Extending NSH services into the VPN L2/L3 domain

    公开(公告)号:US10225104B2

    公开(公告)日:2019-03-05

    申请号:US15084332

    申请日:2016-03-29

    IPC分类号: H04L12/46 H04L12/725

    摘要: Embodiments of the present disclosure are directed to augmenting a Network Service Header (NSH) metadata of a data packet with a virtual routing and forwarding identifier (VRF-ID) and forgoing augmenting a virtual private network (VPN) label into a multiprotocol label switched (MPLS) metadata of the data packet. A provider edge router can use the VRF-ID to identify a next hop for the data packet as a service to be applied prior to forwarding the data packet to a VPN site.

    NSH service plane for L3VPN forwarding

    公开(公告)号:US10142128B2

    公开(公告)日:2018-11-27

    申请号:US15784218

    申请日:2017-10-16

    摘要: A method for applying network services to data traffic forwarded between virtual private network (VPN) sites includes: receiving a data packet addressed to a target site associated with the VPN, determining services to be applied to the data packet according to a service chain, where the determining is a function of at least one of the VPN, the origin site or the target site, adding an indication of a VPN forwarding context onto the data packet, encapsulating the data packet with Network Service Header encapsulation, where a header for the encapsulated data packet indicates at least the service chain; forwarding the encapsulated data packet in accordance with the service chain, receiving the encapsulated data packet at the end of the service chain, terminating the service chain, removing the encapsulation, and forwarding the data packet to a target destination per the indication of a VPN forwarding context.

    NSH service plane for L3VPN forwarding

    公开(公告)号:US09825778B2

    公开(公告)日:2017-11-21

    申请号:US14870722

    申请日:2015-09-30

    CPC分类号: H04L12/4633 H04L63/0272

    摘要: A method for applying network services to data traffic forwarded between virtual private network (VPN) sites includes: receiving a data packet addressed to a target site associated with the VPN, determining services to be applied to the data packet according to a service chain, where the determining is a function of at least one of the VPN, the origin site or the target site, adding an indication of a VPN forwarding context onto the data packet, encapsulating the data packet with Network Service Header encapsulation, where a header for the encapsulated data packet indicates at least the service chain; forwarding the encapsulated data packet in accordance with the service chain, receiving the encapsulated data packet at the end of the service chain, terminating the service chain, removing the encapsulation, and forwarding the data packet to a target destination per the indication of a VPN forwarding context.

    DISTRIBUTED MAPPING OF ADDRESS AND PORT (MAP) BETWEEN A PROVIDER EDGE DEVICE AND CUSTOMER PREMISE EQUIPMENT DEVICES
    8.
    发明申请
    DISTRIBUTED MAPPING OF ADDRESS AND PORT (MAP) BETWEEN A PROVIDER EDGE DEVICE AND CUSTOMER PREMISE EQUIPMENT DEVICES 有权
    提供者边缘设备和客户设备设备之间的地址和端口(MAP)的分布式映射

    公开(公告)号:US20160014071A1

    公开(公告)日:2016-01-14

    申请号:US14328296

    申请日:2014-07-10

    IPC分类号: H04L29/12

    摘要: In one embodiment, a provider edge (PE) device in a computer network determines an IPv4 address and link-layer address for each adjacent customer premise equipment (CPE) device, and assigns each CPE device a unique IPv6 address. The PE device stores a key-pair mapping between the unique IPv6 address and combined IPv4 and link-layer address for each adjacent CPE, the mapping bound by a CPE session context, and uses the CPE session context to convert between IPv4 and IPv6 for all network traffic to and from a particular CPE device.

    摘要翻译: 在一个实施例中,计算机网络中的提供商边缘(PE)设备为每个相邻的客户驻地设备(CPE)设备确定IPv4地址和链路层地址,并为每个CPE设备分配唯一的IPv6地址。 PE设备存储唯一的IPv6地址和每个相邻CPE的组合IPv4和链路层地址之间的密钥对映射,映射由CPE会话环境绑定,并且使用CPE会话上下文在IPv4和IPv6之间转换所有 到特定CPE设备的网络流量。