Distributed tunnel termination
Distributed tunnel aggregator devices address capacity limitations in encapsulation tunnels, enabling efficient and scalable threat mitigation services by managing encapsulated tunnels across the provider's network, reducing latency and enhancing service delivery.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-10-27
- Publication Date
- 2026-03-30
AI Technical Summary
Existing network service providers face capacity limitations in establishing encapsulation tunnels for returning clean traffic due to limited resources and bandwidth constraints, leading to potential delays and increased latency during DDoS attacks.
Deploying distributed tunnel aggregator devices across the provider's network to manage encapsulated tunnels, reducing the load on managed security routers and enabling efficient distribution of clean return traffic through multiple endpoints.
The solution allows for scalable and cost-effective threat mitigation services by distributing encapsulation tunnel capacity, reducing latency, and ensuring efficient routing of clean traffic to customer endpoints.
Smart Images

Figure 2026510073000001_ABST
Abstract
Description
Background Art
[0001] [Cross - Reference to Related Applications] This application claims the benefit of U.S. Provisional Application No. 63 / 381,828, filed on October 1, 2022, entitled "Distributed Tunnel Termination", which is hereby incorporated by reference in its entirety.
[0002] Computing networks are increasingly being targeted by malicious actors who attempt to disrupt the normal functioning or operation of a targeted network. For example, denial - of - service (DoS) and distributed denial - of - service (DDoS) attacks may attempt to overwhelm the hardware or software resources of a computing network by flooding these hardware or software resources with a large number of redundant queries. A large amount of malicious network traffic interferes with or prevents legitimate traffic from being processed by network resources. Customers of network service providers may use threat mitigation services offered by the service provider to help prevent malicious traffic from loading the customers' resources. Using this approach, network traffic is routed to threat mitigation devices on the provider's network, and screened or filtered traffic can be returned to the customer's network with malicious traffic removed. Aspects of the technology disclosed herein are directed to this general technical environment.
Summary of the Invention
[0003] This summary of the invention is provided to introduce in a simplified form the selection of concepts further described below in modes for carrying out the invention. This summary of the invention is not intended to identify any important or essential features of the claimed subject matter, nor is it intended to be used as an aid in determining the scope of the claimed subject matter.
[0004] In a non-exclusive manner, the present invention discloses a method (and an associated system for performing the method) comprising the steps of: establishing a first encapsulation tunnel between a tunnel aggregator device and a first customer routing device; receiving a first plurality of packets addressed to a first customer endpoint from a first managed security router of a provider network in the tunnel aggregator device; encapsulating the first plurality of packets by the tunnel aggregator device; providing the encapsulated first plurality of packets to the first customer routing device using the first encapsulation tunnel; receiving a second plurality of packets addressed to the first customer endpoint from a second managed security router of the provider network in the tunnel aggregator device; encapsulating the second plurality of packets by the tunnel aggregator device; and providing the encapsulated second plurality of packets to the first customer routing device using the first encapsulation tunnel. [Brief explanation of the drawing]
[0005] The following drawings, which form part of this application, are illustrative of the modes of the systems and methods described below and are not intended to limit the scope of this disclosure in any way, and the scope shall be as defined by the claims.
[0006] [Figure 1] This is a block diagram of an example distributed encapsulation tunnel networking environment.
[0007] [Figure 2] This figure shows an exemplary method by which embodiments of this technology can be implemented using a tunnel aggregator device.
[0008] [Figure 3] This figure illustrates an example of how an embodiment of this technology can be implemented by a managed security router.
[0009] [Figure 4] This is a block diagram of an example computing device. [Modes for carrying out the invention]
[0010] Computing networks are routinely targeted by DoS and DDoS attacks (collectively referred to herein as DDoS attacks). In a DDoS attack, a large number of computing devices may attempt to overwhelm the resources of a targeted network by sending a massive volume of service requests or other queries to an organization's network resources. These excessive requests degrade the network resources' ability to serve legitimate requests. In a DDoS attack, attacking devices may simultaneously impersonate multiple Internet Protocol (IP) addresses to conceal their location, making it difficult to mitigate the attack.
[0011] A customer of a network service provider may ask the network service provider to help filter out unwanted network traffic before it reaches the customer's network or computing resources. One technique to mitigate a DDoS attack is to route incoming network traffic through a scrubbing center, which can identify malicious packets in the traffic and remove them before they reach the customer's network. A targeted organization may request threat mitigation services from its network service provider (hereinafter referred to as the Provider), and the Network Service Provider may offer the use of a threat mitigation system that includes a scrubbing center. In an example, a scrubbing center may include multiple scrubbing devices that analyze and clean traffic, and a managed security router (MSR) that manages traffic to and from the scrubbing devices.
[0012] A request for threat mitigation services may include packet routing instructions from the customer, such as instructions on how clean traffic should be routed to return to the customer's network, preferences regarding the data rate or bandwidth of the return path for clean data packets, and / or other instructions and service preference information. The provider may use the received packet routing instructions to configure various resources of the threat mitigation system and / or the provider's own network to deliver threat mitigation services to the requesting customer. For example, the MSR may be configured to route clean return traffic to the customer's network based on the packet routing instructions provided by the customer and / or available network resources or capacity.
[0013] In one example, a customer may provide a routing instruction indicating that clean return traffic should be routed from the scrubbing center to the customer network through an internet circuit / network / service already subscribed to by the customer. The MSR may be configured to identify the customer traffic and route it accordingly to the customer network. In another example, a customer may request that clean return traffic be routed to the customer network through one or more encapsulation tunnels. For example, Generic Routing Encapsulation (GRE) tunnels, Internet Protocol Secure (IPsec) tunnels, or other forms of encapsulation tunneling may be used. Data packet encapsulation involves wrapping a first data packet using one protocol inside an outer data packet (encapsulated packet) using a different protocol, with the packet header attached to the outer encapsulated packet. The header information of the outer encapsulated packet may specify the tunnel endpoints as source and destination IP addresses. The encapsulated data packet is sent from the source network endpoint (such as a provider router) to a specific target destination endpoint (such as a customer's premises router). No intervening network resources (such as other routers that are not the target destination endpoint) access the encapsulated packet directly; they only access the header of the outer packet. When the encapsulated data is received at the destination endpoint, the outer data packet and header are removed, and then the original (initial) data packet can be accessed. In this way, a "tunnel" is formed in which only the two endpoints have access to the original data packet.
[0014] There are several potential benefits that customers may prefer when using encapsulation tunnels such as GRE. Using encapsulation tunnels can allow customers to distribute traffic across multiple return paths, alleviating the load on any one set of network resources (e.g., network resources located in a specific urban or geographical area). Encapsulation tunnels can also facilitate the use of provider services (e.g., threat mitigation services) even when customers use different Internet service providers (ISPs). Encapsulation tunnels can simplify and secure network connectivity between service providers and end customers through third-party ISP networks. Finally, because encapsulation tunnels can provide return paths that are simpler / faster to establish than other methods, they can enable rapid provisioning of threat mitigation or other services for customers experiencing DDoS attacks. In the example, there may be other reasons why a customer might prefer using encapsulation tunnels from their provider to their network.
[0015] In the example, the customer may prefer to receive clean return traffic from the MSR using an encapsulation tunnel established between the MSR (as the source tunnel endpoint) and the customer destination endpoint. However, the number of tunnels that the MSR can support may be limited by resources or the MSR's capacity. For example, the number of physical ports available on the MSR or other performance constraints may limit the number of encapsulation tunnels that the MSR can establish. In addition, bandwidth typically reserved for handling DDoS attacks is occupied by the bandwidth reserved for encapsulation tunnels. As customer demand for threat mitigation services increases, the MSR may be unable to support both of its primary functions: routing traffic in and out of the scrubbing devices in the scrubbing center, and simultaneously meeting customer demand for clean traffic that will be returned via encapsulation tunnels. In the example where the MSR is operating at maximum capacity, but the customer packet routing instruction specifies the use of encapsulation tunnels, the MSR may route the return traffic to another provider network resource that has the capacity to support the encapsulation tunnel return path. For example, a first MSR operating at maximum capacity may route return traffic to a second provider MSR at a different location, where the encapsulation tunnel may then be established with the customer endpoint. This process (which may be referred to as "backhauling") may add significant delay or latency to customer traffic, which may negatively impact the customer.
[0016] As described herein, in an example, the technology alleviates the limitations of MSR encapsulated tunnel capacity by using distributed tunnel aggregator devices across the provider's network. The tunnel aggregator device may be a server or similar computing resource capable of establishing encapsulated tunnels with multiple customer endpoints. Thus, the tunnel aggregator device may receive clean return traffic from the MSR and route the traffic to customer endpoints through the encapsulated tunnel, thereby reducing the routing load on the MSR. Compared to the MSR, the tunnel aggregator device may offer significant benefits to network service providers, such as being easier to operate, easier to procure (available from more vendors), and significantly less expensive than the MSR. Therefore, a network provider may deploy numerous tunnel aggregators across different network nodes spread across different locations served by the provider's network to distribute return traffic routed through encapsulated tunnels. In addition, the use of tunnel aggregators enables network providers to scale network capacity quickly and cost-effectively by having servers that can be deployed on demand.
[0017] In some examples, a provider may deploy a tunnel aggregator device in physical or logical proximity to the MSR, which may facilitate routing return traffic from the MSR to the tunnel aggregator device for final transmission to customer endpoints. In other examples, the tunnel aggregator device may be deployed in proximity to other provider network resources, such as provider edge routers. This type of deployment may require that return traffic be routed from the MSR through the provider network (by clean return virtual routing and forwarding, etc.) to the provider edge router, and then to the tunnel aggregator device, which ultimately delivers the traffic to the customer via the encapsulated tunnel. Further details are provided here by the discussion of the diagrams.
[0018] Figure 1 is a block diagram of an exemplary distributed encapsulated tunnel networking environment 100. The networking environment 100 may include any type of telecommunications network that utilizes IP addresses to connect one or more components of the network.
[0019] In one example, the networking environment 100 includes a provider network 118, which may include provider edge (PE) routers 106a, 106b, and 106c (collectively referred to as 106 herein) for sending and receiving traffic in and out of the provider network 118. The provider network 118 may further include other computing devices or resources of the networking environment 100, such as managed security routers 114 and 115 associated with scrubbing centers 112 and 113 (respectively), a control center 120, and / or other computing devices or resources. The provider network 118 may include additional routers, computing devices, network infrastructure, and / or other equipment that supports IP-based data communication among computing devices / resources coupled to the provider network 118. In some examples, the provider network 118 may be part of an internet backbone.
[0020] In one example, PE router 106a may receive public traffic 102 via the public internet 104, determine the destination IP address of the traffic, determine the route for the traffic (e.g., via the provider network 118), and forward the traffic to another PE router (e.g., router 106b) for delivery to a first customer premises equipment (CPE) 122a.
[0021] The PE router 106 may advertise routes served by the router through border gateway protocol (BGP) or some other routing protocol announcement or notice. In the example, since the encapsulated tunnel will often terminate on the customer's premises, which is outside the network provider's network, BGP is primarily used as the routing protocol. For example, the PE router 106 may provide a BGP notice indicating that CPEs 122a, 122b, and 122c (collectively referred to as 122 in this specification) can be accessed through the PE router 106. In response to the notice, public traffic 102 directed to CPE 122 may be routed by the PE router 106 through the provider network 118 to CPE 122.
[0022] In some examples, the CPE122s may be located close to each other or in the same location, while in other examples, the CPE122s may be geographically dispersed. For example, the first CPE122a and the second CPE122b may be located close enough to the PE router 106b that both CPE122a and 122b receive traffic through the PE router 106b. The third CPE122c may be located in a different geographical area and therefore receive traffic through the PE router 106c.
[0023] In some examples, CPE122 may represent one or more routers or other computing devices owned and / or operated by a single customer at the edge of the customer's internal network. In other examples, each CPE122 may represent an access point for the networks of multiple customers, rather than a single customer. For example, CPE122a may be associated with a first customer, CPE122b may be associated with a second customer, and CPE122c may be associated with a third customer.
[0024] In an example, the CPE 122 may access provider services and / or computing resources available on other networks connected to the provider network 118 via the Internet or the Internet circuits 124a, 124b, and 124c (collectively referred to herein as 124). In some cases, the Internet circuits 124 may include the provider's network and computing resources, while in other cases, the Internet circuits may include a third-party ISP's network and computing resources. In an example, the Internet circuit 124 may be an Internet circuit to which a customer subscribes for the provisioning of networking services to the customer.
[0025] In an example, a computing device of a customer's network may be configured to provide computing services (not shown) to the public and / or members of the customer's organization. Examples of computing services provided by the customer's network may include a web page, an application programming interface (API), or another computing application configured to process requests and provide content in response to the requests. For example, a server on the customer's network may provide content such as text, documents / files, images, audio, video, web pages, IP addresses, domain information, and / or other types of content. The public traffic 102 may include requests directed to the customer's computing services that are accessible through one or more CPEs 122. In some examples, a hacker may attempt to send malicious requests to the customer's computing services to overload the services and prevent legitimate requests from being fulfilled. The malicious requests may take the form of a DDoS attack that floods the customer's services with these excessive requests.
[0026] To counter DDoS attacks, the administrator of the targeted customer's network may purchase threat mitigation services from a provider to clean / scrub network packets identified as threats and directed at the targeted customer's network. As part of the mitigation, incoming public traffic 102 (or other traffic) headed to the customer's network may be re-routed, for example, by a PE router, such as PE router 106a, and / or by other routers in the provider network 118, to the provider's scrubbing center 112. In some examples, the scrubbing center 112 may include an MSR 114 that manages traffic into and out of the scrubbing center 112. In other examples, the MSR 114 may not be located directly within the scrubbing center 112 and may still direct traffic into and out of the scrubbing center 112. Similarly, in some examples, traffic may be re-routed to a different scrubbing center 113 using an associated MSR 115.
[0027] MSR114 (or MSR115, if applicable) may be configured to route incoming traffic to one or more associated scrubbing devices, such as scrubbing device 116 (or 117 for scrubbing center 113), where data packets in the traffic are examined to determine which packets are clean / legitimate and which are suspicious / malicious. For ease of explanation, filtering / scrubbing operations are generally described herein in relation to scrubbing center 112; however, similar operations may be performed in scrubbing center 113. Malicious packets may be dropped by scrubbing device 116 to prevent them from overwhelming the customer's network. Clean / filtered packets are then routed back from scrubbing device 116 to MSR114, where they may be forwarded to the customer's network (e.g., via CPE122). The scrubbing centers 112 and 113 may include additional computing devices not shown in Figure 1, such as scrubbing device controllers or managers, and / or other elements.
[0028] In some cases, customers may prefer to receive clean return traffic in an unencapsulated form. In such cases, MSR114 may return the clean traffic to the customer network via provider network 118, applicable PE router 106, and CPE122 without creating an encapsulation tunnel. In the example, provider network 118 may utilize clean return virtual routing and forwarding (VRF) to route the clean traffic to the customer.
[0029] In another example, a customer may prefer to receive clean return traffic via a dedicated encapsulation tunnel established between the provider's source endpoint and the customer's destination endpoint. The encapsulation tunnel may be, for example, a GRE tunnel created to encapsulate traffic carried from the provider network 118 across the applicable internet circuit 124 to the CPE 122. The destination endpoint of the GRE tunnel may be one of the CPEs 122, which, upon receiving the encapsulated traffic, may decapsulate the received data packets and forward the packets to an appropriate computing device within the customer network. As described, the MSR 114 can function as the source endpoint of the encapsulation tunnel, although the capacity of the MSR 114 to perform tunnel encapsulation may be limited.
[0030] To address the capacity limitations that may be associated with the use of MSR as an encapsulated tunnel endpoint, in an example, the provider may deploy one or more tunnel aggregator devices, such as tunnel aggregator devices 110a, 110b, and / or 110c (collectively referred to as 110 herein) within the provider network 118. The tunnel aggregator device 110 may be a server or other computing device / resource capable of performing encapsulated tunneling functions typically associated with a router. In an example, the tunnel aggregator device 110 may be a server running software that enables the server to operate as an open source or virtual router.
[0031] In non-exclusive examples, the process of establishing an encapsulation tunnel between a source endpoint in the provider network (e.g., tunnel aggregator device 110) and a destination endpoint in the customer network (e.g., CPE 122) may include configuring each endpoint to recognize the IP address of the other endpoint. In some examples, establishing an encapsulation tunnel may include configuring the tunnel's maximum transfer unit (MTU), data segmentation size, and / or other parameters. In other examples, the tunnel may be configured for keep-alive polling, where the tunnel status is checked periodically. In yet another example, establishing an encapsulation tunnel may include configuring the tunnel endpoint to perform data packet encryption / decryption, such as when the encapsulation tunnel is an IPsec tunnel.
[0032] In the example, the establishment of the encapsulation tunnel may be performed automatically by one or more computing devices on the provider network 118 in response to a customer request for threat mitigation services. In the example, customer-provided instructions that may accompany the threat mitigation service request may be used to configure the tunnel. For example, a specific tunnel aggregator device, such as one of the tunnel aggregator devices 110, may be automatically selected as the encapsulation tunnel source endpoint based on the customer-provided instructions. In an example where the customer-provided instructions do not indicate a selection / preference for the tunnel source endpoint, the threat mitigation system may automatically determine which tunnel aggregator device 110 should function as the encapsulation endpoint based on a variety of factors. These factors may include tunnel aggregator device capacity, location, traffic volume, availability of other network resources, other network performance considerations, service provider preferences, and / or other provider policies.
[0033] Once an encapsulated tunnel is established between the tunnel aggregator device 110 and the corresponding customer destination endpoint, each tunnel aggregator device 110 may be configured to notify the customer endpoints served by the tunnel aggregator device 110. The tunnel aggregator devices 110 may then receive clean traffic to be returned to the customer endpoints via the encapsulated tunneling. For example, tunnel aggregator device 110a may establish an encapsulated tunnel with CPE 122 and be configured to notify one or more IP addresses indicating that traffic can be routed to CPE 122 through tunnel aggregator device 110a. In response to the notification, and / or based on its own configuration, MSR 114 may route the clean return traffic to tunnel aggregator device 110a, which may then provide (i.e., send or transmit) the clean packets to the appropriate CPE 122 via encapsulated tunneling. The tunnel aggregator devices 110a and MSR 114 may be configured by the provider to support this type of tunneling deployment in response to customer requests for threat mitigation services, for example, by packet routing instructions provided by the customer. For example, the tunnel aggregator device 110 may be selected to receive data packets from MSR 114 based on a combination of customer-provided instructions, provider routing or other preferences, provider policy, tunnel aggregator device 110 capacity, MSR 114 capacity, network routing capacity, and / or other factors.
[0034] In some examples, to facilitate packet routing from MSR114 to tunnel aggregator device 110a, the tunnel aggregator device 110a may be located in the same location as MSR114, or physically close to it, or otherwise logically near MSR114. Upon receiving clean traffic from MSR114, the tunnel aggregator device 110a may then encapsulate the data packets associated with the clean traffic and provide the encapsulated packets to one of the CPEs 122 through the provider network 118, PE router 106, and internet circuit 124.
[0035] In another example, the tunnel aggregator device 110a may receive clean traffic from an MSR 115 associated with a second scrubbing center 113 that is not located in the same place as or physically near the tunnel aggregator device 110a. The MSR 115 may provide clean traffic to the tunnel aggregator device 110a based on a combination of customer-provided instructions, provider routing or other preferences, provider policies, tunnel aggregator device 110 capacity, MSR 115 capacity, network routing capacity, and / or other factors. For example, the MSR 115 may route clean traffic to the tunnel aggregator device 110a based on notification / announcement of customer endpoint IP addresses by the tunnel aggregator device 110a.
[0036] In yet another example, the tunnel aggregator device 110a may receive clean traffic from both MSRs 114 and 115, and from other MSRs (not shown) that may be connected to the provider network 118. In this example, the tunnel aggregator device 110a may route the clean return traffic received from multiple computing devices / resources on the provider network 118 to one or more customer endpoints via the encapsulated tunnel.
[0037] In some examples, the provider may pair tunnel aggregator devices (e.g., 110b / 110c) with their respective PE routers 106b / 106c, which are located in proximity to the CPE 122. For example, as shown in Figure 1, the tunnel aggregator device 110b may be located in the same location as the PE router 106b, or in a different proximity to it, or logically near it. The tunnel aggregator device 110b may be configured to advertise IP addresses corresponding to CPE 122a and 122b, and may be configured to establish an encapsulated tunnel with CPE 122a and 122b. The MSR 114 may be configured to route clean return traffic through the provider network 118 to the PE router 106b. Based on the notification by the tunnel aggregator device 110b and / or its own configuration, the PE router 106b may then route the clean traffic received from the MSR 114 to the tunnel aggregator device 110b. The tunnel aggregator device 110b (tunnel source endpoint) encapsulates the data packets associated with the clean traffic and provides the encapsulated packets to the CPE 122a (tunnel destination endpoint) through the PE router 106b and the internet circuit 124a, or to the CPE 122b through the PE router 106b and the internet circuit 124b. The CPE router 122a (or, if applicable, the CPE router 122b) may then provide the unencapsulated data packets to computing resources within the customer network. In some examples, the tunnel aggregator device 110b may return clean traffic to the CPE 122a and / or 122b via encapsulated tunneling, and as described above, the MSR 114, PE router 106b, and tunnel aggregator device 110b may thereby be configured during the provisioning of a threat mitigation service requested by the customer.In other examples, the tunnel aggregator device 110 may be selected to receive data packets from the MSR 114 through the PE router 106 based on a combination of customer-provided instructions, provider routing or other preferences, provider policy, MSR 114 capacity, PE router 106 capacity, tunnel aggregator device 110 capacity, provider network 118 routing capacity, and / or other factors.
[0038] In some examples, the tunnel aggregator device 110 may be selected to receive data packets through the PE router 106 from MSR 114, MSR 115, both MSR 114 and 115, and / or additional MSRs connected to the provider network 118. As described above, this selection may be based on a combination of customer or provider preferences, provider policies, computing / network performance, and / or other considerations.
[0039] In a further example, the provider may deploy tunnel aggregator devices with multiple PE routers distributed across the provider network 118, beyond what is shown in Figure 1. This configuration, where encapsulated tunnel source endpoints are spread throughout the provider's network, may reduce the encapsulation tunneling bottleneck in MSR 114 / 115 and allow clean traffic to be routed / distributed more efficiently across the computing resources of the provider network 118 in its unencapsulated form. That is, the encapsulated tunnel may be shorter because the traffic is encapsulated in the tunnel aggregator device 110, which is closer than the CPE 122 (customer tunnel destination endpoint). In the example, this may be beneficial in ensuring that the bloat of additional packets from the encapsulation is carried by as few network elements as possible.
[0040] In some examples, tunnel aggregator devices 110a, 110b, and / or 110c may each include multiple processors or devices. For example, each tunnel aggregator device 110 may be a single server, a cluster of servers, a computing device, a collection of computing devices, and / or some other computing resource. The distributed deployment of tunnel aggregator devices 110 allows the provider to scale the encapsulation tunneling capacity of the provider's threat mitigation services to meet the demands of a particular customer, a set of customers, or a geographically localized set of PE routers 106 that serve a high-traffic area to which a large number of encapsulation tunnels terminate. In this regard, encapsulation tunneling capacity and resources may be deployed / distributed more efficiently to meet customer demands for clean return traffic through encapsulation tunneling.
[0041] In the example, the tunnel aggregator device may be deployed across multiple MSRs and PE routers distributed across the provider's network. In one example, the threat mitigation system may be configured so that multiple encapsulated tunnels are used to return clean traffic to a single customer endpoint. Clean data packets from the scrubbing device 116 may first be routed to the MSR 114, which may then route a portion of the return traffic to a second MSR (e.g., MSR 115). In the example, if properly configured, either the MSR 114 or the MSR 115 may route the return traffic to one or more tunnel aggregators 110, which provide the clean traffic to a common customer endpoint (such as one of the CPEs 122).
[0042] In some examples, the administrator of a customer network may request and configure threat mitigation services by accessing a control center 120, which may be made available by the provider. Although the control system is shown as a separate system in Figure 1, in the example, the control center 120 may be integrated into a scrubbing center, distributed across computing resources including or connected to the provider network 118, or otherwise made available within the networking environment 100. In some examples, the administrator may access the control center 120 of the provider network 118 using a computing device such as a desktop or laptop computer, a smartphone, a customer server, or other type of computing device. The control center 120 may provide a user interface (UI) that the administrator can interact with to configure threat mitigation services. In other examples, the administrator may configure threat mitigation services using a method other than a UI, such as an API or another type of interface or method. In yet another example, the network service provider may configure threat mitigation services without the involvement of the customer network administrator.
[0043] As briefly described above, the configuration of the threat mitigation service by the administrator / customer may include instructions to the provider specifying the parameters of the services to be provided, and may include selectable service options or preferences. For example, as part of the selectable service options, the customer may allow the DDoS threat intelligence service 108 to automatically determine (or recommend for customer confirmation) whether traffic should be redirected to scrubbing centers 112 and / or 113. This determination or recommendation may be based at least in part on traffic information collected by the DDoS threat intelligence service 108, threat profiles provided by the customer, other screening criteria provided by the customer, and / or screening criteria determined by the provider.
[0044] In the examples, the DDoS threat intelligence service 108 may be implemented on a server, a server cluster, a computing device, a collection of computing devices, and / or any other computing resource. In some examples, the DDoS threat intelligence service 108 may be operably connected to one or more other routing or computing elements of the provider network 118, including a PE router and a PE router 106a. In yet another example, the DDoS threat intelligence service 108 may be distributed across computing devices / resources of the provider network 118.
[0045] If the DDoS threat intelligence service 108 determines that traffic directed to the customer network meets one or more threat criteria, it may inform the computing resources of the networking environment that the traffic directed to the customer network should be redirected to a scrubbing center 112, for example, an MSR 114 associated with the scrubbing center 112. In other examples, a threat mitigation service is always activated (so that traffic directed to the customer network is redirected to a scrubbing center 112, for example, an MSR 114 associated with the scrubbing center 112, without any involvement of the DDoS threat intelligence service 108). The process outlined above may then be used to return clean traffic to the customer network, for example, using an encapsulation tunnel. In some examples, traffic directed to the customer network may be redirected to an MSR 115 associated with scrubbing center 113, while in other examples, some traffic may be redirected to both MSR 114 and / or MSR 115 for further routing to associated scrubbing devices 116 and / or 117. In yet another example, traffic may be directed to multiple MSRs and associated scrubbing centers distributed across provider network 118.
[0046] In some examples, the customer's instructions may include the selection of a specific scrubbing center (e.g., scrubbing center 112 or 113) from among several scrubbing centers available across the geographical area served by the provider network 118. For example, the customer may configure the threat mitigation service to redirect traffic suspected of being malicious to a scrubbing center that is closest in distance to the customer network being served, i.e., logically near the customer network, and / or minimizes the latency of clean return traffic provided from the scrubbing center to the customer network. In other examples, the customer may select a scrubbing center from other available scrubbing centers that has more capacity to handle clean return traffic or offers better / higher computing performance. In yet another example, the customer's instructions may not specify a particular scrubbing center selection, leaving the selection of scrubbing centers to the threat mitigation system.
[0047] The instructions provided by the customer may further include routing instructions for the return of clean data packets and / or the bandwidth or data rate of the return traffic. In an example, the routing instructions may include an indication of whether the clean return traffic should be returned via encapsulation tunneling (e.g., through one or more GRE tunnels) and the maximum allowable bandwidth for the clean return traffic. In an example where encapsulation tunneling is selected, the routing instructions may include the selection of an encapsulation tunnel source endpoint, such as the source endpoint closest in distance to the customer network being served, or the selection of a source endpoint that minimizes the latency of the clean return traffic. In another example, the routing instructions may include the selection of an encapsulation tunnel source endpoint located in a specific geographical area. In yet another example, the customer may specify in the routing instructions the number of encapsulation tunnels to be used, the locations of the tunnel source endpoints, and / or other routing preferences for the return traffic. In yet another example, the routing instructions may indicate that the clean traffic should be returned through a combination of encapsulation tunneling and unencapsulated routing. Routing instructions may further include preferences for alternative return paths for clean traffic in the event of network equipment failure.
[0048] In an example, a customer may request threat mitigation services without including any commands or service preferences. In such an example, the provider's computing devices or resources may configure the routing of suspicious / malicious data packets and clean / filtered data packets to different elements within or coupled to the provider network 118. The selection of scrubbing centers (e.g., scrubbing centers 112 and / or 113), MSRs (e.g., MSRs 114 and / or 115), tunnel aggregator devices (e.g., tunnel aggregator device 110), PE routers (e.g., PE router 106), and / or other provider resources / elements may be determined by a combination of provider preferences or policies, performance capacity, resource availability, routing efficiency, and / or other considerations. These considerations may be actively made by the network provider administrator or may be automatically determined by the computing devices / resources in the provider network 118.
[0049] Figure 2 shows an exemplary method 200 in which an aspect of this technology can be implemented by a tunnel aggregator device, for example, tunnel aggregator device 110. In operation 202, an encapsulation tunnel, such as a GRE tunnel, may be established between the tunnel aggregator device (tunnel source endpoint) and one of the CPEs (tunnel destination endpoints), for example, CPE 122. In some examples, the encapsulation tunnel may be established between the tunnel aggregator device and multiple CPEs. The encapsulation tunnels may be established sequentially (i.e., one encapsulation tunnel is established at a time) or in a group or set of encapsulation tunnels. In the examples, the encapsulation tunnels may be established as needed and / or on demand. Furthermore, the tunnel aggregator device may be reconfigured to establish encapsulation tunnels with additional CPEs or other endpoints as needed.
[0050] As discussed, in the examples, establishing an encapsulation tunnel may include configuring each endpoint to recognize the IP address of the other endpoint. In some examples, establishing an encapsulation tunnel may include configuring the tunnel's maximum transmission unit (MTU), data segmentation size, and / or other parameters. In other examples, the tunnel may be configured for keep-alive polling, where the tunnel status is checked periodically. In yet another example, establishing an encapsulation tunnel may include configuring the tunnel endpoint to perform data packet encryption / decryption, such as when the encapsulation tunnel is an IPsec tunnel.
[0051] In the example, the establishment of an encapsulation tunnel may be performed automatically by one or more computing devices on the provider network in response to a customer request for threat mitigation services. In the example, customer-provided instructions that may accompany the threat mitigation service request may be used to configure the tunnel. For example, a specific tunnel aggregator device may be automatically selected as the encapsulation tunnel source endpoint based on customer-provided instructions. In an example where customer-provided instructions do not indicate a selection / preference for the tunnel source endpoint, the threat mitigation system may automatically determine which tunnel aggregator device should act as the encapsulation endpoint based on various factors. As described above, these factors may include tunnel aggregator device capacity, location, traffic volume, availability of other network resources, other network performance considerations, and / or service provider preferences.
[0052] In operation 204, the tunnel aggregator device receives clean data packets addressed to customer endpoints. The packets may be provided by an MSR, e.g., MSR114, configured to route clean data packets to the tunnel aggregator device based on customer-provided instructions or other factors described above. In some examples, the MSR may be located at the same location as the tunnel aggregator device, or be physically or logically close to the tunnel aggregator device. In other examples, the MSR may be the one to which the tunnel aggregator device has notified / announced the IP address of the customer endpoint receiving the clean data packets. In yet another example, the tunnel aggregator device may be selected to receive data packets based on a combination of customer-provided instructions, provider routing or other preferences, provider policy, tunnel aggregator device capacity, MSR capacity, network routing capacity, and / or other factors. In yet another example, the received data packets may be clean / filtered data packets from a scrubbing center associated with the MSR.
[0053] In the example, the tunnel aggregator device may receive clean data packets from one of the PE routers, for example, PE router 106, to which the tunnel aggregator device has notified / announced the IP address of the customer endpoint to which it receives clean data packets. In some examples, the PE router may be located in the same location as the tunnel aggregator device, or be physically and / or logically close to the tunnel aggregator device. In further examples, the PE router may be operationally connected to the CPE, which is the destination endpoint of the encapsulated tunnel, for example, via the internet circuit 124. The clean data packets may be routed from the MSR to the PE router through the provider's network, for example, the provider network 118. The data packets routed to the tunnel aggregator through the PE router may be clean / filtered packets from the scrubbing center associated with the MSR.
[0054] The customer endpoint to which the received data packet is addressed may be different from the encapsulation tunnel destination endpoint. That is, the encapsulation tunnel destination endpoint may be a customer routing device, such as a CPE, while the customer endpoint may be a computing device on the customer's network, such as a server, server cluster, computing device, collection of computing devices, and / or other computing resource. In some examples, the customer endpoint may be a computing device that provides services to other users on the customer's network, such as employees of the customer / organization, internet users, or other users. In the examples, the customer routing device may be a CPE that routes traffic to the customer endpoint.
[0055] In operation 206, the tunnel aggregator device encapsulates the received data packets according to the established tunnel protocol. As described above, data packet encapsulation involves wrapping a first data packet using one protocol inside an outer data packet (encapsulated packet) using a different protocol, with the packet header attached to the outer encapsulated packet. The header information of the outer encapsulated packet may specify the tunnel endpoint as the source and destination IP addresses. The encapsulated data packet is sent from the source network endpoint (e.g., a PE router) to a specific target destination endpoint (e.g., a customer premises router), and no intervening network resources (e.g., other routers that are not the target destination endpoint) access the encapsulated packet itself, only the header of the outer packet. When the encapsulated data is received at the destination endpoint, the outer data packet and header are removed, and then the original (first) data packet can be accessed.
[0056] In operation 208, the tunnel aggregator device provides encapsulated data packets to the customer routing device via the encapsulation tunnel. In some examples, providing data packets may include sending or transmitting data packets synchronously point-to-point. For example, encapsulated data packets may be provided to the customer routing device in defined segments or frames at fixed intervals or within a specific bandwidth, according to a protocol, such as the Internet Protocol. In other examples, encapsulated data packets may be provided to the customer routing device asynchronously. In some examples, data packets may be provided to the customer routing device through an encapsulation tunnel implemented across intervening computing devices or resources, such as intervening routers, that are communicably coupled via a wired or wireless connection.
[0057] In operation 210, the tunnel aggregator device determines whether additional data packets are available to be delivered to the customer endpoint via the encapsulated tunnel. In the example, the tunnel aggregator device may wait for the additional packets to arrive and may continue to advertise the destination IP address to which the tunnel aggregator device is configured to route the encapsulated packets. In the example where no additional data packets are received, the flow proceeds to "No", and the tunnel aggregator device may continue to wait for the additional data packets to arrive.
[0058] In an example where additional data packets are routed to a tunnel aggregator device, the flow proceeds to "yes" and returns to action 204, and the tunnel aggregator device may perform actions 204-210 for the additional packets. In some examples, newly received data packets may be addressed to the same customer endpoint as previously received data packets, while in others, newly received data packets may be addressed to different endpoints of the same customer. In yet another example, newly received data packets may be addressed to one or more endpoints of different customers.
[0059] Figure 3 shows an exemplary method 300 in which an aspect of the present technology can be implemented by one or more managed security routers, e.g., MSR 114 and / or 115. In operation 302, the managed security router receives a data packet addressed to a customer endpoint. In this example, the data packet may be traffic, e.g., public traffic 102, that is directed to a service offered by the customer endpoint or offered by another computing device on the customer's network. In some examples, the received data packet may originate from the public internet, e.g., the internet 104, while in other examples, the data packet may originate from another network, e.g., a private network or a network managed by a third party. In other examples, the received data packet may originate from multiple network sources.
[0060] Data packets may be routed directly to the MSR through a PE router, for example, PE router 106. In some examples, data packets may be routed to the MSR through one or more other elements of the provider's network, for example, provider network 118. In an example, data packets may be routed to the MSR as a result of a customer's request for threat mitigation services. For example, in response to a request for threat mitigation services, a threat intelligence system, for example, threat intelligence 108, may automatically route the traffic to the MSR based on its determination that the traffic may contain malicious data packets. In an example, the threat intelligence system may route the traffic to the MSR based on its identification of a suspected DDoS attack.
[0061] In the example, the MSR may be part of or associated with a scrubbing center, for example, scrubbing center 112. A request for threat mitigation services may include a customer-provided instruction specifying a particular scrubbing center and / or MSR for use in provisioning threat mitigation services. In another example, the MSR may be selected to receive data packets based on the MSR or scrubbing center's proximity to the customer's network, CPE, and / or customer endpoints. In yet another example, the MSR may be selected to receive data packets based on a combination of customer-provided instructions, provider routing or other preferences, provider network policies, MSR capacity, network routing capacity, and / or other factors.
[0062] In operation 304, the MSR delivers the data packet to a threat mitigation device, e.g., one or more scrubbing devices that may be associated with the MSR. The MSR may deliver the suspicious data packet to a threat mitigation device based on the MSR's configuration. In an example, the configuration may be based at least in part on customer-provided instructions included with the request for threat mitigation services. In some examples, the MSR's configuration may be based on a combination of customer-provided instructions, provider preferences, and / or other policies of the provider network. In further examples, the MSR may deliver the suspicious data packet to a threat mitigation device based at least in part on the MSR's capacity, the physical or logical proximity of the threat mitigation device to the MSR, data packet latency, the number of threat mitigation devices, the capacity or availability of the threat mitigation device, and / or other factors. In an example, the MSR may deliver the data packet to one or more threat mitigation devices among several threat mitigation devices provided by the threat mitigation system.
[0063] In operation 306, the MSR receives filtered data packets from the threat mitigation device. The filtered data packets may include traffic from which data packets identified as malicious, or suspected to be malicious, have been removed. The identification and removal of suspicious / malicious data packets is performed by the threat mitigation device, which may be one or more scrubbing devices of the scrubbing centers associated with the MSR (as described above). In the example, the identification and removal of suspicious / malicious data packets by one or more threat mitigation devices may be part of a mitigation technique against a suspected or actual DDoS attack.
[0064] In operation 308, the MSR selects one tunnel aggregator device from several available tunnel aggregator devices. The tunnel aggregator device may be selected based on physical proximity to the MSR, logical proximity to the MSR, and / or other associations with the MSR and / or scrubbing centers. In an example, the MSR's selection of a tunnel aggregator device may be based on customer-provided instructions, provider preferences, and / or other policies of the provider network. In another example, the selection of a tunnel aggregator device may be based at least in part on tunnel aggregator capacity, availability of provider network resources (such as intervening routers or other provider equipment), traffic volume, or other considerations. In yet another example, the MSR may provide filtered data to a tunnel aggregator device that has notified / announced the IP addresses of customer endpoints receiving clean data packets.
[0065] In some examples, the selection of a tunnel aggregator device may be based on the proximity of the tunnel aggregator device to the customer network, for example, proximity to a CPE that functions as an encapsulated tunnel endpoint. Such a tunnel aggregator device may help reduce return traffic latency, enable threat mitigation service providers to distribute return traffic more efficiently, and / or provide other benefits to the provider and / or customer, as described above. In the example, the tunnel aggregator device may be associated with a PE router that is operationally connected to the CPE of the customer network, for example, via an internet circuit. For example, the tunnel aggregator device may be located in the same place as the PE router and / or be physically and / or logically close to the PE router. The tunnel aggregator device may announce / notify the IP addresses of customer endpoints that receive clean data packets.
[0066] In operation 310, the MSR provides filtered or clean data packets to a selected tunnel aggregator device. In an example where the MSR provides filtered data packets to a tunnel aggregator device associated with a PE router, the MSR may route the filtered packets to the tunnel aggregator device through the PE router. Clean return traffic may be routed to the PE router through the provider's network, for example, a portion of the provider's network configured for clean return virtual routing and forwarding.
[0067] Figure 4 is a block diagram of an exemplary computing device 400. The computing device 400, or various components and systems of the computing device 400, may be integrated with or associated with the provider edge router 106, the scrubbing device 116, the DDoS threat intelligence service 108, the managed security router 114, the tunnel aggregator device 110, the control center 120, the customer premises equipment 122, and / or other elements of the provider network 118. As shown in Figure 4, the physical components (e.g., hardware) of the computing device are shown, and these physical components may be used to practice various aspects of this disclosure. The elements described above may be implemented via one or more computing devices 400 together with the elements of the scrubbing center 112.
[0068] The computing device 400 may include at least one processing unit 410 and system memory 420. The system memory 420 may include, but is not limited to, volatile storage (e.g., random access memory), non-volatile storage (e.g., read-only memory), flash memory, or any combination of such memory. The system memory 420 may also include an operating system 430 and one or more program modules 440 that control the operation of the computing device 400. The program module 440 may be responsible for collecting or determining event data 450, including endpoint data and / or network data. Multiple different program modules and data files may be stored in the system memory 420. While running on the processing unit 410, the program module 440 may execute the various processes described above.
[0069] The computing device 400 may have additional features or functions. For example, the computing device 400 may include additional data storage devices (e.g., removable and / or non-removable storage devices) such as magnetic disks, optical disks, or tapes. These additional storage devices are labeled as removable storage 460 and non-removable storage 470.
[0070] Examples of the disclosure may be practiced in discrete electronic elements, packaged or integrated electronic chips including logic gates, electrical circuits including circuits utilizing microprocessors, or on a single chip including electronic elements or microprocessors. For example, examples of the disclosure may be practiced via a system-on-a-chip (SOC) in which each or many of the components shown in Figure 4 can be integrated onto a single integrated circuit. Such an SOC device may include one or more processing units, graphics units, communication units, system virtualization units, and various application functions, all integrated (or "burned") onto a chip substrate as a single integrated circuit.
[0071] When operating via a SOC, the functions described herein may operate via application-specific logic integrated with other components of the computing device 400 on a single integrated circuit (chip). The disclosure may also be put into practice using other techniques capable of performing logical operations such as AND, OR, and NOT, including but not limited to mechanical, optical, fluidic, and quantum techniques.
[0072] The computing device 400 may include one or more communication systems 480 that enable the computing device 400 to communicate with other computing devices 495, such as servers, routers, network devices, client computing devices, etc. Examples of communication systems 480 include, but are not limited to, wireless communication, wired communication, cellular communication, radio frequency (RF) transmitters, receivers, and / or transceiver circuits, Controller Area Network (CAN) buses, universal serial buses (USB), parallel, and serial ports.
[0073] The computing device 400 may have one or more input devices and / or one or more output devices, indicated as input / output devices 490. These input / output devices 490 may include keyboards, sound or voice input devices, haptic devices, touch, force and / or swipe input devices, displays, speakers, etc. The devices described above are examples, and others may be used.
[0074] As used herein, the term "computer-readable medium" may include non-temporary computer storage mediums. Computer storage mediums may include volatile and non-volatile, removable and non-removable media implemented in any method or technique for storing information such as computer-readable instructions, data structures, or program modules.
[0075] System memory 420, removable storage 460, and non-removable storage 470 are all examples of computer storage media (e.g., memory storage). Computer storage media may include RAM, ROM, electrically erasable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other manufactured product that can be used to store information and can be accessed by computing device 400. Any such computer storage media may be part of computing device 400. Computer storage media are tangible and non-transient and do not contain carrier waves or other propagated or modulated data signals.
[0076] Communication media may be embodied by computer-readable instructions, data structures, program modules, or modulated data signals, such as other data in a carrier wave or other transport mechanism, and include any information delivery medium. The term “modulated data signal” may describe a signal having one or more characteristics that are set or modified to encode information in the signal. Exemplary examples, without limitation, communication media may include wired media, such as wired networks or direct wired connections, and wireless media, such as acoustic, radio frequency (RF), infrared, and other wireless media.
[0077] The terminology used herein is for the sole purpose of describing specific embodiments and is not intended to limit the concepts of the present invention. Furthermore, unless expressly stated otherwise, the embodiments described herein are not mutually exclusive. The aspects of the embodiments described herein may be combined in several implementations.
[0078] Regarding the processes in the flowcharts of Figures 2 and 3, it should be understood that the sequence of process stages is not fixed, but can be modified, the order can be changed, they can be executed differently, they can be executed sequentially, simultaneously, or all at once, or they can be changed to any desired sequence, as can be recognized by those skilled in the art.
[0079] Where used herein, the singular forms “a” and “an” are intended to include the plural form as well, unless the context explicitly indicates otherwise. Where used herein, the terms “comprises” and / or “comprising” specify the presence of the features, integers, stages, actions, elements, and / or components mentioned, but do not exclude the presence or addition of one or more other features, integers, stages, actions, elements, components, and / or groups thereof. Where used herein, the terms “and / or” include any and all combinations of one or more items from the associated listed items. Expressions such as “at least one of” following a list of elements modify the entire list of elements, not the individual elements of the list. Furthermore, the use of “may” when describing embodiments of the concept of the present invention refers to “one or more embodiments of the present disclosure.” Also, the term “exemplary” is intended to refer to an example or illustration. As used herein, the terms “use,” “using,” and “used” may be considered synonymous with “utilize,” “utilizing,” and “utilized,” respectively.
[0080] While exemplary embodiments of systems and methods for constructing and using systems and methods have been specifically described and illustrated herein, many modifications and variations will be apparent to those skilled in the art. Therefore, it should be understood that systems and methods for constructing and using systems and methods constructed in accordance with the principles of this disclosure may be embodied in ways other than those specifically described herein. This disclosure is also defined in the following claims and equivalents.
Claims
1. The first step is to establish a first encapsulation tunnel between a tunnel aggregator device and a first customer routing device; The tunnel aggregator device receives a first set of packets addressed to a first customer endpoint from a first managed security router of the provider network; The tunnel aggregator device encapsulates the first plurality of packets; A step of providing the first plurality of encapsulated packets to the first customer routing device using the first encapsulation tunnel; The tunnel aggregator device receives a second set of packets addressed to the first customer endpoint from a second managed security router of the provider network; The tunnel aggregator device encapsulates the second plurality of packets; and The step of providing the encapsulated second plurality of packets to the first customer routing device using the first encapsulation tunnel. A method that includes [a certain feature].
2. The method according to claim 1, wherein the first plurality of packets are received in an unencapsulated form by the tunnel aggregator device via the provider network's clean return virtual routing and forwarding system.
3. The method according to claim 1 or 2, wherein the tunnel aggregator device is logically closer to the first customer routing device than either the first managed security router or the second managed security router.
4. A step of establishing a second encapsulation tunnel between the tunnel aggregator device and the second customer routing device; The tunnel aggregator device receives a third set of packets addressed to a second customer endpoint from the first managed security router of the provider network; The tunnel aggregator device encapsulates the third plurality of packets; and The step of providing the encapsulated third plurality of packets to the second customer routing device using the second encapsulation tunnel. The method according to claim 1 or 2, further comprising:
5. The method according to claim 1, wherein the first plurality of packets and the second plurality of packets are received by the tunnel aggregator device through an on-premises edge router located at the same location as the tunnel aggregator device.
6. The method according to claim 1 or 2, wherein the tunnel aggregator device uses generic routing encapsulation (GRE) to deliver the first plurality of packets and the second plurality of packets to the first customer endpoint.
7. The method according to claim 1 or 2, wherein the tunnel aggregator device uses Internet Protocol Security (IPsec) to provide the first plurality of packets and the second plurality of packets to the first customer endpoint.
8. The first managed security router of the provider network receives a first set of packets addressed to a first customer endpoint; Steps include providing the aforementioned first plurality of packets to one or more threat mitigation devices; The first managed security router receives a first plurality of filtered packets associated with the first plurality of packets from one or more threat mitigation devices; and Steps to provide the first filtered packets to the first tunnel aggregator device for transmission to the first customer endpoint, based on the configuration of the first managed security router. A method that includes [a certain feature].
9. The method according to claim 8, further comprising the step of receiving a customer packet routing command in the first managed security router, wherein the configuration of the first managed security router is at least partially based on the customer packet routing command.
10. The method according to claim 9, wherein the customer packet routing instruction includes an indication that the first plurality of filtered packets should be delivered to the first customer endpoint via an encapsulation tunnel.
11. The method according to claim 9, further comprising the step of selecting the first tunnel aggregator device from a plurality of tunnel aggregator devices, wherein the first tunnel aggregator device is selected by the first managed security router on at least part basis of the customer packet routing instruction.
12. The method according to claim 9, wherein the first plurality of filtered packets are provided in an unencapsulated form to the provider edge router via the provider network's clean return virtual routing and forwarding system.
13. The method according to any one of claims 8 to 12, further comprising the step of selecting the first tunnel aggregator device from a plurality of tunnel aggregator devices, wherein the first tunnel aggregator device is selected from the plurality of tunnel aggregator devices on the basis that the first tunnel aggregator device is logically closer than the first customer endpoint.
14. It is a system, at least one processor; and It is operablely connected to the at least one processor and, when executed by the at least one processor, the system A procedure for establishing a first encapsulation tunnel between a tunnel aggregator device and a first customer routing device; A procedure for a tunnel aggregator device to receive a first set of packets addressed to a first customer endpoint from a first managed security router of a provider network; A procedure for encapsulating the first plurality of packets using the tunnel aggregator device; A procedure for providing the encapsulated first plurality of packets to the first customer routing device; A procedure for receiving a second set of packets addressed to the first customer endpoint from a second managed security router of the provider network in the tunnel aggregator device; A procedure for encapsulating the second plurality of packets using the tunnel aggregator device; and A procedure for providing the encapsulated second plurality of packets to the first customer routing device using the first encapsulation tunnel. Memory that stores instructions for executing a method having A system equipped with these features.
15. The system according to claim 14, wherein the first plurality of packets and the second plurality of packets are received in an unencapsulated form by the tunnel aggregator device via the provider network's clean return virtual routing and forwarding system.
16. The system according to claim 14 or 15, wherein the tunnel aggregator device is logically closer to the first customer routing device than either the first managed security router or the second managed security router.
17. A procedure for establishing a second encapsulation tunnel between the tunnel aggregator device and the second customer routing device; A procedure for the tunnel aggregator device to receive a third set of packets addressed to a second customer endpoint from the first managed security router of the provider network; A procedure for encapsulating the third plurality of packets using the tunnel aggregator device; and Procedure for providing the encapsulated third plurality of packets to the second customer endpoint The system according to claim 14 or 15, further comprising:
18. The system according to claim 14, wherein the first plurality of packets and the second plurality of packets are received by the tunnel aggregator device through a private router located at the same location as the tunnel aggregator device.
19. The system according to claim 14 or 15, wherein the tunnel aggregator device uses generic routing encapsulation (GRE) to deliver the first plurality of packets and the second plurality of packets to the first customer endpoint.
20. The system according to claim 14 or 15, wherein the configuration of the first managed security router is at least partially based on customer packet routing instructions.