-
公开(公告)号:US11582100B2
公开(公告)日:2023-02-14
申请号:US17719792
申请日:2022-04-13
Applicant: Cisco Technology, Inc.
Inventor: Rajagopalan Janakiraman , Sivakumar Ganapathy , Gianluca Mardente , Giovanni Meo , Patel Amitkumar Valjibhai
IPC: G06F15/177 , H04L41/0816 , H04L12/46 , H04L41/0806 , H04L41/0893 , H04L45/02 , H04L45/44
Abstract: Technologies for multi-cloud routing and policy interconnectivity are provided. An example method can include assigning different sets of data plane routers to data plane traffic associated with different address spaces in a cloud site of a multi-cloud fabric to yield a distributed mapping of data plane traffic and data plane routers. The method can further include providing, to an on-premises site in the multi-cloud fabric, routing entries from a control plane router on the cloud site, the routing entries reflecting the distributed mapping and identifying, for each address space, which data plane router handles data plane traffic for that address space; and when a data plane router is deployed at the cloud site, providing, to the on-premises site, updated routing information from the control plane router, the updated routing information identifying the data plane router as a next hop for data plane traffic associated with a respective address space.
-
公开(公告)号:US20210234898A1
公开(公告)日:2021-07-29
申请号:US16750841
申请日:2020-01-23
Applicant: Cisco Technology, Inc.
Inventor: Ronak K. Desai , Rajagopalan Janakiraman , Mohammed Javed Asghar , Azeem Suleman , Patel Amitkumar Valjibhai , Sanjay Kumar Hooda , Victor Manuel Moreno
IPC: H04L29/06 , H04L12/813 , H04L12/947 , H04L29/12
Abstract: The present technology pertains to a system, method, and non-transitory computer-readable medium for orchestrating policies across multiple networking domains. The technology can receive, at a provider domain from a consumer domain, a data request; receive, at the provider domain from the consumer domain, at least one access policy for the consumer domain; translate, at the provider domain, the at least one access policy for the consumer domain into at least one translated access policy understood by the provider domain; apply, at the provider domain, the at least one translated access policy understood by the provider domain to the data request; and send, at the provider domain to the consumer domain, a response to the data request.
-
公开(公告)号:US11838325B2
公开(公告)日:2023-12-05
申请号:US17506553
申请日:2021-10-20
Applicant: Cisco Technology, Inc.
Inventor: Rajagopalan Janakiraman , Sivakumar Ganapathy , Prashanth Matety , Patel Amitkumar Valjibhai
IPC: H04L9/40 , H04L12/46 , H04L12/66 , H04L41/0893 , H04L67/10
CPC classification number: H04L63/20 , H04L12/46 , H04L12/4641 , H04L12/66 , H04L41/0893 , H04L63/0263 , H04L63/101 , H04L67/10 , H04L63/0272
Abstract: Systems, methods, and computer-readable media for elastic policy scaling in multi-cloud fabrics. A method can involve deploying a cluster of policy agents on a hub virtual private cloud (VPC) that interconnects spoke VPCs in a cloud associated with a multi-cloud fabric, and mapping endpoints in the spoke VPCs to the policy agents. The method can involve distributing groups of policies for the endpoints across the policy agents based on the mapping of endpoints to policy agents, and advertising, by each policy agent to a respective first set of virtual gateways in the spoke VPCs, routes associated with endpoints mapped to the policy agent and preventing the policy agent from advertising routes associated with a second set of virtual gateways in the spoke VPCs. The method can involve applying, via the policy agent, a group of policies on the policy agent to traffic received by the policy agent.
-
公开(公告)号:US20210258216A1
公开(公告)日:2021-08-19
申请号:US17244941
申请日:2021-04-29
Applicant: Cisco Technology, Inc.
Inventor: Rajagopalan Janakiraman , Sivakumar Ganapathy , Gianluca Mardente , Giovanni Meo , Patel Amitkumar Valjibhai
IPC: H04L12/24 , H04L12/46 , H04L12/751 , H04L12/715 , H04L12/721
Abstract: Technologies for multi-cloud routing and policy interconnectivity are provided. An example method can include assigning different sets of data plane routers to data plane traffic associated with different address spaces in a cloud site of a multi-cloud fabric to yield a distributed mapping of data plane traffic and data plane routers. The method can further include providing, to an on-premises site in the multi-cloud fabric, routing entries from a control plane router on the cloud site, the routing entries reflecting the distributed mapping and identifying, for each address space, which data plane router handles data plane traffic for that address space; and when a data plane router is deployed at the cloud site, providing, to the on-premises site, updated routing information from the control plane router, the updated routing information identifying the data plane router as a next hop for data plane traffic associated with a respective address space.
-
公开(公告)号:US20200382471A1
公开(公告)日:2020-12-03
申请号:US16426336
申请日:2019-05-30
Applicant: Cisco Technology, Inc.
Inventor: Rajagopalan Janakiraman , Sivakumar Ganapathy , Azeem Suleman , Mohammed Javed Asghar , Patel Amitkumar Valjibhai , Ronak K. Desai
IPC: H04L29/06 , H04L12/721 , H04L29/12 , H04L29/08 , H04L12/46
Abstract: Technologies for extending a subnet across on-premises and cloud-based deployments are provided. An example method may include creating a VPC in a cloud for hosting an endpoint being moved from an on-premises site. For the endpoint to retain its IP address, a subnet range assigned to the VPC, based on the smallest subnet mask allowed by the cloud, is selected to include the IP address of the endpoint. The IP addresses from the assigned subnet range corresponding to on-premises endpoints are configured as secondary IP addresses on a Layer 2 (L2) proxy router instantiated in the VPC. The L2 proxy router establishes a tunnel to a cloud overlay router and directs traffic destined to on-premises endpoints, with IP addresses in the VPC subnet range thereto for outbound transmission. The cloud overly router updates the secondary IP addresses on the L2 proxy router based on reachability information for the on-premises site.
-
公开(公告)号:US20220239559A1
公开(公告)日:2022-07-28
申请号:US17719792
申请日:2022-04-13
Applicant: Cisco Technology, Inc.
Inventor: Rajagopalan Janakiraman , Sivakumar Ganapathy , Gianluca Mardente , Giovanni Meo , Patel Amitkumar Valjibhai
IPC: H04L41/0816 , H04L12/46 , H04L41/0806 , H04L41/0893 , H04L45/02 , H04L45/00 , H04L45/44
Abstract: Technologies for multi-cloud routing and policy interconnectivity are provided. An example method can include assigning different sets of data plane routers to data plane traffic associated with different address spaces in a cloud site of a multi-cloud fabric to yield a distributed mapping of data plane traffic and data plane routers. The method can further include providing, to an on-premises site in the multi-cloud fabric, routing entries from a control plane router on the cloud site, the routing entries reflecting the distributed mapping and identifying, for each address space, which data plane router handles data plane traffic for that address space; and when a data plane router is deployed at the cloud site, providing, to the on-premises site, updated routing information from the control plane router, the updated routing information identifying the data plane router as a next hop for data plane traffic associated with a respective address space.
-
公开(公告)号:US11329876B2
公开(公告)日:2022-05-10
申请号:US17244941
申请日:2021-04-29
Applicant: Cisco Technology, Inc.
Inventor: Rajagopalan Janakiraman , Sivakumar Ganapathy , Gianluca Mardente , Giovanni Meo , Patel Amitkumar Valjibhai
IPC: G06F15/177 , H04L41/0816 , H04L12/46 , H04L41/0806 , H04L41/0893 , H04L45/02 , H04L45/00 , H04L45/44
Abstract: Technologies for multi-cloud routing and policy interconnectivity are provided. An example method can include assigning different sets of data plane routers to data plane traffic associated with different address spaces in a cloud site of a multi-cloud fabric to yield a distributed mapping of data plane traffic and data plane routers. The method can further include providing, to an on-premises site in the multi-cloud fabric, routing entries from a control plane router on the cloud site, the routing entries reflecting the distributed mapping and identifying, for each address space, which data plane router handles data plane traffic for that address space; and when a data plane router is deployed at the cloud site, providing, to the on-premises site, updated routing information from the control plane router, the updated routing information identifying the data plane router as a next hop for data plane traffic associated with a respective address space.
-
公开(公告)号:US11057350B2
公开(公告)日:2021-07-06
申请号:US16426336
申请日:2019-05-30
Applicant: Cisco Technology, Inc.
Inventor: Rajagopalan Janakiraman , Sivakumar Ganapathy , Azeem Suleman , Mohammed Javed Asghar , Patel Amitkumar Valjibhai , Ronak K. Desai
IPC: H04L29/06 , H04L12/721 , H04L12/46 , H04L29/08 , H04L29/12
Abstract: Technologies for extending a subnet across on-premises and cloud-based deployments are provided. An example method may include creating a VPC in a cloud for hosting an endpoint being moved from an on-premises site. For the endpoint to retain its IP address, a subnet range assigned to the VPC, based on the smallest subnet mask allowed by the cloud, is selected to include the IP address of the endpoint. The IP addresses from the assigned subnet range corresponding to on-premises endpoints are configured as secondary IP addresses on a Layer 2 (L2) proxy router instantiated in the VPC. The L2 proxy router establishes a tunnel to a cloud overlay router and directs traffic destined to on-premises endpoints, with IP addresses in the VPC subnet range thereto for outbound transmission. The cloud overly router updates the secondary IP addresses on the L2 proxy router based on reachability information for the on-premises site.
-
9.
公开(公告)号:US20200280587A1
公开(公告)日:2020-09-03
申请号:US16289647
申请日:2019-02-28
Applicant: Cisco Technology, Inc.
Inventor: Rajagopalan Janakiraman , Ronak K. Desai , Sivakumar Ganapathy , Mohammed Javed Asghar , Azeem Suleman , Patel Amitkumar Valjibhai
Abstract: Systems, methods, and computer-readable media for policy splitting in multi-cloud fabrics. In some examples, a method can include discovering a path from a first endpoint in a first cloud to a second endpoint in a second cloud; determining runtime policy table capacities associated with nodes in the path; determining policy distribution and enforcement for traffic from the first endpoint to the second endpoint based on the runtime policy table capacities; based on the policy distribution and enforcement, installing a set of policies for traffic from the first endpoint to the second endpoint across a set of nodes in the path; and applying the set of policies to traffic from the first endpoint in the first cloud to the second endpoint in the second cloud.
-
10.
公开(公告)号:US11165828B2
公开(公告)日:2021-11-02
申请号:US16289647
申请日:2019-02-28
Applicant: Cisco Technology, Inc.
Inventor: Rajagopalan Janakiraman , Ronak K. Desai , Sivakumar Ganapathy , Mohammed Javed Asghar , Azeem Suleman , Patel Amitkumar Valjibhai
Abstract: Systems, methods, and computer-readable media for policy splitting in multi-cloud fabrics. In some examples, a method can include discovering a path from a first endpoint in a first cloud to a second endpoint in a second cloud; determining runtime policy table capacities associated with nodes in the path; determining policy distribution and enforcement for traffic from the first endpoint to the second endpoint based on the runtime policy table capacities; based on the policy distribution and enforcement, installing a set of policies for traffic from the first endpoint to the second endpoint across a set of nodes in the path; and applying the set of policies to traffic from the first endpoint in the first cloud to the second endpoint in the second cloud.
-
-
-
-
-
-
-
-
-