Invention Grant
- Patent Title: Dynamic intent-based firewall
-
Application No.: US16434115Application Date: 2019-06-06
-
Publication No.: US11201854B2Publication Date: 2021-12-14
- Inventor: Vamsidhar Valluri , Saravanan Radhakrishnan , Anand Oswal , Vinay Prabhu , Sarah Adelaide Evans , Suraj Rangaswamy
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Polsinelli PC
- Main IPC: H04L12/46
- IPC: H04L12/46 ; H04L29/06 ; H04L12/751 ; H04L12/741

Abstract:
Systems and methods provide for provisioning a dynamic intent-based firewall. A network controller can generate a master route table for network segments reachable from edge network devices managed by the controller. The controller can receive zone definition information mapping the network segments into zones and Zone-based Firewall (ZFW) policies to apply to traffic between a source and destination zone specified by each ZFW policy. The controller can evaluate a ZFW policy to determine first edge network devices that can reach first network segments mapped to the source zone specified by the ZFW policy, second edge network devices that can reach second network segments mapped to the destination zone specified by the ZFW policy, and routing information (from the route table) between the first network segments, the first and second edge network devices, and the second network segments. The controller can transmit the routing information to the edge network devices.
Public/Granted literature
- US20200177550A1 DYNAMIC INTENT-BASED FIREWALL Public/Granted day:2020-06-04
Information query