白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Recovery from failure in a dynamic scalable services mesh

專利號
US10868845B2
公開日期
2020-12-15
申請人
Netskope, Inc.(US CA Santa Clara)
發(fā)明人
Ravi Ithal; Umesh Bangalore Muniyappa
IPC分類
H04L29/06; H04L29/08; H04L29/12; H04L12/26
技術(shù)領(lǐng)域
service,pod,netskope,services,packet,security,in,cloud,pods,casb
地域: CA CA Santa Clara

摘要

The technology discloses a method of improved recovery from failure of a service instance in a service chain. Instances AA, BA and BB perform services A and B respectively. Instance BA receives from instance AA a first packet that includes an added header with a stream affinity code consistent for packets in the stream. Instance BA with a primary role specified in a distributed service map processes the packet. BA identifies BB as having a secondary role for packets carrying the code and synchronizes BA state information with BB after processing the packet. After failure of instance BA, instance AA receives an updated service map prepares to forward a second packet, with the same code as the first packet, to BA. After determining from the updated map that BA is no longer available and instance BB has the secondary role, AA forwards the second packet to BB, instead of BA.

說明書

Next we describe an example for processing a stream of packets. Construct the 6-tuple using the data from an exemplary packet described earlier. Access the service map for the packet, in the local flow table. If the service action is allowed, transmit the packet and update the stats. If the action is blocked, drop the packet and update the stats in the flow table. If the action is allowed, assert action==inspect and AppID==inspecting and store the states in the flow table.

In a service map example described next, an app firewall security service instance uses the service map when making the decision of where to send a received packet next after processing by the first service, accessing a flow table using outer IP header data carried by the packet to select a second service node, from among a plurality of service nodes performing the second service in the service chain. The next step is routing the packet to the selected second service node upon egress from the first service node. In this example, the service map shows ipsec service is available on pod 8 and pod 9, appfwl is available on pod 1, pod 2 and pod 3, and IPS service is available on pod 4, pod 5 and pod 6. The example shows the IP addresses for each of pods 1, 2 and 3. Additional pod IP addresses are omitted for brevity.

    • Pods: {
      • ipsec: [p8, p9],
      • appfwl [p1, p2, p3],
      • ips: [p4, p5, p6]
    • }
    • Ipaddrs: {
      • p1: 1.1.1.1,

權(quán)利要求

1
微信群二維碼
意見反饋