发明名称 Firewall security between virtual devices
摘要 When communication from a first virtual device to a second virtual device is received, it is determined a first virtual interface associated with the first virtual device and a second virtual interface associated with the second virtual device. It is then determined a first security domain associated with the first virtual interface and a second security domain associated with the second virtual interface to implement a security policy between the first security domain and second security domain. The communication between the virtual devices is allowed or blocked.
申请公布号 US9426117(B2) 申请公布日期 2016.08.23
申请号 US201314391166 申请日期 2013.03.28
申请人 HANGZHOU H3C TECHNOLOGIES CO., LTD. 发明人 Wang Qiyong
分类号 G06F9/00;H04L29/06;G06F9/455 主分类号 G06F9/00
代理机构 Hewlett Packard Enterprise Patent Development 代理人 Hewlett Packard Enterprise Patent Development
主权项 1. A method for firewall security between virtual devices-on-a, the method comprising: receiving by a physical interface of a firewall device, a communication from a first virtual device to a second virtual device, wherein the first virtual device is hosted on a physical device which is separate from the firewall device and the second virtual device is hosted on a physical device which is separate from the firewall device; determining, by the firewall device, a first virtual interface associated with the first virtual device based on an address of the first virtual device and an address set of the first virtual interface; determining, by the firewall device, second virtual interface associated with the second virtual device based on an address of the second virtual device and an address set of the second virtual interface; determining, by the firewall device, a first security domain associated with the first virtual interface and a second security domain associated with the second virtual interface; and to-implementing, by the firewall device, a security policy between the first security domain and second security domain; wherein implementing the security policy comprises blocking the communication based on the security policy, or allowing the communication based on the security policy, wherein allowing the communication includes forwarding the communication to the second virtual device; wherein if the address of the first virtual device and/or address of the second virtual device are dynamically obtained from a Dynamic Host Configuration Protocol (DHCP) server, the first address set and second address set are configured based on a policy of the DHCP server.
地址 Zhejiang CN