Method and system for controlling network equipment at main network equipment
By managing the WAN interfaces of secondary network devices through the primary network device, establishing virtual network interfaces and data tunnels, the problem of resource mismatch during network device upgrades is solved, achieving efficient network performance monitoring and resource utilization, and reducing upgrade costs.
Patent Information
- Application Number
- CN202410766737.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-05-17
- Filing Date
- 2024-06-13
- Publication Date
- 2025-11-18
AI Technical Summary
When upgrading existing network equipment, the lack of centralized control and management leads to uncoordinated network resource allocation, making it difficult to effectively monitor network performance, identify bottlenecks, and optimize resource utilization, and replacement costs are high.
By managing and controlling the WAN interfaces of secondary network devices through the primary network device, virtual network interface connections and data tunnels are established to enable network configuration and data packet transmission for secondary network devices, utilizing the bi-directional relationship between the WAN interface groups of the primary network device and the WAN interface groups of the secondary network device.
It enables centralized management and control of secondary network devices, improves network performance monitoring and resource utilization efficiency, and reduces upgrade costs.
Smart Images

Figure CN120979929A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates generally to network communications. More specifically, the present application relates to a network device utilizing a wide area network (WAN) interface of another network device. BACKGROUND
[0002] Network devices enable connectivity and facilitate Internet access for local devices. As technology advances, connectivity standards and hardware also rapidly evolve to meet the needs of current applications. This requires periodic updates to the firmware and hardware of network devices. While users can find upgrading firmware to be a relatively simple task, the cost associated with replacing devices remains an important consideration.
[0003] When upgrading hardware, it can be costly for a user to always replace an existing network device with a first new network device that has only one or two new features.
[0004] For example, a company deploys a network environment for its employees using a router equipped with two Ethernet WAN interfaces. However, as technology continues to evolve, the company needs to use a cellular WAN interface. The company can consider replacing the existing network device with a first new network device equipped with a cellular module, but this replacement can be costly.
[0005] As an alternative, the company can purchase a second new network device that has limited functionality but includes a cellular module, and connect the second new network device to the existing network device. Since the second new network device with the desired cellular module has only limited functionality, it is typically much less expensive than the first new network device. By integrating the second new network device with limited functionality, including the desired cellular module, into the original network environment, the user can reduce the cost of upgrading while still achieving the desired improvement. In addition, the ability to utilize more WAN resources is always beneficial, whether or not the connections are bound together using binding technology, because it increases the bandwidth and throughput of the overall connection.
[0006] However, in this alternative, the network configurations of the second new network device and the existing network device are independently managed and controlled. The lack of centralized control limits visibility and coordination, making it difficult to effectively monitor network performance, identify bottlenecks, and optimize resource utilization. When network resources lack coordinated, integrated management, it can result in inefficiencies, decreased performance, and potential challenges to maintaining a stable and optimized network environment.
[0007] Accordingly, the present application provides a method and system for managing and controlling at least one secondary network device from a primary network device, and further utilizing a WAN interface of the at least one secondary network device to transmit data packets to an interconnected network. SUMMARY
[0008] A method for a master network device to control and manage network configuration of a secondary network device while utilizing a WAN interface of the secondary network device is disclosed. The master network device can connect to at least one secondary network device through a first link and establish a first connection. The master network device can further establish a second connection and a third connection through the first link for controlling and managing the secondary network device and data packet transmission, respectively. The second connection and the third connection are established on a virtual network interface.
[0009] According to one of the embodiments of the present application, a data tunnel can be further established. The established data tunnel group has a bijective relationship with the WAN interface group of the secondary network device. The network interface for establishing the tunnel and the network interface for establishing the connection can apply different subnets. Therefore, data packets can be transmitted through the corresponding tunnel to utilize a specific WAN interface and further transmitted to an interconnection network.
[0010] According to one of the embodiments of the present application, the WAN interface of the master network device or the WAN interface of the at least one secondary network device can be selected according to a policy to transmit the data packets to an interconnection network.
[0011] According to one of the embodiments of the present application, each WAN interface of the master network device or each WAN interface of the at least one secondary network device can be a local area network (LAN) interface performing the same function as the WAN interface. BRIEF DESCRIPTION OF DRAWINGS
[0012] Figure 1A is a schematic diagram of a master network device according to an embodiment of the present application.
[0013] Figure 1B is a schematic diagram of a secondary network device according to an embodiment of the present application.
[0014] Figure 2A is a schematic diagram of an exemplary network environment according to an embodiment of the present application.
[0015] Figure 2B is a schematic block diagram of another exemplary network environment according to an embodiment of the present application.
[0016] Figure 2C is a schematic block diagram of another exemplary network environment according to an embodiment of the present application.
[0017] Figure 3A is a flowchart of a method performed by a master network device according to an embodiment of the present application.
[0018] Figure 3Bis a flowchart illustrating a method performed by a secondary network device according to embodiments of the present invention.
[0019] Figure 4 is a block diagram illustrating a packet structure during transmission of a data packet according to embodiments of the present invention.
[0020] Figure 5 is a network configuration of a network device according to embodiments of the present invention.
[0021] Figure 6A is a flowchart illustrating steps performed between a primary network device and a secondary network device according to embodiments of the present invention.
[0022] Figure 6B is a flowchart illustrating another set of steps performed between a primary network device and a secondary network device according to embodiments of the present invention.
[0023] Figure 7 is an exemplary network environment according to various embodiments of the present invention.
[0024] Figure 8 is an exemplary graphical user interface of a primary network device according to embodiments of the present invention. DETAILED DESCRIPTION
[0025] The terminology used in the present description is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments of the present invention. In this description, the singular forms "a," "an," and "the" include plural referents unless the context clearly dictates otherwise. In this description, the terms "and / or" and "at least one of" include any and all combinations of one or more of the associated listed items. Expressions such as "at least one of," when preceding a list of two or more items, cover all of the individual items in the list and any combination of two or more individual items. The term "includes" means inclusion by reference, without limitation to, the listed items, and does not exclude the presence or addition of one or more other items. Furthermore, the term "exemplary" is intended to mean an example, rather than an ideal.
[0026] Although the processes, steps, methods, algorithms etc. described in this specification can be described in a sequential order, some of the procedures, steps, methods, algorithms etc. can be configured to be performed in an alternative order. In other words, any sequence or order of steps described in this specification does not, of itself, constitute an inherent requirement of the steps described. The described processes, steps, methods, algorithms etc. can be performed in any practical order.
[0027] When an element is referred to as being "connected", "linked", or "coupled" to another element, it can be directly connected or linked to the other element or joined thereto by way of another element. In contrast, when an element is referred to as being "directly connected", "directly linked", or "directly coupled" to another element, it should be understood that there are no intervening elements.
[0028] The terms "non-transitory computer-readable storage medium", "computer-readable medium", "main storage", "secondary storage medium", or "other storage medium" as used herein refers to any medium that participates in providing instructions to a processing unit for execution. A processing unit reads data from a main storage medium and writes data to a secondary storage medium. Thus, even if the data written to the main storage medium is lost due to a related factor such as a momentary power loss, the data can be recovered by transferring the data saved in the secondary storage medium to the main storage medium. A computer-readable medium is merely one example of a machine-readable medium that can carry instructions for implementing any one of the methods and / or techniques described herein. Such a medium can take many forms, including but not limited to, non-volatile media, volatile media, and transmission media. Non-volatile media includes, for example, optical or magnetic disks and the like. Volatile media includes dynamic memory, such as system
[0029] A volatile storage device can be used to store temporary variables or other intermediate information during execution of instructions by a processing unit. A non-volatile storage device or static storage device can be used to store static information and instructions for the processing unit, and different system configurations parameters.
[0030] The storage medium can include a number of software modules, which can implement the software code to be executed by the processing unit using any suitable computer instruction type. The software code can be stored as a series of instructions or commands, or as a program in the storage medium.
[0031] Various forms of computer-readable media can be involved in carrying one or more sequences of one or more instructions to the processor for execution. For example, the instructions can initially be carried on a magnetic disk of a remote computer. Alternatively, a remote computer can load the instructions into its dynamic memory and send the instructions to the system over a telephone line, e.g., using a modem. A remote computer can load the instructions into its dynamic memory and send the instructions to the system over a telephone line, e.g., using a modem.
[0032] The processing unit can be a microprocessor, a microcontroller, a Digital Signal Processor (DSP), any combination of the foregoing, or any other circuitry configured to process information.
[0033] The processing units execute program instructions or code segments for implementing embodiments of the present application. Furthermore, embodiments can be implemented by hardware, software, firmware, middleware, microcode, hardware description languages, or any combination thereof. When implemented in software, firmware, middleware or microcode, the program instructions for carrying out necessary tasks can be stored in a computer readable storage medium. The processing units can be implemented by virtualization and can be virtual processing units, including virtual processing units in cloud-based instances.
[0034] The techniques described in this specification can be used for various wireless communication networks such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-Carrier Frequency Division Multiple Access (SC-FDMA) and other networks. The terms "network" and "system" are often used interchangeably. A CDMA network can implement a radio technology such as Universal Terrestrial Radio Access (UTRA), cdma2000, and so on. UTRA includes Wideband-CDMA (W-CDMA) and other variants of CDMA. cdma2000 covers IS-2000, IS-95 and IS-856 standards. A TDMA network can implement a radio technology such as Global System for Mobile Communications (GSM). An OFDMA network can implement a radio technology such as Evolved UTRA (E-UTRA), Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Flash-OFDMA, and so on. UTRA and E-UTRA are part of Universal Mobile Telecommunication System (UMTS). 3GPP Long Term Evolution (LTE) is a release of UMTS that uses E-UTRA, which employs OFDMA on the downlink and SC-FDMA on the uplink. UTRA, E-UTRA, UMTS, LTE, 5G, and GSM are described in the documents from the organization "3rd Generation Partnership Project" (3GPP). CDMA2000 and UMB are described in the documents from the organization "3rd Generation Partnership Project 2" (3GPP2).
[0035] In this specification, a "tunnel" is a communication channel between two network devices that transports data by encapsulating Internet Protocol (IP) packets of data according to any suitable encryption tunneling protocol. A network device can be any electronic device, client, server, peer, service, application, or other object capable of sending, receiving, or forwarding information over a communication channel in a network. Encryption tunneling protocols include, but are not limited to, Internet Protocol security (IPsec), Secure Socket Layer / Transport Layer Security (SSL / TLS), Datagram Transport Layer Security (DTLS), Microsoft Point-to-Point Encryption (MPPE), and Secure Shell (SSH).
[0036] Figure 1A is a schematic diagram of a primary network device according to an embodiment of the present application. The primary network device 100 includes a processing unit 101, a main memory unit 102, a storage unit 103, and a plurality of network interfaces, such as network interfaces 104a, 104b,..., 104n (collectively referred to as network interfaces 104). The processing unit 101 can be directly connected to the main memory unit 102, and can be connected to other hardware components, such as the storage unit 103 and the network interfaces 104, through a bus 105. However, in some exemplary scenarios, the processing unit 101 can be directly connected to some peripheral hardware components when the processing unit 101 has enough pins; thus, a bus can not be used. The processing unit 101 can execute program instructions or code segments stored in the main memory unit 102 for implementing exemplary embodiments of the present application.
[0037] Figure 1B is a schematic diagram of a secondary network device according to an embodiment of the present application. The secondary network device 110 includes a processing unit 111, a main memory unit 112, a storage unit 113, and a plurality of network interfaces, such as network interfaces 114a, 114b,..., 114n (collectively referred to as network interfaces 114). The processing unit 111 can be directly connected to the main memory unit 112, and can be connected to other hardware components, such as the storage unit 113 and the network interfaces 114, through a bus 1115. In some exemplary scenarios, similar to the primary network device 100, the processing unit 111 can be directly connected to some peripheral hardware components.
[0038] The type of network interface of the primary network device 100 and the secondary network device 110 is not limited. Each of the network interfaces 104, 114 can be a LAN interface or a WAN interface connected to at least one antenna and can function as an interface for a LAN or a WAN.
[0039] In a variant, the WAN interface of the primary network device can perform the same function as the LAN interface.
[0040] In another variant, the LAN interface of the primary network device can perform the same function as the WAN interface.
[0041] In a variant, the WAN interface of the secondary network device can perform the same function as the LAN interface.
[0042] In another variant, the LAN interface of the secondary network device can perform the same function as the WAN interface.
[0043] In a variant, the primary network device 100 and the secondary network device 110 can also comprise at least one wireless communication module (WCM) to communicate over a cellular network using a subscriber identity module (SIM) or an embedded Universal Integrated Circuit Card (eUICC).
[0044] Figures 2A-2C is a series of schematic block diagrams illustrating exemplary network environments according to embodiments of the present application. The primary network devices 200 and 210 exhibit similar functionality to the primary network device 100. The secondary network devices 220, 230, and 240 exhibit similar functionality to the secondary network device 110. The interconnection network 260 can be a public network, a private network, or a combination of both, such as an intranet, an extranet, or the Internet.
[0045] Figure 2A is a series of schematic block diagrams illustrating exemplary network environments according to embodiments of the present application. The primary network devices 200 and 210 exhibit similar functionality to the primary network device 100. The secondary network devices 220, 230, and 240 exhibit similar functionality to the secondary network device 110. The interconnection network 260 can be a public network, a private network, or a combination of both, such as an intranet, an extranet, or the Internet. Figure 2A includes a primary network device 200 and a secondary network device 220. The primary network device 200 includes at least one LAN interface, such as the LAN interfaces 211 and 212, and at least one WAN interface, such as the WAN interface 213. The secondary network device 220 can include network interfaces, such as the LAN interface 221 and the WAN interface 222. The primary network device 200 can be connected to the secondary network device 220 via a first link connected between the WAN interface 213 and the LAN interface 221. The secondary network device 220 can be connected to the interconnection network 260 using the WAN interface 222.
[0046] There is no limitation on the type of LAN and WAN interfaces of the primary network device 200. Each of the LAN and WAN interfaces can be a wired or wireless interface. Each LAN interface of the primary network device 200 can be a LAN interface that performs the same function as a WAN interface, and each WAN interface of the primary network device 200 can be a WAN interface that performs the same function as a LAN interface.
[0047] There is also no limitation on the type of first link established between the network interfaces. The first link can be WiFi, an Ethernet cable, fiber optic, cellular, satellite connection, etc.
[0048] Figure 2B is a schematic block diagram of another exemplary network environment depicted in accordance with an embodiment of the present application. Figure 2B includes a primary network device 210, a secondary network device 220, and a secondary network device 230. The primary network device 210 is similar to the primary network device 200 shown in Figure 2A but further includes WAN interfaces 214 and 215. The secondary network device 230 can include LAN interfaces 231 and 232, and WAN interfaces 233, 234, and 235. The secondary network device 230 can be connected to the interconnecting network 260 through WAN interfaces 233 and 234 with respective links. The primary network device 210 can be connected to the secondary network device 230 via a first link connecting between WAN interface 214 and LAN interface 231, and to the interconnecting network 260 through WAN interface 215 with another first link.
[0049] In one variation, some local devices can be directly connected to a secondary network device (e.g., the secondary network device 230 shown in Figure 2B ) through a LAN interface (e.g., LAN interface 232) of the secondary network device. The secondary network device can normally route packets received from these local devices when performing the steps disclosed in the present application.
[0050] In another variation, in addition to the LAN interface used for the first link, the secondary network device can disable the LAN interface or use the LAN interface as a network interface when allowing the primary network device to manage and control the network configuration of the secondary network device.
[0051] Figure 2C is a schematic block diagram of another exemplary network environment depicted in accordance with an embodiment of the present application. Similar to Figure 2B , Figure 2C the primary network device 210, the secondary network device 220, and the secondary network device 230 are shown. However, the WAN interfaces of the secondary network devices 220 and 230 can be connected to different interconnecting networks. For example, WAN interface 234 is connected to the interconnecting network 260, while WAN interfaces 222 and 233 are connected to the interconnecting network 261.
[0052] Figure 3A is a flowchart illustrating a method performed by a primary network device according to an embodiment of the present application. Figure 3A Should be read in conjunction with Figures 2A-2C .
[0053] Before allowing a local device connected to the primary network device to connect to the inter-network through the WAN interface of the at least one secondary network device, the primary network device can perform the following steps for each of the at least one secondary network device: Figure 3A The method shown.
[0054] In step 301, the primary network device can establish a first link to the at least one secondary network device. The first link can be an Ethernet cable connecting a network interface of the primary network device (hereinafter referred to as "primary network interface") and a network interface of the secondary network device (hereinafter referred to as "secondary network interface"). The primary network interface can be a WAN or LAN interface, while the secondary network interface can also be a WAN or LAN interface. For illustrative purposes, the first link connects the WAN interface 213 of the primary network device 210 and the LAN interface 221 of the secondary network device 220.
[0055] In one variant, both the primary network interface and the secondary network interface support Power over Ethernet (PoE) function. Thus, the primary network device 210 can provide power to the secondary network device 220 through the first link.
[0056] In step 302, a user or administrator of the primary network device 210 can enable a function of managing and controlling the network configuration of the secondary network device 220. For example, the user or administrator can enable the function through a user interface or a command port of the primary network device 210.
[0057] In one variant, the function can be enabled by default without instruction from the user or administrator. Thus, step 303 can be performed without performing step 302.
[0058] In step 303, the primary network device 210 can establish a first connection with the secondary network device 220 through the first link. To establish the first connection, the primary network device 210 can receive a first request from the secondary network device 220 through the first link and send a first reply to reply the first request.
[0059] In one preferred embodiment, the first request can be a Dynamic Host Configuration Protocol (DHCP) discover message, and the first reply can be a DHCP offer message.
[0060] In another embodiment, the first request and the first reply can be Address Resolution Protocol (ARP) request and reply messages, respectively.
[0061] In another embodiment, the first request can be a DHCP request message, and the first reply can be a DHCP acknowledgement (ACK) message.
[0062] In another embodiment, the first request can be a simple request message, and the first reply can be a simple reply message.
[0063] In one variant, the first reply can further include authentication information, such as the authentication information of a digital certificate to be used.
[0064] In another variant, the first request and the first reply can be any combination of the above.
[0065] In another variant, third-party device authentication is required. The master network device 210 can request an acknowledgement from a third device (e.g., a server) before replying to the first request with the first reply. The acknowledgement can be received from the third device if one or more of the following conditions are met: the status of the secondary network device, the subscription of the user, the network configuration, and the result of a whitelist check. If a particular condition is not met, the master network device 210 will not receive the acknowledgement.
[0066] In step 304, after the first connection is established, the master network device 210 can receive a second request from the secondary network device 220 over the first connection.
[0067] In one embodiment, the second request can include device information of the secondary network device 220 selected from one or more of the following: authentication information, network information, configuration, and policy.
[0068] In another embodiment, the authentication information of the secondary network device 220 can be provided by a user or administrator of the master network device 210, such that all or part of the device information can not be included in the second request. For example, the user or administrator can provide the device information according to the factory settings of the secondary network device 220.
[0069] In one variant, the authentication information of the secondary network device 220 is not provided by a user or administrator of the master network device. Instead, the authentication information of the secondary network device 220 is stored in the master network device 210 by default.
[0070] In step 305, the master network device 210 can generate network configuration information for the secondary network device 220 by using the device information of the secondary network device 220. The network configuration information for the secondary network device 220 can include, but is not limited to, one or more of the following: network interfaces, protocols, IP address allocation, virtual local area network (VLAN) configuration, subnet configuration, maximum transmission unit configuration, and port allocation to be used between network interfaces. Details of the network configuration will be discussed later.
[0071] In step 306, the master network device 210 can send a second reply to the secondary network device 220 through the first connection. The second reply can include the network configuration information for the secondary network device 220 to configure its own network configuration.
[0072] In step 307, after disconnecting the first connection, the master network device 210 can establish a second connection through the first link to control and manage the secondary network device 220. The second connection is established between a virtual network interface (hereinafter referred to as "master management interface") created on the master network interface and a virtual network interface (hereinafter referred to as "secondary management interface") created on the secondary network interface.
[0073] In step 308, the master network device 210 can establish a third connection through the first link for packet transmission. More specifically, the third connection is established between a virtual network interface (hereinafter referred to as "master transmission interface") created on the master network interface and a virtual network interface (hereinafter referred to as "secondary transmission interface") created on the secondary network interface. The master transmission interface and the secondary transmission interface are created on top of the network interfaces connected with the first link.
[0074] Since the master management interface and the master transmission interface (collectively referred to as "master interfaces") are created on the master network interface, a reserved IP address can be assigned to each of the master interfaces as a remote IP address for distinction and data transmission. Similarly, since the secondary management interface and the secondary transmission interface (collectively referred to as "secondary interfaces") are created on the secondary network interface, a reserved IP address can be assigned to each of the secondary interfaces as a local IP address for distinction and data transmission. The reserved IP addresses assigned to each of the master interfaces and each of the secondary interfaces are unique.
[0075] There is no limitation on the method or protocol for assigning the reserved IP addresses. For example, the reserved IP addresses can be assigned using automatic private IP addressing (APIPA).
[0076] In one embodiment, the reserved IP address is selected from a pre-designated IP address range and can utilize an address resolution protocol (ARP) process to achieve uniqueness of the private IP address. The pre-designated IP address range is only for communication within the local network and cannot be routed on the Internet.
[0077] In another embodiment, the reserved IP address is randomly selected from a pre-designated IP address range.
[0078] In a preferred embodiment, the pre-designated IP address range is between 168.101.0.0 and 168.101.255.255.
[0079] In another embodiment, the pre-designated IP address range is any private range that anyone can use for any purpose.
[0080] In one variant, the master network device 210 can create a control file for the network configuration information of the secondary network device 220.
[0081] In another variant, the control file can be created by the master network device 210 for the network configuration information of all secondary network devices.
[0082] In one variant, the first connection can perform the same function as the second connection. Thus, the second connection can be equivalent to the first connection, and step 307 is optional. However, the master network device 210 can choose to use the reserved IP address as the remote IP address of the master management interface.
[0083] Figure 3B is a flowchart illustrating a method performed by a secondary network device according to an embodiment of the present application, and Figure 3B should be read in conjunction with Figure 2A -C and Figure 3A for a complete understanding of the present application. For the purpose of illustration, the secondary network device 220 can perform the method shown in Figure 3B .
[0084] In step 310, the secondary network device 220 can establish the first link to the master network device 210.
[0085] In one variant, the secondary network device 220 is being reset before step 310 is performed. There are many reasons for resetting the secondary network device 220, such as minimizing the chance of a crash and reducing the data transfer time of the subsequent steps.
[0086] In another variant, only the network configuration of the secondary network device 220 is reset, instead of the entire device.
[0087] In step 311, the secondary network device 220 can establish the first connection with the primary network device 210 through the first link. To establish the first connection, the secondary network device 220 can send the first request to the primary network device 210 through the first link, and receive the first reply from the primary network device 210 through the first link. If the first reply indicates that the primary network device enables the function of managing and controlling the network configuration of the secondary network device, step 312 can be performed.
[0088] In one variant, when establishing the first connection, a user or an administrator can lock at least one secondary network device to prohibit any modification of the network configuration of the at least one secondary network device except for the modification by the primary network device. More specifically, the locking instruction can be sent with the first reply. The locking can be beneficial for a variety of reasons, such as preventing network configuration conflicts and enhancing security. For example, an identifier (e.g., a string, a security key, or any combination thereof) can be included in the first reply for performing the locking. Accordingly, the at least one secondary network device can perform the locking according to the identifier of the first reply.
[0089] In step 312, after establishing the first connection, the secondary network device 220 can send the second request to the primary network device 210 through the first connection.
[0090] In step 313, the secondary network device 220 can receive the second reply from the primary network device 210 through the first connection.
[0091] In step 314, the secondary network device 220 can configure the network configuration according to the network configuration information in the second reply.
[0092] In step 315, the secondary network device 220 can establish the second connection through the first link according to the network configuration information after disconnecting the first connection.
[0093] In one variant, the first connection can perform the same operation as the second connection. Accordingly, the second connection can be equivalent to the first connection, and step 315 can be optional. However, the secondary network device 220 can choose to use the reserved IP address as the local IP address of the secondary management interface.
[0094] In step 316, the secondary network device 220 can establish the third connection through the first link.
[0095] Figure 4is a block diagram illustrating the packet structure of a data packet during transmission according to an embodiment of the present application. When the primary network device receives the data packet from the local device, the packet structure of the data packet is similar to packet structure 400, which includes a header 401 and a payload 402.
[0096] When the network device performs encapsulation on the data packet, an encapsulated data packet with packet structure 410 can be formed. The encapsulated data packet includes a header 411 and a payload 412; the payload 412 can include at least the data packet.
[0097] In one embodiment, the payload 412 can further include tunnel information.
[0098] In another embodiment, the tunnel information can be part of the header 411 instead of the payload 412.
[0099] Figure 5 A network configuration of network devices according to an embodiment of the present application is shown. For the purpose of illustration, Figure 5 will be described with reference to the network environment in Figure 2B , and tables 501, 502 and 503 present partial network configuration information of the primary network device 210, the secondary network device 220 and the secondary network device 230 respectively.
[0100] Referring to Figure 2B , the WAN interface 213 of the primary network device 210 is connected to the LAN interface 221 of the secondary network device 220 through the first link 510, and the WAN interface 214 of the primary network device 210 is connected to the LAN interface 231 of the secondary network device 230 through the first link 511.
[0101] For each secondary network device and primary network device, a second connection and a third connection can be further established through the first link. More specifically, as Figure 3A shown, the second connection is established between the primary management interface and the secondary management interface (collectively referred to as "management interfaces"), and the third connection is established between the primary transmission interface and the secondary transmission interface (collectively referred to as "transmission interfaces"). Each management interface and transmission interface can be assigned a reserved IP address as its remote IP address or local IP address. Each reserved IP address should be unique and selected from a pre-specified IP address range. All management interfaces and transmission interfaces are in the same subnet, and thus can communicate with each other.
[0102] As Figure 5As shown, a first primary management interface and a first primary transport interface are created over the WAN interface 213 between the primary network device 210 and the secondary network device 220, and the reserved IP addresses are "168.101.33.253" and "168.101.33.101", respectively. On the other hand, a first secondary management interface and a first secondary transport interface are created over the LAN interface 221, and the reserved IP addresses are "168.101.33.254" and "168.101.33.1", respectively. Thus, the second connection can be established between the reserved IP addresses "168.101.33.253" and "168.101.33.254", and the third connection can be established between the reserved IP addresses "168.101.33.101" and "168.101.33.1". It is noted that all the above IP addresses are within the first subnet, i.e., "168.101.33.0 / 24".
[0103] Similarly, a second primary management interface and a second primary transport interface are created over the WAN interface 214 between the primary network device 210 and the secondary network device 230, and the reserved IP addresses are "168.101.34.253" and "168.101.34.101", respectively. On the other hand, a second secondary management interface and a second secondary transport interface are created over the LAN interface 231, and the reserved IP addresses are "168.101.34.254" and "168.101.34.1", respectively. Thus, another second connection can be established between the reserved IP addresses "168.101.34.253" and "168.101.34.254", and another third connection can be established between the reserved IP addresses "168.101.34.101" and "168.101.34.1". It is noted that all the above IP addresses are within the second subnet, i.e., "168.101.34.0 / 24".
[0104] In a preferred embodiment, the primary network device can generate the reserved IP addresses for each network interface. Thus, the uniqueness of the reserved IP addresses can be guaranteed when the primary network device enables the function of controlling and managing more than one secondary network device.
[0105] In another embodiment, the reserved IP addresses can be generated by the secondary network devices.
[0106] For each secondary network device and primary network device, a management tunnel and at least one data tunnel can be further established through the second connection and the third connection, respectively. More specifically, a management tunnel is established between a tunnel interface (hereinafter referred to as "primary management tunnel interface") of the primary network device created on the primary network interface and a tunnel interface (hereinafter referred to as "secondary management tunnel interface") of the primary network device created on the secondary network interface. On the other hand, a data tunnel can be established between a tunnel interface (hereinafter referred to as "primary transport tunnel interface") of the primary network device created on the primary network device and a tunnel interface (hereinafter referred to as "secondary transport tunnel interface") of the primary network device created on the secondary network device.
[0107] Each of the at least one data tunnel is used to connect to the internetwork through the WAN interface of the secondary network device. Therefore, the group of at least one data tunnel established through the third connection can be in a bijective relationship with the group of available WAN interfaces of the secondary network device. As such, the number of at least one data tunnel is equal to the number of available WAN interfaces.
[0108] In one variant, the third connection can be in a bijective relationship with the group of active WAN interfaces of the secondary network device, which are WAN interfaces capable of connecting to the internetwork. Therefore, if additional WAN interfaces are connected to the internetwork, additional tunnels can be established.
[0109] In one embodiment, the primary network device can periodically send a heartbeat packet to determine the availability of the at least one secondary network device. The heartbeat packet can be any form of small packet, such as an ICMP packet, an IP packet, an L2TP control packet, etc., so as not to affect the network performance of the first link.
[0110] The primary management tunnel interface, the secondary management tunnel interface, the primary transport tunnel interface, and the secondary transport tunnel interface can be collectively referred to as "tunnel interfaces". Each tunnel interface can be assigned a reserved IP address as a local tunnel IP address or a remote tunnel IP address. The reserved IP address should be unique and selected from a pre-specified IP address range. All tunnel interfaces are in the same subnet, so the tunnel interfaces can communicate with each other.
[0111] As Figure 5As shown, between primary network device 210 and secondary network device 220, a management tunnel 2210 can be established through the primary management tunnel interface having the reserved IP address "168.101.1.253" and the secondary management tunnel interface having the reserved IP address "168.101.1.254"; a data tunnel 221-1 can be established through the primary transport tunnel interface having the reserved IP address "168.101.1.2" and the secondary transport tunnel interface having the reserved IP address "168.101.1.1". Since there is only one available WAN interface on secondary network device 220, only one data tunnel (i.e., data tunnel 221-1) can be established.
[0112] Similarly, between primary network device 210 and secondary network device 230, a management tunnel 231-0 can be established through the primary management tunnel interface having the reserved IP address "168.101.2.253" and the secondary management tunnel interface having the reserved IP address "168.101.2.254". A data tunnel 231-1 can be established through the first primary transport tunnel interface having the reserved IP address "168.101.2.2" and the first secondary transport tunnel interface having the reserved IP address "168.101.2.1"; a data tunnel 231-2 can be established through the second primary transport tunnel interface having the reserved IP address "168.101.2.6" and the second secondary transport tunnel interface having the reserved IP address "168.101.2.5". A data tunnel 231-3 can be established through the third primary transport tunnel interface having the reserved IP address "168.101.2.10" and the third secondary transport tunnel interface having the reserved IP address "168.101.2.9".
[0113] Table 1 summarizes the relationship between WAN interfaces and bijective data tunnels for the illustrative embodiments: WAN interface Corresponding bijective data tunnel 222 221-1 233 231-1 234 231-2 235 231-3 Table 1
[0114] It should be noted that for each of the secondary network devices and the primary network devices, the tunnel interfaces can have reserved IP addresses within the same subnet. However, the tunnel interfaces cannot reserve the same IP addresses as the management interfaces, the transport interfaces in the same subnet.
[0115] In one variant, the network configuration can be performed by the primary network device and / or the secondary network devices.
[0116] After setting the IP address on the physical or virtual network interface, a data packet received from a local device in the same network will be routed through the network interface to the interconnected network according to a policy. The network interface can be a WAN interface of the primary network device or a WAN interface of the secondary network device, and the policy can be based on one or more of the following: type of network interface, service provider (e.g., Internet Service Provider (ISP)), bandwidth, throughput, latency, cost, location, packet type, application, user, user group, user preference, source address, and destination address.
[0117] In one example embodiment, the policy can be based on latency, in which the data packet is preferably routed through the network interface or connection with the lowest latency. For example, referring to the network environment in Figure 2B , there are four terminal WAN interfaces directly connected to the interconnected network, namely WAN interfaces 222, 233, 234, and 215. If the latencies of WAN interfaces 222, 233, 234, and 215 are 12 milliseconds (ms), 30 ms, 40 ms, and 25 ms, respectively, primary network device 210 can determine that the data packet should be routed through WAN interface 222.
[0118] In another example embodiment, the policy can be based on throughput, in which the data packet is preferably routed through the network interface or connection with the highest throughput. For another example, referring to the network environment in Figure 2B , if the throughputs of WAN interfaces 222, 233, 234, and 215 are 10 Mbps, 30 Mbps, 25 Mbps, and 28 Mbps, respectively, primary network device 210 can determine that the data packet should be routed through WAN interface 233.
[0119] In one embodiment, the primary network device can further update the firmware of the secondary network device by managing the tunnel and / or at least one data tunnel.
[0120] Figure 6A is a flowchart illustrating steps performed between a primary network device and a secondary network device according to an embodiment of the present invention, and Figure 6A should be read in conjunction with Figure 2B and Figure 5 . After receiving a first data packet from a local device, the steps shown in Figure 6A may be performed only when it is determined that the first data packet is to be sent to the interconnected network through a determined WAN interface, which is a network interface of the secondary network device used by the primary network device. For illustrative purposes, primary network device 210 determines that the first data packet is to be routed to the interconnected network through a determined WAN interface, e.g., WAN interface 222 of secondary network device 220.
[0121] In step 601, the primary network device 210 can modify the first data packet into a second data packet. The header of the first data packet can be modified according to network configuration so that the first data packet is considered as originally sent by the WAN interface 222. For example, the source address of the first data packet can be modified from the local device's IP address "192.168.0.1" to the public IP address of the WAN interface 222 (e.g. "30.2.2.2").
[0122] In step 602, the primary network device 210 can encapsulate the second data packet into a third data packet having a packet structure similar to the packet structure 410, which includes a header 411 and a payload 412. The payload 412 includes at least the second data packet, and the header 411 includes at least source and destination addresses corresponding to the primary transport tunnel interface and the secondary transport tunnel interface, respectively. For the purpose of illustration, if the third data packet is assigned to be transmitted through the data tunnel 2211 (which is the determined bijective data tunnel of the WAN interface), the source and destination addresses of the third data packet are "168.101.1.2" and "168.101.1.1", respectively.
[0123] In one variant, the source and destination addresses of the third data packet can be the remote IP address of the primary transport interface and the local IP address of the secondary transport interface, respectively; however, tunnel information can be further required to determine which data tunnel to use for transmission. The tunnel information can be part of the header or part of the payload. For example, if the source and destination addresses of the third data packet are the remote IP address "168.101.33.101" and the local IP address "168.101.33.1", respectively, the third data packet can require a tunnel ID.
[0124] In step 603, the primary network device 210 can transmit the third data packet through the bijective data tunnel.
[0125] In step 604, the secondary network device 220 can receive the third data packet from the primary network device 210 through the bijective data tunnel.
[0126] In step 605, the secondary network device 220 can decapsulate the third data packet into a fourth data packet, which can be equivalent to the second data packet.
[0127] In step 606, the secondary network device 220 can transmit the fourth data packet to the interconnection network through the WAN interface corresponding to the bijective data tunnel used in step 603. The WAN interface is determined according to one or more of the following packet information of the third data packet: source address, destination address, and tunnel information.
[0128] In one embodiment, the WAN interface for routing is determined according to the source address and / or destination address of the third packet. For example, if the destination address of the third packet is the local tunnel IP address of data tunnel 221-1, the secondary network device can determine that WAN interface 222 corresponding to data tunnel 221-1 is available for routing.
[0129] In another embodiment, tunnel information can be further required to determine which WAN interface is available for routing. For example, if the destination address of the third packet is the local IP address of the third connection, other information or data (e.g., tunnel ID) can be required to determine that WAN interface 222 corresponding to data tunnel 221-1 is available for routing.
[0130] In one variant, the WAN interface for routing is determined after encapsulation in step 606. Thus, the source address and / or destination address of the fourth packet can be used to determine that WAN interface 222 is available for routing.
[0131] The modification process is not limited to be performed by the primary network device; the modification process can also be performed by the secondary network device. The modification process can also be replaced by the encapsulation process, and vice versa.
[0132] Figure 6B A flowchart showing another set of steps performed between the primary network device and the secondary network device is shown in FIG. 6B, and Figure 6B should be read in conjunction with Figure 2B and Figure 5 When the secondary network device (e.g., secondary network device 220) receives the fifth packet from the interconnecting network and specifies the local device to which the primary network device is connected, step 611 is performed.
[0133] In step 611, secondary network device 220 can encapsulate the fifth packet as a sixth packet having a packet structure similar to packet structure 410, which includes a header 411 and a payload 412. Payload 412 includes at least the fifth packet, while header 411 includes at least a source address and a destination address, corresponding to the secondary transport tunnel interface and the primary transport tunnel interface, respectively. For illustrative purposes, if the fifth packet is received through WAN interface 222, the bijective data tunnel can be tunnel 221-1, and thus the source address and the destination address of the sixth packet can be "168.101.1.1" and "168.101.1.2", respectively.
[0134] In one variant, the source address and destination address of the sixth data packet can be the local IP address of the secondary transport interface and the remote IP address of the primary transport interface, respectively; however, tunnel information can further be required to determine which data tunnel to use for transmission. The tunnel information can be part of the header or part of the payload. For example, if the source address and destination address of the sixth data packet are the local IP address "168.101.33.1" and the remote IP address "168.101.33.101", respectively, the sixth data packet can require a tunnel ID.
[0135] In step 612, the secondary network device 220 can send the sixth data packet to the primary network device through the bijective data tunnel.
[0136] In step 613, the primary network device 210 can receive the sixth data packet through the bijective data tunnel.
[0137] In step 614, the primary network device 210 can decapsulate the sixth data packet to form a seventh data packet, which can be equivalent to the fifth data packet.
[0138] In step 615, the primary network device 210 can further route the seventh data packet to a local device of the primary network device 210 for further transmission.
[0139] It is noted that there is no limitation on how to modify the source address and destination address of the data packet.
[0140] In one embodiment, the modification of the IP address can be performed by a Network Address Translator (NAT) component or any other form of network address translation.
[0141] In another embodiment, the modification of the IP address can be performed by a Port Address Translator (PAT) component or any other form of port address translation. This can be done due to the need to change the port number during the routing process.
[0142] In one embodiment, if the number of the at least one data tunnel is greater than 1, the at least one data tunnel can be grouped into at least one aggregated tunnel.
[0143] In one variant, each of the at least one aggregated tunnel is a Virtual Private Network (VPN) tunnel as shown in Figure 7
[0144] Figure 7 Exemplary network environments according to various embodiments of the present application are shown, and are based on Figure 2B a network environment. The network environment includes a network server 770, and the network server 770 includes a network interface 771. The network server 770 can establish the first link with the interconnecting network 260.
[0145] For illustrative purposes, the local device connects to the server through the primary network device, and can further establish at least one VPN connection.
[0146] In one embodiment, each of the at least one VPN connection is an end-to-end connection established between a WAN interface of the local device and a WAN interface of the server.
[0147] In another embodiment, each of the at least one VPN connection is an end-to-end connection established between a WAN interface of the primary network device and a WAN interface of the server.
[0148] For illustrative purposes, each of the VPN connections 701a, 701b, 701c, and 701d is established between a WAN interface of the primary network device 210 and a WAN interface of the network server 770. For example, the VPN connection 701a is established between the WAN interface 213 and the network interface 771 via the WAN interface 222; the VPN connection 701b is established between the WAN interface 214 and the network interface 771 via the WAN interface 233; the VPN connection 701c is established between the WAN interface 214 and the network interface 771 via the WAN interface 234; and the VPN connection 701d is established between the WAN interface 215 and the network interface 771.
[0149] In one variant, if the number of the at least one VPN connection is more than one, the at least one VPN connection can be combined or aggregated together to form an aggregated VPN connection. The benefits of transmitting data through an aggregated connection include higher reliability and security as compared to non-aggregated VPN connections.
[0150] Figure 8 An exemplary graphical user interface of the primary network device is shown, and should be viewed in conjunction with Figure 5 When the primary network device manages and controls at least one secondary network device, the network performance and network configuration of the at least one secondary network device and the network performance and network configuration of the primary network device itself can be viewed, managed, and controlled in one place. Thus, a list of available network interfaces of the at least one primary network device and the at least one secondary network device can be displayed on the graphical user interface.
[0151] As Figure 8As shown, each row of the list shows each of the available WAN interfaces in each of the at least one secondary network interfaces controlled by the primary network interface, as well as the available WAN interfaces of the primary network device itself. Connection information for each of the available WAN interfaces is displayed on the user interface, such as the status of the WAN interface or WAN connection, the device to which the WAN interface belongs, priority, signal strength, or throughput.
[0152] In one variant, only the terminal WAN interfaces are displayed instead of the available WAN interfaces. As mentioned above, the terminal WAN interfaces are the WAN interfaces that directly connect to the interconnection network.
[0153] In Figure 8 In the embodiment shown, there are five available WAN interfaces from either the primary network device or the secondary network devices, and the primary network device 210 is utilized to transmit data to the interconnection network by establishing five available WAN connections corresponding to the five WAN interfaces. The available WAN connections include four active WAN connections named "Home_Wifi", "Satellite", "Ethernet", "4G", and one inactive WAN connection named "Broadband". Thus, on the user interface, the status of "Broadband" is displayed as "Disconnected" (indicated by an open circle), while the remaining WAN connections are displayed as "Connected" (indicated by a filled circle).
[0154] For the active WAN connections, further connection information can also be displayed, such as Figure 8 the priority, signal, device, etc. as shown. There is no limitation on the connection information that can be displayed. Details of each connection information are discussed below.
[0155] One of the connection information that can be displayed is the origin of each WAN interface, as the WAN interface can be a WAN interface of the primary network device or a WAN interface of at least one of the secondary network devices.
[0156] Another connection information that can be displayed is the priority. The priority can be assigned to each WAN connection based on the policy. As mentioned above, the policy can be based on one or more of the following: network interface type, service provider, bandwidth, throughput, latency, cost, location, packet type, application, user, user group, user preference, source address, and destination address.
[0157] For example, as Figure 8As shown, the priorities of the WAN connections named "Home_Wifi", "Satellite", "Ethernet" and "4G" are "medium", "low", "high" and "backup", respectively. Thus, data packets tend to be transmitted to the Internet through the WAN connection with the highest priority, i.e. "Ethernet". If "Ethernet" is unavailable, data packets can be transmitted to the Internet through the WAN connection with the second highest priority, i.e. "Home_Wifi", and so on. If all these connections are unavailable, the backup WAN connection "4G" will be used to transmit data packets.
[0158] Another piece of connection information that can be displayed is latency. WAN connections with low latency are more suitable for data transmission.
[0159] For example, as shown in Figure 8 the latencies of the WAN connections "Home_Wifi", "Satellite", "Ethernet" and "4G" are 10ms, 31ms, 11ms and 5ms, respectively. If the priorities of the WAN connections are based on latency, data packets are preferentially transmitted to the Internet through the WAN connection with the lowest latency, i.e. "4G", followed by "Home_Wifi", "Ethernet" and "Satellite". In Figure 8 the illustrative example, "Home_Wifi" has the highest priority, followed by "Home_Wifi" and "Satellite", thus the priority is not based on or partially based on latency.
[0160] The establishment of a new WAN connection, or the disconnection or change of an existing WAN connection, can happen. For example, a change in Ethernet connection, a change in Wi-Fi connection or an obstruction in satellite connection. Thus, the network information corresponding to the at least one secondary network device can be actively updated to the primary network device, and the connection information displayed on the user interface of the primary network device can be updated in time.
[0161] In one embodiment, the at least one secondary network device can respond to the heartbeat packet with a change in network connection status.
[0162] In another embodiment, when the at least one secondary network device detects a change in network connection, the at least one secondary network device can actively send the change in network connection to the primary network device through the corresponding management tunnel or management connection.
[0163] In one variant, the at least one secondary network device can send the change in network connection to the primary network device upon request from the primary network device.
Claims
1. A method for transmitting data packets at a primary network device through a wide area network (WAN) interface of at least one secondary network device, comprising: a. Enable the function of managing and controlling the network configuration of the at least one secondary network device; b. Establish a first connection and a second connection with the at least one secondary network device; c. Establish a management tunnel through the first connection; d. Establish at least one data tunnel through the second connection; as well as e. According to the strategy, the data packets are transmitted through the WAN interface of the second connection using the first data tunnel; The first connection is established between the first management interface and the second management interface; The second connection is established between the first transmission interface and the second transmission interface. The first data tunnel is a data tunnel established between the first data tunnel interface and the second data tunnel interface; The first data tunnel corresponds to the WAN interface.
2. The method of claim 1, further comprising: a. Receive a first request from at least one secondary network device; as well as b. Send a first response to reply to the first request.
3. The method of claim 2, wherein the primary network device may request authentication from a third device before responding to the first request with the first response.
4. The method of claim 1, wherein the at least one secondary network device only allows modifications to the network configuration of the at least one secondary network device to be made by the primary network device.
5. The method of claim 1, wherein the strategy may be based on one or more of the following: network interface type, service provider, bandwidth, throughput, latency, cost, location, packet type, application, user, user group, user preference, source address, and destination address.
6. The method of claim 1, wherein the first management interface, the second management interface, the first transmission interface and the second transmission interface are virtual network interfaces.
7. The method of claim 1, further comprising: Each of the first management interface, the second management interface, the first transmission interface, and the second transmission interface is assigned a reserved IP address.
8. The method of claim 1, wherein the first management interface and the first transmission interface are located in the first subnet.
9. The method of claim 8, wherein the first data tunnel interface is located in the second subnet.
10. The method of claim 9, wherein the first subnet and the second subnet are different subnets.
11. A main network device, comprising: At least one processing unit; Multiple network interfaces; as well as At least one non-transitory computer-readable storage medium storing program instructions executable by the at least one processing unit for: a. Enable the function of managing and controlling the network configuration of at least one secondary network device; b. Establish a first connection and a second connection with the at least one secondary network device; c. Establish a management tunnel through the first connection; d. Establish at least one data tunnel through the second connection; as well as e. Transmit data packets via the WAN interface of the second connection through the first data tunnel, according to the strategy; The first connection is a connection established between the first management interface and the second management interface; The second connection is the connection established between the first transmission interface and the second transmission interface. The first data tunnel is a data tunnel established between the first data tunnel interface and the second data tunnel interface; The first data tunnel corresponds to the WAN interface.
12. The main network device of claim 11, wherein the at least one non-transitory computer-readable storage medium further stores program instructions executable by the at least one processing unit for: a. Receive a first request from the at least one secondary network device; and b. Send a first response to reply to the first request.
13. The primary network device of claim 12, wherein the primary network device may request authentication from a third device before responding to the first request with the first response.
14. The primary network device of claim 11, wherein the at least one secondary network device only allows modifications to the network configuration of the at least one secondary network device to be made by the primary network device.
15. The main network device of claim 11, wherein the policy may be based on one or more of the following: network interface type, service provider, bandwidth, throughput, latency, cost, location, packet type, application, user, user group, user preference, source address, and destination address.
16. The main network device as claimed in claim 11, wherein, The first management interface, the second management interface, the first transmission interface, and the second transmission interface are virtual network interfaces.
17. The main network device of claim 11, wherein the at least one non-transitory computer-readable storage medium further stores program instructions executable by the at least one processing unit for: Each of the first management interface, the second management interface, the first transmission interface, and the second transmission interface is assigned a reserved IP address.
18. The main network device of claim 11, wherein the first management interface and the first transmission interface are located in the first subnet.
19. The main network device of claim 18, wherein the first data tunnel interface is located in the second subnet.
20. The main network device of claim 19, wherein the first subnet and the second subnet are different subnets.