US2023388269A1PendingUtilityA1

Software defined branch single internet protocol orchestration

Assignee: CISCO TECH INCPriority: Apr 8, 2021Filed: Aug 11, 2023Published: Nov 30, 2023
Est. expiryApr 8, 2041(~14.7 yrs left)· nominal 20-yr term from priority
H04L 61/5007H04L 43/0811H04L 12/4633H04L 12/4641H04L 41/40
64
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems, methods, and computer-readable media are provided for software defined branch single IP orchestration. An example method can include establishing, by a controller, a secure tunnel agent to an orchestrator, generating, by the controller, a single IP address on a virtual router for a virtual branch site, and monitoring, by the controller, reachability of the single IP address on the virtual router.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 establishing, by a network appliance implemented through a virtualized infrastructure of a virtual branch site, a secure tunnel agent to an orchestrator, the secure tunnel agent and the orchestrator being components of the virtualized infrastructure of the virtual branch site;   managing reachability of a single IP address on a virtual router for the virtual branch site; and   controlling use of the single IP address between the network appliance and the virtual router based on the reachability of the virtual router to maintain a connection between the orchestrator and the virtual branch site through the secure tunnel agent when the virtual router is unreachable,   wherein the network appliance is a Network Function Virtualization Infrastructure Software (NFVIS).   
     
     
         2 . The method of  claim 1 , wherein managing reachability of the single IP address comprises:
 generating the single IP address on the virtual router of the virtual branch site; and   monitoring the reachability of the single IP address.   
     
     
         3 . The method of  claim 2 , wherein monitoring the reachability of the single IP address includes receiving, by the NFVIS, gateway reachability data from a gateway associated with the virtual router. 
     
     
         4 . The method of  claim 1 , further comprising:
 determining, by the network appliance, that the reachability of the single IP address on the virtual router is lost; and   reallocating, by the network appliance, the single IP address.   
     
     
         5 . The method of  claim 4 , further comprising:
 managing, by the orchestrator, the virtual branch site when connectivity with the virtual router via the single IP address is lost.   
     
     
         6 . The method of  claim 1 , further comprising:
 pushing, from the orchestrator, a site specific configuration to the virtual branch site.   
     
     
         7 . The method of  claim 2 , wherein the monitoring of the reachability of the single IP address on the virtual router includes receiving, by the NFVIS, health-related data of the virtual router. 
     
     
         8 . A system comprising:
 one or more processors; and   at least one computer-readable storage medium having stored therein instructions which, when executed by the one or more processors, cause the system to:
 establish, by a network appliance implemented through a virtualized infrastructure of a virtual branch site, a secure tunnel agent to an orchestrator, the secure tunnel agent and the orchestrator being components of the virtualized infrastructure of the virtual branch site; 
 manage reachability of a single IP address on a virtual router for the virtual branch site; and 
 control use of the single IP address between the network appliance and the virtual router based on the reachability of the virtual router to maintain a connection between the orchestrator and the virtual branch site through the secure tunnel agent when the virtual router is unreachable, 
   wherein the network appliance is a Network Function Virtualization Infrastructure Software (NFVIS).   
     
     
         9 . The system of  claim 8 , wherein the instructions which, when executed by the one or more processors, cause the system to:
 generate the single IP address on the virtual router of the virtual branch site; and   monitor the reachability of the single IP address.   
     
     
         10 . The system of  claim 9 , wherein the instructions which, when executed by the one or more processors, cause the system to monitor the reachability of the single IP address by monitoring the reachability of the single IP address includes receiving, by the NFVIS, gateway reachability data from a gateway associated with the virtual router. 
     
     
         11 . The system of  claim 8 , wherein the instructions which, when executed by the one or more processors, cause the system to:
 determine, by the network appliance, that the reachability of the single IP address on the virtual router is lost; and   reallocate, by the network appliance, the single IP address.   
     
     
         12 . The system of  claim 11 , wherein the instructions which, when executed by the one or more processors, cause the system to:
 manage, by the orchestrator, the virtual branch site when connectivity with the virtual router via the single IP address is lost.   
     
     
         13 . The system of  claim 8 , wherein the instructions which, when executed by the one or more processors, cause the system to:
 push, from the orchestrator, a site specific configuration to the virtual branch site.   
     
     
         14 . The system of  claim 9 , wherein the monitored reachability of the single IP address on the virtual router includes receiving, by the NFVIS, health-related data of the virtual router. 
     
     
         15 . A non-transitory computer-readable storage medium comprising:
 instructions stored on the non-transitory computer-readable storage medium, the instructions, when executed by one or more processors, cause the one or more processors to:
 establish, by a network appliance implemented through a virtualized infrastructure of a virtual branch site, a secure tunnel agent to an orchestrator, the secure tunnel agent and the orchestrator being components of the virtualized infrastructure of the virtual branch site; 
 manage reachability of a single IP address on the virtual router for the virtual branch site; and 
 control use of the single IP address between the network appliance and a virtual router based on the reachability of the virtual router to maintain a connection between the orchestrator and the virtual branch site through the secure tunnel agent when the virtual router is unreachable, 
 wherein the network appliance is a Network Function Virtualization Infrastructure Software (NFVIS). 
   
     
     
         16 . The non-transitory computer-readable storage medium of  claim 15 , wherein the instructions, when executed by the one or more processors, cause the one or more processors to:
 generate the single IP address on the virtual router of the virtual branch site; and   monitor the reachability of the single IP address.   
     
     
         17 . The non-transitory computer-readable storage medium of  claim 15 , wherein the instructions, when executed by the one or more processors, cause the one or more processors to monitor the reachability of the single IP address by monitoring the reachability of the single IP address includes receiving, by the NFVIS, gateway reachability data from a gateway associated with the virtual router. 
     
     
         18 . The non-transitory computer-readable storage medium of  claim 15 , wherein the instructions, when executed by the one or more processors, cause the one or more processors to:
 determine, by the network appliance, that the reachability of the single IP address on the virtual router is lost; and   reallocate, by the network appliance, the single IP address.   
     
     
         19 . The non-transitory computer-readable storage medium of  claim 18 , wherein the instructions, when executed by the one or more processors, cause the one or more processors to:
 manage, by the orchestrator, the virtual branch site when connectivity with the virtual router via the single IP address is lost.   
     
     
         20 . The non-transitory computer-readable storage medium of  claim 15 , wherein the instructions, when executed by the one or more processors, cause the one or more processors to:
 push, from the orchestrator, a site specific configuration to the virtual branch site.

Join the waitlist — get patent alerts

Track US2023388269A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.