System for performing input processing on a data packet
    1.
    发明授权
    System for performing input processing on a data packet 有权
    用于对数据包进行输入处理的系统

    公开(公告)号:US07242690B2

    公开(公告)日:2007-07-10

    申请号:US10091837

    申请日:2002-03-05

    IPC分类号: H04L12/56

    摘要: A system for performing an input processing function on a data packet. The system has an input port to which a first processor is coupled, which determines an attribute of the data packet, and a memory coupled to the first processor having a number of queues. The data packet is assigned to one of the queues based upon the attribute determined, which may be an indicator of a priority characterizing said data packet. Input processing is thus performed in a fixed amount of time, deferring variable latency operations until after the input memory.

    摘要翻译: 一种用于在数据分组上执行输入处理功能的系统。 系统具有耦合第一处理器的输入端口,其确定数据分组的属性,以及耦合到具有多个队列的第一处理器的存储器。 基于确定的属性将数据分组分配给一个队列,其可以是表征所述数据分组的优先级的指示符。 因此,以固定的时间量执行输入处理,推迟可变等待时间操作直到输入存储器之后。

    Methods and apparatus for selection of mirrored traffic
    2.
    发明申请
    Methods and apparatus for selection of mirrored traffic 有权
    用于选择镜像流量的方法和装置

    公开(公告)号:US20050220092A1

    公开(公告)日:2005-10-06

    申请号:US10813766

    申请日:2004-03-31

    IPC分类号: H04L12/24 H04L12/28 H04L29/06

    摘要: One embodiment disclosed relates to a method for mirroring of select network traffic. A data packet is received by a network device. A determination is made as to whether a designated aspect of the packet matches a flagged entry in a look-up table on the network device. If a match is found, then copy of the packet is sent to an associated mirror destination. Another embodiment disclosed relates to a networking apparatus. The apparatus includes at least an operating system, a look-up table, and a mirroring engine. The operating system includes routines utilized to control the apparatus, and the look-up table includes selection information for mirror sources. The mirroring engine forwards copies of selected packets to a corresponding mirror destination. Another embodiment disclosed relates to a method of selecting packets to mirror that includes checking state information relating to the network traffic against dynamic mirroring criteria.

    摘要翻译: 公开的一个实施例涉及一种用于对选择网络业务进行镜像的方法。 数据包由网络设备接收。 确定分组的指定方面是否与网络设备上的查找表中的标记条目匹配。 如果发现匹配,则将数据包的副本发送到关联的镜像目的地。 公开的另一实施例涉及网络装置。 该装置至少包括操作系统,查找表和镜像引擎。 操作系统包括用于控制设备的例程,查找表包括用于镜像源的选择信息。 镜像引擎将所选数据包的副本转发到相应的镜像目的地。 所公开的另一实施例涉及一种选择要镜像的分组的方法,包括根据动态镜像标准检查与网络流量有关的状态信息。

    Per-port penalty queue system for re-prioritization of network traffic sent to a processor
    3.
    发明申请
    Per-port penalty queue system for re-prioritization of network traffic sent to a processor 审中-公开
    用于重新优先发送到处理器的网络流量的每端口惩罚队列系统

    公开(公告)号:US20070183416A1

    公开(公告)日:2007-08-09

    申请号:US11350347

    申请日:2006-02-07

    IPC分类号: H04L12/56

    摘要: In an embodiment of the invention, a method and system for a per-port penalty queue system in a network device includes: selecting a state for a port in the network device; wherein the selected state comprises either a normal state or a restricted state; wherein the normal state permits a packet received at the port to be copied to a first queue; and wherein the restricted state causes the packet to be copied to a penalty queue which has lower priority than the first queue or causes the packet to not be copied to a queue. In another embodiment of the invention, a method and system permit using the port state for modifying a forwarding decision for a packet, so that the penalized packet will use a sub-optimal or less optimal routing path to the packet destination. In another embodiment of the invention, a method and system permit using the port state as a search key into an access control list (ACL) operation related to packet forwarding decisions or packet filtering decisions.

    摘要翻译: 在本发明的一个实施例中,网络设备中的每端口处理队列系统的方法和系统包括:为网络设备中的端口选择状态; 其中所述选择状态包括正常状态或限制状态; 其中所述正常状态允许在所述端口处接收到的分组被复制到第一队列; 并且其中所述受限状态使得所述分组被复制到具有比所述第一队列低的优先级的惩罚队列,或者使得所述分组不被复制到队列。 在本发明的另一个实施例中,一种方法和系统允许使用端口状态来修改分组的转发决定,使得受惩罚的分组将使用到分组目的地的次优或不太优化的路由路径。 在本发明的另一个实施例中,方法和系统允许将端口状态用作搜索关键字进入与分组转发决定或分组过滤决策相关的访问控制列表(ACL)操作。

    Remote mirroring using IP encapsulation
    4.
    发明申请
    Remote mirroring using IP encapsulation 有权
    使用IP封装进行远程镜像

    公开(公告)号:US20050114522A1

    公开(公告)日:2005-05-26

    申请号:US10723041

    申请日:2003-11-26

    IPC分类号: G06F15/16 H04L29/06 H04L29/08

    摘要: One embodiment disclosed relates to a method for remote mirroring of network traffic. A data packet to be remotely mirrored is received by an entry device. The entry device is pre-configured with a destination Internet Protocol (IP) address to which to mirror the data packet. An IP header is generated and added to IP encapsulate the data packet. The IP header includes the aforementioned destination IP address. The IP-encapsulated packet is forwarded to an exit device associated with the destination IP address. Subsequently, the exit device may decapsulate the IP-encapsulated packet to reproduce the original data packet.

    摘要翻译: 公开的一个实施例涉及一种用于远程镜像网络业务的方法。 要进行远程镜像的数据包由入口设备接收。 入口设备预先配置有与之对应的数据包的目标Internet协议(IP)地址。 生成IP报头并将其添加到IP封装数据包。 IP报头包括上述目的地IP地址。 IP封装的数据包转发到与目标IP地址相关联的退出设备。 随后,出口设备可以对IP封装的分组进行解封装以再现原始数据分组。

    Secure remote mirroring
    5.
    发明申请
    Secure remote mirroring 审中-公开
    安全远程镜像

    公开(公告)号:US20050220091A1

    公开(公告)日:2005-10-06

    申请号:US10813730

    申请日:2004-03-31

    摘要: One embodiment disclosed relates to a method for remote mirroring of network traffic. A data packet to be remotely mirrored is received by an entry device. The entry device is pre-configured with a destination address to which to mirror the data packet. The packet to be mirrored is encrypted. An encapsulating header is generated and added to encapsulate the encrypted packet. The encapsulating header includes the aforementioned destination address. The encapsulated packet is forwarded to an exit device associated with the destination address, where the packet may be decapsulated, and then decrypted, before being sent out of a port. In another embodiment, the entry and exit devices are remotely configured with encryption and decryption keys, respectively.

    摘要翻译: 公开的一个实施例涉及一种用于远程镜像网络业务的方法。 要进行远程镜像的数据包由入口设备接收。 入口设备预先配置了镜像数据包的目的地址。 要镜像的数据包被加密。 生成并添加封装头来封装加密的数据包。 封装头包括上述目的地址。 封装的分组被转发到与目的地地址相关联的出口设备,其中分组可以被解封装,然后在被发送出端口之前被解密。 在另一个实施例中,入口和出口设备分别被配置有加密和解密密钥。

    Method for testing network devices using breakpointing
    8.
    发明申请
    Method for testing network devices using breakpointing 有权
    使用断点测试网络设备的方法

    公开(公告)号:US20070101195A1

    公开(公告)日:2007-05-03

    申请号:US11263188

    申请日:2005-10-31

    IPC分类号: G06F11/00

    摘要: A method for testing a network device having modules for receiving and sending data packets in a network includes generating in the network device at least one internal data structure associated with a data packet received by the network device from the network. A predefined action on the network device is then preformed responsive to the internal data structure indicating that the data packet satisfies a predefined condition.

    摘要翻译: 一种用于测试具有用于在网络中接收和发送数据分组的模块的网络设备的方法包括在网络设备中生成与由网络设备从网络接收的数据分组相关联的至少一个内部数据结构。 然后响应于指示数据分组满足预定义条件的内部数据结构,执行网络设备上的预定义动作。

    Prioritization of network traffic sent to a processor by using packet importance
    9.
    发明申请
    Prioritization of network traffic sent to a processor by using packet importance 有权
    通过使用数据包重要性将优先级发送到处理器的网络流量

    公开(公告)号:US20070030803A1

    公开(公告)日:2007-02-08

    申请号:US11198056

    申请日:2005-08-05

    IPC分类号: H04L12/26

    摘要: In one embodiment of the invention, a method for prioritizing network packets, includes: comparing a packet with at least one copy rule; and if the packet matches the copy rule, then buffering the packet in a queue. The method further includes: processing the packet after buffering the packet in the queue.

    摘要翻译: 在本发明的一个实施例中,一种用于优先化网络分组的方法包括:将分组与至少一个复制规则进行比较; 并且如果分组匹配复制规则,则将分组缓冲在队列中。 该方法还包括:在缓存队列中的分组之后处理分组。