发明名称 PROVIDING FIREWALL RULES FOR WORKLOAD SPREAD ACROSS MULTIPLE DATA CENTERS
摘要 A method of replicating firewall rules for a tenant that has several data compute nodes across a group of data centers. The method receives a first set of firewall rules that references first and second sets of objects in a first data center. The first set of objects includes identifiers that are recognized by the network manager of the first data center. The second set of objects includes identifiers that are not recognized by the first network manager. The first set of objects is translated into a set of global objects by searching a local inventory of objects. The second set of objects is translated into a set of global objects by searching a global inventory of objects. The first set of firewall rules is translated into a second set of firewall rules by using the translated objects and is replicated to the network managers of every data center.
申请公布号 US2017005867(A1) 申请公布日期 2017.01.05
申请号 US201514811402 申请日期 2015.07.28
申请人 Nicira, Inc. 发明人 Masurekar Uday;Bansal Kaushal
分类号 H04L12/24;H04L29/06 主分类号 H04L12/24
代理机构 代理人
主权项 1. A method of replicating firewall rules for a tenant having a plurality of data compute nodes (DCNs) across a plurality of data centers, each data center comprising a set of hosts and a network manager, each host configured to host one or more DCNs, the method comprising: receiving a first set of firewall rules referencing first and second sets of objects, each of the first set of objects comprising an identifier identifiable by a first network manager in a first data center, each of the second set of objects comprising an identifier not identifiable by the first network manager; translating the first set of objects by searching a first inventory of objects, the first inventory of objects mapping the identifiers of the first set of objects into a first set of identifiers that are identifiable by the network managers of the plurality of data centers; translating the second set of objects by searching a second inventory of objects, the second inventory of objects mapping the identifiers of the second set of objects into a second set of identifiers identifiable by the network managers of the plurality of data centers; translating the first set of firewall rules into a second set of firewall rules using the first and second sets of identifiers; and replicating the second set of firewall rules to the network managers across the plurality of data centers.
地址 Palo Alto CA US