-
公开(公告)号:AU2020290944B2
公开(公告)日:2024-12-19
申请号:AU2020290944
申请日:2020-06-11
Applicant: CISCO TECHNOLOGY INC
Inventor: SUNDARARAJAN BALAJI , VALLURI VAMSIDHAR , BALASUBRAMANIAN CHANDRAMOULI , OSWAL ANAND , SINGH RAM DULAR
IPC: H04L45/121 , H04L41/50 , H04L45/30 , H04L45/42 , H04L45/64
Abstract: In one embodiment, a method includes providing a first profile to a plurality of edge routers of the SD-WAN, the plurality of edge routers operable to interface a plurality of devices to the SD-WAN. The first profile enables the plurality of edge routers to discover which devices of the plurality of devices support a first application. The method includes receiving, from one or more of the edge routers, information indicating which devices of the plurality of devices support the first application and building a first application fabric based on the information indicating which devices of the plurality of devices support the first application.
-
公开(公告)号:AU2020341323B2
公开(公告)日:2024-10-17
申请号:AU2020341323
申请日:2020-08-17
Applicant: CISCO TECHNOLOGY INC
Inventor: SUNDARARAJAN BALAJI , JABR KHALIL A , OSWAL ANAND , AGARWAL VIVEK , BALASUBRAMANIAN CHANDRAMOULI
Abstract: Systems, methods, and computer-readable media for interconnecting SDWANs through segment routing. A first SDWAN and a second SDWAN of a SDWAN fabric can be identified. A segment routing domain that interconnects the first SDWAN and the second SDWAN can be formed across a WAN underlay of the SDWAN fabric. Data transmission between the first SDWAN and the second SDWAN can be controlled by performing segment routing through the segment routing domain formed between the first SDWAN and the second SDWAN.
-
公开(公告)号:AU2019388833B2
公开(公告)日:2024-08-22
申请号:AU2019388833
申请日:2019-11-19
Applicant: CISCO TECHNOLOGY INC
Inventor: HOODA SANJAY KUMAR , OSWAL ANAND , BHAU NEHAL , EDATHARA ANIL , MEHTA MUNISH
Abstract: Systems and methods provide for end-to-end identity-aware routing across multiple administrative domains. A first ingress edge device of a second overlay network can receive a first encapsulated packet from a first egress edge device of a first overlay network. The first ingress edge device can de-encapsulate the first encapsulated packet to obtain an original packet and a user or group identifier. The first ingress edge device can apply a user or group policy matching the user or group identifier to determine a next hop for the original packet. The first ingress edge device can encapsulate the original packet and the user or group identifier to generate a second encapsulated packet. The first ingress edge device can forward the second encapsulated packet to the next hop.
-
公开(公告)号:AU2020341323A1
公开(公告)日:2022-04-21
申请号:AU2020341323
申请日:2020-08-17
Applicant: CISCO TECHNOLOGY INC
Inventor: SUNDARARAJAN BALAJI , JABR KHALIL A , OSWAL ANAND , AGARWAL VIVEK , BALASUBRAMANIAN CHANDRAMOULI
Abstract: Systems, methods, and computer-readable media for interconnecting SDWANs through segment routing. A first SDWAN and a second SDWAN of a SDWAN fabric can be identified. A segment routing domain that interconnects the first SDWAN and the second SDWAN can be formed across a WAN underlay of the SDWAN fabric. Data transmission between the first SDWAN and the second SDWAN can be controlled by performing segment routing through the segment routing domain formed between the first SDWAN and the second SDWAN.
-
公开(公告)号:AU2019390284B2
公开(公告)日:2024-08-01
申请号:AU2019390284
申请日:2019-11-12
Applicant: CISCO TECHNOLOGY INC
Inventor: VALLURI VAMSIDHAR , RADHAKRISHNAN SARAVANAN , OSWAL ANAND , PRABHU VINAY , EVANS SARAH ADELAIDE , RANGASWAMY SURAJ
Abstract: Systems and methods provide for provisioning a dynamic intent-based firewall. A network controller can generate a master route table for network segments reachable from edge network devices managed by the controller. The controller can receive zone definition information mapping the network segments into zones and Zone-based Firewall (ZFW) policies to apply to traffic between a source and destination zone specified by each ZFW policy. The controller can evaluate a ZFW policy to determine first edge network devices that can reach first network segments mapped to the source zone specified by the ZFW policy, second edge network devices that can reach second network segments mapped to the destination zone specified by the ZFW policy, and routing information (from the route table) between the first network segments, the first and second edge network devices, and the second network segments. The controller can transmit the routing information to the edge network devices.
-
-
-
-