Invention Grant
- Patent Title: On-demand security policy provisioning
-
Application No.: US18058113Application Date: 2022-11-22
-
Publication No.: US11863591B2Publication Date: 2024-01-02
- Inventor: Murukanandam Panchalingam , Umamaheswararao Karyampudi , Gianluca Mardente , Aram Aghababyan
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Polsinelli
- Main IPC: H04L9/40
- IPC: H04L9/40 ; H04L41/0806 ; H04L41/12 ; H04L41/0893

Abstract:
Systems, methods, and computer-readable media for on-demand security provisioning using whitelist and blacklist rules. In some examples, a system in a network including a plurality of pods can configure security policies for a first endpoint group (EPG) in a first pod, the security policies including blacklist and whitelist rules defining traffic security enforcement rules for communications between the first EPG and a second EPG in a second pods in the network. The system can assign respective implicit priorities to the one or more security policies based on a respective specificity of each policy, wherein more specific policies are assigned higher priorities than less specific policies. The system can respond to a detected move of a virtual machine associated with the first EPG to a second pod in the network by dynamically provisioning security policies for the first EPG in the second pod and removing security policies from the first pod.
Public/Granted literature
- US20230096045A1 ON-DEMAND SECURITY POLICY PROVISIONING Public/Granted day:2023-03-30
Information query