Enhanced Internet Protocol Security Controls for Virtual Private Network Concentrators
The adaptive IPsec management system optimizes VPN concentrator tunnel usage by actively maintaining only the highest priority tunnel and reinstating backups as needed, significantly increasing scalability and connection capacity.
Patent Information
- Application Number
- JP2025529768
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-11-22
- Filing Date
- 2023-11-20
- Publication Date
- 2025-11-28
AI Technical Summary
Current VPN concentrators are limited in scalability due to the requirement of maintaining multiple redundant IPsec tunnels, which restricts the number of simultaneous connections and configurations, especially in large-scale enterprise networks with many remote users.
An adaptive IPsec management system that identifies and maintains only the highest priority IPsec tunnel actively, deleting redundant tunnels until the primary becomes inactive, allowing backup tunnels to be reinstated when necessary, thus optimizing tunnel usage and increasing the number of simultaneous connections.
This approach enhances VPN concentrator scalability by allowing up to 1600 UCPEs with three WANs each to connect simultaneously, compared to 666 with traditional methods, while maintaining secure communication.
Smart Images

Figure 2025538541000001_ABST
Abstract
Description
[Technical Field]
[0001] [CROSS-REFERENCE TO RELATED APPLICATIONS] This application is related to and claims priority under 35 U.S.C. §119(e) from U.S. patent application Ser. No. 63 / 384,771, entitled "ENHANCED INTERNET PROTOCOL SECURITY MANAGEMENT FOR VIRTUAL PRIVATE NETWORK CONCENTRATORS," filed November 22, 2022, the entire contents of which are incorporated herein by reference for all purposes.
[0002] FIELD OF THE INVENTION Embodiments of the present invention generally relate to systems and methods for managing Internet Protocol Security (IPsec) for virtual private network (VPN) concentrators. [Background technology]
[0003] Virtual private network (VPN) concentrators are used to connect client and remote networks to another network. Security protocols may be implemented to protect communications. However, VPN scaling for security protocols may be limited, and current techniques may require persistent security protocol tunnels on each wireless area network, where only one security protocol session may be used for data traffic, while other tunnels may be redundant. Summary of the Invention
[0004] A method for managing Internet Protocol Security (IPsec) for a virtual private network (VPN) concentrator may include: an edge gateway backend system identifying a first IPsec tunnel, a second IPsec tunnel, and a third IPsec tunnel between a VPN client and a VPN concentrator of the edge gateway backend system; the edge gateway backend system determining that the first IPsec tunnel is a highest priority tunnel between the VPN client and the VPN concentrator; and the edge gateway backend system determining that the highest priority tunnel between the VPN client and the VPN concentrator is active, wherein based on the determination that the highest priority tunnel between the VPN client and the VPN concentrator is active, fully qualified domain names of the second IPsec tunnel and the third IPsec tunnel are absent from the VPN concentrator.
[0005] A system for managing Internet Protocol Security (IPsec) for a Virtual Private Network (VPN) concentrator may include a memory coupled to at least one processor of an edge gateway backend system, wherein the at least one processor is configured to: identify a first IPsec tunnel between a VPN client and a VPN concentrator of the edge gateway backend system; identify a second IPsec tunnel between the VPN client and the VPN concentrator; identify a third IPsec tunnel between the VPN client and the VPN concentrator; determine that the first IPsec tunnel is a highest priority tunnel between the VPN client and the VPN concentrator; and determine that the highest priority tunnel between the VPN client and the VPN concentrator is active, wherein based on the determination that the highest priority tunnel between the VPN client and the VPN concentrator is active, fully qualified domain names of the second IPsec tunnel and the third IPsec tunnel are absent from the VPN concentrator.
[0006] A non-transitory computer-readable storage medium may comprise instructions that, when executed by at least one processor of an edge gateway backend system for managing Internet Protocol Security (IPsec) for a virtual private network (VPN) concentrator, cause the at least one processor to: identify a first IPsec tunnel between a VPN client and a VPN concentrator of the edge gateway backend system; identify a second IPsec tunnel between the VPN client and the VPN concentrator; identify a third IPsec tunnel between the VPN client and the VPN concentrator; and determine that the first IPsec tunnel is a highest priority tunnel between the VPN client and the VPN concentrator; and cause the edge gateway backend system to determine that the highest priority tunnel between the VPN client and the VPN concentrator is active, wherein based on the determination that the highest priority tunnel between the VPN client and the VPN concentrator is active, fully qualified domain names of the second IPsec tunnel and the third IPsec tunnel are absent from the VPN concentrator. [Brief explanation of the drawings]
[0007] [Figure 1] 1 illustrates an exemplary system for managing Internet Protocol Security (IPsec) for a Virtual Private Network (VPN) concentrator, according to one embodiment.
[0008] [Figure 2] 2 illustrates an exemplary process for an adaptive system for managing IPsec for the VPN concentrator of FIG. 1 when the highest priority IPsec tunnel goes down, according to one embodiment.
[0009] [Figure 3]1 illustrates an exemplary process for an adaptive system for managing IPsec for the VPN concentrator of FIG. 1 when a top-priority IPsec tunnel goes down and then becomes active again as shown in FIG. 2 , according to one embodiment.
[0010] [Figure 4] 1 is a flow diagram of a process for managing IPsec for a VPN concentrator, according to one embodiment.
[0011] [Figure 5] FIG. 1 illustrates an example of a computing system that may be used in implementing embodiments of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0012] Aspects of the present disclosure involve systems, methods, and the like for enhanced management of Internet Protocol Security (IPsec) for Virtual Private Network (VPN) concentrators.
[0013] A virtual private network (VPN) concentrator is a network device used to connect a client and remote network to another network. A VPN concentrator allows multiple (possibly encrypted) VPN tunnels to access the VPN network simultaneously (e.g., simultaneous VPN tunnels for many users) and represents a larger-scale version of a VPN router. A VPN concentrator may provide a different address for each user, maintain data encryption, ensure resources are accessed only by authorized users, and protect end-to-end delivery of data. For example, a large enterprise with many remote users can benefit from the use of a VPN concentrator.
[0014] Edge gateways and universal customer premises equipment (UCPE) may have virtual network functions and VPN clients. A VPN client may have multiple Internet Protocol Security (IPsec) tunnels to a VPN concentrator, but only one tunnel per VPN client can be used at a time for data traffic. Other Internet Protocol Security (IPsec) tunnels between the VPN client and the VPN concentrator may be backup / redundant tunnels.
[0015] When UCPE is expanded to establish multiple Internet Protocol Security (IPsec) tunnels for multiple VPN clients, too many tunnels and corresponding configurations may be established for the VPN concentrator. For example, each tunnel's wireless area network may use a fully qualified domain name (FQDN) that will be managed by the VPN concentrator. The VPN concentrator may be limited in the number of tunnels and configurations it can maintain, which may limit the scalability of the UCPE and edge gateway.
[0016] Therefore, there is a need for enhanced management of IPsec for VPN concentrators.
[0017] In one or more embodiments, an adaptive IPsec management design for a VPN concentrator may include an algorithm for adding all wireless area networks (e.g., FQDNs) to the VPN concentrator and learning the number of wide area networks (WANs) and their priorities from an ordering system.
[0018] In one or more embodiments, a UCPE may initiate an IPsec session over any WAN during the activation / staging phase and establish an IPsec tunnel with the VPN concentrator. If the UCPE calls home from the customer premises, an adaptive algorithm may be initiated and only the highest priority WAN IPsec may be retained, while other IPsec tunnels destined for the UCPE to the VPN concentrator may be deleted (e.g., by removing the FQDN configuration from the VPN concentrator). As a result, the session threshold of the VPN concentrator may increase.
[0019] In one or more embodiments, the VPN concentrator may periodically monitor active IPsec sessions. If an active IPsec session goes down, all other WAN FQDNs may be added to the VPN concentrator to establish IPsec on the backup / redundant WAN, and the learning / monitoring process may continue. If the most preferred WAN becomes active again, the other WAN FQDNs may be removed from the VPN concentrator. In this way, rather than maintaining the backup / redundant IPsec FQDNs in the VPN concentrator and limiting the VPN concentrator's session scalability, the backup / redundant IPsec FQDNs may be removed from the VPN concentrator until it is detected that the most preferred WAN has become inactive, at which point they may be added to the VPN concentrator to maintain communication with the UCPE / edge gateway.
[0020] In one or more embodiments, the VPN concentrator may be configured with a capacity threshold (e.g., 80% or some other value) to allow the remaining capacity to be reserved for redundant / backup tunnels. The backup reservation percentage may change based on a learning process.
[0021] For comparison, existing persistent IPsec management techniques may have a VPN concentrator capacity of 2000 tunnels, so the number of UCPEs with three WANs each that may simultaneously connect to the VPN concentrator is 666. The adaptive IPsec management techniques herein may have the same 2000 tunnel capacity, but may allow up to 1600 UCPEs with three WANs each to simultaneously connect to the VPN concentrator.
[0022] The above description is for purposes of illustration and not limitation. Numerous other examples, configurations, processes, etc. may exist, some of which are described in more detail below. Exemplary embodiments will now be described with reference to the accompanying drawings.
[0023] FIG. 1 illustrates an exemplary system for managing Internet Protocol Security (IPsec) for a Virtual Private Network (VPN) concentrator, according to one embodiment.
[0024] Referring to FIG. 1 , system 100 may include UCPE / edge gateways (e.g., UCPE / edge gateway 102, UCPE / edge gateway 104) that connect to edge gateway backend system 106. UCPE / edge gateway 102 may include virtual network function (VNF) 108 for connecting VPN client 110 to edge gateway backend system 106 using Internet 112. In particular, VPN client 110 may have multiple tunnels (e.g., tunnel 114, tunnel 116, and tunnel 118) that may connect to edge gateway backend system 106 via VPN concentrator 120 using a secure protocol such as IPsec. Tunnels 114, 116, and 118 may be used simultaneously as persistent management IPsec sessions. Similarly, UCPE / edge gateway 104 may include VNF 122 for connecting VPN client 124 to edge gateway backend system 106 using Internet 112. In particular, VPN client 124 may have multiple tunnels (e.g., tunnel 126, tunnel 128, and tunnel 130) that may connect to edge gateway backend system 106 through VPN concentrator 120 using a secure protocol such as IPsec. Tunnels 126, 128, and 130 may be used simultaneously as persistent management IPsec sessions. Edge gateway backend system 106 may include management and orchestration system 132 and operational support system (OSS) / business support system (BSS) (e.g., OSS / BSS system 134).
[0025] 1 , the number of UCPEs / edge gateways that can connect to edge gateway backend system 106 through VPN concentrator 120 can be increased by using system 150 in relation to system 100 because of the way tunnels are managed by VPN concentrator 120. In particular, VPN concentrator 120 can maintain one of the tunnels (e.g., tunnel 152 of VPN client 110) as a persistent managed IPsec session (e.g., the highest priority tunnel / session), while tunnels 154 and 156 of VPN client 110 can be backup / inactive IPsec sessions that can only be activated by edge gateway backend system 106, as described further herein. Similarly, VPN concentrator 120 may maintain one of the tunnels (e.g., tunnel 158 of VPN client 124) as a persistent managed IPsec session (e.g., the highest priority tunnel / session), while tunnels 160 and 162 of VPN client 124 may be backup / inactive IPsec sessions that may only be activated by edge gateway backend system 106, as described further herein. In particular, edge gateway backend system 106 of system 150 may include MANO system 132, OSS / BSS system 134, and edge gateway backend system 151 having adaptive IPsec management system 170 for adaptively managing which tunnels of a given VPN client are active and which tunnels of a given VPN client are backup / inactive at a given time.
[0026] In one or more embodiments, the adaptive IPsec management system 170 may include an algorithm for adding all wireless area networks (e.g., FQDNs) to the VPN concentrator 120 and learning the number of WANs (e.g., corresponding to each tunnel) and their priorities from an ordering system.
[0027] In one or more embodiments, a UCPE (e.g., UCPE / edge gateway 102) may initiate IPsec sessions over all WANs (e.g., tunnel 152, tunnel 154, and tunnel 156) during the activation / staging phase and establish IPsec tunnels with VPN concentrator 120. When a UCPE calls home from a customer premises, an adaptive algorithm in adaptive IPsec management system 170 may be initiated and only the highest priority WAN IPsec (e.g., tunnel 152) may be retained, while other IPSec tunnels (e.g., tunnels 154 and 156) destined for the UCPE to VPN concentrator 120 may be deleted (e.g., by removing the FQDN configuration from VPN concentrator 120). As a result, the session threshold of the VPN concentrator may increase. For example, if VPN concentrator 120 has a tunnel capacity of 2000 tunnels that can be maintained simultaneously, and if each VPN client uses three WANs tunneled to VPN concentrator 120 at once, the number of VPN clients that can be connected is 666 (e.g., 2000 divided by 3 active WANs per device = 666 devices). However, using system 150, if an 80% capacity limit is used, the capacity of connected VPN clients increases to 1600 (e.g., 2000 divided by 1 active WAN per device = 2000 devices x 0.8 capacity = 1600 devices).
[0028] In one or more embodiments, VPN concentrator 120 may periodically monitor the tunnel's active IPsec session. If the active IPsec session goes down (e.g., as shown in FIG. 2), all other WAN FQDNs may be added to VPN concentrator 120 (e.g., by adaptive IPsec management system 170) to establish IPsec on the backup / redundant WAN, and the learning / monitoring process may continue. If the primary WAN becomes active again (e.g., as shown in FIG. 3), the other WAN FQDNs may be removed from VPN concentrator 120 (e.g., by adaptive IPsec management system 170). In this way, rather than maintaining a backup / redundant IPsec FQDN at VPN concentrator 120 and limiting the VPN concentrator's session scalability, the backup / redundant IPsec FQDN may be removed from VPN concentrator 120 until VPN concentrator 120 detects that the primary WAN has become inactive, at which point the backup / redundant IPsec FQDN may be added to VPN concentrator 120 (e.g., by adaptive IPsec management system 170) to maintain communication with the UCPE / edge gateway.
[0029] In one or more embodiments, VPN concentrator 120 may be configured with a capacity threshold (e.g., 80% or some other value) to allow the remaining capacity to be reserved for redundant / backup tunnels. The backup reservation percentage may change based on a learning process.
[0030] FIG. 2 illustrates an exemplary process for an adaptive system for managing IPsec for the VPN concentrator of FIG. 1 when the highest priority IPsec tunnel goes down, according to one embodiment.
[0031] 2, using system 150 of FIG. 1 with adaptive IPsec management system 170, if active tunnel 152 (e.g., as the highest priority tunnel for VPN client 110) goes down, adaptive IPsec management system 170 can add the WAN FQDNs of tunnels 154 and 156 (e.g., backup / inactive WAN) for VPN client 110 to VPN concentrator 120 to establish IPsec on the backup / redundant WAN, and the learning / monitoring process can continue. If the highest priority WAN becomes active again (e.g., as shown in FIG. 3), adaptive IPsec management system 170 can remove the other WAN FQDNs (e.g., for tunnels 154 and 156) from VPN concentrator 120 (e.g., by adaptive IPsec management system 170). In this way, rather than maintaining a backup / redundant IPsec FQDN at VPN concentrator 120 and limiting the VPN concentrator's session scalability, the backup / redundant IPsec FQDN may be removed from VPN concentrator 120 until VPN concentrator 120 detects that the primary WAN has become inactive, at which point the backup / redundant IPsec FQDN may be added to VPN concentrator 120 (e.g., by adaptive IPsec management system 170) to maintain communication with the UCPE / edge gateway.
[0032] FIG. 3 illustrates an exemplary process for an adaptive system for managing IPsec for the VPN concentrator of FIG. 1 when the highest priority IPsec tunnel goes down and then becomes active again, as shown in FIG. 2, according to one embodiment.
[0033] 3, if the most preferred WAN (e.g., for tunnel 152) becomes active again (e.g., after being inactive as shown in FIG. 2), adaptive IPsec management system 170 may remove (e.g., by adaptive IPsec management system 170) the other WAN FQDNs (e.g., for tunnels 154 and 156) from VPN concentrator 120. In this manner, rather than maintaining a backup / redundant IPsec FQDN in VPN concentrator 120 and limiting the VPN concentrator's session scalability, the backup / redundant IPsec FQDN may be removed from VPN concentrator 120 until VPN concentrator 120 detects that the most preferred WAN has become inactive, at which point the backup / redundant IPsec FQDN may be added (e.g., by adaptive IPsec management system 170) to VPN concentrator 120 to maintain communication with the UCPE / edge gateway.
[0034] FIG. 4 is a flow diagram for a process 400 for managing IPsec for a VPN concentrator, according to one embodiment.
[0035] In block 402, a device (e.g., adaptive IPsec management system 170 of FIG. 1) may identify IPsec tunnels between a VPN client and a VPN concentrator (e.g., VPN concentrator 120 of FIG. 1). Each VPN client may be permitted to have multiple IPsec tunnels to the VPN concentrator, each with its own WAN and FQDN, but not all of each VPN client's IPsec tunnels may be considered active by the device (or VPN concentrator) at one time.
[0036] The device may determine the highest priority IPsec tunnel for any VPN client connected to the VPN concentrator in block 404. The device may learn the highest priority IPsec tunnel using a learning algorithm.
[0037] In block 405, the device may add the FQDN of each VPN client's highest priority IPsec tunnel to the VPN concentrator and may delete or deactivate the FQDNs of other IPSec tunnels between each VPN client and the VPN concentrator, so that more VPN clients may connect to the VPN concentrator simultaneously. The VPN client's non-high priority IPSec tunnels may be considered backup / redundant IPSec tunnels whose FQDNs and respective configurations may not be maintained by the device at the VPN concentrator until the VPN client's highest priority IPSec tunnel is deactivated.
[0038] At block 406, the device may determine whether the VPN client's highest-priority IPsec tunnel is active. If so, process 400 may continue to block 408, where the FQDN and configuration of the highest-priority IPsec tunnel are maintained in the VPN concentrator, and the FQDNs and configurations of the non-high-priority IPsec tunnels are deleted or deactivated from the VPN concentrator. If not, at block 406, process 400 may continue to block 410, where the device may add the FQDNs and configurations of the VPN client's backup / redundant IPsec tunnels to the VPN concentrator. Process 400 may continue from block 408 or block 410 back to block 406 and continue monitoring whether the VPN client's highest-priority IPsec tunnel is active or whether it has become active again after being inactive.
[0039] It is understood that the above description is intended to be illustrative and not restrictive.
[0040] FIG. 5 is a block diagram illustrating an example of a computing device or computer system 500 that may be used in implementing embodiments of the components of the network disclosed above. For example, the computing system 500 of FIG. 5 may represent at least a portion of the system 150 shown in FIG. 1, as discussed above. The computer system (system) includes one or more processors 502-506, the edge gateway backend system 151 of FIG. 1, and a hypervisor 511 for facilitating VNFs. The processors 502-506 may include one or more internal-level caches (not shown) and a bus controller 522 or bus interface unit that directs interaction with a processor bus 512. The processor bus 512, also known as a host bus or front-side bus, may be used to couple the processors 502-506 to a system interface 524. The system interface 524 may be connected to the processor bus 512 to interface other components of the system 500 with the processor bus 512. For example, system interface 524 may include a memory controller 518 for interfacing main memory 516 with processor bus 512. Main memory 516 typically includes one or more memory cards and control circuitry (not shown). System interface 524 may also include an input / output (I / O) interface 520 for interfacing one or more I / O bridges 525 or I / O devices with processor bus 512. One or more I / O controllers and / or I / O devices, such as I / O controller 528 and I / O device 530, may be connected to I / O bus 526, as shown.
[0041] The I / O devices 530 may also include input devices (not shown), such as an alphanumeric input device including alphanumeric and other keys for communicating information and / or command selections to the processors 502-506. Another type of user input device includes a cursor control, such as a mouse, trackball, or cursor direction keys, for communicating directional information and command selections to the processors 502-506 and for controlling cursor movement on a display device.
[0042] System 500 may include a dynamic storage device referred to as main memory 516, or random access memory (RAM), or other computer-readable device coupled to processor bus 512 for storing information and instructions to be executed by processors 502-506. Main memory 516 may also be used for storing temporary variables or other intermediate information during execution of instructions by processors 502-506. System 500 may also include read-only memory (ROM) and / or other static storage devices coupled to processor bus 512 for storing static information and instructions for processors 502-506. The system outlined in FIG. 5 is but one possible example of a computer system that may employ or be configured in accordance with aspects of the present disclosure.
[0043] According to one embodiment, the above techniques may be performed by computer system 500 in response to processor 504 executing one or more sequences of one or more instructions contained in main memory 516. These instructions may be read into main memory 516 from another machine-readable medium, such as a storage device. Execution of the sequences of instructions contained in main memory 516 may cause processors 502-506 to perform the process steps described herein. In alternative embodiments, circuitry may be used in place of or in combination with software instructions. Thus, embodiments of the present disclosure may include both hardware and software components.
[0044] Machine-readable media include any mechanism for storing or transmitting information in a form (e.g., software, processing application) readable by a machine (e.g., a computer). Such media may take the form of non-volatile and volatile media, including, but not limited to, removable data storage media, non-removable data storage media, and / or external storage devices made available via wired or wireless network architectures with such computer program products, including one or more database management products, web server products, application server products, and / or other additional software components. Examples of removable data storage media include compact disc read-only memories (CD-ROMs), digital versatile disc read-only memories (DVD-ROMs), magneto-optical disks, flash drives, and the like. Examples of non-removable data storage media include internal magnetic hard disks, solid-state drives, and the like. The one or more memory devices 506 may include volatile memory (e.g., dynamic random access memory (DRAM), static random access memory (SRAM), etc.) and / or non-volatile memory (e.g., read-only memory (ROM), flash memory, etc.).
[0045] A computer program product including mechanisms for implementing systems and methods according to the presently described technology may reside in main memory 516, which may be referred to as a machine-readable medium. It will be understood that a machine-readable medium may include any tangible, non-transitory medium that can store or encode instructions for performing any one or more of the operations of the present disclosure for execution by a machine, or that can store or encode data structures and / or modules utilized by or associated with such instructions. A machine-readable medium may include a single medium or multiple media (e.g., a centralized or distributed database, and / or associated caches and servers) that store one or more executable instructions or data structures.
[0046] Embodiments of the present disclosure include various steps described herein that may be performed by hardware components or embodied in machine-executable instructions that cause a general-purpose or special-purpose processor programmed with the instructions to perform the steps. Alternatively, the steps may be performed by a combination of hardware, software, and / or firmware.
[0047] Various modifications and additions may be made to the exemplary embodiments discussed without departing from the scope of the present invention. For example, while the embodiments described above refer to particular features, the scope of the present invention also includes embodiments having different combinations of features and embodiments that do not include all of the described features. Accordingly, the scope of the present invention is intended to embrace all such alternatives, modifications, and variations, together with all equivalents thereof.
Claims
1. 1. A method for managing Internet Protocol Security (IPsec) for a Virtual Private Network (VPN) concentrator, comprising: at least one processor of an edge gateway backend system identifying a first IPsec tunnel between a VPN client and a VPN concentrator of the edge gateway backend system; the at least one processor identifying a second IPsec tunnel between the VPN client and the VPN concentrator; the at least one processor identifying a third IPsec tunnel between the VPN client and the VPN concentrator; determining, by the at least one processor, that the first IPsec tunnel is a highest priority tunnel between the VPN client and the VPN concentrator; the at least one processor determining that the highest priority tunnel between the VPN client and the VPN concentrator is active; and the at least one processor deactivating fully qualified domain names of the second IPsec tunnel and the third IPsec tunnel from the VPN concentrator based on the determination that the highest priority tunnel between the VPN client and the VPN concentrator is active. A method for providing the above.
2. 2. The method of claim 1, wherein the second IPsec tunnel and the third IPsec tunnel are inactive at the VPN concentrator based on the highest priority tunnel between the VPN client and the VPN concentrator being active.
3. determining that the highest priority tunnel between the VPN client and the VPN concentrator is inactive; and adding the fully qualified domain names of the second IPsec tunnel and the third IPsec tunnel to the VPN concentrator based on the determination that the highest priority tunnel between the VPN client and the VPN concentrator is inactive. The method of claim 1 or 2, further comprising:
4. determining that the highest priority tunnel between the VPN client and the VPN concentrator has become active after being inactive; and deactivating the fully qualified domain names of the second IPsec tunnel and the third IPsec tunnel from the VPN concentrator based on the determination that the highest priority tunnel between the VPN client and the VPN concentrator has become active after being inactive. The method of claim 3 further comprising:
5. identifying a fourth IPsec tunnel between a second VPN client and the VPN concentrator; identifying a fifth IPsec tunnel between the second VPN client and the VPN concentrator; identifying a sixth IPsec tunnel between the second VPN client and the VPN concentrator; determining that the fourth IPsec tunnel is a highest priority tunnel between the second VPN client and the VPN concentrator; determining that the highest priority tunnel between the second VPN client and the VPN concentrator is active; and deactivating fully qualified domain names of the fifth IPsec tunnel and the sixth IPsec tunnel from the VPN concentrator based on the determination that the highest priority tunnel between the second VPN client and the VPN concentrator is active. The method of claim 3 further comprising:
6. determining that the highest priority tunnel between the second VPN client and the VPN concentrator is inactive; and adding the fully qualified domain names of the fifth IPsec tunnel and the sixth IPsec tunnel to the VPN concentrator based on the determination that the highest priority tunnel between the second VPN client and the VPN concentrator is inactive. The method of claim 5 further comprising:
7. determining that the highest priority tunnel between the second VPN client and the VPN concentrator has become active after being inactive; and deactivating the fully qualified domain names of the fifth IPsec tunnel and the sixth IPsec tunnel from the VPN concentrator based on the determination that the highest priority tunnel between the second VPN client and the VPN concentrator has become active after being inactive. The method of claim 6 further comprising:
8. 3. The method of claim 1, further comprising determining a maximum number of active IPsec tunnels to be maintained by the VPN concentrator.
9. 9. The method of claim 8, further comprising determining a maximum number of VPN clients that may connect to the VPN concentrator based on the maximum number of active IPsec tunnels that will be maintained by the VPN concentrator.
10. 1. A system for managing Internet Protocol Security (IPsec) for a Virtual Private Network (VPN) concentrator, comprising: a memory coupled to at least one processor of an edge gateway backend system, the at least one processor comprising: identifying a first IPsec tunnel between a VPN client and a VPN concentrator of the edge gateway backend system; identifying a second IPsec tunnel between the VPN client and the VPN concentrator; identifying a third IPsec tunnel between the VPN client and the VPN concentrator; determining that the first IPsec tunnel is a highest priority tunnel between the VPN client and the VPN concentrator; determining that the highest priority tunnel between the VPN client and the VPN concentrator is active; and deactivating fully qualified domain names of the second IPsec tunnel and the third IPsec tunnel from the VPN concentrator based on the determination that the highest priority tunnel between the VPN client and the VPN concentrator is active. The system is configured as follows:
11. 11. The system of claim 10, wherein the second IPsec tunnel and the third IPsec tunnel are inactive at the VPN concentrator based on the highest priority tunnel between the VPN client and the VPN concentrator being active.
12. The at least one processor: determining that the highest priority tunnel between the VPN client and the VPN concentrator is inactive; and adding the fully qualified domain names of the second IPsec tunnel and the third IPsec tunnel to the VPN concentrator based on the determination that the highest priority tunnel between the VPN client and the VPN concentrator is inactive; 12. The system of claim 10 or 11, further configured to:
13. The at least one processor: determining that the highest priority tunnel between the VPN client and the VPN concentrator has become active after being inactive; and deactivating the fully qualified domain names of the second IPsec tunnel and the third IPsec tunnel from the VPN concentrator based on the determination that the highest priority tunnel between the VPN client and the VPN concentrator has become active after being inactive. The system of claim 12 further configured to:
14. The at least one processor: identifying a fourth IPsec tunnel between a second VPN client and the VPN concentrator; identifying a fifth IPsec tunnel between the second VPN client and the VPN concentrator; identifying a sixth IPsec tunnel between the second VPN client and the VPN concentrator; determining that the fourth IPsec tunnel is a highest priority tunnel between the second VPN client and the VPN concentrator; determining that the highest priority tunnel between the second VPN client and the VPN concentrator is active; and deactivating fully qualified domain names of the fifth IPsec tunnel and the sixth IPsec tunnel from the VPN concentrator based on the determination that the highest priority tunnel between the second VPN client and the VPN concentrator is active. The system of claim 12 further configured to:
15. The at least one processor: determining that the highest priority tunnel between the second VPN client and the VPN concentrator is inactive; and adding the fully qualified domain names of the fifth IPsec tunnel and the sixth IPsec tunnel to the VPN concentrator based on the determination that the highest priority tunnel between the second VPN client and the VPN concentrator is inactive; The system of claim 14 further configured to:
16. The at least one processor: determining that the highest priority tunnel between the second VPN client and the VPN concentrator has become active after being inactive; and deactivating the fully qualified domain names of the fifth IPsec tunnel and the sixth IPsec tunnel from the VPN concentrator based on the determination that the highest priority tunnel between the second VPN client and the VPN concentrator has become active after being inactive. The system of claim 15 further configured to:
17. 12. The system of claim 10 or 11, wherein the at least one processor is further configured to determine a maximum number of active IPsec tunnels to be maintained by the VPN concentrator.
18. 12. The system of claim 10 or 11, wherein the at least one processor is further configured to determine a maximum number of VPN clients that may connect to the VPN concentrator based on the maximum number of active IPsec tunnels that will be maintained by the VPN concentrator.
19. In at least one processor of an edge gateway backend system for managing Internet Protocol Security (IPsec) for a virtual private network (VPN) concentrator: identifying a first IPsec tunnel between a VPN client and a VPN concentrator of the edge gateway backend system; identifying a second IPsec tunnel between the VPN client and the VPN concentrator; identifying a third IPsec tunnel between the VPN client and the VPN concentrator; determining that the first IPsec tunnel is a highest priority tunnel between the VPN client and the VPN concentrator; determining that the highest priority tunnel between the VPN client and the VPN concentrator is active; and a deactivation procedure for deactivating the fully qualified domain names of the second IPsec tunnel and the third IPsec tunnel from the VPN concentrator based on the determination that the highest priority tunnel between the VPN client and the VPN concentrator is active. A computer program for executing
20. 20. The computer program product of claim 19, wherein the second IPsec tunnel and the third IPsec tunnel are inactive at the VPN concentrator based on the highest priority tunnel between the VPN client and the VPN concentrator being active.