Logical network abstraction for network access control
Abstract:
Systems and methods for NAC access policy creation and reconfiguration of access points to enforce same are provided. A NAC device maintains (i) an access point model that maps logical networks to a corresponding enforcement action implementation for each access point associated with a private network and (ii) access policies each specifying a current state of a particular endpoint device and an enforcement action, specified with reference to a logical network. Responsive to an event associated with an endpoint, the NAC device receives an attribute of the endpoint. A matching access policy is identified based on the attribute. The corresponding enforcement action implementation for the access point to which the endpoint is connected is retrieved based on the logical network specified in the matching access policy. Finally, the access point is reconfigured by the NAC device to perform the enforcement action based on the retrieved enforcement action implementation.
Public/Granted literature
Information query
Patent Agency Ranking
0/0