发明名称 INTERFACE GROUPS FOR RULE-BASED NETWORK SECURITY
摘要 Systems and methods for designating interfaces of a network security appliance as source/destination interfaces in connection with defining a security rule are provided. According to one embodiment, a security rule configuration interface is displayed through which a network administrator can specify parameters of security rules to be applied to traffic attempting to traverse the network security appliance. Information defining a traffic flow to be controlled by a security rule is received via the security rule configuration interface. The information defining the traffic flow includes: (i) a set of source interfaces; and (ii) a set of destination interfaces. At least one of which includes multiple interfaces such that the security rule permits the traffic flow to be defined in terms of multiple source interfaces and/or multiple destination interfaces.
申请公布号 US2017063796(A1) 申请公布日期 2017.03.02
申请号 US201615350363 申请日期 2016.11.14
申请人 Fortinet, Inc. 发明人 Pan Yixin;Li Hongwei;Xie Michael
分类号 H04L29/06;H04L12/851 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method comprising: causing to be displayed, by a network security appliance, a security rule configuration interface through which a network administrator can specify parameters of a plurality of security rules to be applied to network traffic attempting to traverse the network security appliance through one or more of a plurality of interfaces of the network security appliance; receiving, by the network security appliance via the security rule configuration interface, information defining a traffic flow to be controlled by a security rule of the plurality security rules, wherein the information defining the traffic flow includes: a set of source interfaces of the plurality of interfaces, representing a proper subset of the plurality of interfaces, from which traffic associated with the traffic flow being defined may be received by the network security appliance;a set of destination interfaces of the plurality of interfaces, representing a proper subset of the plurality of interfaces, through which traffic associated with the traffic flow being defined may be transmitted by the network security appliance if the security rule allows the traffic flow; andwherein the set of source interfaces include multiple interfaces of the plurality of interfaces, whereby the security rule permits the traffic flow to be defined in terms of multiple source interfaces; receiving, by the network security appliance via the security rule configuration interface, information regarding the action to be performed on the network traffic when the network traffic matches the security rule; and storing, by the network security appliance, the security rule as part of a ruleset to be applied to the network traffic.
地址 Sunnyvale CA US