Method and system of a cloud-based multipath routing protocol
Abstract
In one aspect, a computerized system useful for implementing a cloud-based multipath routing protocol to an Internet endpoint includes an edge device that provides an entry point into an entity's core network. The entity's core network includes a set of resources to be reliably accessed. The computerized system includes a cloud-edge device instantiated in a public-cloud computing platform. The cloud-edge device joins a same virtual routing and forwarding table as the edge device. The cloud-edge device receives a set of sources and destinations of network traffic that are permitted to access the edge device and the set of resources
Claims
exact text as granted — not AI-modified1 - 19 . (canceled)
20 . A system for implementing a wide area network for an entity, the system comprising:
a client device operating outside of a branch office of the entity; in the branch office of the entity:
a local area network (LAN),
a set of computers connected to the LAN, and
a first edge device connected to the LAN to serve as entry/exit device for data message traffic exchanged between a particular computer and the client device;
outside of the branch office:
a gateway to connect to the first edge device;
a second edge device deployed in a public cloud datacenter to connect to the client device and the gateway.
21 . The system of claim 20 , wherein the client device securely connects to the particular computer through virtual private network (VPN) connection established between the particular computer and the client device.
22 . The system of claim 21 , wherein the VPN connection comprises a VPN connection between the client device and the second edge device.
23 . The system of claim 21 , wherein the VPN connection comprises a VPN connection between the first edge device and the gateway.
24 . The system of claim 21 , wherein through the secure VPN connection data message traffic is exchanged between the client device and the particular computer.
25 . The system of claim 20 , wherein the second edge device is a virtual machine instantiated in the public-cloud datacenter.
26 . The system of claim 20 , wherein the particular computer is a server that is accessed by the client device through the first and second edge devices and the gateway.
27 . A method for implementing a wide area network for an entity to allow a client device operating outside of a branch office of the entity to access at least one particular computer at the branch that are connected to a local area network (LAN) of the branch, the method comprising:
deploying a first edge device connected to the LAN to serve as entry/exit device for data message traffic exchanged between the particular computer and the client device; deploying, outside of the branch, a gateway to connect to the first edge device; deploying a second edge device in a public cloud datacenter outside of the branch to connect to the client device and the gateway.
28 . The method of claim 27 further comprising establishing a virtual private network (VPN) connection established between the particular computer and the client device.
29 . The method of claim 28 , wherein the establishing the VPN connection comprises establishing a VPN connection between the client device and the second edge device.
30 . The method of claim 28 , wherein establishing the VPN connection comprises establishing a VPN connection between the first edge device and the gateway.
31 . The method of claim 27 , wherein the second edge device is a virtual machine instantiated in the public-cloud datacenter.
32 . The method of claim 27 further comprising:
configuring the second edge device to permit data message traffic from a set of network traffic to access the particular computer through the first edge device and the LAN; and
configuring the second edge device to deny any inbound network traffic that is not in the set of network traffic that is permitted to access the particular computer.
33 . The method of claim 27 further comprising enforcing a firewall rule that allows a public Internet protocol (IP) address of the client device to reach the particular computer via another public IP address assigned to the second edge device.
34 . The method of claim 33 , wherein the other public IP address assigned to the second edge device is assigned to LAN side of the first edge device.
35 . The method of claim 33 , wherein the other public IP address assigned to the second edge device is not assigned to LAN.Join the waitlist — get patent alerts
Track US2022337553A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.