Invention Grant
- Patent Title: Zone-based firewall policy model for a virtualized data center
-
Application No.: US14627223Application Date: 2015-02-20
-
Publication No.: US09461968B2Publication Date: 2016-10-04
- Inventor: David Chang , Abhijit Patra , Nagaraj Bagepalli , Rajesh Kumar Sethuraghavan
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Main IPC: H04L12/721
- IPC: H04L12/721 ; H04L29/06 ; H04L12/931 ; H04L29/08 ; G06F21/53

Abstract:
Techniques are provided for implementing a zone-based firewall policy. At a virtual network device, information is defined and stored that represents a security management zone for a virtual firewall policy comprising one or more common attributes of applications associated with the security zone. Information representing a firewall rule for the security zone is defined and comprises first conditions for matching common attributes of applications associated with the security zone and an action to be performed on application traffic. Parameters associated with the application traffic are received that are associated with properly provisioned virtual machines. A determination is made whether the application traffic parameters satisfy the conditions of the firewall rule and in response to determining that the conditions are satisfied, the action is performed.
Public/Granted literature
- US20150163200A1 Zone-Based Firewall Policy Model for a Virtualized Data Center Public/Granted day:2015-06-11
Information query