Invention Grant
- Patent Title: Data network microsegmentation
-
Application No.: US15382443Application Date: 2016-12-16
-
Publication No.: US10009383B2Publication Date: 2018-06-26
- Inventor: Marc Woolward
- Applicant: vArmour Networks, Inc.
- Applicant Address: US CA Mountain View
- Assignee: vArmour Networks, Inc.
- Current Assignee: vArmour Networks, Inc.
- Current Assignee Address: US CA Mountain View
- Agency: Carr & Ferrell LLP
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Methods and systems for microsegmentation of data networks are provided herein. Exemplary methods include: receiving a high-level declarative policy; getting metadata associated with a plurality of containers from an orchestration layer; determining a low-level firewall rule set using the high-level declarative policy and the metadata; and configuring by a plurality of enforcement points a respective virtual switch of a plurality of virtual switches to process packets in accordance with the low-level firewall ruleset, the virtual switches being collectively communicatively coupled to the plurality of containers, such that network communications between a first group of containers and a second group of containers of the plurality of containers are not permitted, and communications between containers of the first group of containers are permitted.
Public/Granted literature
- US20170374102A1 Data Network Microsegmentation Public/Granted day:2017-12-28
Information query