白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Bypassing a firewall for authorized flows using software defined networking

專利號
US10079805B2
公開日期
2018-09-18
申請人
FUJITSU LIMITED(JP Kawasaki)
發(fā)明人
David D. Jameson; Russell DeMolay
IPC分類
G06F9/00; H04L29/06
技術(shù)領(lǐng)域
sdn,firewall,router,may,data,flow,criteria,packet,network,pe
地域: Kawasaki-Shi, Kanagawa

摘要

Methods and systems for managing authorized data flows using software defined networking include receiving flow criteria sent from a firewall and extracted from a first data packet, determining whether flow criteria of the first data packet matches an entry in a master data flow list, inserting the flow criteria from the first data packet into the master data flow list on a software defined networking controller, and sending the flow criteria of the first data packet to the router. The router may forward a second data packet associated with the data flow toward a destination based on the validation of the first data packet by the firewall. The flow criteria may not match an entry in a router data flow list on the router and may include at least two of: a source IP address, a destination IP address, a destination port, and a protocol of transmission.

說明書

SDN controller 206 may determine whether the flow criteria matches an entry in a master data flow list of data flows. SDN controller may determine whether the flow criteria matching an entry needs to be updated. In one embodiment, the update may be based on the determination that the data flow has been encountered recently, which may use a timeout value to determine whether the data flow has been encountered before the expiration of the timeout. In another embodiment, the update may be based on the determination that the bandwidth of the data flow exceeds a threshold, which may be based on the capability of network 200, which may be defined using any suitable criteria, including but not limited to the proximity of PE router 208 to firewall 212 and client 102-2. In this case, SDN controller 206 may open or establish an additional connection between client 102-1 and client 102-2. The additional connection may bypass or skip at least one network element, such as PE router 208. The connection may be a wavelength-division multiplexing (WDM) connection, which may use fiber-optic communication and may support additional bandwidth requirements.

SDN controller 206 may include logic to determine whether the flow criteria was sent to PE router 208 within a delay or wait period. This delay period may account for the latency associated with the link 220 between SDN controller 206 and PE router 208. The delay period may enable SDN controller 206 to avoid saturation of link 220 before an authorized data flow may be managed with the assistance of PE router 208. The delay period may be less than the timeout associated with the data flow, which may ensure that the entry is not invalidated, deleted, and/or removed before the flow criteria is received and processed by PE router 208.

權(quán)利要求

1
微信群二維碼
意見反饋