发明名称 Virtual private network (VPN)-aware customer premises equipment (CPE) edge router
摘要 A network architecture includes a communication network that supports one or more network-based Virtual Private Networks (VPNs). The communication network includes a plurality of boundary routers that are connected by access links to CPE edge routers belonging to the one or more VPNs. To prevent traffic from outside a customer's VPN (e.g., traffic from other VPNs or the Internet at large) from degrading the QoS provided to traffic from within the customer's VPN, the present invention gives precedence to intra-VPN traffic over extra-VPN traffic on each customer's access link through access link prioritization or access link capacity allocation, such that extra-VPN traffic cannot interfere with inter-VPN traffic. Granting precedence to intra-VPN traffic over extra-VPN traffic in this manner entails partitioning between intra-VPN and extra-VPN traffic on the physical access link using layer 2 multiplexing and configuration of routing protocols to achieve logical traffic separation between intra-VPN traffic and extra-VPN traffic at the VPN boundary routers and CPE edge routers. By configuring the access networks, the VPN boundary routers and CPE edge routers, and the routing protocols of the edge and boundary routers in this manner, the high-level service of DoS attack prevention is achieved.
申请公布号 US6778498(B2) 申请公布日期 2004.08.17
申请号 US20010023331 申请日期 2001.12.17
申请人 MCI, INC. 发明人 MCDYSAN DAVID E.
分类号 H04L12/56;H04L12/14;H04L12/24;H04L12/46;H04L29/06;H04L29/08;H04L29/12;H04M3/22;H04M3/42;H04M3/436;H04M3/46;H04M7/00;H04M15/00;H04Q3/00;H04Q7/38;H04W12/12;(IPC1-7):H04J3/14;H04L12/66 主分类号 H04L12/56
代理机构 代理人
主权项
地址