Invention Grant
- Patent Title: Migrating a network to tunnel-less encryption
- Patent Title (中): 将网络迁移到无隧道加密
-
Application No.: US12337315Application Date: 2008-12-17
-
Publication No.: US08307423B2Publication Date: 2012-11-06
- Inventor: W. Scott Wainner , Brian E. Weis
- Applicant: W. Scott Wainner , Brian E. Weis
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Hickman Palermo Truong Becker Bingham Wong LLP
- Main IPC: G06F9/00
- IPC: G06F9/00

Abstract:
A method comprises, in a network comprising VPN gateway devices configured only for plaintext data communication, configuring a policy server with a security policy including DO NOT ENCRYPT statements temporarily overriding PERMIT statements defining which packets should be encrypted; selecting one sub-group of the VPN gateway devices in which tunnel-less encryption is not configured; configuring of the VPN gateway devices in the sub-group for tunnel-less encryption by: configuring each device in a passive mode of operation in which the device is configured to receive either encrypted packets or plaintext packets matching encryption policy; configuring local DO NOT ENCRYPT statements matching traffic that is currently being converted to ciphertext; removing, from the access control list of the policy server, DO NOT ENCRYPT statements referring to protected LAN CIDR blocks behind the VPN gateway devices in the selected sub-group; configuring the sub-group to send encrypted packets by removing, from each of the VPN gateway devices in the selected sub-group, the local DO NOT ENCRYPT statements for the CIDR blocks currently being converted and protected by the selected sub-group; repeating the configuring each of the VPN gateway devices in the selected sub-group for tunnel-less encryption, and the configuring the sub-group to send encrypted packets, for each other one of the sub-groups; and removing the passive mode on each of the VPN gateway devices.
Public/Granted literature
- US20100154028A1 MIGRATING A NETWORK TO TUNNEL-LESS ENCRYPTION Public/Granted day:2010-06-17
Information query