Application services based on dynamic split tunneling

US9455909B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9455909-B2
Application numberUS-201514841919-A
CountryUS
Kind codeB2
Filing dateSep 1, 2015
Priority dateMay 16, 2013
Publication dateSep 27, 2016
Grant dateSep 27, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

One embodiment provides selectively routing Domain Name System (DNS) request for sub-domains associated with a first network through a tunnel associated with the first network via the interface. DNS requests for sub-domains associated with a second network are selectively routed through a tunnel associated with the second network via the interface. Embodiments include replacing the destination address for DNS requests for sub-domains associated with the second network to match an address of a DNS server associated with the second network. Data representative of DNS requests for sub-domains associated with the second network is stored. Embodiments forward the DNS requests for sub-domains associated with the second network with the address of the DNS server associated with the second network.

First claim

Opening claim text (preview).

We claim: 1. An apparatus, comprising: an interface; a virtual private network (VPN) client coupled with the interface, wherein: the VPN client selectively routes Domain Name System (DNS) requests for sub-domains associated with a first network through a tunnel associated with the first network via the interface; the VPN client selectively routes DNS requests for sub-domains associated with a second network through a tunnel associated with the second network via the interface; the VPN client replaces a destination address for DNS requests for sub-domains associated with the second network to match an address of a DNS server associated with the second network; the VPN client stores data representative of DNS requests for sub-domains associated with the second network; and the VPN client forwards the DNS requests for sub-domains associated with the second network with the address of the DNS server associated with the second network. 2. The apparatus set forth in claim 1 , wherein the VPN client matches DNS responses received from the second network with stored DNS request employing the stored data representative of DNS requests; the VPN client replaces the source address of the DNS responses with the destination addresses of the DNS requests; and the VPN client forwards the DNS responses with destination addresses of the DNS requests. 3. The apparatus set forth in claim 1 , wherein the VPN client associates service Internet Protocol (IP) addresses for sub-domains associated with the first and second networks to dummy service IP addresses; and the VPN client replaces the service IP addresses in DNS responses for sub-domains associated with the first and second networks with dummy service IP addresses in and provides the DNS responses with the dummy service IP addresses. 4. The apparatus set forth in claim 3 , wherein the VPN client is responsive to receiving a packet having a dummy service IP address associated with the first network as the destination address to replace the dummy service IP address with an appropriate service IP address; and forward the packet with the appropriate IP address to the first network through the first tunnel via the interface. 5. The apparatus set forth in claim 3 , wherein the VPN client is responsive to receiving a packet having a source address via the first tunnel from the first network to replace the source address with the appropriate dummy service IP address; and the VPN client forwards the packet with the appropriate dummy service IP address. 6. The apparatus set forth in claim 3 , wherein the VPN client is responsive to receiving a packet having a dummy service IP address associated with the second network as the destination address to replace the dummy service IP address with an appropriate service IP address; and forward the packet with the appropriate IP address to the second network through the second tunnel. 7. The apparatus set forth in claim 3 , wherein the VPN client is responsive to receiving a packet having a source address via the second tunnel from the second network to replace the source address with the appropriate dummy service IP address; and the VPN client forwards the packet with the appropriate dummy service IP address. 8. The apparatus set forth in claim 3 , wherein the dummy service IP addresses allocated for service IP addresses associated with the first network and service IP associated with the second network are contiguous. 9. A method, comprising: selectively routing Domain Name System (DNS) requests for sub-domains associated with a first network through a tunnel associated with the first network via the interface; selectively routing DNS requests for sub-domains associated with a second network through a tunnel associated with the second network via the interface; replacing a destination address for DNS requests for sub-domains associated with the second network to match an address of a DNS server associated with the second network; storing data representative of DNS requests for sub-domains associated with the second network; and forwarding the DNS requests for sub-domains associated with the second network with the address of the DNS server associated with the second network. 10. The method set forth in claim 9 , further comprising: matching DNS responses received from the second network with stored DNS request employing the stored data representative of DNS requests; replacing the source address of the DNS responses with destination addresses of the DNS requests; and forwarding the DNS responses with the destination addresses of the DNS requests. 11. The method set forth in claim 9 , further comprising: associating service Internet Protocol (IP) addresses for sub-domains associated with the first and second networks to dummy service IP addresses; and replacing the service IP addresses in DNS responses for sub-domains associated with the first and second networks with dummy service IP addresses in and provides the DNS responses with the dummy service IP addresses. 12. The method set forth in claim 11 , further comprising: responsive to receiving a packet having a dummy service IP address associated with the first network as the destination address, replacing the dummy service IP address with an appropriate service IP address; and forwarding the packet with the appropriate IP address to the first network through the first tunnel via the interface. 13. The method set forth in claim 11 , further comprising: responsive to receiving a packet having a source address via the first tunnel from the first network, replacing the source address with the appropriate dummy service IP address; and forwarding the packet with the appropriate dummy service IP address. 14. The method set forth in claim 11 , further comprising: responsive to receiving a packet having a dummy service IP address associated with the second network as the destination address, replacing the dummy service IP address with an appropriate service IP address; and forwarding the packet with the appropriate IP address to the second network through the second tunnel. 15. The method set forth in claim 11 , further comprising: responsive to receiving a packet having a source address via the second tunnel from the second network, replacing the source address with the appropriate dummy service IP address; and forwarding the packet with the appropriate dummy service IP address. 16. The method set forth in claim 11 , wherein the dummy service IP addresses allocated for service IP addresses associated with the first network and service IP associated with the second network are contiguous. 17. A non-transitory computer-readable medium storing computer program code that, when executed, performs an operation, comprising: selectively routing Domain Name System (DNS) requests for sub-domains associated with a first network through a tunnel associated with the first network via the interface; selectively routing DNS requests for sub-domains associated with a second network through a tunnel associated with the second network via the interface; replacing a destination address for DNS requests for sub-domains associated with the second network to match an address of a DNS server associated with the second network; storing data representative of DNS requests for sub-domains associated with the second network; and forwarding the DNS requests for sub-domains associated with the second network with the address of the DNS server associated with the second network. 18. The non-transitory computer-readable

Assignees

Inventors

Classifications

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9455909B2 cover?
One embodiment provides selectively routing Domain Name System (DNS) request for sub-domains associated with a first network through a tunnel associated with the first network via the interface. DNS requests for sub-domains associated with a second network are selectively routed through a tunnel associated with the second network via the interface. Embodiments include replacing the destination …
Who is the assignee on this patent?
Cisco Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/0272. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 27 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).