Invention Grant
- Patent Title: Implementing logical network security on a hardware switch
-
Application No.: US16240654Application Date: 2019-01-04
-
Publication No.: US10659431B2Publication Date: 2020-05-19
- Inventor: Benjamin C. Basler
- Applicant: Nicira, Inc.
- Applicant Address: US CA Palo Alto
- Assignee: NICIRA, INC.
- Current Assignee: NICIRA, INC.
- Current Assignee Address: US CA Palo Alto
- Agency: Adeli LLP
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Some embodiments provide a method for applying a security policy defined for a logical network to an MHFE that integrates physical workloads (e.g., physical machines connected to the MHFE) with the logical network. The method applies the security policy to the MHFE by generating a set of ACL rules based on the security policy's definition and configuring the MHFE to apply the ACL rules on the network traffic that is forwarded to and/or from the physical machines. In order to configure an MHFE to implement the different LFEs of a logical network, some embodiments propagate an open source database stored on the MHFE, using an open source protocol. Some embodiments propagate a particular table of the database such that each record of the table creates an association between a port of an LFE stored in a logical forwarding table and one or more ACL rules stored in an ACL table.
Public/Granted literature
- US20190141011A1 IMPLEMENTING LOGICAL NETWORK SECURITY ON A HARDWARE SWITCH Public/Granted day:2019-05-09
Information query