Role information propagation in access switches

    公开(公告)号:US12107754B2

    公开(公告)日:2024-10-01

    申请号:US17712342

    申请日:2022-04-04

    CPC classification number: H04L45/02 H04L12/4641 H04L45/04 H04L63/08 H04L63/105

    Abstract: In an example, a switch may receive an authentication request from a host associated with a first wireless access point (WAP) connected to the switch. The switch acts as a VXLAN Tunnel Endpoint (VTEP) in a Border Gateway Protocol (BGP) Ethernet Virtual Private Network (EVPN) based Virtual Extensible Local Area Network (VXLAN). The switch forwards the authentication request to an authentication server and on successful authentication of the host, may associate a role information with the host based on an authentication response from the authentication server. Further, the switch may create a BGP extended community field carrying the role identifier indicative of network policies to be implemented for the host and attach the BGP extended community field with a route advertisement. The switch then sends the route advertisement to another switch. The another switch is configured as a peer VTEP in the VXLAN. The switch and the another switch is configured in a single Virtual Local Area Network (VLAN).

    Dynamic traffic redirection for a virtual gateway of a distributed tunnel fabric

    公开(公告)号:US11528224B1

    公开(公告)日:2022-12-13

    申请号:US17503157

    申请日:2021-10-15

    Abstract: A system for redirecting traffic is provided. The system can allow a first switch to participate in a virtual switch in conjunction with a second switch of an overlay tunnel fabric. A path between a respective switch pair of an underlying network of the fabric can be determined based on a routing process. The first and second switches may individually participate in the routing process. Hence, the packets to a tunnel to the virtual switch can be distributed among paths to the first and second switches. The system can determine a trigger condition indicating that packets subsequently received via the tunnel is to be directed to a path to the second switch. The first and second switches can remain in an operational state. The system can then advertise a high cost for a link to the first switch for the routing process in the underlying network.

    Protocol-independent multicast designated router (PIM-DR) failover in a multi-chassis environment

    公开(公告)号:US11108622B2

    公开(公告)日:2021-08-31

    申请号:US16690290

    申请日:2019-11-21

    Abstract: Systems and methods are provided for performing a node-level redundant failover-type process with respect to the protocol-independent multicast (PIM) functionality in a multi-chassis environment. When a PIM-related failure occurs on a first network device, but otherwise it remains operational, a second network device is configured to assume responsibility for performing PIM data traffic forwarding. Upon detecting the PIM-related failure of the first network device, the second network device sends a PIM-DR failover event signal to the second network device's PIM module by loading multicast route states used by the first network device into the PIM data traffic forwarding hardware of the second network device. Upon the second network device assuming responsibility, the first network device disables its PIM data traffic forwarding functionality.

    Achieving L2 tunnel reduncancy and L3 load balancing

    公开(公告)号:US10924396B2

    公开(公告)日:2021-02-16

    申请号:US16276853

    申请日:2019-02-15

    Abstract: A method for use in a network, including: receiving network traffic at a redundant gateway device established according to a redundant gateway protocol; forwarding known unicast traffic received at the redundant gateway device from the redundant gateway device to a tunnel endpoint through a tunnel established according to a tunneling protocol; forwarding broadcast, unknown unicast, and multicast traffic to the tunnel endpoint through the tunnel if the redundant gateway device is a master gateway under the redundant gateway protocol; and dropping the broadcast, unknown unicast, and multicast traffic if the redundant gateway device is a backup gateway under the redundant gateway protocol.

    Achieving L2 Tunnel Reduncancy and L3 Load Balancing

    公开(公告)号:US20200084144A1

    公开(公告)日:2020-03-12

    申请号:US16276853

    申请日:2019-02-15

    Abstract: A method for use in a network, including: receiving network traffic at a redundant gateway device established according to a redundant gateway protocol; forwarding known unicast traffic received at the redundant gateway device from the redundant gateway device to a tunnel endpoint through a tunnel established according to a tunneling protocol; forwarding broadcast, unknown unicast, and multicast traffic to the tunnel endpoint through the tunnel if the redundant gateway device is a master gateway under the redundant gateway protocol; and dropping the broadcast, unknown unicast, and multicast traffic if the redundant gateway device is a backup gateway under the redundant gateway protocol.

    SUPPORTING BFD PACKETS IN A VIRTUALIZED SWITCH ENVIRONMENT

    公开(公告)号:US20200044965A1

    公开(公告)日:2020-02-06

    申请号:US16201319

    申请日:2018-11-27

    Abstract: Examples disclosed herein relate to a method comprising receiving, at a first switch, a bidirectional forwarding detection packet, wherein the first switch and a second switch are part of a virtualized switch and each switch in the virtualized switch has a same Media Access Control (MAC) address, determining, at the first switch, that a destination MAC address included in the bidirectional forwarding detection packet is not owned by the first switch, determining, at the first switch, that the destination MAC address is owned by the second switch and bridging, from the first switch, the bidirectional forwarding detection packet to the second switch that owns the MAC address.

    Enabling restriction on transmission of data packets at ingress network device

    公开(公告)号:US11888901B2

    公开(公告)日:2024-01-30

    申请号:US17409179

    申请日:2021-08-23

    CPC classification number: H04L63/20 H04L63/0236 H04L63/105

    Abstract: Examples disclosed herein relate to a method for defining an ingress access policy at an ingress network device based on instructions from an egress network device. The egress network device receives data packets directed to a first entity from a second entity connected to an ingress network device. Each data packet transmitted includes a source role tag corresponding to the second entity. At the egress network device, the data packets may be dropped based on the enforcement of an egress access policy. When the number of data packets that are being dropped increases beyond a pre-defined threshold, the egress network device transmits a command to the ingress network device instructing the ingress network device to create a restriction on the transmission of subsequent data packets. The command is transmitted in a Border Gateway Protocol (BGP) Flow Specification (FlowSpec) route.

Patent Agency Ranking