发明名称 IMPLEMENTATION OF REFLEXIVE ACCESS CONTROL LISTS ON DISTRIBUTED PLATFORMS
摘要 Systems and methods are provided to facilitate the filtering of data packets without substantially interrupting traffic flow in distributed systems. In one implementation, a network device includes a first line card associated with a first interface and adapted to maintain a first access control list. The network device further includes a second line card associated with a second interface and adapted to maintain a second access control list. A service card of the network device is adapted to maintain a reflexive access control list, wherein the reflexive access control list is referenced by an entry of the first access control list and by an entry of the second access control list. Outbound and inbound data packets matching the entries of the first or second access control lists may be forwarded to the service card for processing while unmatching data packets may be passed between networks or dropped as appropriate.
申请公布号 WO2007136937(A2) 申请公布日期 2007.11.29
申请号 WO2007US66186 申请日期 2007.04.06
申请人 CISCO TECHNOLOGY, INC.;BAMNOLKER, YEHUDA 发明人 BAMNOLKER, YEHUDA
分类号 G06F15/173 主分类号 G06F15/173
代理机构 代理人
主权项
地址