ADDRESS RESOLUTION PROTOCOL (ARP) FOR MULTI-HOMED DEVICES

    公开(公告)号:US20230050404A1

    公开(公告)日:2023-02-16

    申请号:US17398301

    申请日:2021-08-10

    IPC分类号: H04L29/12 H04L12/24

    摘要: A method for synchronizing a binding process among a group of network devices connected to a server that is multi-homed to the group of network devices in provided. The method is executed by a first network device among the group of network devices and includes: receiving, from the server, network traffic associated with a host executing on the server; configuring, using the network traffic, a binding between the first network device and the host and setting a binding status of the first network device for the host to a first status; and transmitting, in response to the setting and via an out-of-band (OOB) channel to a second network device among the plurality of network devices, first binding instructions for causing the second network device set a binding status of the second network device for the host to a second status different from the first status.

    MAC mobility for 802.1x addresses for virtual machines

    公开(公告)号:US11558349B2

    公开(公告)日:2023-01-17

    申请号:US16989107

    申请日:2020-08-10

    摘要: A system and method for provisionally authenticating a host moving from one router to another router in a network using border gateway protocol (BGP) is disclosed. A host is initially authenticated at a first BGP router, this discovery is advertised to a second BGP router pursuant to BGP with a new extended community indicating successful authentication (or pre-authentication) of the host at the first BGP router. An indication for re-authentication of the host at the second BGP router is then received, which blocks network traffic from the host to the second BGP router. Due to the notification of a previous authentication of the host, the second BGP router begins a provisional authentication session. In response to a successful completion of the provisional authentication session, the host is authorized to transmit network traffic on the second BGP router and subsequently blocked from doing the same at the first BGP router.

    SPANNING TREE PROTOCOL WITH ETHERNET VIRTUAL PRIVATE NETWORK ALL-ACTIVE MULTIHOMING

    公开(公告)号:US20220191061A1

    公开(公告)日:2022-06-16

    申请号:US17122208

    申请日:2020-12-15

    IPC分类号: H04L12/44 H04L12/46

    摘要: Systems and methods are provided herein for supporting Spanning Tree Protocol (STP) in networks that use Ethernet Virtual Private Network (EVPN) All-Active (A-A) multihoming. This may be accomplished by a network administrator defining a super root group comprising a plurality of network devices, wherein each network device provides A-A multihoming to a multihomed device. All network devices in the super root group use a common bridge ID when generating BPDU messages for STP. All network devices in the super root group will send BPDU messages comprising the common bridge ID to the multihomed device. Because the BPDU messages comprise a common bridge ID, the multihomed device treats the network devices in the super root group as a single local bridge, thus STP is enabled without causing STP flapping.

    DISTRIBUTING ADDRESS RESOLUTION MESSAGES

    公开(公告)号:US20210075759A1

    公开(公告)日:2021-03-11

    申请号:US16568014

    申请日:2019-09-11

    IPC分类号: H04L29/12

    摘要: Systems and methods for handling an address resolution probe. An illustrative method includes receiving, at a first device on a network, an address resolution message from a second device on the network, determining whether the address resolution message is an address resolution probe message, and in response to determining that the address resolution message is an address resolution probe message, transmitting the address resolution message to a third device on the network regardless of whether a binding for a destination internet protocol (IP) address included in the address resolution message is stored in a bindings table accessible to the first device.

    MAC MOBILITY FOR 802.1x ADDRESSES FOR PHYSICAL MACHINES

    公开(公告)号:US20230137465A1

    公开(公告)日:2023-05-04

    申请号:US18148314

    申请日:2022-12-29

    IPC分类号: H04L9/40 H04L45/02 H04L45/00

    摘要: A system and method for provisionally authenticating a host moving from a source port of a switch device to a destination port of the switch device is disclosed. The host is initially authenticated at the source port and blocked from forwarding network traffic at the destination port. During a provisional authentication session, an authentication agent executing on the switch intercepts one or more authentication packets sourced by the host and headed for the destination port of the switch device and redirects the authentication packets to an authentication server for validating the host at the destination port of the switch device. The switch device removes the block at the destination port in response to receiving an acknowledgment of successful authentication at the destination port from the authentication server.

    Method and system for symmetric integrated routing and bridging

    公开(公告)号:US11296979B2

    公开(公告)日:2022-04-05

    申请号:US16718532

    申请日:2019-12-18

    发明人: Alton Lo

    摘要: In general, embodiments of the invention relate to managing the processing of network data units (NDUs) received by a network device. More specifically, embodiments of the invention relate to minimize the use of a peer link between two multichassis link aggregation group (MLAG) peers to transmit NDUs that are to be routed or bridged by the MLAG peers. The aforementioned minimization of the use of the peer link may be achieved, e.g., using a shared media access control (MAC) address.

    Fast failover and recovery for overlay networks

    公开(公告)号:US11171861B2

    公开(公告)日:2021-11-09

    申请号:US16726168

    申请日:2019-12-23

    摘要: Systems and methods for generating a route advertisement including a sequence number associated with a network layer address. An illustrative method includes receiving a first route advertisement advertising a path to a primary device, the first route advertisement including a network layer address, a first link layer address, and a first sequence number associated with the network layer address; receiving a gratuitous address resolution message from a standby device, the gratuitous address resolution message including the network layer address and a second link layer address; generating a second route advertisement advertising a path to the standby device, the second route advertisement including the network layer address, the second link layer address, and a second sequence number associated with the network layer address, wherein the second sequence number is incremented by a predetermined increment value over the first sequence number; and transmitting the second route advertisement.

    EFFICIENT ARP PACKET PROPAGATION
    10.
    发明申请

    公开(公告)号:US20210226912A1

    公开(公告)日:2021-07-22

    申请号:US16749846

    申请日:2020-01-22

    摘要: Techniques disclosed herein provide a method for efficiently propagating address resolution reply messages. A first router in a first network receives an address resolution request message from a second router in a second network. The first router generates an entry for the address resolution request message and stores the entry in a pending address resolution requests table. When the first router receives a route advertisement, it extracts a network layer address from the route advertisement and determines whether the pending address resolution requests table includes an entry for the network layer address. If so, the router extracts a link layer address from the route advertisement and generates an address resolution reply message comprising the network layer address and the link layer address. The router then transmits the address resolution reply message to the second router.