发明名称 Method for propagating access policies
摘要 The present disclosure describes a network appliance and associated access policy protocol (APP) that communicates and obeys access policies within a network. The network appliance (APP node) propagates access policies to other APP nodes that can utilize the policies most effectively. When an access policy reaches the network boundary, intra network bandwidth is optimized. The access policies may be distributed and executed in the cloud—e.g. proxy firewall, proxy policy execution.
申请公布号 US9621554(B2) 申请公布日期 2017.04.11
申请号 US201213533478 申请日期 2012.06.26
申请人 Cisco Technology, Inc. 发明人 Fong Rodney;Sreedharan Jaya;Kumar Vinayak
分类号 G06F17/00;H04L29/06;H04L12/28 主分类号 G06F17/00
代理机构 Merchant & Gould P.C. 代理人 Merchant & Gould P.C.
主权项 1. A method comprising: determining a plurality of neighboring network devices; exchanging access policy protocol databases between the plurality of neighboring network devices; requesting that the plurality of neighboring network devices execute access policies contained in the exchanged access policy protocol databases; managing an active access policy protocol database and an inactive access policy protocol database at each of the plurality of neighboring network devices, wherein the active access policy protocol database and the inactive access policy protocol database are separate databases, and wherein the inactive access policy protocol database further separately maintains inactive policies originated by a network device associated with the inactive access policy protocol database and inactive policies propagated by a network device not associated with the inactive access policy protocol database; detecting that a neighboring network device is offline; and moving access control policies associated with the offline neighboring network device from the inactive access policy protocol database to the active access policy protocol database.
地址 San Jose CA US