FALLBACK SEGMENTATION SECURITY
    1.
    发明公开

    公开(公告)号:US20230308484A1

    公开(公告)日:2023-09-28

    申请号:US17689378

    申请日:2022-03-08

    IPC分类号: H04L9/40 H04L101/622

    摘要: In general, embodiments relate to a network device, including network device hardware including a processor; and memory comprising instructions which, when executed by the processor, performs a method for creating segment mapping in a network. The method includes entering a fallback mode in response to detecting a fallback scenario, determining, based on the fallback mode, a segment identification (ID) for a client device of the network, wherein the segment ID identifies a segment of the network including a client device, obtaining an Internet Protocol (IP) address to segment ID mapping, wherein the client device is associated with the IP address, and processing at least one packet from the client device using the IP address to segment ID mapping.

    Fallback segmentation security
    2.
    发明授权

    公开(公告)号:US12052288B2

    公开(公告)日:2024-07-30

    申请号:US17689378

    申请日:2022-03-08

    IPC分类号: H04L9/40 H04L101/622

    摘要: In general, embodiments relate to a network device, including network device hardware including a processor; and memory comprising instructions which, when executed by the processor, performs a method for creating segment mapping in a network. The method includes entering a fallback mode in response to detecting a fallback scenario, determining, based on the fallback mode, a segment identification (ID) for a client device of the network, wherein the segment ID identifies a segment of the network including a client device, obtaining an Internet Protocol (IP) address to segment ID mapping, wherein the client device is associated with the IP address, and processing at least one packet from the client device using the IP address to segment ID mapping.

    PER-HOST ACCESS LISTS
    3.
    发明公开

    公开(公告)号:US20240015157A1

    公开(公告)日:2024-01-11

    申请号:US17859895

    申请日:2022-07-07

    IPC分类号: H04L9/40

    摘要: Methods and network devices for applying access-control lists (ACL) to hosts are disclosed. An ACL to apply to a host is determined and an ACL identifier is associated with this determined ACL. The ACL identifier is associated with a media access control (MAC) address of the host. An ACL entry, including the ACL and the ACL identifier for the ACL, is created in a special purpose memory. When a packet is received from the host, the MAC of the host is determined from the packet and the ACL identifier for the ACL is determined from the association between the ACL identifier and the MAC address. Based on the ACL identifier, a lookup is performed in the special purpose memory to determine the ACL from the ACL entry in the special purpose memory such that the ACL is applied to the packet received from the host.