白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Bypassing a firewall for authorized flows using software defined networking

專利號(hào)
US10079805B2
公開日期
2018-09-18
申請(qǐng)人
FUJITSU LIMITED(JP Kawasaki)
發(fā)明人
David D. Jameson; Russell DeMolay
IPC分類
G06F9/00; H04L29/06
技術(shù)領(lǐng)域
sdn,firewall,router,may,data,flow,criteria,packet,network,pe
地域: Kawasaki-Shi, Kanagawa

摘要

Methods and systems for managing authorized data flows using software defined networking include receiving flow criteria sent from a firewall and extracted from a first data packet, determining whether flow criteria of the first data packet matches an entry in a master data flow list, inserting the flow criteria from the first data packet into the master data flow list on a software defined networking controller, and sending the flow criteria of the first data packet to the router. The router may forward a second data packet associated with the data flow toward a destination based on the validation of the first data packet by the firewall. The flow criteria may not match an entry in a router data flow list on the router and may include at least two of: a source IP address, a destination IP address, a destination port, and a protocol of transmission.

說明書

As described above, SDN controller 206 may communicate with PE router 208 using link 220 to direct PE router 208 to insert the flow criteria into the router data flow list. The insertion may include a timeout and/or a timestamp. The router data flow list may be used for future data packets associated with the same data flow as the original data packet to forward the future data packets toward a destination. For example PE router 208 may use the router data flow list to forward a future data packet to customer-edge (CE) router 210 using link 222, rather than routing the data packet to firewall 212. Bypassing firewall 212, in this instance, may reduce the network bandwidth required and/or reduce the number of physical ports required on firewall 212 and/or PE router 208. Firewall 212, for instance, may be located in a location separate from one or more domains in the network, which may increase the latency of authenticating a data packet. Bypassing firewall 212 may reduce the latency and may decrease the bandwidth requirements of the network. A data packet routed to CE router 210 may then be routed toward client 102-2, which may be the destination of a communication with client 102-1.

Although, SDN controller 206 is shown as communicating with PE router 208, SDN controller may communicate with any number of routers within network 100 using any number of links 112. Moreover, although two domains are shown, any number of domains may be used.

權(quán)利要求

1
微信群二維碼
意見反饋