发明名称 Method and system for network security
摘要 In accordance with one embodiment of the present invention, a method includes receiving a packet at a physical interface of a network security gateway. The packet is tagged with a first VLAN identifier associated with an external network. The method also includes communicating a copy of the packet to a first processor, analyzing the copy of the packet at the first processor to determine whether the packet violates a security condition, and communicating a reply message from the first processor to the interface. The reply message indicates whether the packet violates a security condition. If the packet does not violate a security condition, the method includes re-tagging the packet with a second VLAN identifier associated with a protected network by using a second processor at the physical interface. The method further includes communicating the re-tagged packet to the protected network if the packet does not violate a security condition.
申请公布号 US7562389(B1) 申请公布日期 2009.07.14
申请号 US20040903391 申请日期 2004.07.30
申请人 CISCO TECHNOLOGY, INC. 发明人 GOYAL RAJAN;MIHAILOVICI VIRGIL N.;GUPTA RAHUL;MONCLUS PERE;HABIB AHSAN;PRABHU KIRTIKUMAR L.;PAGGEN CHRISTOPHE J.;KALUVE SHYAMASUNDAR S.
分类号 G06F11/00;H04L9/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址