METHODS FOR MICRO-SEGMENTATION IN SD-WAN FOR VIRTUAL NETWORKS

    公开(公告)号:US20220353190A1

    公开(公告)日:2022-11-03

    申请号:US17569526

    申请日:2022-01-06

    Applicant: VMware, Inc.

    Abstract: Some embodiments of the invention provide a method for micro-segmenting traffic flows in a software defined wide area network (SD-WAN). At a first edge forwarding node of a first multi-machine site in the SD-WAN, the method receives, from a particular forwarding element, a first packet of a packet flow originating from a second multi-machine site that is external to the SD-WAN, the packet flow destined for a particular machine at the first multi-machine site. The method uses deep packet inspection (DPI) on the first packet to identify contextual information not provided by the particular forwarding element about the first packet and the packet flow. Based on the identified contextual information, the method applies one or more policies to the first packet before forwarding the first packet to the particular machine.

Patent Agency Ranking