Invention Grant
- Patent Title: Dynamic device isolation in a network
-
Application No.: US15446707Application Date: 2017-03-01
-
Publication No.: US10356124B2Publication Date: 2019-07-16
- Inventor: Pascal Thubert , Eric Levy-Abegnoli , Eliot Lear , Brian E. Weis
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Behmke Innovation Group LLC
- Agent James Bahmke; Stephen D. LeBarron
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/12

Abstract:
In one embodiment, a device in a network inserts a profile tag into an address request sent by an endpoint node in the network to a lookup service. The lookup service is configured to identify one or more addresses with which the endpoint node is authorized to communicate based on a profile for the endpoint node associated with the inserted profile tag. The device receives an address response sent from the lookup service to the endpoint node that indicates the set of one or more addresses with which the endpoint node is authorized to communicate. The device determines whether a communication between the endpoint node and a particular network address is authorized using the set of one or more addresses with which the endpoint node is authorized to communicate. The device blocks the communication based on a determination that the particular network address is not in the set of one or more addresses with which the endpoint node is authorized to communicate.
Public/Granted literature
- US20180255092A1 DYNAMIC DEVICE ISOLATION IN A NETWORK Public/Granted day:2018-09-06
Information query