04L41/0876—Aspects of the degree of configuration automation
- H04L41/0886—Fully automatic configuration
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/08—Configuration management of networks or network elements
- H04L41/0894—Policy-based network configuration management
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0227—Filtering policies
- H04L63/0236—Filtering by address, protocol, port number or service, e.g. IP-address or URL
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0272—Virtual private networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/029—Firewall traversal, e.g. tunnelling or, creating pinholes
Definitions
- SD-WAN Software Defined Wide Area Networks
- SaaS Software-as-a-Service
- SASE Secure Access Service Edge
- FIG. 1 illustrates an example environment that may implement various aspects of the technologies directed to automatically integrating SD-WAN constructs to SASE security policies and automating security policy enrichment based on events in the SD-WAN.
- FIG.2A illustrates an example of a security cloud provider’s dashboard used to define a security policy for an entity as described herein. 1 Atty Docket No. C237-0641PCT Client Docket No.
- FIG.2B illustrates an example of an SD-WAN controller dashboard used to map a security policy received from the security cloud provider to network constructs as described herein.
- FIG.3 is a flow diagram illustrating an example method associated with the techniques described herein for mapping a security policy to network constructs.
- FIG.4 illustrates a block diagram illustrating an example packet switching system that can be utilized to implement various aspects of the technologies disclosed herein.
- FIG.5 illustrates a block diagram illustrating certain components of an example node that can be utilized to implement various aspects of the technologies disclosed herein.
- FIG. 6 is a computer architecture diagram showing an illustrative computer hardware architecture for implementing a server device that can be utilized to implement aspects of the various technologies presented herein.
- DESCRIPTION OF EXAMPLE EMBODIMENTS OVERVIEW [0013] Aspects of the invention are set out in the independent claims and preferred features are set out in the dependent claims. Features of one aspect may be applied to each aspect alone or in combination with other features.
- This disclosure describes method(s) for mapping networking constructs on a SD-WAN to a label that is used in a policy definition by a security cloud provider.
- the method includes defining, by a security cloud provider, a security policy for an entity, the entity represented by a Virtual Private Network (VPN) policy label, wherein the security policy is absent source Classless Inter-Domain Routing (CIDR) Internet Protocol (IP) addresses and destination CIDR IP addresses.
- the method includes notifying, by the security cloud provider, an SD- WAN controller of the security policy.
- the method also includes, mapping, by the SD-WAN controller, the VPN security policy label to an IP address pool and a VPN ID.
- the method includes, adding, by the SD- WAN controller, automatically and based at least in part on the mapping, source CIDR IP addresses and destination CIDR IP addresses to the security policy to generate an enhanced security policy.
- the method also includes transmitting, by the SD-WAN controller, the enhanced security policy to the security cloud provider.
- the method may also include, deploying, by the SD-WAN controller, the enhanced security policy to an SD-WAN branch router.
- the method includes generating, by the SD-WAN controller, a VPN segment between the SD-WAN branch router and the security cloud provider to establish a common secure internet gateway tunnel for the IP address pool.
- SD-WAN Software Defined Wide Area Network
- Enterprise organizations are rapidly transitioning their infrastructure from a centralized data center model to a decentralized cloud model with features that are designed to deliver secure site-to-site and site-to-cloud connectivity from any location.
- SD-WAN can optimize user experience and efficiency for SaaS and public-cloud applications, 2 Atty Docket No. C237-0641PCT Client Docket No. C/P/1039088/WO/SEC/1 and simplify operations with automation and cloud-based management that enables enterprise organization to securely connect users and applications across multiple locations.
- SASE Secure Access Service Edge
- SASE SASE Secure Internet Gateway
- a SIG provider administrator is expected to know, from an SD-WAN administrator, SD-WAN network constructs (e.g., segmentation, IP address, VPN, CDIRs, or any other constructs associated with the SD- WAN necessary for implementing a security policy) in order to effectively define a security policy for an entity connected to the SD-WAN.
- SD-WAN network constructs e.g., segmentation, IP address, VPN, CDIRs, or any other constructs associated with the SD- WAN necessary for implementing a security policy
- a security cloud provider administrator when defining a security policy for the engineering department of an enterprise organization, a security cloud provider administrator is required to know the SD-WAN network constructs (e.g., IP pool subnet information for engineering department) and manually enter them into a security cloud provider dashboard in order to successfully configure the security policy for the engineering department and have the policy successfully applied to all network communications to and from engineering personnel associated with the enterprise organization.
- the security cloud provider administrator is unaware of the SD-WAN network constructs and therefore, must coordinate with SD-WAN network operations in order to acquire the necessary information which then must be manually entered by a security operations administrator in order to be effectively configure the security policy.
- This disclosure describes techniques for automatically integrating SD-WAN constructs to SASE security policies.
- the security cloud provider can define a policy and the SD-WAN controller can automatically map the network constructs to the security policy label, thereby enhancing the security policy, and push the enhanced security policy, with constructs included, to the security cloud provider, as well as deploy the enhanced security policy to network edges or branch devices.
- security policy labels e.g., “engineering department” in the example above
- SIG provider e.g., Cisco Umbrella, Zscaler, etc.
- the security cloud provider only needs to enter a security policy label (e.g., “engineering department”), and policy details (e.g., allow (or block) access to an application for users in the “engineering department”).
- the security operations administrator does not need to input any SD-WAN network segmentation details for the policy.
- source CIDR IP addresses and destination CIDR IP address need not be known and input by the security operations administrator of the security cloud provider.
- the security operations administrator defines the security policy
- the SD-WAN network administrator defines IP pools for individual VPNs, sites, regions or geo-locations via a network operations dashboard user interface of an SD-WAN controller.
- the IP pool is defined in the private IP space with a VPN ID encoded in the IP address as the second octet.
- the SD-WAN controller reads the security policy labels, defined by and received from the security cloud provider, and maps the security policy labels to the department name (e.g., engineering department) and VPN ID.
- the SD-WAN controller pulls the IP pool information for the VPN ID to auto define the per VPN Dynamic Host Configuration Protocol (DHCP) pool template and the SD-WAN controller 3 Atty Docket No. C237-0641PCT Client Docket No. C/P/1039088/WO/SEC/1 pushes the enhanced security policy to SD-WAN devices.
- the SD-WAN controller enhances the security policy to include network segmentation details (e.g., source CIDR addresses and destination CIDR addresses) and sends an HTTP PUT request with the enhanced security policy back to the security cloud provider.
- a security policy is defined by a security cloud provider with just a security policy label representing the network segmentation in the SD-WAN (e.g., enterprise organization department name, site name, geo-location name, etc.).
- the security policy defined by the SIG provider is pulled into an SD-WAN controller via an Application Programming Interface (API) when triggered by events such as VPN definition, IP address pool creation, new branch device onboarding, etc.
- API Application Programming Interface
- the extended information of the segmentation present on the SD- WAN side is automatically mapped to the security policy label by an SD-WAN controller, enhancing the security policy.
- This extension of the security policy binds the networking side details (e.g., IP addresses, tunnel names, etc.) that represent the site and device information, into the security policy.
- the SD-WAN controller converts the policy intent from the security cloud provider to an SD-WAN security policy to be pushed to SD-WAN devices to maintain the same security posture for non-SIG traffic.
- the security posture is defined once and used for both cloud and on-prem security.
- a periodic pull may be configured with a security policy pull time interval, to periodically pull security definitions from the security cloud provider.
- the SD-WAN controller will be notified of the change due to the periodic pull of security definitions from the security cloud provider via the API.
- security policy enhancement is automated based on events in the SD-WAN.
- VPN add/delete or network device add/delete may automatically trigger a security policy update by the SD-WAN controller.
- the security policy can be automatically updated by the SD-WAN controller.
- the SD-WAN controller can update the security policy with the correct networking information.
- the SD-WAN controller automatically pushes the enhanced/updated policy to the security cloud provider as well as deploying the enhanced/updated security policy to SD-WAN devices.
- FIG. 1 illustrates an example environment 100 that may implement various aspects of the technologies directed to automatically integrating SD-WAN constructs to SASE security policies.
- Environment 100 includes security operations 102 and network operations 104.
- the security operations 102 is responsible for defining security policies and network operations 104 is responsible for bring up the SD-WAN overlay.
- Security operations 102 is 4 Atty Docket No.
- Security operations 102 in example environment 100 includes a security cloud provider 106.
- the security cloud provider 106 provides a Secure Internet Gateway (SIG) connection for enterprise organizations.
- SIG Secure Internet Gateway
- the security cloud provider 106 shown in FIG.1 includes features such as DNS layer security, a secure web gateway, a cloud delivered firewall, a cloud access security broker (CASB), and interactive threat intel.
- Security operations 102 also includes a security operations administrator 108 for the security cloud provider 106.
- the security operations administrator 108 may define a security policy for a network enterprise via a security cloud provider’s dashboard, this process is described in detail below with reference to FIG.2A.
- Network operations 104 includes one or more SD-WAN network controllers 110.
- the SD-WAN network controllers 110 include a network management system with a dashboard that functions as a window into the SD- WAN and through which network administration may interact with the system.
- the network operations dashboard is described in detail below with reference to FIG.2B.
- SD-WAN branch router-1 112 that includes an enterprise organization’s engineering and marketing departments
- SD-WAN branch router-2114 that includes the enterprise organizations engineering and sales departments.
- FIG. 1 Also included in FIG. 1 are direct internet access tunnels (IPsec VPN tunnels) 116 connecting SD-WAN branch router-1112 and SD-WAN branch router-2114 to the security cloud provider 106.
- IPsec VPN tunnels direct internet access tunnels
- the security cloud provider 106 defines a security policy for an entity with just a VPN security policy label representing the network segmentation in the SD-WAN.
- the security administrator 108 may define security policies for “engineering department”, “marketing department”, and “sales department” that are present at SD-WAN branch router-1 112 and SD-WAN branch router-2 114.
- the VPN security policy labels representing the security policies may be entered by the security administrator 108 into a security cloud provider 106 dashboard described below with reference to FIG. 2A.
- the security administrator does not need to know, and does not need to manually input, the network segmentation information such as protocol, tunnel names, source CIDR IP addresses and destination CIDR IP addresses, etc. 5 Atty Docket No. C237-0641PCT Client Docket No.
- the security policies defined by the security cloud provider 106 are pulled into the SD-WAN network controller(s) 110 of the network operations 104 by an out of band API.
- the SD-WAN network controller(s) 110 map the VPN security policy labels to IP address pools and VPN ID’s.
- Source CIDR IP addresses and destination CIDR IP addresses are added to the security policies to generate an enhanced security policy, and the enhanced security policies are pushed (via an HTTP PUT request) back to the cloud security provider 106.
- IP pool information is used to auto define the per VPN DHCP pool template and pushed to the SD-WAN network edge and branch devices.
- the SD-WAN network controller 110 then generates an IPsec VPN segment between the SD-WAN branch router (e.g., SD-WAN branch router-1112 and SD-WAN branch router-2114) and the security cloud provider 106 as illustrated in FIG.1 as the IPsec direct internet access tunnels 116.
- the IPsec VPN segment establishes a common Secure Internet Gateway tunnel between the branch device and the security cloud provider 106.
- the SD-WAN controller 110 In addition to pushing the enhanced security policy back to the cloud security provider 106, the SD-WAN controller 110 also deploys the enhanced security policy to on-prem devices, thus providing the same security posture for on-prem and cloud security.
- FIG.2A illustrates an example security cloud provider dashboard 200A for defining a security policy for an entity.
- the security provider dashboard 200A is merely an example, and any given security cloud provider dashboard may have more or fewer options, similar or different option, the same or different interactive elements (e.g., pull down menus, selection buttons, text boxes, etc.), and may be displayed in a similar or different layout.
- the security cloud provider dashboard 200A may be used by an administrator of security operations 202 to define a security policy for an entity.
- a security policy label 204 is defined as “Sales” indicating that it is a security policy for the sales department of an enterprise organization.
- the policy for the sales department is to “Block” access to an application or specific data, etc. (not specifically shown).
- an administrator is required to know, and manually input, the protocol to specify as well as source and destination tunnels, CIDR IP addresses and ports.
- the protocols, source and destination tunnels, CIDR IP addresses, and ports are not required to be manually input by the security operations administrator of the security cloud provider. They may be set to “any” or remain blank, there is no need to explicitly specify any particular protocol, tunnels, CIDR IP addresses, or ports.
- the security policy is simply defined by a security policy label that indicates a department, site, region, etc. of an enterprise organization. This greatly reduces the prolonged interaction and coordination between security operations 202 and network operations 206 (illustrated in FIG.2B) required to define and implement security policies for enterprise organizations, as the security operations administrator does not need to know network segmentation detail in order to define a security policy as has been traditionally required.
- FIG.2B illustrates an example of an SD-WAN controller dashboard 200B used to map a security policy received from the security operations 202 of a security cloud provider to network constructs as described herein. Similar to the security provider dashboard illustrated in FIG.2A, the SD-WAN controller dashboard 200B is merely an example, and any given security cloud provider dashboard may have more or fewer options, the same or different options, the same or different interactive elements, and may be displayed in a similar of different manner.
- the SD-WAN controller dashboard may be used by an administrator of network operations 206 to define IP pools as illustrated in FIG.2B.
- IP pools Three IP pools have previously been defined (Engineering, region, site) and are shown on the display of the dashboard Pools window 208.
- FIG.2B Also included in FIG.2B is an example add pool pop- up window 210 for defining new IP pools.
- the security policy label “Sales” as defined in the security cloud provider dashboard 200A of FIG. 2A, is pulled into the SD-WAN controller dashboard 200B via an API, and is shown in the “Pool Name” in the add pool pop-up window 210.
- the SD-WAN controller knows which IP pool is allocated for the sales department, so the SD-WAN maps the VPN ID, IP subnet, and prefix length to the “Sales” security policy label by automatically populating the VPN ID, IP subnet, and prefix length in the add pool pop-up window 210 when the pool name “Sales” is indicated as the IP pool to add.
- the SD-WAN controller enhances the “Sales” security policy and pushes the enhanced security policy back to the SIG provider via an HTTP PUT request, and deploys the enhanced security policy to SD-WAN network devices, for example SD-WAN branch router-1112 and SD-WAN branch router-2114 as illustrated in FIG.1 and described above.
- FIGS.3 is a flow diagram illustrating an example method 300 associated with the techniques described herein for seamlessly integrating SD-WAN constructs to SASE security policies.
- Example method 300 illustrates aspects of the functions performed by the security operations 102 and network operation 104 as described in FIG. 1.
- the logical operations described herein with respect to FIGS. 3 may be implemented (1) as a sequence of computer-implemented acts or program modules running on a computing system and/or (2) as interconnected machine logic circuits or circuit modules within the computing system.
- the method(s) 300 may be performed by a system comprising one or more processors and one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform the method(s) 300.
- a system comprising one or more processors and one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform the method(s) 300.
- the logical operations described herein are referred to variously as operations, structural devices, acts, or modules. These operations, structural devices, acts, and modules can be implemented in software, in firmware, in special purpose digital logic, and any combination thereof. It should also be appreciated that more or fewer operations might be performed than shown in the FIGS.3 and described herein.
- a security cloud provider defines a security policy for an entity.
- the entity is represented by a VPN security policy label and the security policy does not include a source CIDR IP address or a destination CIDR IP address for which to apply the security policy.
- the policy defined by the security cloud provider is a simple language version of policy instructions. For example, “allow (or block) access to the Internet by the engineering department”.
- the policy is absent any network construct details.
- the security cloud provider 106 may define a security policy for engineering, marketing, and/or sales. Further detail is shown in FIG.2A, where security operations defines a VPN security policy label 204, “Sales” in a security cloud operations dashboard 200A.
- the security policy does not required input of any network constructs.
- protocol and source and destination information (tunnels, CIDR IP addresses, and ports) are entered as “any”.
- the security cloud provider notifies an SD-WAN controller of the security policy.
- the SD-WAN controller pulls the policy into a dashboard via an out of band API.
- the SD-WAN network controller 110 receives the security policy defined by the security cloud provider 106.
- FIG.2B shows the pool name “Sales” in the pool name of the add pool pop-up window 210 that corresponds to the security policy label 204 “Sales” as defined by security operations 202 in the security cloud provider dashboard 200A as shown in FIG.2A.
- the SD-WAN controller maps the VPN security policy label to an IP address pool and a VPN ID.
- the SD-WAN controller reads the VPN security policy label received from the security cloud provider, and maps the VPN security policy label to the VPN ID and pulls IP address pool information for the VPN ID. For example, in FIG.2B, once the SD-WAN controller pulls in the security policy label “Sales” into the pool name of the add pool pop-up window 210, the VPN ID, IP subnet, and prefix length sections of the add pool pop-up window 208 are automatically populated with the network segmentation information associated with “Sales”. [0040] At operation 308, the SD-WAN controller automatically adds source CIDR IP addresses and destination CIDR IP addresses to the security policy to generate an enhanced security policy. For example, in FIG.
- the SD-WAN controller transmits the enhanced security policy to the security cloud provider.
- the enhanced security policy is pushed back to the security cloud provider 106, for example by an HTTP PUT request.
- a triggering event occurs in the SD-WAN, such as VPN add/delete or network device add/delete, an enhanced security policy is automatically updated by the SD-WAN network controller 110 and pushed to the security cloud provider 106.
- the SD-WAN controller deploys the enhanced security policy to an SD-WAN branch router.
- the SD-WAN network controller 110 deploys the enhanced security policy to SD-WAN network devices like the SD-WAN branch router-1112 and SD-WAN branch router-2114.
- a triggering event occurs in the SD-WAN, such as VPN add/delete or network device add/delete, an enhanced 8 Atty Docket No. C237-0641PCT Client Docket No.
- C/P/1039088/WO/SEC/1 security policy is automatically updated by the SD-WAN network controller 110 and deployed to SD-WAN network devices like the SD-WAN branch router-1112 and SD-WAN branch router-2114.
- a policy intent from the security cloud provider 106 is converted to an SD-WAN security policy and pushed to SD-WAN device to maintain the same security posture for non-SIG traffic.
- the SD-WAN controller generates a VPN segment between the SD-WAN branch router and the security cloud provider to establish a common secure internet gateway tunnel for the IP address pool.
- FIG. 4 illustrates a block diagram illustrating an example packet switching device (or system) 400 that can be utilized to implement various aspects of the technologies disclosed herein.
- packet switching device(s) 400 may be employed in various networks, such as, for example, SD-WAN branch router-1 112 and SD-WAN branch router-2114 in the SD-WAN network described with respect to FIG.1.
- a packet switching device 400 may comprise multiple line card(s) 402, 410, each with one or more network interfaces for sending and receiving packets over communications links (e.g., possibly part of a link aggregation group).
- the packet switching device 400 may also have a control plane with one or more processing elements for managing the control plane and/or control plane processing of packets associated with forwarding of packets in a network.
- the packet switching device 400 may also include other cards 408 (e.g., service cards, blades) which include processing elements that are used to process (e.g., forward/send, drop, manipulate, change, modify, receive, create, duplicate, apply a service) packets associated with forwarding of packets in a network.
- the packet switching device 400 may comprise hardware-based communication mechanism 406 (e.g., bus, switching fabric, and/or matrix, etc.) for allowing its different entities, line cards 402, 404, 408 and 410 to communicate.
- Line card(s) 402, 410 may typically perform the actions of being both an ingress and/or an egress line card 402, 410, in regard to multiple other particular packets and/or packet streams being received by, or sent from, packet switching device 400.
- FIG. 5 illustrates a block diagram illustrating certain components of an example node 500 that can be utilized to implement various aspects of the technologies disclosed herein.
- node(s) 500 may be employed in various networks, such as, for example, the SD-WAN network as described with respect to FIG.1.
- node 500 may include any number of line cards 502 (e.g., line cards 502(1)-(N), where N may be any integer greater than 1) that are communicatively coupled to a forwarding engine 510 (also referred to as a packet forwarder) and/or a processor 520 via a data bus 530 and/or a result bus 540.
- Line cards 502(1)-(N) may include any number of port processors 550(1)(A)-(N)(N) which are controlled by port processor controllers 560(1)-(N), where N may be any integer greater than 1.
- forwarding engine 510 and/or processor 520 are not only coupled to one another via the data bus 530 and the result bus 540, but may also communicatively coupled to one another by a communications link 570.
- the processors e.g., the port processor(s) 550 and/or the port processor controller(s) 560
- each line card 502 may be mounted on a single printed circuit board.
- the 9 Atty Docket No. C237-0641PCT Client Docket No. C/P/1039088/WO/SEC/1 packet or packet and header may be identified and analyzed by node 500 (also referred to herein as a router) in the following manner.
- a packet (or some or all of its control information) or packet and header may be sent from one of port processor(s) 550(1)(A)-(N)(N) at which the packet or packet and header was received and to one or more of those devices coupled to the data bus 530 (e.g., others of the port processor(s) 550(1)(A)-(N)(N), the forwarding engine 510 and/or the processor 520). Handling of the packet or packet and header may be determined, for example, by the forwarding engine 510. For example, the forwarding engine 510 may determine that the packet or packet and header should be forwarded to one or more of port processors 550(1)(A)-(N)(N).
- FIG.6 shows an example computer architecture for a computing device (or network routing device) 600 capable of executing program components for implementing the functionality described above.
- the computing device 600 illustrates a conventional server computer, workstation, desktop computer, laptop, tablet, network appliance, e-reader, smartphone, or other computing device, and can be utilized to execute any of the software components presented herein.
- the computing device 600 may, in some examples, correspond to a SD- WAN network controller 110, the packet switching system 400, and/or the node 500 described herein with respect to FIGS.1, 4, and 5, respectively.
- the computing device 600 includes a baseboard 602, or “motherboard,” which is a printed circuit board to which a multitude of components or devices can be connected by way of a system bus or other electrical communication paths.
- one or more central processing units (“CPUs”) 604 operate in conjunction with a chipset 606.
- the CPUs 604 can be standard programmable processors that perform arithmetic and logical operations necessary for the operation of the computing device 600. [0051] The CPUs 604 perform operations by transitioning from one discrete, physical state to the next through the manipulation of switching elements that differentiate between and change these states. Switching elements generally include electronic circuits that maintain one of two binary states, such as flip-flops, and electronic circuits that provide an output state based on the logical combination of the states of one or more other switching elements, such as logic gates. These basic switching elements can be combined to create more complex logic circuits, including registers, adders-subtractors, arithmetic logic units, floating-point units, and the like.
- the chipset 606 provides an interface between the CPUs 604 and the remainder of the components and 10 Atty Docket No. C237-0641PCT Client Docket No. C/P/1039088/WO/SEC/1 devices on the baseboard 602.
- the chipset 606 can provide an interface to a RAM 608, used as the main memory in the computing device 600.
- the chipset 606 can further provide an interface to a computer-readable storage medium such as a read-only memory (“ROM”) 610 or non-volatile RAM (“NVRAM”) for storing basic routines that help to startup the computing device 600 and to transfer information between the various components and devices.
- ROM read-only memory
- NVRAM non-volatile RAM
- the ROM 610 or NVRAM can also store other software components necessary for the operation of the computing device 600 in accordance with the configurations described herein.
- the computing device 600 can operate in a networked environment using logical connections to remote computing devices and computer systems through a network, such as the network 624.
- the chipset 606 can include functionality for providing network connectivity through a NIC 612, such as a gigabit Ethernet adapter.
- the NIC 612 is capable of connecting the computing device 600 to other computing devices over the network 624. It should be appreciated that multiple NICs 612 can be present in the computing device 600, connecting the computer to other types of networks and remote computer systems.
- the computing device 600 can be connected to a storage device 618 that provides non-volatile storage for the computing device 600.
- the storage device 618 can store an operating system 620, programs 622, and data, which have been described in greater detail herein.
- the storage device 618 can be connected to the computing device 600 through a storage controller 614 connected to the chipset 606.
- the storage device 618 can consist of one or more physical storage units.
- the storage controller 614 can interface with the physical storage units through a serial attached SCSI (“SAS”) interface, a serial advanced technology attachment (“SATA”) interface, a fiber channel (“FC”) interface, or other type of interface for physically connecting and transferring data between computers and physical storage units.
- SAS serial attached SCSI
- SATA serial advanced technology attachment
- FC fiber channel
- the computing device 600 can store data on the storage device 618 by transforming the physical state of the physical storage units to reflect the information being stored.
- the specific transformation of physical state can depend on various factors, in different embodiments of this description. Examples of such factors can include, but are not limited to, the technology used to implement the physical storage units, whether the storage device 618 is characterized as primary or secondary storage, and the like.
- the computing device 600 can store information to the storage device 618 by issuing instructions through the storage controller 614 to alter the magnetic characteristics of a particular location within a magnetic disk drive unit, the reflective or refractive characteristics of a particular location in an optical storage unit, or the electrical characteristics of a particular capacitor, transistor, or other discrete component in a solid-state storage unit.
- the computing device 600 can further read information from the storage device 618 by detecting the physical states or characteristics of one or more particular locations within the physical storage units. [0057] In addition to the mass storage device 618 described above, the computing device 600 can have access to other computer-readable storage media to store and retrieve information, such as program modules, data structures, or other data. It should be appreciated by those skilled in the art that computer-readable storage media is any available media that provides for the non-transitory storage of data and that can be accessed by the computing 11 Atty Docket No. C237-0641PCT Client Docket No.
- C/P/1039088/WO/SEC/1 device 600 the operations performed by the network device(s) 102-108, and or any components included therein, may be supported by one or more devices similar to computing device 600. Stated otherwise, some or all of the operations performed by the network device(s) 102-108, and or any components included therein, may be performed by one or more computing device 600 operating in a cloud-based arrangement.
- computer-readable storage media can include volatile and non- volatile, removable and non-removable media implemented in any method or technology.
- Computer-readable storage media includes, but is not limited to, RAM, ROM, erasable programmable ROM (“EPROM”), electrically- erasable programmable ROM (“EEPROM”), flash memory or other solid-state memory technology, compact disc ROM (“CD-ROM”), digital versatile disk (“DVD”), high definition DVD (“HD-DVD”), BLU-RAY, or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information in a non-transitory fashion.
- the storage device 618 can store an operating system 620 utilized to control the operation of the computing device 600.
- the operating system comprises the LINUX operating system.
- the operating system comprises the WINDOWS® SERVER operating system from MICROSOFT Corporation of Redmond, Washington.
- the operating system can comprise the UNIX operating system or one of its variants. It should be appreciated that other operating systems can also be utilized.
- the storage device 618 can store other system or application programs and data utilized by the computing device 600. [0060] In one embodiment, the storage device 618 or other computer-readable storage media is encoded with computer-executable instructions which, when loaded into the computing device 600, transform the computer from a general-purpose computing system into a special-purpose computer capable of implementing the embodiments described herein. These computer-executable instructions transform the computing device 600 by specifying how the CPUs 604 transition between states, as described above.
- the computing device 600 has access to computer-readable storage media storing computer-executable instructions which, when executed by the computing device 600, perform the various processes described above with regard to FIG.3.
- the computing device 600 can also include computer-readable storage media having instructions stored thereupon for performing any of the other computer-implemented operations described herein.
- the computing device 600 can also include one or more input/output controllers 616 for receiving and processing input from a number of input devices, such as a keyboard, a mouse, a touchpad, a touch screen, an electronic stylus, or other type of input device.
- an input/output controller 616 can provide output to a display, such as a computer monitor, a flat-panel display, a digital projector, a printer, or other type of output device.
- a display such as a computer monitor, a flat-panel display, a digital projector, a printer, or other type of output device.
- the computing device 600 might not include all of the components shown in FIG.6, can include other components that are not explicitly shown in FIG. 6, or might utilize an architecture completely different than that shown in FIG.6.
- the techniques may include defining, by a security cloud provider, a security policy for an entity, the entity represented by a VPN security policy label and the security policy absent source and destination CIDR IP 12 Atty Docket No. C237-0641PCT Client Docket No.
- the security cloud provider notifies an SD-WAN controller of the security policy.
- the SD-WAN controller maps the VPN security policy label to an IP address pool and a VPN ID.
- the SD-WAN controller generates an enhanced security policy by automatically adding source and destination CIDR IP addresses to the security policy.
- the SD-WAN controller deploys the enhanced security policy to an SD-WAN branch router and generates a VPN segment between the SD-WAN branch router and the security cloud provider to establish a common secure internet gateway tunnel for the IP address pool.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Automation & Control Theory (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202480002390.8A CN119678434A (en) | 2023-07-20 | 2024-07-12 | Integrate SD-WAN fabric with security policies |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US18/224,220 US12470601B2 (en) | 2023-07-20 | 2023-07-20 | Integrating SD-WAN constructs with SASE security policies |
| US18/224,220 | 2023-07-20 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025019331A1 true WO2025019331A1 (en) | 2025-01-23 |
Family
ID=92259027
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/US2024/037828 Pending WO2025019331A1 (en) | 2023-07-20 | 2024-07-12 | Integrating sd-wan constructs with security policies |
Country Status (3)
| Country | Link |
|---|---|
| US (2) | US12470601B2 (en) |
| CN (1) | CN119678434A (en) |
| WO (1) | WO2025019331A1 (en) |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20250279980A1 (en) * | 2024-02-29 | 2025-09-04 | Versa Networks, Inc. | Methods and systems for providing network connectivity to a secure access service edge (sase) domain via an isp using ip pools |
| US12615257B2 (en) | 2024-02-29 | 2026-04-28 | Versa Networks, Inc. | Methods and systems for providing network connectivity to a secure access service edge (SASE) domain via an ISP |
Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20150326532A1 (en) * | 2014-05-06 | 2015-11-12 | At&T Intellectual Property I, L.P. | Methods and apparatus to provide a distributed firewall in a network |
| US20190075133A1 (en) * | 2016-06-09 | 2019-03-07 | LGS Innovations LLC | Methods and systems for establishment of vpn security policy by sdn applicaiton |
| US20200195607A1 (en) * | 2018-12-12 | 2020-06-18 | Vmware, Inc. | Static routes for policy-based vpn |
| US20200389796A1 (en) * | 2019-06-06 | 2020-12-10 | Cisco Technology Inc. | Systems and methods for distributing sd-wan policies |
| EP3841723B1 (en) * | 2018-08-20 | 2022-05-18 | Cisco Technology, Inc. | Elastic policy scaling in multi-cloud fabrics |
| EP4187868A1 (en) * | 2021-11-24 | 2023-05-31 | INTEL Corporation | Load balancing and networking policy performance by a packet processing pipeline |
Family Cites Families (10)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20100275008A1 (en) * | 2009-04-27 | 2010-10-28 | Motorola, Inc. | Method and apparatus for secure packet transmission |
| US9112911B1 (en) | 2011-01-04 | 2015-08-18 | Juniper Networks, Inc. | Adding firewall security policy dynamically to support group VPN |
| CN104601526B (en) * | 2013-10-31 | 2018-01-09 | 华为技术有限公司 | A kind of method, apparatus of collision detection and solution |
| US10237240B2 (en) * | 2016-07-21 | 2019-03-19 | AT&T Global Network Services (U.K.) B.V. | Assessing risk associated with firewall rules |
| US11159487B2 (en) * | 2019-02-26 | 2021-10-26 | Juniper Networks, Inc. | Automatic configuration of perimeter firewalls based on security group information of SDN virtual firewalls |
| US11563601B1 (en) * | 2019-08-22 | 2023-01-24 | Juniper Networks, Inc. | Proactive tunnel configuration computation for on-demand SD-WAN tunnels |
| US11546302B2 (en) | 2019-12-17 | 2023-01-03 | Fortinet, Inc. | Automatic establishment of network tunnels by an SDWAN controller based on group and role assignments of network devices |
| US11411765B2 (en) | 2020-01-10 | 2022-08-09 | Cisco Technology, Inc. | Automating a software-defined wide area network policy for internet of things end points |
| US12563067B2 (en) * | 2022-06-29 | 2026-02-24 | Netapp, Inc. | Identifying anomalous activities in a cloud computing environment |
| US20240236142A1 (en) * | 2023-01-11 | 2024-07-11 | Vmware, Inc. | Security threat analysis |
-
2023
- 2023-07-20 US US18/224,220 patent/US12470601B2/en active Active
-
2024
- 2024-07-12 WO PCT/US2024/037828 patent/WO2025019331A1/en active Pending
- 2024-07-12 CN CN202480002390.8A patent/CN119678434A/en active Pending
-
2025
- 2025-10-21 US US19/364,204 patent/US20260046316A1/en active Pending
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20150326532A1 (en) * | 2014-05-06 | 2015-11-12 | At&T Intellectual Property I, L.P. | Methods and apparatus to provide a distributed firewall in a network |
| US20190075133A1 (en) * | 2016-06-09 | 2019-03-07 | LGS Innovations LLC | Methods and systems for establishment of vpn security policy by sdn applicaiton |
| EP3841723B1 (en) * | 2018-08-20 | 2022-05-18 | Cisco Technology, Inc. | Elastic policy scaling in multi-cloud fabrics |
| US20200195607A1 (en) * | 2018-12-12 | 2020-06-18 | Vmware, Inc. | Static routes for policy-based vpn |
| US20200389796A1 (en) * | 2019-06-06 | 2020-12-10 | Cisco Technology Inc. | Systems and methods for distributing sd-wan policies |
| EP4187868A1 (en) * | 2021-11-24 | 2023-05-31 | INTEL Corporation | Load balancing and networking policy performance by a packet processing pipeline |
Also Published As
| Publication number | Publication date |
|---|---|
| CN119678434A (en) | 2025-03-21 |
| US12470601B2 (en) | 2025-11-11 |
| US20250030737A1 (en) | 2025-01-23 |
| US20260046316A1 (en) | 2026-02-12 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12399886B2 (en) | Parsing logical network definition for different sites | |
| US11218420B2 (en) | Virtual network interface objects | |
| CN116366449B (en) | System and method for user customization and automated operations on software defined networks | |
| CN115380513A (en) | Network management system for federated multi-site logical networks | |
| US20170366373A1 (en) | Programmable infrastructure gateway for enabling hybrid cloud services in a network environment | |
| US20260046316A1 (en) | Integrating sd-wan constructs with sase security policies | |
| US20250126059A1 (en) | Data sovereignty and service insertion in multisite network fabric | |
| US20250350578A1 (en) | Security solution orchestration | |
| US11831498B1 (en) | Integrating an existing cloud network into a target environment | |
| US11962498B1 (en) | Symmetric networking for orphan workloads in cloud networks | |
| EP4569744B1 (en) | Scalable creation of connections | |
| US20250202806A1 (en) | Intent-based application steering using sd-wan router affinity | |
| EP4725172A1 (en) | End-to-end neutral host network-as-a-service |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| WWE | Wipo information: entry into national phase |
Ref document number: 202480002390.8 Country of ref document: CN |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24752208 Country of ref document: EP Kind code of ref document: A1 |
|
| WWP | Wipo information: published in national office |
Ref document number: 202480002390.8 Country of ref document: CN |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 202617018575 Country of ref document: IN |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2024752208 Country of ref document: EP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| WWP | Wipo information: published in national office |
Ref document number: 202617018575 Country of ref document: IN |