发明名称 SYSTEM, METHOD AND APPARATUS THAT ISOLATE VIRTUAL PRIVATE NETWORK (VPN) AND BEST EFFORT TRAFFIC TO RESIST DENIAL OF SERVICE ATTACKS
摘要 <p>A network architecture (20) in accordance with the present invention includes a communication network that supports one or more network-based Virtual Private Networks (VPNs). The communication network includes a plurality of boundary routers (22a-22d) that are connected by access links to CPE edge routers (24b-24d and 25a-25d) belonging to the one or more VPNs. To prevent traffic from outside a customer's VPN (e.g., traffic from other VPNs or the Internet at large) from degrading the QoS provided to traffic from within the customer's VPN, the present invention gives precedence to intra-VPN traffic over extra-VPN traffic on each customer's access link through access link prioritisation or access link capacity allocation, such that extra-VPN traffic can not interfere with inter-VPN traffic.</p>
申请公布号 WO2002076029(A1) 申请公布日期 2002.09.26
申请号 US2002008345 申请日期 2002.03.20
申请人 发明人
分类号 主分类号
代理机构 代理人
主权项
地址