Zone-Based Firewall Policy Model for a Virtualized Data Center
    3.
    发明申请
    Zone-Based Firewall Policy Model for a Virtualized Data Center 审中-公开
    虚拟化数据中心基于区域的防火墙策略模型

    公开(公告)号:US20150163200A1

    公开(公告)日:2015-06-11

    申请号:US14627223

    申请日:2015-02-20

    Abstract: Techniques are provided for implementing a zone-based firewall policy. At a virtual network device, information is defined and stored that represents a security management zone for a virtual firewall policy comprising one or more common attributes of applications associated with the security zone. Information representing a firewall rule for the security zone is defined and comprises first conditions for matching common attributes of applications associated with the security zone and an action to be performed on application traffic. Parameters associated with the application traffic are received that are associated with properly provisioned virtual machines. A determination is made whether the application traffic parameters satisfy the conditions of the firewall rule and in response to determining that the conditions are satisfied, the action is performed.

    Abstract translation: 提供了实现基于区域的防火墙策略的技术。 在虚拟网络设备处,定义和存储表示虚拟防火墙策略的安全管理区域的信息,该虚拟防火墙策略包括与安全区域相关联的应用的一个或多个公共属性。 定义表示安全区域的防火墙规则的信息,并且包括用于匹配与安全区域相关联的应用的通用属性的第一条件以及要对应用流量执行的动作。 接收到与正确配置的虚拟机相关联的与应用程序流量相关联的参数。 确定应用业务参数是否满足防火墙规则的条件,并且响应于确定满足条件,执行动作。

    Zone-Based Firewall Policy Model for a Virtualized Data Center
    6.
    发明申请
    Zone-Based Firewall Policy Model for a Virtualized Data Center 审中-公开
    虚拟化数据中心基于区域的防火墙策略模型

    公开(公告)号:US20170012940A1

    公开(公告)日:2017-01-12

    申请号:US15270476

    申请日:2016-09-20

    Abstract: Techniques are provided for implementing a zone-based firewall policy. At a virtual network device, information is defined and stored that represents a security management zone for a virtual firewall policy comprising one or more common attributes of applications associated with the security zone. Information representing a firewall rule for the security zone is defined and comprises first conditions for matching common attributes of applications associated with the security zone and an action to be performed on application traffic. Parameters associated with the application traffic are received that are associated with properly provisioned virtual machines. A determination is made whether the application traffic parameters satisfy the conditions of the firewall rule and in response to determining that the conditions are satisfied, the action is performed.

    Abstract translation: 提供了实现基于区域的防火墙策略的技术。 在虚拟网络设备处,定义和存储表示虚拟防火墙策略的安全管理区域的信息,该虚拟防火墙策略包括与安全区域相关联的应用的一个或多个公共属性。 定义表示安全区域的防火墙规则的信息,并且包括用于匹配与安全区域相关联的应用的通用属性的第一条件以及要对应用流量执行的动作。 接收到与正确配置的虚拟机相关联的与应用程序流量相关联的参数。 确定应用业务参数是否满足防火墙规则的条件,并且响应于确定满足条件,执行动作。

    LOCATION-AWARE VIRTUAL SERVICE PROVISIONING IN A HYBRID CLOUD ENVIRONMENT
    7.
    发明申请
    LOCATION-AWARE VIRTUAL SERVICE PROVISIONING IN A HYBRID CLOUD ENVIRONMENT 有权
    位于混合云环境中的位置虚拟服务提供

    公开(公告)号:US20160188359A1

    公开(公告)日:2016-06-30

    申请号:US15060758

    申请日:2016-03-04

    Abstract: A sense of location is provided for distributed virtual switch components into the service provisioning scheme to reduce latency observed in conducting policy evaluations across a network in a hybrid cloud environment. A management application in a first virtual network subscribes to virtual network services provided by a second virtual network. A first message is sent to the second virtual network, the first message comprising information configured to start a virtual switch in the second virtual network that switches network traffic for one or more virtual machines in the second virtual network that are configured to extend services provided by the first virtual network into the second virtual network. A second message is sent to the second virtual network, the second message comprising information configured to start a virtual service node in the second virtual network that provides network traffic services for the one or more virtual machines.

    Abstract translation: 将分布式虚拟交换机组件的位置感提供到服务提供方案中,以减少在混合云环境中跨网络进行策略评估时观察到的延迟。 第一虚拟网络中的管理应用订阅由第二虚拟网络提供的虚拟网络服务。 将第一消息发送到第二虚拟网络,第一消息包括被配置为启动第二虚拟网络中的虚拟交换机的信息,该第二虚拟网络切换第二虚拟网络中的一个或多个虚拟机的网络流量,所述虚拟机被配置为扩展由 第一个虚拟网络进入第二个虚拟网络。 第二消息被发送到第二虚拟网络,第二消息包括被配置为启动在第二虚拟网络中为一个或多个虚拟机提供网络业务服务的虚拟服务节点的信息。

    Elastic service chains
    9.
    发明授权
    Elastic service chains 有权
    弹性服务链

    公开(公告)号:US09467382B2

    公开(公告)日:2016-10-11

    申请号:US14170750

    申请日:2014-02-03

    CPC classification number: H04L47/125 H04L41/50 H04L45/38 H04L47/782 H04L63/20

    Abstract: Presented herein are elastic service chain techniques. In one example, a network element receives data traffic to be processed by a service chain that specifies an ordered sequence of service pools including a first service pool and second service pool, wherein each service pool comprises a plurality of network services. A network service is determined from the first service pool to be applied to the data traffic, and data traffic is forwarded to the network service in the first service pool.

    Abstract translation: 这里提出的是弹性服务链技术。 在一个示例中,网络元件接收要由服务链处理的数据流量,所述服务链指定包括第一服务池和第二服务池的服务池的有序序列,其中每个服务池包括多个网络服务。 从要应用于数据流量的第一服务池确定网络服务,并将数据流量转发到第一服务池中的网络服务。

Patent Agency Ranking