-
公开(公告)号:US10530712B2
公开(公告)日:2020-01-07
申请号:US15373616
申请日:2016-12-09
Applicant: Cisco Technology, Inc.
Inventor: Sameer Dilip Merchant , Sarang Dharmapurikar , Praveen Jain
IPC: H04L29/06 , H04L12/931 , H04L12/725 , H04L12/721 , H04L12/743
Abstract: Techniques for providing a reflexive access control list (ACL) on a virtual switch are provided. Embodiments receive a first packet corresponding to a first network flow and a second packet corresponding to a second network flow. Upon determining that a SYN flag is set within the first packet, a first entry is created in the reflexive ACL for the first network flow. Upon determining that the first packet was received over a client port of the first physical switch, the first packet is forwarded to a second physical switch within virtual switch. Upon determining that the second packet has a SYN flag enabled, a second entry is created in the reflexive ACL. Finally, upon determining that the second packet was received from the second physical switch, the second packet is forwarded over an uplink port to a destination defined by the second packet.