白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Bypassing a firewall for authorized flows using software defined networking

專利號
US10079805B2
公開日期
2018-09-18
申請人
FUJITSU LIMITED(JP Kawasaki)
發(fā)明人
David D. Jameson; Russell DeMolay
IPC分類
G06F9/00; H04L29/06
技術(shù)領(lǐng)域
sdn,firewall,router,may,data,flow,criteria,packet,network,pe
地域: Kawasaki-Shi, Kanagawa

摘要

Methods and systems for managing authorized data flows using software defined networking include receiving flow criteria sent from a firewall and extracted from a first data packet, determining whether flow criteria of the first data packet matches an entry in a master data flow list, inserting the flow criteria from the first data packet into the master data flow list on a software defined networking controller, and sending the flow criteria of the first data packet to the router. The router may forward a second data packet associated with the data flow toward a destination based on the validation of the first data packet by the firewall. The flow criteria may not match an entry in a router data flow list on the router and may include at least two of: a source IP address, a destination IP address, a destination port, and a protocol of transmission.

說明書

Software control systems may enable the flexibility to implement solutions that may not have been possible without virtualization. This flexibility, however, may often result in less efficiency in virtualized solutions than non-virtualized or hardware counterparts. As a result, software control systems may not employ the same solutions or approaches as non-virtualized or hardware. Rather, software control systems may be optimized for certain functions, such as computing or storing information.

As demand for data increases, particularly with the rise in demand of video, video-conferencing, and cloud computing, the size of data flows and associated network bandwidth may also increase. Such large data flows, also known as elephant flows may overwhelm a network with data path processing. Physical network ports and additional compute power may need to be purchased at a high cost to support a data path with numerous elephant flows.

As will be described in further detail, methods and systems are disclosed for using an SDN controller to bypass a firewall for authorized flows and to authorize flows. In this manner, fewer physical network ports and less compute power may be required to support elephant flows.

權(quán)利要求

1
微信群二維碼
意見反饋