NETWORKING CONNECTION MANAGEMENT BASED ON CONTAINER IDENTIFICATION

    公开(公告)号:US20190394281A1

    公开(公告)日:2019-12-26

    申请号:US16125792

    申请日:2018-09-10

    申请人: NICIRA, INC.

    摘要: Described herein are systems, methods, and software to enhance packet . In one implementation, a host computing element identifies a packet from a process executing on the host computing element. In response to identifying the packet, the host computing element determines whether the packet originates from a container namespace corresponding to a container on the host computing element or a host namespace corresponding to the host computing element. If the packet originates from a container namespace, the host computing element may determine supplemental information for the container associated with the container namespace, and process the packet based on the supplemental information.

    Flow-based forwarding element configuration

    公开(公告)号:US11888899B2

    公开(公告)日:2024-01-30

    申请号:US15915096

    申请日:2018-03-08

    申请人: NICIRA, INC.

    摘要: Example methods are provided for flow-based forwarding element configuration in a network environment. An example method may comprise obtaining a set of security policies associated with the group of workloads; and based on the set of security policies, identifying an allowed forwarding path between a destination and a first workload. The method may also comprise configuring a whitelist set of flow entries and sending configuration information to the flow-based forwarding element to cause the flow-based forwarding element to apply the whitelist set. The whitelist set may include a first flow entry specifying match fields and a first action to allow communication over the allowed forwarding path, but excludes a second flow entry specifying a second action to block communication over a forbidden forwarding path between the destination and the second workload. The match fields may include transport layer information and network layer information.

    NETWORKING CONNECTION MANAGEMENT BASED ON CONTAINER IDENTIFICATION

    公开(公告)号:US20220279044A1

    公开(公告)日:2022-09-01

    申请号:US17745228

    申请日:2022-05-16

    申请人: Nicira, Inc.

    摘要: Described herein are systems, methods, and software to enhance packet processing. In one implementation, a host computing element identifies a packet from a process executing on the host computing element. In response to identifying the packet, the host computing element determines whether the packet originates from a container namespace corresponding to a container on the host computing element or a host namespace corresponding to the host computing element. If the packet originates from a container namespace, the host computing element may determine supplemental information for the container associated with the container namespace, and process the packet based on the supplemental information.