发明名称 Method and apparatus for learning endpoint addresses of IPSec VPN tunnels
摘要 Customer Edge (CE) network elements can automatically learn IPSec tunnel endpoints for other CEs connected to sites in a Virtual Private Network (VPN) so that manual configuration of IPSec tunnel endpoints is not required and so that a centralized database of IPSec tunnel endpoints is not required to be separately maintained. According to an embodiment of the invention, a BGP export route policy is set on all CEs, so that when they announce their VPN routes in the standard format, the application of this export route policy changes the announcement to replace the BGP peering point address that would ordinarily be advertised with the IPSec tunnel endpoint address. When any given site receives a VPN route update formatted in this manner, it processes the VPN route update and learns from the update the IPSec tunnel endpoint as well as the associated VPN routes.
申请公布号 US2008080509(A1) 申请公布日期 2008.04.03
申请号 US20060540104 申请日期 2006.09.29
申请人 NORTEL NETWORKS LIMITED 发明人 KHANNA BAKUL;CHAO JOHN;JESURAJ RAMASAMY;LEE ROBERT
分类号 H04L12/56 主分类号 H04L12/56
代理机构 代理人
主权项
地址