Performing Message Payload Processing Functions In A Network Element On Behalf Of An Application
    11.
    发明申请
    Performing Message Payload Processing Functions In A Network Element On Behalf Of An Application 有权
    在应用程序的网络元素中执行消息有效负载处理功能

    公开(公告)号:US20110208867A1

    公开(公告)日:2011-08-25

    申请号:US13100144

    申请日:2011-05-03

    IPC分类号: G06F15/16

    CPC分类号: H04L51/00 G06F9/546 H04L69/08

    摘要: A method is disclosed for performing message payload processing functions in a network element on behalf of an application. According to one aspect, a network element intercepts data packets comprising network layer or transport layer headers having an address of a destination which destination differs from the network element. The network element determines whether information contained in layer 2-4 headers of the data packet satisfies specified criteria. If the information satisfies the specified criteria, the network element directs the data packets to a blade of the network element that performs processing based on an application layer message at least partially contained in the data packets. If the information does not satisfy the specified criteria, the network element forwards the data packets towards the destination without sending them to the blade.

    摘要翻译: 公开了一种代表应用程序在网络元件中执行消息有效载荷处理功能的方法。 根据一个方面,网络元件拦截包括网络层或传输层报头的数据分组,其具有目的地与网络元素不同的目的地地址。 网元确定包含在数据包的第2-4层头中的信息是否满足指定的标准。 如果信息满足指定的标准,则网络元件将数据分组引导到基于至少部分地包含在数据分组中的应用层消息执行处理的网元的叶片。 如果信息不符合规定的标准,则网络单元将数据包转发到目的地,而不将其发送到刀片。

    Implementing PVLANs in a large-scale distributed virtual switch
    13.
    发明授权
    Implementing PVLANs in a large-scale distributed virtual switch 有权
    在大规模分布式虚拟交换机中实现PVLAN

    公开(公告)号:US09331872B2

    公开(公告)日:2016-05-03

    申请号:US13477605

    申请日:2012-05-22

    摘要: In one embodiment, a list of source identifiers is maintained at a virtual switch. These source identifiers are allowed to send packets through the virtual switch to ports in a private virtual local area network (PVLAN). When a packet is received at the virtual switch from a particular source destined for a particular port in the PVLAN, the virtual switch determines whether a particular identifier associated with the particular source matches one of the source identifiers in the list. If that particular source identifier is not on the list, the packet is prevented from being forwarded to the particular port in the PVLAN.

    摘要翻译: 在一个实施例中,在虚拟交换机上维护源标识符的列表。 允许这些源标识符通过虚拟交换机发送到私有虚拟局域网(PVLAN)中的端口。 当虚拟交换机从虚拟交换机接收目的地为PVLAN中的特定端口的分组时,虚拟交换机确定与特定源相关联的特定标识符是否与列表中的一个源标识符匹配。 如果该特定源标识符不在列表中,则阻止该数据包转发到PVLAN中的特定端口。

    Performing message payload processing functions in a network element on behalf of an application
    15.
    发明授权
    Performing message payload processing functions in a network element on behalf of an application 有权
    代表应用程序在网络元素中执行消息有效负载处理功能

    公开(公告)号:US08312148B2

    公开(公告)日:2012-11-13

    申请号:US13100144

    申请日:2011-05-03

    IPC分类号: G06F15/16

    CPC分类号: H04L51/00 G06F9/546 H04L69/08

    摘要: A method is disclosed for performing message payload processing functions in a network element on behalf of an application. According to one aspect, a network element intercepts data packets comprising network layer or transport layer headers having an address of a destination which destination differs from the network element. The network element determines whether information contained in layer 2-4 headers of the data packet satisfies specified criteria. If the information satisfies the specified criteria, the network element directs the data packets to a blade of the network element that performs processing based on an application layer message at least partially contained in the data packets. If the information does not satisfy the specified criteria, the network element forwards the data packets towards the destination without sending them to the blade.

    摘要翻译: 公开了一种代表应用程序在网络元件中执行消息有效载荷处理功能的方法。 根据一个方面,网络元件拦截包括网络层或传输层报头的数据分组,其具有目的地与网络元素不同的目的地地址。 网元确定包含在数据包的第2-4层头中的信息是否满足指定的标准。 如果信息满足指定的标准,则网络元件将数据分组引导到基于至少部分地包含在数据分组中的应用层消息执行处理的网元的叶片。 如果信息不符合规定的标准,则网络单元将数据包转发到目的地,而不将其发送到刀片。

    Policy based configuration of interfaces in a virtual machine environment
    17.
    发明授权
    Policy based configuration of interfaces in a virtual machine environment 有权
    虚拟机环境中基于策略的接口配置

    公开(公告)号:US08639783B1

    公开(公告)日:2014-01-28

    申请号:US12584010

    申请日:2009-08-28

    IPC分类号: G06F15/177 G06F13/00

    摘要: In one embodiment, an apparatus includes a port profile manager for receiving a port configuration policy and creating a port profile for the port configuration policy. The apparatus further includes a management interface for transmitting the port profile to a management station operable to receive input mapping the port profile to one or more interfaces associated with virtual machines. The port profile manager receives and stores the mapping input at the management station, for use in configuring the interfaces according to the port configuration policy. A method for policy based configuration of interfaces in a virtual machine environment is also disclosed.

    摘要翻译: 在一个实施例中,一种装置包括端口简档管理器,用于接收端口配置策略并为端口配置策略创建端口配置文件。 该装置还包括用于将端口简档发送到管理站的管理接口,管理站可操作以接收将端口简档映射到与虚拟机相关联的一个或多个接口的输入。 端口配置文件管理器在管理站接收并存储映射输入,用于根据端口配置策略配置接口。 还公开了一种用于虚拟机环境中的接口的基于策略的配置的方法。

    Virtual local area networks in a virtual machine environment
    18.
    发明申请
    Virtual local area networks in a virtual machine environment 审中-公开
    虚拟局域网在虚拟机环境中

    公开(公告)号:US20120131662A1

    公开(公告)日:2012-05-24

    申请号:US12927785

    申请日:2010-11-23

    IPC分类号: G06F21/00 G06F9/455

    摘要: In one embodiment, a method includes identifying virtual machines operating at a network device and virtual local area networks associated with the virtual machines, creating an allowed list of virtual local area networks at the network device based on the virtual machines operating at the network device, and updating the allowed list in response to changes in the virtual machines at the network device. The network device is configured to forward traffic received from the virtual local area networks on the allowed list to a virtual switch at the network device, and drop traffic received from a virtual local area network not on the allowed list. An apparatus and logic are also disclosed.

    摘要翻译: 在一个实施例中,一种方法包括识别在网络设备上操作的虚拟机以及与虚拟机相关联的虚拟局域网,基于在网络设备上操作的虚拟机在网络设备上创建允许的虚拟局域网列表, 以及响应于网络设备上的虚拟机的变化来更新允许的列表。 网络设备被配置为将从允许的列表上的虚拟局域网接收的流量转发到网络设备上的虚拟交换机,并且丢弃从不在允许列表上的虚拟局域网接收的流量。 还公开了一种装置和逻辑。

    Performing message payload processing functions in a network element on behalf of an application
    20.
    发明授权
    Performing message payload processing functions in a network element on behalf of an application 有权
    代表应用程序在网络元素中执行消息有效负载处理功能

    公开(公告)号:US07987272B2

    公开(公告)日:2011-07-26

    申请号:US11005978

    申请日:2004-12-06

    IPC分类号: G06F15/16

    CPC分类号: H04L51/00 G06F9/546 H04L69/08

    摘要: A method is disclosed for performing message payload processing functions in a network element on behalf of an application. According to one aspect, a network element receives user-specified input that indicates a particular message classification. The network element also receives one or more data packets. Based on the data packets, the network element determines that an application layer message, which is collectively contained in payload portions of the data packets, matches the particular message classification. The network element processes at least a portion of the message by performing, on behalf of the application to which the message is directed, and relative to at least the portion of the message, one or more actions that are (a) specified in the user-specified input and (b) associated with the particular message classification.

    摘要翻译: 公开了一种代表应用程序在网络元件中执行消息有效载荷处理功能的方法。 根据一个方面,网络元件接收指示特定消息分类的用户指定的输入。 网元还接收一个或多个数据包。 基于数据分组,网元确定在数据分组的有效载荷部分中共同包含的应用层消息与特定消息分类相匹配。 网络元件通过代表消息所针对的应用程序并相对于消息的至少一部分执行一个或多个动作(a)在用户中指定的处理消息的至少一部分 指定的输入和(b)与特定消息分类相关联。