Invention Grant
- Patent Title: Layer-3 policy enforcement for layer-7 data flows
-
Application No.: US17718634Application Date: 2022-04-12
-
Publication No.: US12294569B2Publication Date: 2025-05-06
- Inventor: Alberto Rodriguez-Natal , Lorand Jakab , Fabio R. Maino
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Lee & Hayes, P.C.
- Main IPC: H04L9/40
- IPC: H04L9/40 ; H04L43/0823 ; H04L43/0864 ; H04L47/10 ; H04L47/20

Abstract:
Techniques for using proxies with overprovisioned IP addresses to demultiplex data flows, which may otherwise look the same at L7, into multiple subflows for L3 policy enforcement without having to modify an underlying L3 network. The techniques may include establishing a subflow through a network between a first proxy and a second proxy, the subflow associated with a specific policy. In some examples, the first proxy node may receive an encrypted packet that is to be sent through the network and determine, based at least in part on accessing an encrypted application layer of the packet, a specific application to which the packet is to be sent. The first proxy node may then alter an IP address included in the packet to cause the packet to be sent through the network via the subflow such that the packet is handled according to the specific policy.
Public/Granted literature
- US20230328038A1 LAYER-3 POLICY ENFORCEMENT FOR LAYER-7 DATA FLOWS Public/Granted day:2023-10-12
Information query