发明名称 Policy Verification in a Network
摘要 A determination is made at a network connected device that a network policy is to be verified. The network policy is applied to network packets sent to an endpoint within a network, and the application of the policy to network traffic can result in at least two outcomes. Another determination is made at the network connected device that a switch is provisionable to host the endpoint. The network connected device provisions a simulated endpoint version of the endpoint at the switch to host the policy. At least one packet is sent to the simulated endpoint via the network connected device for each of the at least two outcomes of the policy. At least one response is received by the network connected device from the simulated endpoint indicating how the policy was applied to each of the packets.
申请公布号 US2016366019(A1) 申请公布日期 2016.12.15
申请号 US201514736523 申请日期 2015.06.11
申请人 Cisco Technology, Inc. 发明人 Pani Ayaskant;Raju Ravi;Ganapathy Jalajadevi;Sanyal Aubin;Doddapaneni Krishna;Thyamagundalu Sanjay;Cafiero Igino C.
分类号 H04L12/24;H04L12/26;H04L12/813;H04L29/06 主分类号 H04L12/24
代理机构 代理人
主权项 1. A method comprising: determining, at a network connected device, a network policy to be verified, wherein the network policy is applied to network packets sent to an endpoint within a network, wherein application of the policy to network traffic can result in at least two outcomes; determining, at the network connected device, a switch that is provisionable to host the endpoint; provisioning, via the network connected device, a simulated endpoint version of the endpoint at the switch; sending, over the network via the network connected device, at least one packet for each of the at least two outcomes of the policy to the simulated endpoint; and receiving, via the network at the network connected device, at least one response from the simulated endpoint indicating how the policy was applied to each of the packets.
地址 San Jose CA US