Secure manufacturing devices in a switched Ethernet network
    11.
    发明授权
    Secure manufacturing devices in a switched Ethernet network 有权
    在交换以太网中安全制造设备

    公开(公告)号:US07607166B2

    公开(公告)日:2009-10-20

    申请号:US10890500

    申请日:2004-07-12

    IPC分类号: G06F7/04

    摘要: A method and apparatus for providing security to factory automation devices in a switched Ethernet network. Traffic between factory automation devices and an Ethernet switch is limited to packets including approved TCP/UDP port numbers and to selected data rates.

    摘要翻译: 一种用于向交换以太网中的工厂自动化设备提供安全性的方法和装置。 工厂自动化设备和以太网交换机之间的通信仅限于包括经过批准的TCP / UDP端口号和所选数据速率的数据包。

    SUBNET SCOPED MULTICAST/BROADCAST PACKET DISTRIBUTION MECHANISM OVER A ROUTED NETWORK
    12.
    发明申请
    SUBNET SCOPED MULTICAST/BROADCAST PACKET DISTRIBUTION MECHANISM OVER A ROUTED NETWORK 有权
    分布式网络上的子网多媒体/广播分发机制

    公开(公告)号:US20120207160A1

    公开(公告)日:2012-08-16

    申请号:US13455822

    申请日:2012-04-25

    IPC分类号: H04L12/56

    摘要: In one embodiment, a subnet-scoped multicast packet is received on an interface of a forwarding device that is connected to a host device of a subnet of a forwarding domain. The received subnet-scoped multicast packet is transmitted from one or more other interfaces of the forwarding device that are connected to one or more other host devices of the subnet. The received subnet-scoped multicast packet is also encapsulated with an additional header. The encapsulated subnet-scoped multicast packet is forwarded from the forwarding device to an intermediate router which routes the encapsulated subnet-scoped multicast packet to one or more other forwarding devices configured to decapsulate the encapsulated subnet-scoped multicast packet and transmit the decapsulated subnet-scoped multicast packet to one or more connected host devices of an additional portion of the subnet.

    摘要翻译: 在一个实施例中,在连接到转发域的子网的主机设备的转发设备的接口上接收子网范围的组播分组。 接收到的子网范围的组播数据包是从连接到子网的一个或多个其他主机设备的转发设备的一个或多个其他接口传送的。 接收到的子网范围的组播数据包也封装了一个额外的头。 封装的子网范围组播数据包从转发设备转发到中间路由器,路由器将封装的子网范围组播数据包路由到一个或多个其他转发设备,该转发设备配置为对封装的子网范围组播数据包进行解封装,并传送解封装的子网范围 组播分组到子网的附加部分的一个或多个连接的主机设备。

    Cross stack rapid transition protocol
    16.
    发明授权
    Cross stack rapid transition protocol 有权
    交叉堆栈快速转换协议

    公开(公告)号:US07480258B1

    公开(公告)日:2009-01-20

    申请号:US10614257

    申请日:2003-07-03

    IPC分类号: H04L12/28

    CPC分类号: H04L45/00 H04L45/48

    摘要: A cross stack rapid transition protocol is provided for permitting multiple network devices organized as a stack to rapidly transition their ports in response to network changes so as to minimize traffic flow disruptions while avoiding loops. Each switch in the stack has a stack port that connects the switch to another switch in the stack, and a plurality of ports for connecting the switch to other entities of the computer network. Each switch includes a Spanning Tree Protocol (STP) entity that transitions the ports of the switch among a plurality of states including a forwarding state and a blocking state. Each switch also tracks which other switches are members of the switch stack. The stack port of each switch is transitioned to the forwarding state, and a single switch having connectivity to a root is elected to be a Stack Root. One or more other switches may have Alternate Stack Root Ports, that provide alternate paths to the root. If the current Stack Root loses connectivity to the root, the switch whose Alternate Stack Root Port represents the next best path to the root issues one or more proposal messages to the other members of the switch stack. These other members respond with an Acknowledgement, and the former Stack Root transitions its port to the blocking state. Once the proposing switch receives an Acknowledgment from all other active members of the switch stack, it transitions its Alternate Stack Root Port to the forwarding state so that network messages can be forwarded to and from switch stack.

    摘要翻译: 提供了一种交叉堆栈快速转换协议,用于允许组织为堆栈的多个网络设备响应于网络变化快速转换其端口,以便最大限度地减少流量中断,同时避免环路。 堆叠中的每个交换机都具有将交换机连接到堆叠中的另一个交换机的堆叠端口,以及用于将交换机连接到计算机网络的其他实体的多个端口。 每个交换机包括生成树协议(STP)实体,其在包括转发状态和阻塞状态的多个状态之间转换交换机的端口。 每个开关还跟踪哪些其他交换机是交换机堆栈的成员。 每个交换机的堆叠端口转换到转发状态,并且具有到根的连接的单个交换机被选为堆栈根。 一个或多个其他交换机可以具有备用堆叠根端口,其提供到根的备用路径。 如果当前的堆叠根路径与根的连接失败,交换机的备用堆叠根端口表示到根的下一个最佳路径会向交换机堆栈的其他成员发出一个或多个提议消息。 这些其他成员响应一个确认,并且前一个堆栈根转换其端口到阻塞状态。 一旦提议交换机从交换机堆叠的所有其他活动成员收到确认,它将其备用堆叠根端口转换为转发状态,以便网络消息可以转发到交换机堆栈。

    Method and apparatus for locating rogue access point switch ports in a wireless network related patent applications
    17.
    发明申请
    Method and apparatus for locating rogue access point switch ports in a wireless network related patent applications 有权
    在无线网络相关专利申请中定位流氓接入点交换机端口的方法和装置

    公开(公告)号:US20060200862A1

    公开(公告)日:2006-09-07

    申请号:US11073317

    申请日:2005-03-03

    IPC分类号: G06F12/14

    摘要: Methods and apparatus are disclosed for locating and disabling the switch port of a rogue wireless access point. In one embodiment, a network management device is configured to detect the presence of a rogue access point on a managed wireless network. Once detected, the management device may then instruct a special client, such as a scanning AP, to associate with the rogue access point and send a discovery packet through the rogue access point to network management device. The network management device upon receiving the discovery packet may thereby determine that the rogue access point is connected to a network managed by said network device. The network device may then utilize information contained in the discovery packet to locate the switch port to which the rogue access point is connected, and ultimately disable the switch port to which the rogue access point is connected.

    摘要翻译: 公开了用于定位和禁用流氓无线接入点的交换机端口的方法和装置。 在一个实施例中,网络管理设备被配置为检测被管理无线网络上的恶意接入点的存在。 一旦检测到,管理设备然后可以指示诸如扫描AP的特殊客户端与流氓接入点关联,并通过流氓接入点将发现分组发送到网络管理设备。 因此,网络管理装置在接收到发现分组时可以确定恶意接入点连接到由所述网络设备管理的网络。 然后,网络设备可以利用包含在发现分组中的信息来定位与恶意接入点连接的交换机端口,并且最终禁用与恶意接入点连接的交换机端口。