发明名称 SUPPORTING ACCESS CONTROL LIST RULES THAT APPLY TO TCP SEGMENTS BELONGING TO 'ESTABLISHED' CONNECTION
摘要 Embodiments presented herein provide a TCAM-based access control list that supports disjunction operations in rules. According to one embodiment, a numeric range table is tied to the access control list. Each entry in the numeric range table includes an encode field that provides for scanning TCP flags in a TCP header of an incoming Ethernet frame. Further, each entry provides a first mask and a second mask used to test for desired set and unset TCP flags in a given frame. Each entry also provides an operation field that performs a disjunction operation that compares the first mask, the second mask, and set TCP flags in a given frame.
申请公布号 US2015341269(A1) 申请公布日期 2015.11.26
申请号 US201414284811 申请日期 2014.05.22
申请人 International Business Machines Corporation 发明人 Basso Claude;Kirscht Joseph A.;Vaidhyanathan Natarajan
分类号 H04L12/743;H04L12/801;H04L12/26 主分类号 H04L12/743
代理机构 代理人
主权项
地址 Armonk NY US