Invention Grant
- Patent Title: Identity-based policy implementation in network address translation (NAT) environments
-
Application No.: US15447291Application Date: 2017-03-02
-
Publication No.: US10397060B2Publication Date: 2019-08-27
- Inventor: Sanjay Kumar Hooda , Syam Sundar V Appala , Kaushik Kumar Dam , Vimarsh Puneet
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Edell, Shapiro & Finnan, LLC
- Main IPC: G06F15/16
- IPC: G06F15/16 ; H04L12/24 ; H04L29/08 ; H04L29/12

Abstract:
A policy server correlates information from several messages associated with a client device to implement an identity-based network access policy. The policy server receives a first message from a network element connected to the client device. The first message requests an identity-based policy for the client device, and includes a first network address. The policy server receives a second message from an identity server. The second message includes information indicating an identity role and a second network address. The policy server receives a third message from a NAT device. The third message includes a NAT mapping that correlates the first network address with the second network address. After the policy server determines the identity-based policy based on a combination of the first message, the second message, and the third message, the policy server implements the identity-based policy in the network element.
Public/Granted literature
- US20180255017A1 IDENTITY-BASED POLICY IMPLEMENTATION IN NETWORK ADDRESS TRANSLATION (NAT) ENVIRONMENTS Public/Granted day:2018-09-06
Information query