发明名称 |
SUPPORTING ACCESS CONTROL LIST RULES THAT APPLY TO TCP SEGMENTS BELONGING TO 'ESTABLISHED' CONNECTION |
摘要 |
Embodiments presented herein provide a TCAM-based access control list that supports disjunction operations in rules. According to one embodiment, a numeric range table is tied to the access control list. Each entry in the numeric range table includes an encode field that provides for scanning TCP flags in a TCP header of an incoming Ethernet frame. Further, each entry provides a first mask and a second mask used to test for desired set and unset TCP flags in a given frame. Each entry also provides an operation field that performs a disjunction operation that compares the first mask, the second mask, and set TCP flags in a given frame. |
申请公布号 |
US2015341269(A1) |
申请公布日期 |
2015.11.26 |
申请号 |
US201414284811 |
申请日期 |
2014.05.22 |
申请人 |
International Business Machines Corporation |
发明人 |
Basso Claude;Kirscht Joseph A.;Vaidhyanathan Natarajan |
分类号 |
H04L12/743;H04L12/801;H04L12/26 |
主分类号 |
H04L12/743 |
代理机构 |
|
代理人 |
|
主权项 |
|
地址 |
Armonk NY US |