- 专利标题: Method and apparatus for distributing firewall rules
-
申请号: US14968795申请日: 2015-12-14
-
公开(公告)号: US10264021B2公开(公告)日: 2019-04-16
- 发明人: Kaushal Bansal , Uday Masurekar , Aravind Srinivasan , Shadab Shah , Serge Maskalik
- 申请人: Nicira, Inc.
- 申请人地址: US CA Palo Alto
- 专利权人: NICIRA, INC.
- 当前专利权人: NICIRA, INC.
- 当前专利权人地址: US CA Palo Alto
- 代理机构: Adeli LLP
- 主分类号: H04L12/813
- IPC分类号: H04L12/813 ; H04L29/06 ; H04L12/26
摘要:
Some embodiments of the invention provide a novel method for specifying firewall rules. In some embodiments, the method provides the ability to specify for a particular firewall rule, a set of network nodes (also called a set of enforcement points) at which the particular firewall should be enforced. To provide this ability, the method of some embodiments adds an extra tuple (referred to below as the AppliedTo tuple) to a firewall rule. This added AppliedTo tuple lists the set of enforcement points at which the firewall rule has to be applied (i.e., enforced). As the AppliedTo tuples of the firewall rules can refer to dynamically modifiable constructs, the application of the AppliedTo firewall rules (i.e., rules that are specified to include an AppliedTo tuple) can be dynamically adjusted for different locations within a network by dynamically adjusting the membership of these modifiable constructs.
公开/授权文献
- US20160191570A1 METHOD AND APPARATUS FOR DISTRIBUTING FIREWALL RULES 公开/授权日:2016-06-30
信息查询