HYBRID CLOUD SECURITY GROUPS
    13.
    发明申请

    公开(公告)号:US20170104755A1

    公开(公告)日:2017-04-13

    申请号:US14881649

    申请日:2015-10-13

    Abstract: In one embodiment, a request may be received from a first cloud network of a hybrid cloud environment to transmit data to a second cloud network of the hybrid cloud environment, wherein the request can include a security profile related to the data. The security profile may be automatically analyzed to determine access permissions related to the data. Based at least in part on the access permissions, data can be allowed to access to the second cloud network.

    Workload based service chain insertion in a network environment
    14.
    发明授权
    Workload based service chain insertion in a network environment 有权
    基于工作负载的服务链插入到网络环境中

    公开(公告)号:US09130872B2

    公开(公告)日:2015-09-08

    申请号:US13843233

    申请日:2013-03-15

    CPC classification number: H04L41/5041 H04L49/15 H04L49/70

    Abstract: An example method for workload based service chain insertion in a network environment is provided and includes partitioning a service-path into fragments at a service controller, where the service-path comprises an ordered sequence of services to be provided to a packet associated with a workload in a network. The method also includes determining a location of service nodes providing the services; and provisioning the fragments at interfaces at a distributed virtual switch. The method could further include generating a plurality of service insertion points corresponding to the fragments at a service dispatcher. The service dispatcher can include a plurality of data plane components, and the service insertion points are generated at the data plane components.

    Abstract translation: 提供了一种在网络环境中基于工作负载的服务链插入的示例方法,并且包括将服务路径划分为服务控制器处的分段,其中服务路径包括要提供给与工作负载关联的分组的有序序列的服务 在网络中。 该方法还包括确定提供服务的服务节点的位置; 并在分布式虚拟交换机的接口处配置片段。 该方法还可以包括在服务分派器处生成与片段相对应的多个服务插入点。 服务调度器可以包括多个数据平面组件,并且在数据平面组件处生成服务插入点。

    Zone-Based Firewall Policy Model for a Virtualized Data Center
    15.
    发明申请
    Zone-Based Firewall Policy Model for a Virtualized Data Center 审中-公开
    虚拟化数据中心基于区域的防火墙策略模型

    公开(公告)号:US20150163200A1

    公开(公告)日:2015-06-11

    申请号:US14627223

    申请日:2015-02-20

    Abstract: Techniques are provided for implementing a zone-based firewall policy. At a virtual network device, information is defined and stored that represents a security management zone for a virtual firewall policy comprising one or more common attributes of applications associated with the security zone. Information representing a firewall rule for the security zone is defined and comprises first conditions for matching common attributes of applications associated with the security zone and an action to be performed on application traffic. Parameters associated with the application traffic are received that are associated with properly provisioned virtual machines. A determination is made whether the application traffic parameters satisfy the conditions of the firewall rule and in response to determining that the conditions are satisfied, the action is performed.

    Abstract translation: 提供了实现基于区域的防火墙策略的技术。 在虚拟网络设备处,定义和存储表示虚拟防火墙策略的安全管理区域的信息,该虚拟防火墙策略包括与安全区域相关联的应用的一个或多个公共属性。 定义表示安全区域的防火墙规则的信息,并且包括用于匹配与安全区域相关联的应用的通用属性的第一条件以及要对应用流量执行的动作。 接收到与正确配置的虚拟机相关联的与应用程序流量相关联的参数。 确定应用业务参数是否满足防火墙规则的条件,并且响应于确定满足条件,执行动作。

    Highly Scalable Architecture for Application Network Appliances
    16.
    发明申请
    Highly Scalable Architecture for Application Network Appliances 审中-公开
    应用网络设备的高可扩展架构

    公开(公告)号:US20130318341A1

    公开(公告)日:2013-11-28

    申请号:US13859833

    申请日:2013-04-10

    Abstract: A highly scalable application network appliance is described herein. According to one embodiment, a network element includes a switch fabric, a first service module coupled to the switch fabric, and a second service module coupled to the first service module over the switch fabric. In response to packets of a network transaction received from a client over a first network to access a server of a data center having multiple servers over a second network, the first service module is configured to perform a first portion of OSI (open system interconnection) compatible layers of network processes on the packets while the second service module is configured to perform a second portion of the OSI compatible layers of network processes on the packets. The first portion includes at least one OSI compatible layer that is not included in the second portion. Other methods and apparatuses are also described.

    Abstract translation: 这里描述了高度可扩展的应用网络设备。 根据一个实施例,网络元件包括交换结构,耦合到交换结构的第一服务模块以及通过交换结构耦合到第一服务模块的第二服务模块。 响应于通过第一网络从客户端接收的网络事务的分组来访问具有多个服务器的数据中心的服务器,所述第一服务模块被配置为执行OSI的第一部分(开放系统互连) 在第二服务模块被配置为执行分组上的OSI兼容的网络进程层的第二部分时,分组上的网络进程的兼容层。 第一部分包括不包括在第二部分中的至少一个OSI兼容层。 还描述了其它方法和装置。

    DEFAULT GATEWAY EXTENSION
    18.
    发明申请

    公开(公告)号:US20200177543A1

    公开(公告)日:2020-06-04

    申请号:US16780170

    申请日:2020-02-03

    Abstract: Many hybrid cloud topologies require virtual machines in a public cloud to use a router in a private cloud, even when the virtual machine is transmitting to another virtual machine in the public cloud. Routing data through an enterprise router on the private cloud via the internet is generally inefficient. This problem can be overcome by placing a router within the public cloud that mirrors much of the routing functionality of the enterprise router. A switch configured to intercept address resolution protocol (ARP) request for the enterprise router's address and fabricate a response using the MAC address of the router in the public cloud.

    Elastic service chains
    20.
    发明授权
    Elastic service chains 有权
    弹性服务链

    公开(公告)号:US09467382B2

    公开(公告)日:2016-10-11

    申请号:US14170750

    申请日:2014-02-03

    CPC classification number: H04L47/125 H04L41/50 H04L45/38 H04L47/782 H04L63/20

    Abstract: Presented herein are elastic service chain techniques. In one example, a network element receives data traffic to be processed by a service chain that specifies an ordered sequence of service pools including a first service pool and second service pool, wherein each service pool comprises a plurality of network services. A network service is determined from the first service pool to be applied to the data traffic, and data traffic is forwarded to the network service in the first service pool.

    Abstract translation: 这里提出的是弹性服务链技术。 在一个示例中,网络元件接收要由服务链处理的数据流量,所述服务链指定包括第一服务池和第二服务池的服务池的有序序列,其中每个服务池包括多个网络服务。 从要应用于数据流量的第一服务池确定网络服务,并将数据流量转发到第一服务池中的网络服务。

Patent Agency Ranking