发明名称 Specifying point of enforcement in a firewall rule
摘要 Some embodiments of the invention provide a novel method for specifying firewall rules. In some embodiments, the method provides the ability to specify for a particular firewall rule, a set of network nodes (also called a set of enforcement points below) at which the particular firewall should be enforced. To provide this ability, the method of some embodiments adds an extra tuple (referred to below as the AppliedTo tuple) to a firewall rule. This added AppliedTo tuple lists the set of enforcement points at which the firewall rule has to be applied (i.e., enforced).
申请公布号 US9276904(B2) 申请公布日期 2016.03.01
申请号 US201414231682 申请日期 2014.03.31
申请人 NICIRA, INC. 发明人 Bansal Kaushal;Masurekar Uday;Srinivasan Aravind;Shah Shadab;Maskalik Serge
分类号 H04L12/22;H04L29/06 主分类号 H04L12/22
代理机构 Adeli LLP 代理人 Adeli LLP
主权项 1. A method of specifying firewall rules, the method comprising: specifying a plurality of high-level firewall rules that each includes a high-level construct tuple that identifies a set of high-level constructs in a network where the high-level firewall rule has to be enforced; translating each high-level firewall rule to a set of lower-level firewall rules, each lower-level firewall rule comprising a lower-level enforcement-node tuple that identifies a first set of lower-level enforcement nodes associated with the high-level construct of the high-level firewall rule; and distributing at least two different subsets of the lower-level firewall rules to at least two enforcement devices, each enforcement device comprising a second set of lower-level enforcement nodes for which the distributed subset of lower-level firewall rules are enforced according to a precedence hierarchy that defines a precedence order for the lower-level firewall rules.
地址 Palo Alto CA US