白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Firewall control device, method and firewall device

專利號
US10097515B2
公開日期
2018-10-09
申請人
FUJITSU LIMITED(JP Kawasaki)
發(fā)明人
Dai Suzuki
IPC分類
H04L29/06; G06F9/455
技術(shù)領(lǐng)域
fw,fwc,fws,entry,in,discarded,discarding,packets,address,packet
地域: Kawasaki-shi, Kanagawa

摘要

A firewall control device controls a plurality of firewall devices provided between a core network and a plurality of sub-networks respectively, the firewall control device is configured to receive, from the plurality of firewall devices, data amount information indicating an amount of the data discarded in the plurality of firewall devices respectively and node information indicating a transmission source node of the discarded data, identify, based on the data amount information and the node information, a data flow including the discarded data which is transmitted from an information processing device indicated by the node information and of which total amount of the discarded data exceeds a threshold value, and set, in a first firewall device which is included in the plurality of firewall devices and which is coupled to the information processing device, a first discarding flow entry defining discarding of data of the identified data flow.

說明書

Next, there will be described an example of a method in which, based on a flow entry set for one of the FWs 5 (conveniently expressed as a “reception FW 5”), which receives a flow, an administrator performs a setting on one of the FWs 5 (conveniently expressed as a “transmission source FW 5”), which corresponds to a transmitting side of the relevant flow.

It is assumed that, as illustrated in, for example, in FIG. 6, a new entry for permitting the transfer of a flow having the TCP port number=“80” is set for the FW #4 in accordance with the procedure exemplified in FIG. 4 or FIG. 5. In addition, it is assumed that a transmission source address and a destination address are unspecified in the relevant new entry. Note that the “transmission source address” is an example of transmission source information indicating a transmission source of a packet.

In this case, since the transmission source address is unspecified, there is a possibility that packets of flows corresponding to the new entry are addressed, to the FW #4, and transmitted from all the sub-networks 3. Therefore, in response to the setting of the new entry for the reception FW #4, the FWC 7 may set and register, based on the new entry set in the reception FW #4, new entries for the other FWs (transmission source FWs) #1 to #3 each having the possibility of transmitting packets to the reception FW #4.

權(quán)利要求

1
微信群二維碼
意見反饋