-
公开(公告)号:US12166681B2
公开(公告)日:2024-12-10
申请号:US18170917
申请日:2023-02-17
Applicant: VMware LLC
Inventor: Arijit Chanda , Rajiv Krishnamurthy
Abstract: Described herein are systems, methods, and software to enhance the implementation of communication rules in a computing network. In one example, a method of operating a communication settings system maintains communication rules for a plurality of networks, wherein the communication rules define forwarding actions for ingress and egress packets to and from applications in the plurality of computing networks. The service further identifies a configuration request from a computing network with applications executing in the computing network, identifies a subset of the communication rules based on the plurality of applications, and provides the subset of the communication rules to the computing network.
-
公开(公告)号:US12197971B2
公开(公告)日:2025-01-14
申请号:US17397936
申请日:2021-08-09
Applicant: VMware LLC
Inventor: Sirisha Myneni , Arijit Chanda , Laxmikant Vithal Gunda , Arnold Koon-Chee Poon , Farzad Ghannadian , Kausum Kumar
Abstract: Some embodiments of the invention provide a simplified mechanism to deploy and control a multi-segmented application by using application-based manifests that express how application segments of the multi-segment application are to be defined or modified, and how the communication profiles between these segments. In some embodiments, these manifests are application specific. Also, in some embodiments, deployment managers in a software defined datacenter (SDDC) provide these manifests as templates to administrators, who can use these templates to express their intent when they are deploying multi-segment applications in the datacenter. Application-based manifests can also be used to control previously deployed multi-segmented applications in the SDDC. Using such manifests would enable the administrators to be able to manage fine grained micro-segmentation rules based on endpoint and network attributes.
-