Network policy validation
    2.
    发明授权

    公开(公告)号:US12101227B2

    公开(公告)日:2024-09-24

    申请号:US18313131

    申请日:2023-05-05

    CPC classification number: H04L41/0894 H04L41/0681

    Abstract: In an example, a validation system comprises processing circuitry having access to a storage device and is configured to obtain flow records indicative of packet flows among workloads deployed to a cluster of one or more computing devices configured with a network policy, wherein each flow record of the flow records indicates a corresponding packet flow was allowed or denied by the cluster; receive an updated network policy; determine whether a corresponding packet flow for a flow record of the flow records has a discrepancy with the updated network policy; and in response to determining the corresponding packet flow for the flow record of the flow records has a discrepancy with the updated network policy, output an indication of an error.

    VENDOR AGNOSTIC PROFILE-BASED MODELING OF SERVICE ACCESS ENDPOINTS IN A MULTITENANT ENVIRONMENT

    公开(公告)号:US20210058295A1

    公开(公告)日:2021-02-25

    申请号:US16588699

    申请日:2019-09-30

    Abstract: An access profile includes configuration characteristics that are defined using device and operating system agnostic attributes. Thus, the access profiles are not necessarily dependent or otherwise tied to any particular vendor or network OS. When a system administrator configures one or more service access points, the system administrator need only specify the vendor and network OS agnostic characteristics that are to be associated with the service access point. A configuration generator can generate vendor specific and/or network specific configuration commands and data from the vendor and network OS agnostic access profile attributes. The generated configuration commands and data can be provided to a network device hosting the service access point using a vendor specific and/or network OS specific configuration application program interface.

    Service chaining with physical network functions and virtualized network functions

    公开(公告)号:US11956141B2

    公开(公告)日:2024-04-09

    申请号:US18297291

    申请日:2023-04-07

    CPC classification number: H04L45/02 H04L12/4641 H04L41/12

    Abstract: Techniques are described in which a centralized controller, such as a software defined networking (SDN) controller, constructs a service chain that includes a physical network function (PNF) between a bare metal server (BMS) and a virtual execution element (e.g., virtual machine or container), or in some instances a remote BMS, or vice-versa. In accordance with the techniques disclosed herein, the controller may construct an inter-network service chain that includes PNFs, or a combination of PNFs and virtualized network functions (VNFs). The controller may construct an inter-network service chain to steer traffic between a BMS and a virtual execution element or remote BMS through an inter-network service chain using Virtual Extensible Local Area Network (VXLAN) as an underlying transport technology through the service chain.

    Service chaining with physical network functions and virtualized network functions

    公开(公告)号:US11652727B2

    公开(公告)日:2023-05-16

    申请号:US17454979

    申请日:2021-11-15

    CPC classification number: H04L45/02 H04L12/4641 H04L41/12

    Abstract: Techniques are described in which a centralized controller, such as a software defined networking (SDN) controller, constructs a service chain that includes a physical network function (PNF) between a bare metal server (BMS) and a virtual execution element (e.g., virtual machine or container), or in some instances a remote BMS, or vice-versa. In accordance with the techniques disclosed herein, the controller may construct an inter-network service chain that includes PNFs, or a combination of PNFs and virtualized network functions (VNFs). The controller may construct an inter-network service chain to steer traffic between a BMS and a virtual execution element or remote BMS through an inter-network service chain using Virtual Extensible Local Area Network (VXLAN) as an underlying transport technology through the service chain.

    VENDOR AGNOSTIC PROFILE-BASED MODELING OF SERVICE ACCESS ENDPOINTS IN A MULTITENANT ENVIRONMENT

    公开(公告)号:US20220217047A1

    公开(公告)日:2022-07-07

    申请号:US17655718

    申请日:2022-03-21

    Abstract: An access profile includes configuration characteristics that are defined using device and operating system agnostic attributes. Thus, the access profiles are not necessarily dependent or otherwise tied to any particular vendor or network OS. When a system administrator configures one or more service access points, the system administrator need only specify the vendor and network OS agnostic characteristics that are to be associated with the service access point. A configuration generator can generate vendor specific and/or network specific configuration commands and data from the vendor and network OS agnostic access profile attributes. The generated configuration commands and data can be provided to a network device hosting the service access point using a vendor specific and/or network OS specific configuration application program interface.

    DATA CENTER TENANT NETWORK ISOLATION USING LOGICAL ROUTER INTERCONNECTS FOR VIRTUAL NETWORK ROUTE LEAKING

    公开(公告)号:US20210377164A1

    公开(公告)日:2021-12-02

    申请号:US17247858

    申请日:2020-12-28

    Abstract: Network controllers are described that enable creation of logical interconnects between logical routers of different, isolated virtual networks and for auto-generation and deployment of routing policies to control “leaking” of select routes amongst the different virtual networks. In one example, a network controller includes a memory and processing circuitry configured to identify a source logical router of a first virtual network and a destination logical router of a second virtual network implemented on one or more physical devices of a switch fabric, form a policy defining one or more rules for controlling leaking of one or more of the routes through a logical router interconnect from the source logical router to the destination logical router, and push the policy to the one or more physical devices of the switch fabric for application to communications through the logical router interconnect.

    SERVICE CHAINING WITH PHYSICAL NETWORK FUNCTIONS AND VIRTUALIZED NETWORK FUNCTIONS

    公开(公告)号:US20230246941A1

    公开(公告)日:2023-08-03

    申请号:US18297291

    申请日:2023-04-07

    CPC classification number: H04L45/02 H04L12/4641 H04L41/12

    Abstract: Techniques are described in which a centralized controller, such as a software defined networking (SDN) controller, constructs a service chain that includes a physical network function (PNF) between a bare metal server (BMS) and a virtual execution element (e.g., virtual machine or container), or in some instances a remote BMS, or vice-versa. In accordance with the techniques disclosed herein, the controller may construct an inter-network service chain that includes PNFs, or a combination of PNFs and virtualized network functions (VNFs). The controller may construct an inter-network service chain to steer traffic between a BMS and a virtual execution element or remote BMS through an inter-network service chain using Virtual Extensible Local Area Network (VXLAN) as an underlying transport technology through the service chain.

Patent Agency Ranking