Invention Grant
- Patent Title: Anti-spoof check of IPv4-in-IPv6 fragments without reassembly
-
Application No.: US16682882Application Date: 2019-11-13
-
Publication No.: US11451585B2Publication Date: 2022-09-20
- Inventor: Ashish Suresh Ghule , Jagadish Narasimha Grandhi
- Applicant: Juniper Networks, Inc.
- Applicant Address: US CA Sunnyvale
- Assignee: Juniper Networks, Inc.
- Current Assignee: Juniper Networks, Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: Shumaker & Sieffert, P.A.
- Main IPC: H04L9/40
- IPC: H04L9/40 ; H04L45/02 ; H04L45/00 ; H04L47/32 ; H04L49/90 ; H04L69/22 ; H04L101/686

Abstract:
A network device may receive, from a first network, one or more fragments of a first network packet of a first network packet type, where the first network packet encapsulates a second network packet of a second network packet type. The network device may buffer the one or more fragments in. The network device may, upon receiving a fragment of the first network packet that includes an indication of a source network address and a source port for the second network packet, perform an anti-spoof check of the fragment flow without assembling the first network packet. The network device may, based on the fragment flow passing the anti-spoof check, in response to receiving all fragments of the first network packet: assemble the first network packet, decapsulate the second network packet from the assembled first network packet, and forward, to a second network, the second network packet.
Public/Granted literature
- US20210144173A1 ANTI-SPOOF CHECK OF IPV4-IN-IPV6 FRAGMENTS WITHOUT REASSEMBLY Public/Granted day:2021-05-13
Information query