白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Bypassing a firewall for authorized flows using software defined networking

專利號
US10079805B2
公開日期
2018-09-18
申請人
FUJITSU LIMITED(JP Kawasaki)
發(fā)明人
David D. Jameson; Russell DeMolay
IPC分類
G06F9/00; H04L29/06
技術領域
sdn,firewall,router,may,data,flow,criteria,packet,network,pe
地域: Kawasaki-Shi, Kanagawa

摘要

Methods and systems for managing authorized data flows using software defined networking include receiving flow criteria sent from a firewall and extracted from a first data packet, determining whether flow criteria of the first data packet matches an entry in a master data flow list, inserting the flow criteria from the first data packet into the master data flow list on a software defined networking controller, and sending the flow criteria of the first data packet to the router. The router may forward a second data packet associated with the data flow toward a destination based on the validation of the first data packet by the firewall. The flow criteria may not match an entry in a router data flow list on the router and may include at least two of: a source IP address, a destination IP address, a destination port, and a protocol of transmission.

說明書

PE router 208 may also receive the data packet and may determine whether the data packet is unknown or new. This determination may include matching flow criteria from the data packet to entry in the PE router data flow list. PE router 208 may also send the data packet to an appropriate firewall using a default flow entry list. For instance, firewall 212 may receive the data packet from PE router 208 using link 216. Links 218, 220, and 308 may be implemented using any suitable communication protocol for flow criteria, including but not limited to RESTful protocols, NETCONF, OpenFlow, SNMP, CLI, and TL1. Links 302, 306, 304, and 216 may be implemented using any suitable communication protocol for data packets, including but not limited to an IP link.

SDN controller 206 may be connected to firewall 212, PE router 208, and CE router 210. SDN controller 206 may send the flow criteria associated with a data flow, validated or authorized by firewall 212, to PE router 208 or CE router 210. The CE router may insert the received flow criteria in a router data flow list to forward future data packets from a client directly to a destination within the same domain. For example, client 102-1 may send a future data packets associated with a data flow to client 102-2 via CE router 210 while bypassing PE router 206 and/or firewall 212. Accordingly, SDN controller 206 may manage authorized data flows, which may reduce the bandwidth requirements of network 300 and/or reduce the number of network ports on CE router 210, PE router 208, and/or firewall 212.

權利要求

1
微信群二維碼
意見反饋