发明名称 System and methods for network segmentation
摘要 A routing mechanism provides network segmentation preservation by route distribution with segment identification, policy distribution for a given VPN segment, and encapsulation/decapsulation for each segment using an Ethernet VLAN_ID, indicative of the VPN segment (subnetwork). Encapsulated segmentation information in a message packet identifies which routing and forwarding table is employed for the next hop. A common routing instance receives the message packets from the common interface, and indexes a corresponding VRF table from the VLAN ID, or segment identifier, indicative of the subnetwork (e.g. segment). In this manner, the routing instance receives the incoming message packet, decapsulates the VLAN ID in the incoming message packet, and indexes the corresponding VRF and policy ID from the VLAN ID, therefore employing a common routing instance over a common subinterface for a plurality of segments (subnetworks) coupled to a particular forwarding device (e.g. VPN router).
申请公布号 US2007058638(A1) 申请公布日期 2007.03.15
申请号 US20050226011 申请日期 2005.09.14
申请人 GUICHARD JAMES N;WAINNER W S;ADLER SAUL;JABR KHALIL A;VAN DE HOUTEN S S 发明人 GUICHARD JAMES N.;WAINNER W. S.;ADLER SAUL;JABR KHALIL A.;VAN DE HOUTEN S. S.
分类号 H04L12/28 主分类号 H04L12/28
代理机构 代理人
主权项
地址