发明名称 System and Method for Managing Access Control Lists
摘要 Systems and methods consistent with the present invention provide better scheme for updating access control list (ACL) rule entries in a ternary content addressable memory (TCAM). In a firewall, ACL rules are scanned for each packet arriving in a router or switch to determine if a match exists between the packet and any of the patterns. Depending on the pattern matched, the corresponding action may be either to accept or to deny the packet. These rules are stored in a TCAM, and new or updated rules may be added to the TCAM. Systems and methods consistent with the present invention determine whether the new or updated rule has a dependency conflict with existing rules in the TCAM. If not, the rule can be inserted anywhere in the TCAM. Accordingly, the TCAM associated with a firewall's ACL can be updated more quickly and efficiently.
申请公布号 US2009125470(A1) 申请公布日期 2009.05.14
申请号 US20070938060 申请日期 2007.11.09
申请人 JUNIPER NETWORKS, INC. 发明人 SHAH SANDIP;BAJAJ SANDEEP
分类号 G06F17/00;G06F21/00;G06N5/00 主分类号 G06F17/00
代理机构 代理人
主权项
地址