白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Bypassing a firewall for authorized flows using software defined networking

專利號(hào)
US10079805B2
公開(kāi)日期
2018-09-18
申請(qǐng)人
FUJITSU LIMITED(JP Kawasaki)
發(fā)明人
David D. Jameson; Russell DeMolay
IPC分類
G06F9/00; H04L29/06
技術(shù)領(lǐng)域
sdn,firewall,router,may,data,flow,criteria,packet,network,pe
地域: Kawasaki-Shi, Kanagawa

摘要

Methods and systems for managing authorized data flows using software defined networking include receiving flow criteria sent from a firewall and extracted from a first data packet, determining whether flow criteria of the first data packet matches an entry in a master data flow list, inserting the flow criteria from the first data packet into the master data flow list on a software defined networking controller, and sending the flow criteria of the first data packet to the router. The router may forward a second data packet associated with the data flow toward a destination based on the validation of the first data packet by the firewall. The flow criteria may not match an entry in a router data flow list on the router and may include at least two of: a source IP address, a destination IP address, a destination port, and a protocol of transmission.

說(shuō)明書(shū)

At 702, a first packet of a data flow may be received. The first packet may be received by a router, such as a PE router or a CE router. At 704, it may be determined whether the data flow is unknown or new. The router may make this determination, which may include determining whether flow criteria extracted from the data flow matches an entry in a router data flow list. The extraction may be performed by a match logic unit within the router. The router data flow list may be implemented using a data memory or a data cache, such as a content-addressable memory (CAM) or a TCAM.

At 706, the first data packet may be routed to a firewall. The routing may be determined by a default flow entry list, which may facilitate the routing of data packets to two or more firewalls communicatively coupled to the router. The connection between the router and the firewall may be of any suitable type for data packets, including but not limited to an IP link. At 708, the first data packet may be validated or authorized. The validation or authorization may be performed by the firewall, which may include logic tailored for identification and validation of a data flow to protect a network. The firewall may be a stateless firewall or a stateful firewall. A stateless firewall may validate each traffic or data packet separately and may only validate each traffic based on the header of the traffic. A stateful firewall may validate a data flow rather than each traffic separately, and may perform the validation based on both the header of the traffic and the contents of the traffic.

權(quán)利要求

1
微信群二維碼
意見(jiàn)反饋