-
公开(公告)号:US20250141799A1
公开(公告)日:2025-05-01
申请号:US18495474
申请日:2023-10-26
Applicant: Hewlett Packard Enterprise Development LP
Inventor: Venkatavaradhan Devarajan , Tathagata Nandy
IPC: H04L45/745 , H04L9/40 , H04L45/24
Abstract: An access switch, which can connect one or more end devices to a network, is provided. During operation, the access switch can identify a multicast flow associated with a multicast group based on one or more packets received at the access switch. The access switch can store a flow identifier of the multicast flow in an entry of a data structure stored in a storage device of the access switch. Subsequently, the access switch can facilitate deep-packet inspection on the multicast flow. To do so, the access switch can determine a set of properties associated with the multicast flow based on a plurality of packets of the multicast group and determine a multicast traffic class for the multicast flow based on the set of properties. The access switch can then store a label identifying the multicast traffic class in the entry of the data structure.
-
公开(公告)号:US20250141576A1
公开(公告)日:2025-05-01
申请号:US18533718
申请日:2023-12-08
Applicant: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
IPC: H04J3/06
Abstract: In some examples, a first network device including a first time clock sends, over a first network path, a first timing message of a time synchronization process to synchronize the first time clock and a second time clock that is connected to a second network device. The first network device receives an indication associated with a second timing message of the time synchronization process, where the second timing message is to be sent from the second time clock. Based on receiving the indication, the first network device sends a first join message to a first intermediate network device that is part of the first network path, and a second join message to a second intermediate network device that is part of a second network path different from the first network path. The first network device receives, over the first network path, the second timing message sent by the second time clock, the second timing message communicated over the first network path based on the forwarding information built in the first intermediate network device and the second network device.
-
公开(公告)号:US20250007742A1
公开(公告)日:2025-01-02
申请号:US18345382
申请日:2023-06-30
Applicant: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Inventor: Anil Raj , Tathagata Nandy , Subramanian Muthukumar , Srijith Ponnappan
IPC: H04L12/18
Abstract: A process includes receiving, at a downstream interface of a high availability pair of network devices, a join request. The availability pair of network devices includes a first network device and a second network device. The join request represents a request by a client device to join a multicast group associated with a source address and a multicast group address. The process includes, responsive to the join request, exporting, by the first network device, first static multicast route information from a second interface of the first network device. The first static multicast route information corresponds to a routing of multicast traffic associated with the multicast group through the first network device. The process further includes, responsive to the join message, controlling, by the second network device, exporting of second static multicast route information from the second network device to prevent duplicate multicast traffic associated with the multicast group from being sent by the high availability pair. The second static multicast route information corresponds to a routing of the multicast traffic associated with the multicast group through the second network device.
-
公开(公告)号:US20240259373A1
公开(公告)日:2024-08-01
申请号:US18103341
申请日:2023-01-30
Applicant: Hewlett Packard Enterprise Development LP
Inventor: Vinayak Joshi , Tathagata Nandy
Abstract: A system for enforcement of a set of segmentation policies at a gateway switch of a network is provided. Here, the segmentation policies can indicate which other roles are allowed to communicate with a respective role, which can indicate a set of privileges in the network. During operation, the switch can receive a first message associated with a join request for a multicast group from a host. The switch can also receive a second message comprising data from a source of the multicast group. The first and second messages can indicate first and second roles, respectively, of the host and source. Based on the first and second roles and a corresponding segmentation policy, the system can determine whether the host is allowed to receive the data from the source. If not allowed, the system can prevent the second message from being forwarded to the host from the gateway switch.
-
公开(公告)号:US20240243993A1
公开(公告)日:2024-07-18
申请号:US18154094
申请日:2023-01-13
Applicant: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Abstract: A resource optimization processor is disclosed for inclusion in peer routers. The resource optimization processor performs a method for resource optimization of the routers. The method includes disabling an inter-switch link (ISL) between peer routers and monitoring downstream links between a primary router and downstream devices connected to the primary router. The method further includes identifying a failure of at least one downstream link and enabling the ISL between the first router and the second router for the failed downstream link upon identification of the failure.
-
公开(公告)号:US11888901B2
公开(公告)日:2024-01-30
申请号:US17409179
申请日:2021-08-23
Applicant: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Inventor: Vinayak Joshi , Venkatavaradhan Devarajan , Rajib Majila , Tathagata Nandy
CPC classification number: H04L63/20 , H04L63/0236 , H04L63/105
Abstract: Examples disclosed herein relate to a method for defining an ingress access policy at an ingress network device based on instructions from an egress network device. The egress network device receives data packets directed to a first entity from a second entity connected to an ingress network device. Each data packet transmitted includes a source role tag corresponding to the second entity. At the egress network device, the data packets may be dropped based on the enforcement of an egress access policy. When the number of data packets that are being dropped increases beyond a pre-defined threshold, the egress network device transmits a command to the ingress network device instructing the ingress network device to create a restriction on the transmission of subsequent data packets. The command is transmitted in a Border Gateway Protocol (BGP) Flow Specification (FlowSpec) route.
-
公开(公告)号:US20220345326A1
公开(公告)日:2022-10-27
申请号:US17364173
申请日:2021-06-30
Applicant: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
IPC: H04L12/18
Abstract: Some examples relate to selection of a rendezvous point in an IP multicast network managing multicast group traffic. An example includes transmitting, from a controller in a cloud computing system, messages to a source device and a host device in an IP multicast-capable network, which may include two peer network devices that are virtualized to function as one virtual device. Based on the response to the messages, the controller may determine that the source device is present in OSI layer 3 and the host device is present in OSI layer 2. The controller may determine that the peer network are located downstream in relation to the determined layer of the source device. The controller may select a non-peer network device as a rendezvous point in the IP multicast-capable network. Further to the selection, the controller may synchronize an active-active configuration between the peer network devices.
-
公开(公告)号:US11212164B2
公开(公告)日:2021-12-28
申请号:US16850526
申请日:2020-04-16
Applicant: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Inventor: Tathagata Nandy , Venkatavaradhan Devarajan , Prasad Moola Mangalam , Viswanath Reddy Bayapureddy
IPC: G06F11/00 , H04L12/24 , H04L12/18 , H04L12/437 , H04L12/46
Abstract: Examples disclosed herein relate to a method comprising determining, at a first node, that a first Ethernet Ring Protection Switching (ERPS) port of the first node is down, wherein the first node belongs to a plurality of network nodes connected in a ring topology to form an access network. The method includes determining, at the first node, that the first ERPS port is a querier port, wherein the first ERPS port is paired with a second ERPS port of the first node and marking the second ERPS port as the querier port of the first node. The method includes transmitting, by the first node, an IGMP join message to a device part of a multicast implementation, wherein the multicast implementation covers at least the ring topology.
-
公开(公告)号:US20210336814A1
公开(公告)日:2021-10-28
申请号:US17221812
申请日:2021-04-04
Applicant: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Inventor: Tathagata Nandy , David Corrales Lopez
IPC: H04L12/18 , H04L12/741 , H04L12/721
Abstract: Examples include receiving a first multicast packet, determining a first flow for the first multicast packet based on a multicast protocol, and storing the first flow in a routing table. The first flow comprises a first source and a first group and the routing table comprises a second flow with a second source and the first group. Additionally, examples include programming the first flow into a hardware memory resource and programming a summary flow into the hardware memory resource. The hardware memory resource comprises the second flow and the summary flow comprises a wild character that matches the first source and the second source.
-
公开(公告)号:US10897471B2
公开(公告)日:2021-01-19
申请号:US15953420
申请日:2018-04-14
Applicant: Hewlett Packard Enterprise Development LP
Inventor: Tathagata Nandy , Vijay Kannan , Saheli Ganguly
IPC: H04L9/00 , H04L29/06 , H04L12/927 , H04L12/931 , G06F21/55 , G06F11/30 , H04L29/08
Abstract: In some examples, a network device includes an interface, and a processor to apply a restriction on multicast communication associated with an entity on the interface. The restriction on multicast communication includes detecting, on the interface, a multicast communication pattern associated with the entity, indicating, based on the multicast communication pattern on the interface violating a threshold, that the entity is malicious, and blocking processing of the multicast communication associated with the entity in response to indicating that the entity is malicious.
-
-
-
-
-
-
-
-
-