摘要:
The disclosure provides an authentication network. In one embodiment the authentication network includes: (1) an authentication server for receiving authentication requests, (2) at least one network node for forwarding authentication requests from user devices to the authentication server, and (3) a flooding disabler in the at least one network node for selectively disabling the flooding of packets from the user device by the at least one network node.
摘要:
A system comprises a router having stored thereon a respective incoming label table including at least one set of LSP information (e.g., a LSP designator, a label denoting normal flow routing functionality and a label denoting controlled flow routing functionality). The router is configured for receiving a plurality of different traffic flows each including a plurality of frames, for correlating a configuration of the flow routing label of each one of the frames received thereby to a respective one of the traffic flows using information contained in the incoming label table thereof, for flooding a frame of the traffic flows of the router to all local access ports on an active VPLS domain thereof when the frame requires normal flow routing functionality, and for dropping the frame without being flooded to all of the local access ports on the active VPLS domain when the frame requires controlled flow routing functionality.
摘要:
The disclosure provides an authentication network. In one embodiment the authentication network includes: (1) an authentication server for receiving authentication requests, (2) at least one network node for forwarding authentication requests from user devices to the authentication server, and (3) a flooding disabler in the at least one network node for selectively disabling the flooding of packets from the user device by the at least one network node.
摘要:
A method and apparatus for controlling data packet flooding in a data-communication network to promote network security and provide for more efficient utilization of network resources. One or more network nodes include a flooding disable device, for example a disable bit in a L2 hardware lookup table associated with a particular device in an Ethernet application. When the disabler is set, packets from the particular device are not flooded on all ports even when the node cannot associate a particular port with the packets' intended destination. The flooding disable in the network node may be set statically or dynamically, either by a network operator or by a communication received from a server or other network device.
摘要:
A system comprises a router having stored thereon a respective incoming label table including at least one set of LSP information (e.g., a LSP designator, a label denoting normal flow routing functionality and a label denoting controlled flow routing functionality). The router is configured for receiving a plurality of different traffic flows each including a plurality of frames, for correlating a configuration of the flow routing label of each one of the frames received thereby to a respective one of the traffic flows using information contained in the incoming label table thereof, for flooding a frame of the traffic flows of the router to all local access ports on an active VPLS domain thereof when the frame requires normal flow routing functionality, and for dropping the frame without being flooded to all of the local access ports on the active VPLS domain when the frame requires controlled flow routing functionality.
摘要:
A method and apparatus for controlling data packet flooding in a data-communication network to promote network security and provide for more efficient utilization of network resources. One or more network nodes include a flooding disable device, for example a disable bit in a L2 hardware lookup table associated with a particular device in an Ethernet application. When the disabler is set, packets from the particular device are not flooded on all ports even when the node cannot associate a particular port with the packets' intended destination. The flooding disable in the network node may be set statically or dynamically, either by a network operator or by a communication received from a server or other network device.
摘要:
Aggregation Switches connected to an edge node by a multi-chassis link aggregation group, wherein the Aggregation Switches are connected by a virtual fabric link that provides a connection for exchange of information between the Aggregation Switches regarding MAC addressing to synchronize MAC address tables.
摘要:
Aggregation Switches connected to an edge node by a multi-chassis link aggregation group, wherein the Aggregation Switches are connected by a virtual fabric link that provides a connection for exchange of information between the Aggregation Switches regarding MAC addressing to synchronize MAC address tables.
摘要:
A network interfaced unit includes a first data processing device, a second data processing device coupled to the first data processing device, memory coupled to the first data processing device, and instructions accessible from the memory by the first data processing device. The instructions are configured for causing the first data processing device to carry out operations for causing a copy of a frame received by the second data processing device to be received by the first data processing device in response to a destination address of the frame failing to be found in an address lookup table accessibly by the second data processing device and for causing the first data processing device to query other network interface units after receiving the copy of the frame for determining if the destination address of the frame has been learned on any one of the other network interface units.
摘要:
A network interfaced unit includes a first data processing device, a second data processing device coupled to the first data processing device, memory coupled to the first data processing device, and instructions accessible from the memory by the first data processing device. The instructions are configured for causing the first data processing device to carry out operations for causing a copy of a frame received by the second data processing device to be received by the first data processing device in response to a destination address of the frame failing to be found in an address lookup table accessibly by the second data processing device and for causing the first data processing device to query other network interface units after receiving the copy of the frame for determining if the destination address of the frame has been learned on any one of the other network interface units.