白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Bypassing a firewall for authorized flows using software defined networking

專(zhuān)利號(hào)
US10079805B2
公開(kāi)日期
2018-09-18
申請(qǐng)人
FUJITSU LIMITED(JP Kawasaki)
發(fā)明人
David D. Jameson; Russell DeMolay
IPC分類(lèi)
G06F9/00; H04L29/06
技術(shù)領(lǐng)域
sdn,firewall,router,may,data,flow,criteria,packet,network,pe
地域: Kawasaki-Shi, Kanagawa

摘要

Methods and systems for managing authorized data flows using software defined networking include receiving flow criteria sent from a firewall and extracted from a first data packet, determining whether flow criteria of the first data packet matches an entry in a master data flow list, inserting the flow criteria from the first data packet into the master data flow list on a software defined networking controller, and sending the flow criteria of the first data packet to the router. The router may forward a second data packet associated with the data flow toward a destination based on the validation of the first data packet by the firewall. The flow criteria may not match an entry in a router data flow list on the router and may include at least two of: a source IP address, a destination IP address, a destination port, and a protocol of transmission.

說(shuō)明書(shū)

At 730, the flow criteria may be sent to a router from the SDN controller. The flow criteria received from a router may be used to update the router flow table. At 732, it may be determined whether the bandwidth of the flow criteria is greater than or equal to a threshold. The threshold may be determined based on the capacity of the network. At 734, an additional connection may be established. The additional connection, which may be a WDM connection, may enable an authorized data flow to bypass at least one additional network element. At 736, another data packet associated with the same data flow may be received and may be forwarded toward a destination. The forwarding may include bypassing at least one network element, including but not limited to a router and/or a firewall. At 738, the flow criteria may be removed, invalidated, or deleted after the timeout associated with the flow criteria entry expires. The expiration may influence the storage of the flow criteria in the firewall, router, and/or SDN controller.

The above disclosed subject matter is to be considered illustrative, and not restrictive, and the appended claims are intended to cover all such modifications, enhancements, and other embodiments which fall within the true spirit and scope of the present disclosure. Thus, to the maximum extent allowed by law, the scope of the present disclosure is to be determined by the broadest permissible interpretation of the following claims and their equivalents, and shall not be restricted or limited by the foregoing detailed description.

權(quán)利要求

1
微信群二維碼
意見(jiàn)反饋