Clientless VPN roaming with 802.1x authentication

    公开(公告)号:US11617076B2

    公开(公告)日:2023-03-28

    申请号:US16901248

    申请日:2020-06-15

    Abstract: The present disclosure is directed to systems and methods for clientless virtual private network (VPN) roaming with 802.1x authentication and includes one or more processors and one or more computer-readable non-transitory storage media coupled to the one or more processors and comprising instructions that, when executed by the one or more processors, cause one or more components to perform operations including, receiving, at a local proxy, an 802.1x communication including authentication information from a remote device wirelessly connected to a visited network, wherein the remote device requests access to an enterprise network; authenticating the remote device with the enterprise network using the authentication information; establishing an encrypted tunnel between the visited network and the enterprise network; and transmitting data between the remote device and the enterprise network through the encrypted tunnel.

    ON-PATH DYNAMIC POLICY ENFORCEMENT AND ENDPOINT-AWARE POLICY ENFORCEMENT FOR ENDPOINTS

    公开(公告)号:US20200322230A1

    公开(公告)日:2020-10-08

    申请号:US16782769

    申请日:2020-02-05

    Abstract: Systems, methods, and computer-readable media for locally applying endpoint-specific policies to an endpoint in a network environment. A network device local to one or more endpoints in a network environment can receive from a centralized network controller one or more network-wide endpoint policies. A first endpoint of the one or more endpoints can be configured to inject policy metadata into first data traffic. Policy metadata injected into the first traffic data can be received from the first endpoint. The network device can determine one or more first endpoint-specific polices for the first endpoint by evaluation the first policy metadata with respect to the one or more network-wide endpoint policies. As follows, the one or more first endpoint-specific policies can be applied to control data traffic associated with the first endpoint.

    System and method for transporting information to services in a network environment
    4.
    发明授权
    System and method for transporting information to services in a network environment 有权
    将信息传输到网络环境中的服务的系统和方法

    公开(公告)号:US09479443B2

    公开(公告)日:2016-10-25

    申请号:US14285843

    申请日:2014-05-23

    Abstract: An example method is provided in one example embodiment and may include receiving a packet for a subscriber at a gateway, wherein the gateway includes a local policy anchor for interfacing with one or more policy servers and one or more classifiers for interfacing with one or more service chains, each service chain including one or more services accessible by the gateway; determining a service chain to receive the subscriber's packet; appending the subscriber's packet with a header, wherein the header includes, at least in part, identification information for the subscriber and an Internet Protocol (IP) address for the local policy anchor; and injecting the packet including the header into the service chain determined for the subscriber.

    Abstract translation: 在一个示例性实施例中提供了示例性方法,并且可以包括在网关处接收订户的分组,其中所述网关包括用于与一个或多个策略服务器进行接口的本地策略锚点以及用于与一个或多个服务 每个服务链包括由网关可访问的一个或多个服务; 确定服务链以接收订户的分组; 用标题附加订户的分组,其中该报头至少部分地包括用户的标识信息和用于本地策略锚的因特网协议(IP)地址; 以及将包括所述头部的分组注入到为所述用户确定的服务链中。

    Distributed network address and port translation for migrating flows between service chains in a network environment
    5.
    发明授权
    Distributed network address and port translation for migrating flows between service chains in a network environment 有权
    分布式网络地址和端口转换,用于在网络环境中的服务链之间迁移流

    公开(公告)号:US09413659B2

    公开(公告)日:2016-08-09

    申请号:US14301767

    申请日:2014-06-11

    CPC classification number: H04L45/745 H04L47/18 H04L47/2441

    Abstract: An example method for distributed network address and port translation (NAPT) for migrating flows between service chains in a network environment is provided and includes distributing translation state for a flow traversing the network across a plurality of NAPT service nodes in the network, with packets belonging to the flow being translated according to the translation state, associating the flow with a first service chain at a flow classifier in the network, and updating the association when the flow migrates from the first service chain to a second service chain, with packets belonging to the migrated flow also being translated according to the translation state. The method may be executed at a pool manager in the network. In specific embodiments, the pool manager may include a distributed storage located across the plurality of NAPT service nodes.

    Abstract translation: 提供了一种用于在网络环境中的服务链之间迁移流的分布式网络地址和端口转换(NAPT)的示例方法,并且包括:跨越网络中的多个NAPT服务节点的跨流过的流的分发转换状态,分组属于 根据所述翻译状态对所述流进行翻译,将所述流与所述网络中的流分类器处的第一服务链相关联,以及当所述流从所述第一服务链迁移到第二服务链时更新所述关联,其中分组属于 迁移流也根据翻译状态进行翻译。 该方法可以在网络中的池管理器处执行。 在具体实施例中,池管理器可以包括跨越多个NAPT服务节点的分布式存储器。

    Providing virtual private service chains in a network environment
    10.
    发明授权
    Providing virtual private service chains in a network environment 有权
    在网络环境中提供虚拟专用服务链

    公开(公告)号:US09413655B2

    公开(公告)日:2016-08-09

    申请号:US14304043

    申请日:2014-06-13

    Abstract: A method provided in one embodiment includes receiving a first data packet of a data flow at a first classifier in which the first data packet includes a first identifier. The method further includes determining a second classifier associated with the first identifier in which the second classifier is further associated with at least one service chain of a service chain environment. The method still further includes forwarding the first data packet to the second classifier. The second classifier is configured to receive the first data packet, determine a particular service chain of the at least one service chain to which the first data packet is to be forwarded, and forward the first data packet to the particular service chain.

    Abstract translation: 在一个实施例中提供的方法包括在第一分类器处接收数据流的第一数据分组,其中第一数据分组包括第一标识符。 该方法还包括确定与第一标识符相关联的第二分类器,其中第二分类器进一步与服务链环境的至少一个服务链相关联。 该方法还包括将第一数据分组转发到第二分类器。 第二分类器被配置为接收第一数据分组,确定要转发第一数据分组的至少一个服务链的特定服务链,并将第一数据分组转发到特定服务链。

Patent Agency Ranking