HYBRID CLOUD SECURITY GROUPS
    1.
    发明申请

    公开(公告)号:US20220360583A1

    公开(公告)日:2022-11-10

    申请号:US17556468

    申请日:2021-12-20

    Abstract: In one embodiment, a request may be received from a first cloud network of a hybrid cloud environment to transmit data to a second cloud network of the hybrid cloud environment, wherein the request can include a security profile related to the data. The security profile may be automatically analyzed to determine access permissions related to the data. Based at least in part on the access permissions, data can be allowed to access to the second cloud network.

    DEFAULT GATEWAY EXTENSION
    2.
    发明申请

    公开(公告)号:US20210306299A1

    公开(公告)日:2021-09-30

    申请号:US17345882

    申请日:2021-06-11

    Abstract: Many hybrid cloud topologies require virtual machines in a public cloud to use a router in a private cloud, even when the virtual machine is transmitting to another virtual machine in the public cloud. Routing data through an enterprise router on the private cloud via the internet is generally inefficient. This problem can be overcome by placing a router within the public cloud that mirrors much of the routing functionality of the enterprise router. A switch configured to intercept address resolution protocol (ARP) request for the enterprise router's address and fabricate a response using the MAC address of the router in the public cloud.

    Elastic Service Chains
    3.
    发明申请
    Elastic Service Chains 有权
    弹性服务链

    公开(公告)号:US20150222640A1

    公开(公告)日:2015-08-06

    申请号:US14170750

    申请日:2014-02-03

    CPC classification number: H04L47/125 H04L41/50 H04L45/38 H04L47/782 H04L63/20

    Abstract: Presented herein are elastic service chain techniques. In one example, a network element receives data traffic to be processed by a service chain that specifies an ordered sequence of service pools including a first service pool and second service pool, wherein each service pool comprises a plurality of network services. A network service is determined from the first service pool to be applied to the data traffic, and data traffic is forwarded to the network service in the first service pool.

    Abstract translation: 这里提出的是弹性服务链技术。 在一个示例中,网络元件接收要由服务链处理的数据流量,所述服务链指定包括第一服务池和第二服务池的服务池的有序序列,其中每个服务池包括多个网络服务。 从要应用于数据流量的第一服务池确定网络服务,并将数据流量转发到第一服务池中的网络服务。

    Service-Function Chaining
    4.
    发明申请
    Service-Function Chaining 有权
    服务功能链

    公开(公告)号:US20150215172A1

    公开(公告)日:2015-07-30

    申请号:US14168447

    申请日:2014-01-30

    CPC classification number: H04L43/026 H04L41/5041

    Abstract: Presented herein are service-function chaining techniques. In one example, a service controller in a network comprising a plurality of service nodes receives one is configured to identify one or more service-functions hosted by each of the service nodes. The service controller defines a service-function chain in terms of service-functions to be applied to traffic in the network and provides information descriptive of the service-function chain to a classifier node.

    Abstract translation: 这里提供的是服务功能链接技术。 在一个示例中,包括多个服务节点的网络中的服务控制器接收一个服务控制器被配置为识别由每个服务节点托管的一个或多个服务功能。 服务控制器根据服务功能定义服务功能链,以应用于网络中的流量,并向分类器节点提供描述服务功能链的信息。

    Zone-based firewall policy model for a virtualized data center
    5.
    发明授权
    Zone-based firewall policy model for a virtualized data center 有权
    虚拟化数据中心基于区域的防火墙策略模型

    公开(公告)号:US08990885B2

    公开(公告)日:2015-03-24

    申请号:US13945091

    申请日:2013-07-18

    Abstract: Techniques are provided for implementing a zone-based firewall policy. At a virtual network device, information is defined and stored that represents a security management zone for a virtual firewall policy comprising one or more common attributes of applications associated with the security zone. Information representing a firewall rule for the security zone is defined and comprises first conditions for matching common attributes of applications associated with the security zone and an action to be performed on application traffic. Parameters associated with the application traffic are received that are associated with properly provisioned virtual machines. A determination is made whether the application traffic parameters satisfy the conditions of the firewall rule and in response to determining that the conditions are satisfied, the action is performed.

    Abstract translation: 提供了实现基于区域的防火墙策略的技术。 在虚拟网络设备处,定义和存储表示虚拟防火墙策略的安全管理区域的信息,该虚拟防火墙策略包括与安全区域相关联的应用的一个或多个公共属性。 定义表示安全区域的防火墙规则的信息,并且包括用于匹配与安全区域相关联的应用的通用属性的第一条件以及要对应用流量执行的动作。 接收到与正确配置的虚拟机相关联的与应用程序流量相关联的参数。 确定应用业务参数是否满足防火墙规则的条件,并且响应于确定满足条件,执行动作。

    Hybrid cloud security groups
    6.
    发明授权

    公开(公告)号:US11218483B2

    公开(公告)日:2022-01-04

    申请号:US16581601

    申请日:2019-09-24

    Abstract: In one embodiment, a request may be received from a first cloud network of a hybrid cloud environment to transmit data to a second cloud network of the hybrid cloud environment, wherein the request can include a security profile related to the data. The security profile may be automatically analyzed to determine access permissions related to the data. Based at least in part on the access permissions, data can be allowed to access to the second cloud network.

    Highly scalable architecture for application network appliances
    8.
    发明授权
    Highly scalable architecture for application network appliances 有权
    应用网络设备的高度可扩展架构

    公开(公告)号:US09491201B2

    公开(公告)日:2016-11-08

    申请号:US14745524

    申请日:2015-06-22

    Abstract: A highly scalable application network appliance is described herein. According to one embodiment, a network element includes a switch fabric, a first service module coupled to the switch fabric, and a second service module coupled to the first service module over the switch fabric. In response to packets of a network transaction received from a client over a first network to access a server of a data center having multiple servers over a second network, the first service module is configured to perform a first portion of OSI (open system interconnection) compatible layers of network processes on the packets while the second service module is configured to perform a second portion of the OSI compatible layers of network processes on the packets. The first portion includes at least one OSI compatible layer that is not included in the second portion. Other methods and apparatuses are also describe.

    Abstract translation: 这里描述了高度可扩展的应用网络设备。 根据一个实施例,网络元件包括交换结构,耦合到交换结构的第一服务模块以及通过交换结构耦合到第一服务模块的第二服务模块。 响应于通过第一网络从客户端接收的网络事务的分组来访问具有多个服务器的数据中心的服务器,所述第一服务模块被配置为执行OSI的第一部分(开放系统互连) 在第二服务模块被配置为执行分组上的OSI兼容的网络进程层的第二部分时,分组上的网络进程的兼容层。 第一部分包括不包括在第二部分中的至少一个OSI兼容层。 还描述了其他方法和装置。

    HYBRID CLOUD SECURITY GROUPS
    10.
    发明申请

    公开(公告)号:US20200021594A1

    公开(公告)日:2020-01-16

    申请号:US16581601

    申请日:2019-09-24

    Abstract: In one embodiment, a request may be received from a first cloud network of a hybrid cloud environment to transmit data to a second cloud network of the hybrid cloud environment, wherein the request can include a security profile related to the data. The security profile may be automatically analyzed to determine access permissions related to the data. Based at least in part on the access permissions, data can be allowed to access to the second cloud network.

Patent Agency Ranking