Claims
- 1. A method for remotely managing a network, comprising:
receiving a customer description of a desired customer network configuration over the internet; automatically translating said customer description into device-level configuration data using software running at a service center; and transmitting said device-level configuration data over the internet to devices of a network of said customer.
- 2. The method of claim 1 wherein said software running at a service center includes the following modules:
a policy generation layer that operates to generate policy in a non-device specific format; and a device plug-in layer for converting policy from said policy generation layer into device specific format, and transmitting the converted policy to said devices of said network of said customer.
- 3. The method of claim 2 wherein said policy generation layer includes separate modules for generating policy for different types of policy, including a first module for virtual private networks (VPN) and a second policy for application management services (AMS) and a third module for security.
- 4. The method of claim 1 wherein said transmitting comprises using a secure in-band channel over the internet.
- 5. The method of claim 4 wherein said secure in-band channel is an IPSec tunnel.
- 6. The method of claim 1 wherein said configuration data comprises network policies.
- 7. The method of claim 6 wherein said network policies include intranet and extranet virtual private networks (VPNs).
- 8. The method of claim 1 wherein:
said customer description is translated into a device-neutral file; said device neutral file is subsequently translated into a device-specific file.
- 9. The method of claim 8 wherein said device-neutral file is an XML file.
- 10. A method for configuring a network device, comprising:
establishing a secure communication link to said network device over a public network; and downloading configuration information to said network device using said secure communication link over said public network.
- 11. The method of claim 10 wherein said public network is the internet.
- 12. The method of claim 10 wherein said secure communication link is an IPSec tunnel.
- 13. The method of claim 10 wherein said configuration information is a network policy.
- 14. The method of claim 13 wherein said network policy is a virtual private network (VPN) policy.
- 15. A method for configuring a network device, comprising:
establishing an IPSec tunnel to said network device over the internet; and downloading virtual private network (VPN) policy configuration information to said network device using said IPSec tunnel over the internet.
- 16. The method of claim 15 wherein said network device is a router.
- 17. The method of claim 15 wherein said network device is an operating system.
- 18. A modular system for providing network management services over the internet, comprising:
a customer interface module for receiving customer inputs of network policy; a policy generator module for converting said customer inputs into non-device specific format; and a device plug-in module, for receiving said network policy in said non-device specific format, converting said policy into device specific format, and transmitting said policy to devices in a network of said customer.
- 19. The system of claim 18 wherein said non-device specific format is XML-based.
CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application is related to copending application Ser. No. ______, “Selection and Storage of Policies in Network Management” (Attorney Docket No. 20063P-001210US), Ser. No. ______, “Policy Engine for Modular Generation of Policy for a Flat, Per-Device Database” (Attorney Docket No. 20063P-00130US), Ser. No. ______, “Event Management for a Remote Network Policy Management System” (Attorney Docket No. 20063P-001410US) and Ser. No. ______, “Device Plug-in System for Configuring Network Devices over a Public Network” (Attorney Docket No. 20063P-001510US), all filed even date herewith and assigned to the same assignee, and all incorporated herein by reference.
STATEMENT AS TO RIGHTS TO INVENTIONS MADE UNDER FEDERALLY SPONSORED RESEARCH OR DEVELOPMENT
[0002] NOT APPLICABLE
Provisional Applications (1)
|
Number |
Date |
Country |
|
60312499 |
Aug 2001 |
US |