-
公开(公告)号:US20200059494A1
公开(公告)日:2020-02-20
申请号:US16248828
申请日:2019-01-16
Applicant: VMWARE, INC.
Abstract: One or more embodiments provide a firewall policy between a first virtual data center and a second virtual data center. A method includes: establishing a communication link between a first firewall server in the first virtual data center and a second firewall server in the second virtual data center over a network, the first firewall server having a first firewall defined by polices applied to groups of objects in the first virtual data center; obtaining, at the first firewall server, an inventory of objects in the second virtual data center from the second firewall server; determining firewall rule tuples by mapping the policies of the first firewall to groups of objects in the inventory of the second virtual data center; and sending the firewall rule tuples to enforcement points in the second virtual data center.
-
公开(公告)号:US20200059493A1
公开(公告)日:2020-02-20
申请号:US16248824
申请日:2019-01-16
Applicant: VMWARE, INC.
Inventor: Bhaskar Subramanyam Annadata , Abhinav Vijay Bhagwat , Sachin Thakkar , Debashis Basak , Serge Maskalik
Abstract: An example method of migrating a firewall policy between a first virtual data center and a second virtual data center includes: generating a static firewall from a firewall document at a first firewall server in the first virtual data center, the firewall document defining polices applied to groups of objects in the first virtual data center, the static firewall including firewall rule tuples; sending the static firewall from the first firewall server to a second firewall server in the second virtual data center; migrating a plurality of virtual machines (VMs) from the first virtual data center to the second virtual data center; and importing the firewall document from the first firewall server to the second firewall server by mapping the policies of the first firewall to groups of objects in an inventory of the second virtual data center.
-
公开(公告)号:US11310277B2
公开(公告)日:2022-04-19
申请号:US16248828
申请日:2019-01-16
Applicant: VMWARE, INC.
Abstract: One or more embodiments provide a firewall policy between a first virtual data center and a second virtual data center. A method includes: establishing a communication link between a first firewall server in the first virtual data center and a second firewall server in the second virtual data center over a network, the first firewall server having a first firewall defined by polices applied to groups of objects in the first virtual data center; obtaining, at the first firewall server, an inventory of objects in the second virtual data center from the second firewall server; determining firewall rule tuples by mapping the policies of the first firewall to groups of objects in the inventory of the second virtual data center; and sending the firewall rule tuples to enforcement points in the second virtual data center.
-
公开(公告)号:US11184397B2
公开(公告)日:2021-11-23
申请号:US16248824
申请日:2019-01-16
Applicant: VMWARE, INC.
Inventor: Bhaskar Subramanyam Annadata , Abhinav Vijay Bhagwat , Sachin Thakkar , Debashis Basak , Serge Maskalik
Abstract: An example method of migrating a firewall policy between a first virtual data center and a second virtual data center includes: generating a static firewall from a firewall document at a first firewall server in the first virtual data center, the firewall document defining polices applied to groups of objects in the first virtual data center, the static firewall including firewall rule tuples; sending the static firewall from the first firewall server to a second firewall server in the second virtual data center; migrating a plurality of virtual machines (VMs) from the first virtual data center to the second virtual data center; and importing the firewall document from the first firewall server to the second firewall server by mapping the policies of the first firewall to groups of objects in an inventory of the second virtual data center.
-
-
-