Invention Grant
- Patent Title: Dynamic security actions for network tunnels against spoofing
-
Application No.: US16732140Application Date: 2019-12-31
-
Publication No.: US11570207B2Publication Date: 2023-01-31
- Inventor: Ashish Suresh Ghule , Jagadish Narasimha Grandhi
- Applicant: Juniper Networks, Inc.
- Applicant Address: US CA Sunnyvale
- Assignee: Juniper Networks, Inc.
- Current Assignee: Juniper Networks, Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: Shumaker & Sieffert, P.A.
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/40 ; H04L47/32 ; H04L61/2592 ; H04L69/22 ; H04L12/46 ; H04L101/686

Abstract:
An example network device receives an encapsulated network packet via a network tunnel; extracts IPv6 header information from the encapsulated network packet; extracts IPv4 header information from the encapsulated network packet; determines that the encapsulated network packet is a spoofed network packet based on the IPv6 header information and the IPv4 header information; and in response to detecting the spoofed network packet, transmits a message to a Tunnel Entry Point (TEP) device, the message including data representing the IPv6 header information and IPv4 header information. A tunnel entry point (TEP) device may receive the message and use the message to detect spoofed IPv6 traffic, e.g., when an IPv6 header and an IPv4 header of an encapsulated packet matches the IPv6 header and the IPv4 header specified in the message. In this manner, the TEP device may block, rate limit, or redirect spoofed network traffic.
Public/Granted literature
- US20210203688A1 DYNAMIC SECURITY ACTIONS FOR NETWORK TUNNELS AGAINST SPOOFING Public/Granted day:2021-07-01
Information query