Virtual interworking trunk interface and method of operating a universal virtual private network device
Granted 23 Dec 2008 · 4 office actions
Current assignee: Shopify Inc. · originally AT&T Company
Law firm: Law firm · Log in to unlock
Attorney: Attorney · Log in to unlock
Inventors: Kuo-Hui Liu, Chin Yuan · Examiner: Hanh Nguyen · AU 2416 · TC 2400
Life of the application
20 dated eventsAbstract
The present invention relates generally to a data communication system, a virtual interworking trunk interface within a device to form a universal virtual private network, and methods of operating a virtual private network. In a particular embodiment, the data communication system includes a first portion of a virtual private network, a second portion of the virtual private network, a virtual switch instance associated with the first portion of the virtual private network, a virtual router instance associated with the second portion of the virtual private network, and a virtual interworking trunk interface coupled to the virtual switch instance and to the virtual router instance.
Description
6 parts›FIELD OF THE INVENTION
The present invention relates generally to a virtual interworking trunk interface and a method of operating a virtual private network.
›BACKGROUND
In today's networking environment, there are data service customers that have equipment at many different business sites and at various locations. All of the customer's equipment may be networked by the service provider. Some of the sites may be interconnected via an internet protocol (IP) virtual private network (VPN) service (a layer 3 VPN), and other sites are interconnected through an Ethernet-based layer 2 VPN VPLS (virtual private LAN service). Regardless of the specific interconnecting technology, from the customer perspective, there is only a single virtual private network that is dedicated to the customer. To provide the customer with a single VPN view, interworking is required between the two VPNs. In addition, each of the different VPN types have both positive and negative attributes. For example, while Ethernet-based layer 2 networks provide plug-and-play advantages, it is not as scalable as IP-VPN networks and requires fiber-based transport. As another example, with layer 3 IP-VPN networks, operational scalability is hampered due to IP routing configuration requirements for each IP interface and close coordination required between service providers and customers.
Accordingly, there is a need for an interworking mechanism between layer 2 and layer 3 VPN networks and for an improved method of operating a virtual private network. However, in today's implementation, an external interworking trunk is required to interconnect a layer 2 VPN device and a layer 3 VPN device. There is no device that has implemented a mechanism to perform this interworking function inside a box. The present disclosure is intended to address this issue.
›SUMMARY
The present disclosure relates generally to a data communication system, a virtual interworking trunk interface within a device to form a universal virtual private network, and methods of operating a virtual private network. In a particular embodiment, the data communication system includes a first portion of a virtual private network, a second portion of the virtual private network, a virtual switch instance associated with the first portion of the virtual private network, a virtual router instance associated with the second portion of the virtual private network, and a virtual interworking trunk interface coupled to the virtual switch instance and to the virtual router instance.
In another embodiment, a virtual interworking trunk interface within a virtual private network is disclosed. The virtual interworking trunk interface includes a first virtual interface to a virtual switch instance associated with a first portion of the virtual private network, and a second virtual interface to a virtual router instance associated with a second portion of the virtual private network.
In another embodiment, the method of operating a virtual private network includes receiving data to be communicated at a virtual switch instance associated with a first portion of the virtual private network, forwarding the data to a virtual interworking trunk interface coupled to the virtual switch instance, and forwarding the data from the virtual interworking trunk interface to a virtual router instance associated with a second portion of the virtual private network.
In another embodiment, the method of operating a virtual private network includes receiving data to be communicated at a virtual router instance associated with a second portion of the virtual private network, forwarding the data to a virtual interworking trunk interfaced coupled to the virtual router instance, and forwarding the data from the virtual interworking trunk interface to a virtual switch instance associated with a first portion of the virtual private network.
›BRIEF DESCRIPTION OF THE DRAWINGS
FIG. 1 is a general diagram of a universal virtual private network.
FIG. 2 is general diagram that further illustrates the universal virtual private network of FIG. 1 .
FIG. 3 is a general diagram that further illustrates the universal virtual private network of FIG. 1 .
FIG. 4 is a flow chart that illustrates operation of a virtual private network.
FIG. 5 is a flow chart that illustrates operation of a virtual private network.
FIG. 6 is a flow chart that illustrates further detailed operation of an interface to a virtual router instance of a virtual private network.
FIG. 7 is a flow chart that illustrates further detailed operation of an interface to a virtual switch instance of a virtual private network.
The use of the same reference symbols in different drawings indicates similar or identical items.
›DETAILED DESCRIPTION OF THE FIGURES · 1 of 2
Referring to FIG. 1 , a particular embodiment of a universal virtual private network (VPN) 102 is disclosed. The virtual private network 102 has a first portion 106 and a second portion 104 . The first portion 106 of the VPN 102 is a Layer 2 network and the second portion 104 of the VPN 102 is a layer 3 network. The first portion 106 is an Ethernet-based switching network, and the second portion 104 is an internet protocol (IP) network. The first portion 106 of the VPN 102 includes a virtual switch instance (VSI) 112 which is coupled to a first set of customer equipment, such as CE 4 140 , CE 5 142 , and CE 6 144 . The second portion 104 of the VPN 102 includes a virtual router interface (VRI) 110 , which is coupled to a second set of customer equipment CE 1 130 , CE 2 132 , and CE 3 134 . The virtual switch instance 112 is coupled to the virtual router instance (VRI) 110 via a virtual interworking trunk (VIT) 114 . The virtual switch instance 112 is coupled to the virtual interworking trunk 114 via a first virtual interface 118 , and the virtual router instance is coupled to the virtual interworking trunk 114 via a second virtual interface 116 . The second virtual interface 116 on the VRI 110 is treated no differently from other terminated interfaces from the perspective of the customer equipment 130 , 132 and 134 within the second portion 104 of the virtual private network 102 . Similarly, the first virtual interface 118 on the VSI 112 is treated in a similar manner as other terminated interfaces from the perspective of the customer equipment 140 , 142 , and 144 , within the first portion 106 of the virtual private network 102 . The VRI 110 , the VSI 112 , and the VIT 114 may be included within a provider edge (RE) device 108 . In a particular illustrative embodiment, a data communication system may be provided that may include a first portion of the VPN 102 , a second portion of the VPN 102 , the VSI 112 associated with the first portion of the VPN 102 , the VRI 110 associated with the second portion of the VPN 102 , and the VIT interfaces 116 and 118 coupled to the VSI 112 and to the VRI 110 within the PE device 108 .
Referring to FIG. 2 , a portion 200 of a virtual private network is illustrated. In this particular illustrated embodiment, the second virtual interface 116 on the VRI 110 represents the internet protocol (IP) subnet of the virtual switch instance (VSI) in the VPLS cloud. The VPLS network is illustrated as LAN 202 in FIG. 2 . Thus, an equivalent internet protocol virtual private network (IP-VPN) corresponding to a portion of VPN 102 , is illustrated.
Referring to FIG. 3 , further details regarding the first virtual interface 118 on the VSI 112 is illustrated. The first virtual interface 118 on the VSI 112 represents an attached shared virtual customer equipment node 302 , which includes all of the customer equipment (CE 1 , CE 2 , CE 3 ) on the particular VRI 110 . Thus, FIG. 3 illustrates an equivalent VPLS network corresponding to a portion of VPN 102 .
Referring to FIG. 4 , a method of operating a virtual private network is illustrated. The method describes data transfer for data that begins at the first portion 106 of the VPN 102 and is passed to the second portion 104 of the VPN 102 over the virtual interworking trunk 114 . Data to be communicated is received at a virtual switch instance, such as VSI 114 of a first portion 106 of a VPN 112 , at 402 . The received data is forwarded based on a medium access control (MAC) table lookup to a virtual interworking trunk interface, at 404 . The data from the virtual interworking trunk interface is forwarded to a virtual router instance of a second portion of the VPN, at 406 . For example, the virtual interworking trunk interface may be virtual interworking trunk interface 116 on the VRI 110 .
Referring to FIG. 5 , a method of operating the VPN 102 where data is communicated from the second portion 104 of the VPN 102 to the first portion 106 of the VPN 102 is illustrated. Data to be communicated at a virtual router instance of a second portion of the VPN is received, at 502 . The received data is forwarded, based on a routing table lookup, to a virtual interworking trunk interface, at 504 . A routing table 508 is present and can be accessed at step 504 of the method in order to obtain an entry to determine proper routing of the data. The data from the virtual interworking trunk interface is forwarded to a virtual switch instance of a first portion of the VPN, at 506 . In a particular example, the virtual interworking trunk interface may be the first interface 118 on the virtual switch instance 112 .
Referring to FIG. 6 , operation of the virtual private network 102 will be described. An IP address and a Psuedo MAC address is assigned to the virtual interworking trunk interface, at 602 . IP to MAC mapping is then performed at the virtual router instance interface of the virtual interworking trunk, at 604 in order to communicate with CE 4 140 , CE 5 142 , and CE 6 144 . IP routing/forwarding is performed at the VRI virtual interface of the virtual interworking trunk, at 606 in order to communicate with CE 1 130 , CE 2 132 , and CE 3 134 . Optional enhanced functions may also be performed including bandwidth control of the virtual interworking trunk and quality of service translation and management between layer 3 and layer 3 VPNs, at 608 .
Referring to FIG. 7 , a method of operating at a virtual interface of the VSI instance is illustrated. MAC learning and layer 2 frame forwarding is performed at the VSI interface of the virtual interworking trunk, at 702 . MAC forwarding is performed at 704 . Optional enhanced functions may also be performed including bandwidth control and quality of service translation and management, at 706 .
The disclosed virtual private network system and method of operation has many benefits. For example, the disclosed system provides cost savings for the service provider when interworking between layer 2 and layer 3 networks. The system saves at least 2 physical ports and the associated transport facility by removing the requirement for a physical interworking trunk. The disclosed system also provides cost savings for the customer because each customer site can be connected to a nearest service provider point of presence using layer 2 or layer 3 VPN depending on availability. Instead of back-hauling to a specific point of presence to access specialized layer 2 or layer 3 equipment, in this scenario interworking can be performed at the best chosen point in the network. The disclosed system further offers service providers a flexible and scalable method to enhance their VPN services by using a hybrid layer 2 /layer 3 VPN.
›DETAILED DESCRIPTION OF THE FIGURES · 2 of 2
VPN customers are also provided a flexible solution to integrate and scale their VPNs in a manner that takes into account support for legacy networks, such as routers that cannot be configured as bridged interfaces and various technologies to handle bridging layer 2 and layer 3 VPNs. In addition, the disclosed system provides a benefit that customers do not need to change their existing customer equipment router configurations when such routers join VPNs. Thus, the amount of routing configuration coordination between customers and the service provider is advantageously reduced. Accordingly, the disclosed system and method provides a cost effective solution to effectively combine advantages of Ethernet based layer 2 VPN and layer 3 IP-VPN, while avoiding several of their disadvantages.
The above disclosed subject matter is to be considered illustrative, and not restrictive, and the appended claims are intended to cover all such modifications, enhancements, and other embodiments which fall within the true spirit and scope of the present invention. Thus, to the maximum extent allowed by law, the scope of the present invention is to be determined by the broadest permissible interpretation of the following claims and their equivalents, and shall not be restricted or limited by the foregoing detailed description
Claims as granted
36 claimsLog in to read the claims of this application.
Log in to unlockClassifications
10 codes- H04L29/06
- H04L12/56
- H04L12/46
- H04L12/28
- H04L12/66
Claim changes
SoonSee which claims were amended, added or cancelled during examination, with every added and removed word marked.
The published claims of this application are not paired with the granted ones in what we hold.
File wrapper
See the full prosecution history — every USPTO and applicant action on this file, in order.
Log in to unlockDocuments
Log in to open the documents of this file: the application as filed, every office action and response, the notice of allowance.
Log in to unlockChain of title
See the full assignment history — every owner this patent has passed through, with recordation dates and reel/frame numbers.
Log in to unlock