-
公开(公告)号:US11991211B1
公开(公告)日:2024-05-21
申请号:US17643781
申请日:2021-12-10
Applicant: Amazon Technologies, Inc.
Inventor: Hrushikesh Jaibheem Gangur , Tomasz Jozef Adamski , Christian Elsen , Baihu Qian , Nick Matthews , Omer Hashmi , Bashuman Deb , Thomas Nguyen Spendley
CPC classification number: H04L63/20 , H04L12/4675 , H04L63/0263 , H04L63/0272
Abstract: Systems and methods are provided for enforcing symmetric flows of cross-region network traffic through firewalls in multi-region network environments. Enforcement may be configured automatically by analyzing network policy data to identify cross-region traffic that is to be firewalled, and configuring gateway nodes in the various regions to implement symmetric bidirectional flows through any firewalls in the communication path. Beneficially, by enforcing symmetric bi-directional flows of traffic through any firewalls in a communication path, the firewalls may maintain the state of a given communication session even when the communication session is between endpoints in different regions that have different architectures.
-
公开(公告)号:US11936558B1
公开(公告)日:2024-03-19
申请号:US17643774
申请日:2021-12-10
Applicant: Amazon Technologies, Inc.
Inventor: Baihu Qian , Bashuman Deb , Justin Lin Hsieh , Daniel William Dacosta , Nick Matthews , Anoop Dawani , Omer Hashmi , Thomas Nguyen Spendley , Viktor Heorhiadi
IPC: H04L45/42 , H04L12/46 , H04L45/00 , H04L45/12 , H04L45/745
CPC classification number: H04L45/42 , H04L12/4641 , H04L45/123 , H04L45/22 , H04L45/745
Abstract: Systems and methods are provided for evaluation of networks and changes thereto using automated analysis of network models. The automated analysis can be used to determine how to implement and mutate networks efficiently and effectively, to determine whether and why network resources are unable to communicate with each other, and the like. Automated analysis can allow users (e.g., network administrators) to define networks and pose changes to networks using high-level policies (e.g., written in a declarative language), have those polices automatically translated to lower-level implementation operations for analysis, and in some cases have results of the analysis presented back to the users in an easy-to-understand form.
-
公开(公告)号:US11824773B2
公开(公告)日:2023-11-21
申请号:US17218031
申请日:2021-03-30
Applicant: Amazon Technologies, Inc.
Inventor: Baihu Qian , Omer Hashmi , Thomas Nguyen Spendley , Bashuman Deb , Shridhar Kulkarni , Paul John Tillotson , Indira Radhika Pulla , Ramin Ali Dousti , Nicholas Ryan Lombardi , Steve Ge , Nick Matthews , Anoop Dawani
IPC: H04L45/586 , H04L45/24 , H04L12/46 , H04L45/00 , H04L45/02
CPC classification number: H04L45/586 , H04L12/4641 , H04L45/02 , H04L45/20 , H04L45/24
Abstract: A pair of virtual routers is configured. In response to programmatic requests, dynamic transfer of routing information between the routers in accordance with configuration settings indicated by a client is enabled. The routing information is associated with a set of isolated networks to which the virtual routers are attached. A network packet originating at an address in a first isolated network is transmitted to an address in a second isolated network using a route determined from routing information transmitted between the virtual routers according to the configuration settings.
-
公开(公告)号:US20230164059A1
公开(公告)日:2023-05-25
申请号:US17456549
申请日:2021-11-24
Applicant: Amazon Technologies, Inc.
Inventor: Anoop Dawani , Bashuman Deb , Baihu Qian , Omer Hashmi , Nick Matthews , Shridhar Kulkarni , Thomas Nguyen Spendley , Indira Radhika Pulla , David Jonathan Adams , Nicholas Ryan Lombardi , Brandon Michael LaRue , Aaron Scott DeBruin , Ramin Ali Dousti
CPC classification number: H04L45/04 , H04L45/306 , H04L45/566 , H04L45/44 , H04L45/02 , H04L63/0272
Abstract: Systems and methods are provided for management of network segments that cross geographic regions and/or other types of network divisions in a cloud-based network environment. Gateway may manage traffic across regions using routing metadata that includes a segment identifier. The gateways may also signal their routes across regions based on segment data, and implement the signaled routes using segment-based routing policies. Route selection may be performed using optimization data.
-
-
-