首页> 外国专利> In order to withstand a denial of service attack, a system for isolating the best effort traffic and virtual private network (VPN), a method and apparatus

In order to withstand a denial of service attack, a system for isolating the best effort traffic and virtual private network (VPN), a method and apparatus

机译:为了抵御拒绝服务攻击,一种用于隔离尽力而为流量和虚拟专用网(VPN)的系统,方法和装置

摘要

A network architecture (20) in accordance with the present invention includes a communication network that supports one or more network-based Virtual Private Networks (VPNs). The communication network includes a plurality of boundary routers (22a-22d) that are connected by access links to CPE edge routers (24b-24d and 25a-25d) belonging to the one or more VPNs. To prevent traffic from outside a customer's VPN (e.g., traffic from other VPNs or the Internet at large) from degrading the QoS provided to traffic from within the customer's VPN, the present invention gives precedence to intra-VPN traffic over extra-VPN traffic on each customer's access link through access link prioritisation or access link capacity allocation, such that extra-VPN traffic can not interfere with inter-VPN traffic.
机译:根据本发明的网络架构(20)包括支持一个或多个基于网络的虚拟专用网(VPN)的通信网络。该通信网络包括多个边界路由器(22a-22d),这些边界路由器通过访问链路连接到属于一个或多个VPN的CPE边缘路由器(24b-24d和25a-25d)。为了防止来自客户的VPN外部的业务(例如,来自其他VPN或整个互联网的业务)降低提供给从客户的VPN内部的业务的QoS,本发明将VPN内业务优先于业务上的额外VPN业务。每个客户的访问链接都通过访问链接优先级或访问链接容量分配来进行,从而使额外VPN流量不会干扰VPN间流量。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号