System and methods for network segmentation
US7688829B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Sep 14, 2005 |
| Grant date | Mar 30, 2010 |
| Priority date | — |
| Expiry date | Aug 7, 2028 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L45/66
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
A routing mechanism provides network segmentation preservation by route distribution with segment identification, policy distribution for a given VPN segment, and encapsulation/decapsulation for each segment using an Ethernet VLAN_ID, indicative of the VPN segment (subnetwork). Encapsulated segmentation information in a message packet identifies which routing and forwarding table is employed for the next hop. A common routing instance receives the message packets from the common interface, and indexes a corresponding VRF table from the VLAN ID, or segment identifier, indicative of the subnetwork (e.g. segment). In this manner, the routing instance receives the incoming message packet, decapsulates the VLAN ID in the incoming message packet, and indexes the corresponding VRF and policy ID from the VLAN ID, therefore employing a common routing instance over a common subinterface for a plurality of segments (subnetworks) coupled to a particular forwarding device (e.g. VPN router).
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.