Sampling rate-limited traffic
    1.
    发明授权
    Sampling rate-limited traffic 有权
    采样率限制流量

    公开(公告)号:US08018845B2

    公开(公告)日:2011-09-13

    申请号:US11339597

    申请日:2006-01-25

    CPC分类号: H04L43/022 H04L43/16

    摘要: Out-of-profile rate-limited traffic is sampled to provide data for analysis, such as for, but not limited to, identifying a threat condition such as a denial-of-service or other malicious attack, or a non-malicious attack such as an error in configuration. A rate limiter including at least three states is typically used, with one of these states being an out-of-profile sampling state wherein the packet traffic is sampled to identify one or more sampled packets on which analysis can be performed, with defensive action possibly taken in response to the analysis.

    摘要翻译: 采样失速率限制流量以提供用于分析的数据,例如用于但不限于识别威胁状况,例如拒绝服务或其他恶意攻击,或非恶意攻击,例如非恶意攻击 作为配置错误。 通常使用包括至少三个状态的速率限制器,其中这些状态之一是失真采样状态,其中对分组业务进行采样以识别可以在其上进行分析的一个或多个采样分组,具有可能的防御动作 作为回应分析。

    Sampling rate-limited traffic
    2.
    发明申请
    Sampling rate-limited traffic 有权
    采样率限制流量

    公开(公告)号:US20070171824A1

    公开(公告)日:2007-07-26

    申请号:US11339597

    申请日:2006-01-25

    IPC分类号: H04L12/26

    CPC分类号: H04L43/022 H04L43/16

    摘要: Out-of-profile rate-limited traffic is sampled to provide data for analysis, such as for, but not limited to, identifying a threat condition such as a denial-of-service or other malicious attack, or a non-malicious attack such as an error in configuration. A rate limiter including at least three states is typically used, with one of these states being an out-of-profile sampling state wherein the packet traffic is sampled to identify one or more sampled packets on which analysis can be performed, with defensive action possibly taken in response to the analysis.

    摘要翻译: 采样失速率限制流量以提供用于分析的数据,例如用于但不限于识别威胁状况,例如拒绝服务或其他恶意攻击,或非恶意攻击,例如非恶意攻击 作为配置错误。 通常使用包括至少三个状态的速率限制器,其中这些状态之一是失真采样状态,其中对分组业务进行采样以识别可以在其上进行分析的一个或多个采样分组,具有可能的防御动作 作为回应分析。

    Scaling VLANs in a data network
    3.
    发明申请
    Scaling VLANs in a data network 有权
    在数据网络中扩展VLAN

    公开(公告)号:US20060007939A1

    公开(公告)日:2006-01-12

    申请号:US10888866

    申请日:2004-07-09

    IPC分类号: H04L12/28

    CPC分类号: H04L12/465

    摘要: A technique for scaling virtual local area networks (VLANs) in a manner that allows existing standards to be used to process VLAN traffic and provide loop-free topologies for the VLANs. A data network is divided into customer, domain and core networks. VLANs are apportioned between the core network and domain networks such that VLANs apportioned to the core networks are global to both the core and domain networks and VLANs apportioned to the domain networks are local to each domain. Packets transported in the domain network contain domain VLAN (DVLAN) tags which are conventional VIDs that identify VLANs used to transport the packets in the domain network. Packets transported in the core network contain transport VLAN (TVLAN) tags which are conventional VIDs that identify VLANs used to transport the packets in the core network. In addition, packets transported in the core network contain pseudo-LAN (P-LAN) tags that are used in combination with TVLAN tags to identify DVLAN tags associated with the packet.

    摘要翻译: 一种用于缩放虚拟局域网(VLAN)的技术,可以使现有标准用于处理VLAN流量,并为VLAN提供无环路拓扑。 数据网络分为客户,域和核心网。 VLAN在核心网络和域网络之间分配,使得分配给核心网络的VLAN对于核心域和域网都是全局的,分配给域网络的VLAN是每个域的本地。 在域网络中传输的数据包包含域VLAN(DVLAN)标签,这些标签是标识用于传输域网络中的数据包的VLAN的常规VID。 在核心网络中传输的数据包包含传输VLAN(TVLAN)标签,这些标签是标识用于传输核心网络中的数据包的VLAN的常规VID。 另外,在核心网络中传送的分组包含与TVLAN标签组合使用的伪LAN(P-LAN)标签,以识别与分组相关联的DVLAN标签。

    System and method for building large-scale layer 2 computer networks
    4.
    发明授权
    System and method for building large-scale layer 2 computer networks 有权
    构建大型二层计算机网络的系统和方法

    公开(公告)号:US07821972B1

    公开(公告)日:2010-10-26

    申请号:US11238925

    申请日:2005-09-29

    IPC分类号: H04L12/28 H04L12/56 G06F15/16

    摘要: A grand computer network is formed from layer 2 (L2) networking technology in which groups of Provider L2 bridges are organized into formations, and different formations are interconnected via network-network interface (NNI) links. Customer sites are coupled to the formations. Customers identify their traffic, e.g., frames, by labeling or tagging it with a Customer Virtual Local Area Network (VLAN) Identifier (C-VLAN ID) or Customer Service Instance (CSI). Within the formations, the C-VLAN ID is mapped to a Service VLAN ID (S-VLAN ID) or Provider Service Instance (PSI), and the S-VLAN ID is appended to the customer traffic. The PSIs are hierarchical, such that each PSI belongs to at most one other “outer” or higher-level PSI, but may itself own any number of “inner” or lower-level PSIs. As a given frame traverses through the different formations of the Grand Network via the NNI links, the frame acquires an encapsulation, sheds an encapsulation or exchanges its current encapsulation for a different one. Bridges within the formations run a Hierarchical Spanning Tree Program (HSTP) to block intra-formation loops, and a GARP L2-NNI Registration Protocol (GLRP) to block inter-formation loops.

    摘要翻译: 第二层(L2)网络技术形成了一个大型计算机网络,其中提供商L2网络组织成地层,并且不同的地层通过网络 - 网络接口(NNI)链路相互连接。 客户站点耦合到地层。 客户通过用客户虚拟局域网(VLAN)标识符(C-VLAN ID)或客户服务实例(CSI)标记或标记它们来识别其流量,例如帧。 在地层中,C-VLAN ID映射到服务VLAN ID(S-VLAN ID)或提供商服务实例(PSI),S-VLAN ID附加到客户流量。 PSI是分层的,使得每个PSI最多属于另一个“外部”或更高级别的PSI,但是它本身可以拥有任何数量的“内部”或较低级别的PSI。 当给定的帧通过NNI链路穿过Grand网络的不同格局时,帧获取封装,散布封装或交换其当前的封装。 地层内的桥梁运行层次生成树程序(HSTP)以阻止内部循环,以及GARP L2-NNI注册协议(GLRP)来阻止内部循环。

    METHOD AND APPARATUS FOR EFFICIENT LOAD DISTRIBUTION ON LINK AGGREGATIONS
    5.
    发明申请
    METHOD AND APPARATUS FOR EFFICIENT LOAD DISTRIBUTION ON LINK AGGREGATIONS 有权
    用于链路聚合的有效负载分配的方法和装置

    公开(公告)号:US20060198381A1

    公开(公告)日:2006-09-07

    申请号:US11072487

    申请日:2005-03-04

    IPC分类号: H04L12/56 H04J3/24

    摘要: A system for providing a substantially balanced distribution of traffic over an aggregation of output lines carrying digital information makes use of m random or pseudo-random bits substantially greater in number than the number of bits (n) used for selection of individual lines. The m bits address a table populated with n-bit entries whose bit combinations correspond with the respective output lines, with the relative numbers of the bit combinations being such as to provide substantially equal loads on the individual lines.

    摘要翻译: 用于在承载数字信息的输出线的聚合上提供基本平衡的业务分布的系统利用在数量上比用于选择各个线路的位数(n)大得多的m个随机或伪随机位。 m位地址填充有n位条目的表,其位组合对应于相应的输出行,其中位组合的相对数量使得在各行上提供基本相等的负载。

    Reducing Flooding in a Bridged Network
    6.
    发明申请
    Reducing Flooding in a Bridged Network 有权
    减少洪水泛滥网络

    公开(公告)号:US20100067374A1

    公开(公告)日:2010-03-18

    申请号:US12209622

    申请日:2008-09-12

    IPC分类号: H04L12/56

    摘要: Disclosed are, inter alia, methods, apparatus, computer-storage media, mechanisms, and means associated with loss of reducing flooding in a bridged network, typically including a device directly connected to multiple upstream bridges. These bridges are configured such that the device receives broadcast/multicast traffic from a single interface of one of the bridges, while allowing unicast traffic over each of the communications links connecting the device to the bridges. In one configuration, the device implements virtual machine(s), each including a virtual network interface associated with a MAC address; and the directly connected bridges are configured, for each particular MAC address of these MAC addresses of the virtual interfaces, such that one and only one of the bridges will forward packets having the particular MAC address as its destination address over a communications link directly connected to the device.

    摘要翻译: 公开的方法,装置,计算机存储介质,机制和与桥接网络中的减少洪泛的损失相关联的装置,通常包括直接连接到多个上游桥的设备。 这些网桥被配置为使得设备从一个桥接器的单个接口接收广播/多播业务,同时允许通过将设备连接到网桥的每个通信链路上的单播流量。 在一个配置中,设备实现虚拟机,每个虚拟机包括与MAC地址相关联的虚拟网络接口; 并且针对虚拟接口的这些MAC地址的每个特定MAC地址配置直接连接的桥,使得桥中的一个且仅一个将通过直接连接到的通信链路将具有特定MAC地址的分组转发到其目的地地址 装置。

    Traffic forwarding for virtual machines
    8.
    发明授权
    Traffic forwarding for virtual machines 有权
    虚拟机的流量转发

    公开(公告)号:US08589919B2

    公开(公告)日:2013-11-19

    申请号:US12387174

    申请日:2009-04-28

    IPC分类号: G06F9/455

    摘要: In one embodiment, an apparatus configured for communication with a plurality of virtual machines includes a virtual switch in communication with one or more of the virtual machines, an interface in communication with one or more of the virtual machines and configured for communication with a hardware implemented switch, and a mode selector for assigning to each of the virtual machines, a mode of operation for forwarding data from the virtual machine and switching the assigned mode of operation at one or more of the virtual machines. The mode of operation is selected from a first mode wherein the data is forwarded by the hardware implemented switch and a second mode wherein the data is forwarded by the virtual switch.

    摘要翻译: 在一个实施例中,被配置为与多个虚拟机通信的装置包括与虚拟机中的一个或多个通信的虚拟交换机,与虚拟机中的一个或多个通信的接口,并被配置为与实现的硬件进行通信 交换机和模式选择器,用于向每个虚拟机分配用于从虚拟机转发数据并在一个或多个虚拟机处切换分配的操作模式的操作模式。 从第一模式中选择操作模式,其中数据由硬件实现的交换机转发,以及其中数据由虚拟交换机转发的第二模式。

    Distributed data center access switch
    9.
    发明申请
    Distributed data center access switch 有权
    分布式数据中心接入交换机

    公开(公告)号:US20100214949A1

    公开(公告)日:2010-08-26

    申请号:US12380072

    申请日:2009-02-23

    IPC分类号: H04L12/56 H04L12/28 H04L12/66

    摘要: In one embodiment, an apparatus includes a processor configured for operation in a control plane in a distributed virtual switch in communication with a plurality of virtual machines each having a virtual interface. The processor is operable to identify other control planes in the distributed virtual switch, assign a virtual interface identifier to one of the virtual interfaces, receive a configuration for the virtual interface, and share the configuration with the other control planes in the distributed virtual switch. The virtual interface identifier provides a unique identifier for the virtual interface across all of the control planes. The apparatus further includes memory for storing the configuration of the virtual interface. A method for operating a network device associated with a control in the distributed virtual switch is also disclosed.

    摘要翻译: 在一个实施例中,一种装置包括处理器,其被配置为在分布式虚拟交换机中的控制平面中进行操作,所述分布式虚拟交换机与多个虚拟机具有虚拟接口。 处理器可操作以识别分布式虚拟交换机中的其他控制平面,将虚拟接口标识符分配给虚拟接口之一,接收虚拟接口的配置,并与分布式虚拟交换机中的其他控制平面共享配置。 虚拟接口标识符为所有控制平面上的虚拟接口提供唯一的标识符。 该装置还包括用于存储虚拟接口的配置的存储器。 还公开了一种用于操作与分布式虚拟交换机中的控制相关联的网络设备的方法。

    Method and device for efficient transmission of flood data frames in a backbone network
    10.
    发明授权
    Method and device for efficient transmission of flood data frames in a backbone network 有权
    用于在骨干网中有效传输洪泛数据帧的方法和装置

    公开(公告)号:US07724745B1

    公开(公告)日:2010-05-25

    申请号:US11372902

    申请日:2006-03-09

    IPC分类号: H04L12/28

    摘要: A method and device for efficient transmission of flood data frames in a backbone network comprising a plurality of virtual local area networks (VLANs). A flood data frame is received at an intermediate network device communicatively coupled to a backbone network, wherein the destination of the flood data frame is unknown. A customer associated with the flood data frame is identified. A customer multicast group associated with the customer is identified, the customer multicast group identifying at least one destination intermediate network device coupled to the backbone network. The flood data frame is forwarded to at least one destination intermediate network device of the customer multicast group.

    摘要翻译: 一种用于在包括多个虚拟局域网(VLAN)的骨干网络中有效传输洪泛数据帧的方法和装置。 在通信地耦合到骨干网的中间网络设备处接收洪泛数据帧,其中洪泛数据帧的目的地是未知的。 识别与洪水数据帧相关联的客户。 识别与客户相关联的客户多播组,客户多播组识别耦合到骨干网络的至少一个目的地中间网络设备。 洪泛数据帧被转发到客户多播组的至少一个目的中间网络设备。