发明名称 Rule-based network traffic interception and distribution scheme
摘要 Using a hash function, an L2/L3 switch can produce an FID for a data packet. The L2/L3 switch can select, from among potentially several stored VLAN flooding tables, a particular VLAN flooding table that is associated with a particular VLAN on which the data packet is to be carried. The rows of the particular VLAN flooding table can specify different combinations of the particular VLAN's egress ports. The L2/L3 switch can locate, in the particular VLAN flooding table, a particular row that specifies the FID. The L2/L3 switch can read, from the particular row, a specified subset of the egress ports that are associated with the particular VLAN. The L2/L3 switch can transmit copies of the data packet out each of the egress ports specified in the subset, toward analytic servers connected to those egress ports.
申请公布号 US9565138(B2) 申请公布日期 2017.02.07
申请号 US201414320138 申请日期 2014.06.30
申请人 Brocade Communications Systems, Inc. 发明人 Chen Xiaochu;Hsu Ivy Pei-Shan;Chinthalapati Eswara;Chhabria Sanjeev
分类号 H04L12/28;H04L12/935;H04L12/931;H04L12/803 主分类号 H04L12/28
代理机构 Kilpatrick Townsend & Stockton LLP 代理人 Kilpatrick Townsend & Stockton LLP
主权项 1. A network device comprising: a plurality of egress ports; one or more processors; and a memory coupled with and readable by the one or more processors, the memory including instructions that, when executed by the one or more processors, cause at least one processor from the one or more processors to perform operations including: generating an identifier for a first data packet using a hash function and one or more attributes of the data packet; determining a first class for the first data packet based on a specified first set of attributes of the first data packet; determining a second class for a second data packet based on a specified second set of attributes of the second data packet; determining a first set of ports from the plurality of egress ports, wherein the first set of ports is determined using the identifier and a first table from a plurality of tables, wherein the first table is associated with a first VLAN from a plurality of VLANS, wherein the first VLAN is associated with the first class but not the second class; determining a second set of ports from the plurality of egress ports, wherein the second set of ports is determined using a second table from the plurality of tables, wherein the second table is associated with a second VLAN from the plurality of VLANS, wherein the second VLAN is associated with the second class but not the first class; sending a copy of the first data packet through each egress port from the first set of ports; and sending a copy of the second data packet through each egress port from the second set of ports.
地址 San Jose CA US