Method and apparatus for supporting access control lists in a multi-tenant environment
    1.
    发明授权
    Method and apparatus for supporting access control lists in a multi-tenant environment 有权
    在多租户环境中支持访问控制列表的方法和装置

    公开(公告)号:US08751650B2

    公开(公告)日:2014-06-10

    申请号:US13468739

    申请日:2012-05-10

    IPC分类号: G06F15/16 G06F12/00

    CPC分类号: H04L63/101

    摘要: In one embodiment, a method includes identifying common access control list (ACL) parameters and variable ACL parameters among a plurality of tenants in a network, mapping parameter values for the variable ACL parameters to the tenants, generating a multi-tenant access control list for the tenants, storing the multi-tenant access control list and mapping at a network device, and applying the multi-tenant access control list to ports at the network device. The multi-tenant access control list includes the common ACL parameters and variable ACL parameters.

    摘要翻译: 在一个实施例中,一种方法包括在网络中的多个租户中识别公共访问控制列表(ACL)参数和可变ACL参数,将可变ACL参数的参数值映射到租户,生成多租户访问控制列表, 租户,在网络设备上存储多租户访问控制列表和映射,以及将多租户访问控制列表应用于网络设备的端口。 多租户访问控制列表包括通用ACL参数和可变ACL参数。

    METHOD AND APPARATUS FOR SUPPORTING ACCESS CONTROL LISTS IN A MULTI-TENANT ENVIRONMENT
    2.
    发明申请
    METHOD AND APPARATUS FOR SUPPORTING ACCESS CONTROL LISTS IN A MULTI-TENANT ENVIRONMENT 有权
    在多个环境中支持访问控制列表的方法和装置

    公开(公告)号:US20130304917A1

    公开(公告)日:2013-11-14

    申请号:US13468739

    申请日:2012-05-10

    IPC分类号: G06F15/173

    CPC分类号: H04L63/101

    摘要: In one embodiment, a method includes identifying common access control list (ACL) parameters and variable ACL parameters among a plurality of tenants in a network, mapping parameter values for the variable ACL parameters to the tenants, generating a multi-tenant access control list for the tenants, storing the multi-tenant access control list and mapping at a network device, and applying the multi-tenant access control list to ports at the network device. The multi-tenant access control list includes the common ACL parameters and variable ACL parameters.

    摘要翻译: 在一个实施例中,一种方法包括在网络中的多个租户中识别公共访问控制列表(ACL)参数和可变ACL参数,将可变ACL参数的参数值映射到租户,生成多租户访问控制列表, 租户,在网络设备上存储多租户访问控制列表和映射,以及将多租户访问控制列表应用于网络设备的端口。 多租户访问控制列表包括通用ACL参数和可变ACL参数。

    Adaptive infrastructure for distributed virtual switch
    3.
    发明授权
    Adaptive infrastructure for distributed virtual switch 有权
    分布式虚拟交换机的自适应基础设施

    公开(公告)号:US09288162B2

    公开(公告)日:2016-03-15

    申请号:US13566030

    申请日:2012-08-03

    IPC分类号: G06F21/00 H04L12/931

    CPC分类号: H04L49/70

    摘要: In one embodiment, a method includes identifying at a network device, characteristics of a distributed virtual switch comprising a control plane component and a plurality of data plane components, grouping the data plane components, and adapting operation of the distributed virtual switch for one or more groups of the data plane components based on the characteristics. An apparatus and logic are also disclosed herein.

    摘要翻译: 在一个实施例中,一种方法包括在网络设备处识别包括控制平面组件和多个数据平面组件的分布式虚拟交换机的特性,对数据平面组件进行分组,以及将分布式虚拟交换机的操作适配于一个或多个 基于特征的数据平面组件组。 本文还公开了一种装置和逻辑。

    Location independent dynamic IP address assignment
    4.
    发明申请
    Location independent dynamic IP address assignment 审中-公开
    位置独立的动态IP地址分配

    公开(公告)号:US20130024553A1

    公开(公告)日:2013-01-24

    申请号:US13135918

    申请日:2011-07-18

    IPC分类号: G06F15/177

    摘要: In one embodiment, a method includes receiving at a network device operating as a relay agent, a Dynamic Host Configuration Protocol (DHCP) request from an end host, inserting a group identifier into the DHCP request and forwarding the DHCP request to a DHCP server, the end host associated with a group identified by the group identifier, receiving a response from the DHCP server, and forwarding the response to the end host. The response includes configuration information for the end host, at least some of the configuration information selected based on the group identifier. An apparatus is also disclosed.

    摘要翻译: 在一个实施例中,一种方法包括在作为中继代理工作的网络设备处接收来自终端主机的动态主机配置协议(DHCP)请求,将组标识符插入到DHCP请求中并将DHCP请求转发给DHCP服务器, 与由组标识符标识的组相关联的终端主机,从DHCP服务器接收响应,并将响应转发到终端主机。 响应包括终端主机的配置信息,基于组标识符选择的至少一些配置信息。 还公开了一种装置。

    ADAPTIVE INFRASTRUCTURE FOR DISTRIBUTED VIRTUAL SWITCH
    5.
    发明申请
    ADAPTIVE INFRASTRUCTURE FOR DISTRIBUTED VIRTUAL SWITCH 有权
    分布式虚拟交换机的自适应基础设施

    公开(公告)号:US20140036730A1

    公开(公告)日:2014-02-06

    申请号:US13566030

    申请日:2012-08-03

    IPC分类号: H04L12/56

    CPC分类号: H04L49/70

    摘要: In one embodiment, a method includes identifying at a network device, characteristics of a distributed virtual switch comprising a control plane component and a plurality of data plane components, grouping the data plane components, and adapting operation of the distributed virtual switch for one or more groups of the data plane components based on the characteristics. An apparatus and logic are also disclosed herein.

    摘要翻译: 在一个实施例中,一种方法包括在网络设备处识别包括控制平面组件和多个数据平面组件的分布式虚拟交换机的特性,对数据平面组件进行分组,以及将分布式虚拟交换机的操作适配于一个或多个 基于特征的数据平面组件组。 本文还公开了一种装置和逻辑。

    Distributed network flow exporter
    6.
    发明授权
    Distributed network flow exporter 有权
    分布式网络流出口商

    公开(公告)号:US08654765B2

    公开(公告)日:2014-02-18

    申请号:US13288417

    申请日:2011-11-03

    IPC分类号: H04L12/28

    CPC分类号: H04L43/026 H04L43/04

    摘要: A network appliance that is part of a distributed virtual switch collects network flow information for network flows passing through the network appliance. The network flow information is encapsulated into packets as a data record for transport. Network flow exporter type information is added to the network flow records configured to indicate that the packets are from a distributed exporter. An option template is sent to the network flow data collectors that includes a device identifier that is configured to uniquely identify the network appliance. The packets are exported to the network flow data collector. The network flow data collector uses the network flow exporter type information and the device identifier to associate the network flow information with the distributed virtual switch.

    摘要翻译: 作为分布式虚拟交换机一部分的网络设备收集通过网络设备的网络流的网络流信息。 网络流信息被封装成数据包作为传输数据记录。 网络流量导出器类型信息被添加到配置为指示分组来自分布式导出器的网络流记录中。 将选项模板发送到网络流数据收集器,其中包括配置为唯一标识网络设备的设备标识符。 数据包被导出到网络流数据收集器。 网络流数据收集器使用网络流量输出器类型信息和设备标识符将网络流信息与分布式虚拟交换机相关联。

    SYSTEM AND METHOD FOR VERIFYING LAYER 2 CONNECTIVITY IN A VIRTUAL ENVIRONMENT
    7.
    发明申请
    SYSTEM AND METHOD FOR VERIFYING LAYER 2 CONNECTIVITY IN A VIRTUAL ENVIRONMENT 有权
    用于在虚拟环境中验证层2连接的系统和方法

    公开(公告)号:US20130219384A1

    公开(公告)日:2013-08-22

    申请号:US13400046

    申请日:2012-02-18

    IPC分类号: G06F9/455

    摘要: A method is provided in one example embodiment that includes detecting a migration of a virtual machine from an origination host to a destination host and comparing a first root bridge to a second root bridge to verify data link layer continuity of the virtual network on the destination host. The virtual machine is connected to a virtual network, the first root bridge is associated with the virtual network on the origination host and the second root bridge is associated with the virtual network on the destination host. The method may further include blocking the migration if the first root bridge and the second root bridge are not the same.

    摘要翻译: 在一个示例实施例中提供了一种方法,其包括检测虚拟机从始发主机到目的主机的迁移,并将第一根网桥与第二根网桥进行比较,以验证目标主机上的虚拟网络的数据链路层连续性 。 虚拟机连接到虚拟网络,第一根网桥与源主机上的虚拟网络相关联,第二根网桥与目标主机上的虚拟网络相关联。 该方法还可以包括如果第一根网桥和第二根网桥不相同则阻止迁移。

    DYNAMIC POLICY BASED INTERFACE CONFIGURATION FOR VIRTUALIZED ENVIRONMENTS
    10.
    发明申请
    DYNAMIC POLICY BASED INTERFACE CONFIGURATION FOR VIRTUALIZED ENVIRONMENTS 有权
    用于虚拟环境的基于动态策略的界面配置

    公开(公告)号:US20130125112A1

    公开(公告)日:2013-05-16

    申请号:US13293421

    申请日:2011-11-10

    IPC分类号: G06F9/455

    CPC分类号: H04L41/0813 G06F9/45558

    摘要: In one embodiment, a method includes receiving static profiles each comprising one or more properties of an operating environment, receiving a dynamic profile for identifying a configuration of an interface based on the static profile associated with said dynamic profile, associating the dynamic profile with one of the static profiles based on the operating environment of the interface, and automatically updating the association upon identifying a change in the operating environment. An apparatus is also disclosed.

    摘要翻译: 在一个实施例中,一种方法包括接收每个包括操作环境的一个或多个属性的静态简档,基于与所述动态简档关联的静态简档接收用于识别接口的配置的动态配置文件,将动态配置文件与 基于接口的操作环境的静态配置文件,以及在识别操作环境的变化时自动更新关联。 还公开了一种装置。