发明授权
- 专利标题: System and methods for network segmentation
- 专利标题(中): 网络分割的系统和方法
-
申请号: US11226011申请日: 2005-09-14
-
公开(公告)号: US07688829B2公开(公告)日: 2010-03-30
- 发明人: James N. Guichard , W. Scott Wainner , Saul Adler , Khalil A. Jabr , S. Scott Van de Houten
- 申请人: James N. Guichard , W. Scott Wainner , Saul Adler , Khalil A. Jabr , S. Scott Van de Houten
- 申请人地址: US CA San Jose
- 专利权人: Cisco Technology, Inc.
- 当前专利权人: Cisco Technology, Inc.
- 当前专利权人地址: US CA San Jose
- 代理机构: Brinks Hofer Gilson & Lione
- 主分类号: H04L12/28
- IPC分类号: H04L12/28
摘要:
A routing mechanism provides network segmentation preservation by route distribution with segment identification, policy distribution for a given VPN segment, and encapsulation/decapsulation for each segment using an Ethernet VLAN_ID, indicative of the VPN segment (subnetwork). Encapsulated segmentation information in a message packet identifies which routing and forwarding table is employed for the next hop. A common routing instance receives the message packets from the common interface, and indexes a corresponding VRF table from the VLAN ID, or segment identifier, indicative of the subnetwork (e.g. segment). In this manner, the routing instance receives the incoming message packet, decapsulates the VLAN ID in the incoming message packet, and indexes the corresponding VRF and policy ID from the VLAN ID, therefore employing a common routing instance over a common subinterface for a plurality of segments (subnetworks) coupled to a particular forwarding device (e.g. VPN router).
公开/授权文献
- US20070058638A1 System and methods for network segmentation 公开/授权日:2007-03-15
信息查询