AUTO-SECURITY FOR NETWORK EXPANSION USING FORWARD REFERENCES IN MULTI-SITE DEPLOYMENTS

    公开(公告)号:US20220329603A1

    公开(公告)日:2022-10-13

    申请号:US17333072

    申请日:2021-05-28

    Applicant: VMWARE, Inc.

    Abstract: The disclosure provides an approach for managing group membership in a multi-site networking environment. Embodiments include receiving, at a local management component on a networking site of a plurality of networking sites, from a global management component associated with the plurality of networking sites, a definition of a group. Embodiments include determining, by the local management component on the networking site, based on the definition, that the group comprises a networking object with a span that does not include the networking site. Embodiments include storing, by the local management component on the networking site, in a data structure, a reference to the networking object in association with the group, wherein the networking object is excluded from a determination of local membership of the group on the networking site.

    Location criteria for security groups

    公开(公告)号:US11777793B2

    公开(公告)日:2023-10-03

    申请号:US17322318

    申请日:2021-05-17

    Applicant: VMware, Inc.

    CPC classification number: H04L41/08

    Abstract: Some embodiments provide a method for distributing a group definition for a group of machines. The method receives the group definition, which includes (i) a span of the group that specifies a set of sites at which the group is to be used and (ii) a set of criteria for machines to be included in the group. The set of criteria includes at least a location criteria specifying one or more sites. The method distributes the group definition to each site in the set of sites. At each site in the set of sites, a local network control system of the site determines a set of machines in the group based on the set of criteria. Only machines in the one or more sites specified by the location criteria are determined to be in the group.

    MULTI-SITE SECURITY GROUPS
    3.
    发明申请

    公开(公告)号:US20210314227A1

    公开(公告)日:2021-10-07

    申请号:US16906955

    申请日:2020-06-19

    Applicant: VMware, Inc.

    Abstract: Some embodiments provide a method for distributing a service rule that is to be enforced across a first set of sites and that is defined by reference to a group identifier that identifies a group of machines. The method distributes the service rule to each site in the first set of sites. The method identifies at least one site in the first set of sites that is not in a second set of sites that has already received a definition of the group. The method distributes the group definition to each identified site in the first set of sites that has not already received the definition of the group.

    LOCATION CRITERIA FOR SECURITY GROUPS

    公开(公告)号:US20210314219A1

    公开(公告)日:2021-10-07

    申请号:US17322318

    申请日:2021-05-17

    Applicant: VMware, Inc.

    Abstract: Some embodiments provide a method for distributing a group definition for a group of machines. The method receives the group definition, which includes (i) a span of the group that specifies a set of sites at which the group is to be used and (ii) a set of criteria for machines to be included in the group. The set of criteria includes at least a location criteria specifying one or more sites. The method distributes the group definition to each site in the set of sites. At each site in the set of sites, a local network control system of the site determines a set of machines in the group based on the set of criteria. Only machines in the one or more sites specified by the location criteria are determined to be in the group.

Patent Agency Ranking