-
公开(公告)号:US20160352576A1
公开(公告)日:2016-12-01
申请号:US14809971
申请日:2015-07-27
Applicant: Cisco Technology, Inc.
Inventor: Joji Thomas Mekkattuparamban , Vijay Chander , Saurabh Jain , Van Lieu , Badhri Madabusi Vijayaraghavan , Praveen Jain , Munish Mehta , Michael R. Smith , Narender Enduri
IPC: H04L12/24
CPC classification number: H04L41/0893 , H04L41/0886 , H04L61/15 , H04L61/6022 , H04L63/101 , H04L63/104
Abstract: Systems, methods, and computer-readable storage media are provided for dynamically setting an end point group for an end point. An endpoint can be assigned a default end point group when added to a network. For example, the default end point group can be a baseline port/security group which is considered an untrusted group. The end point can then be dynamically assigned an end point group based on a set of group selection rules. For example, the group selection rules can identify an end point group based on the MAC address or other attributes. When the end point is added to the network, the MAC address and/or other attributes of the end point can be determined and used to assign an end point group. As another example, an end point group can be assigned based on the amount of traffic or guest operation system.
Abstract translation: 提供了系统,方法和计算机可读存储介质,用于动态设置端点的端点组。 当添加到网络时,端点可以被分配一个默认端点组。 例如,默认端点组可以是被认为是不可信组的基准端口/安全组。 然后可以基于一组组选择规则动态地为端点组分配端点组。 例如,组选择规则可以基于MAC地址或其他属性来识别端点组。 当终点被添加到网络中时,可以确定端点的MAC地址和/或其他属性,并用于分配端点组。 作为另一示例,可以基于流量或客户操作系统的数量来分配端点组。
-
公开(公告)号:US20160330125A1
公开(公告)日:2016-11-10
申请号:US14793301
申请日:2015-07-07
Applicant: Cisco Technology, Inc.
Inventor: Joji Thomas Mekkattuparamban , Vijay Chander
IPC: H04L12/813 , H04L12/18 , H04L12/721
CPC classification number: H04L47/20 , H04L12/185 , H04L12/4633 , H04L41/00 , H04L45/32 , H04L45/58 , H04L49/70
Abstract: Systems, methods, and computer-readable media are provided for enforcing policy for upstream (e.g., traffic from an endpoint to the physical network layer or hardware fabric of a data center) flood traffic (e.g., broadcast, unknown unicast, or multicast traffic) originating from a virtual endpoint via a network fabric. In one embodiment, upstream flood traffic can be transmitted using a special multicast group to which only elements of the data center fabric (e.g., physical switches, routers) are subscribed. That is, upstream flood traffic is assigned to the special multicast group, resulting in unintended endpoints not receiving the flood traffic. However, the hardware fabric receives the flood traffic and will then enforce applicable policies to route the packets to intended endpoints.
Abstract translation: 提供了系统,方法和计算机可读介质,用于执行用于上游的策略(例如,从端点到数据中心的物理网络层或硬件结构的流量)洪泛流量(例如,广播,未知单播或多播流量) 通过网络结构从虚拟端点发起。 在一个实施例中,可以使用只有数据中心结构的元素(例如,物理交换机,路由器)被订阅的特殊多播组来发送上游洪泛业务。 也就是说,上游洪泛流量被分配给特殊的多播组,导致无意的端点没有接收洪泛流量。 然而,硬件结构接收到洪泛流量,然后将强制适用的策略将数据包路由到预期的端点。
-
公开(公告)号:US20250112849A1
公开(公告)日:2025-04-03
申请号:US18625150
申请日:2024-04-02
Applicant: Cisco Technology, Inc.
Inventor: Vijay Chander , Raghu Ram Duddumpudi , Ganesh Narayanaswamy , Sunil Kumar , Michael Chan , Praveen Kumar Patnala
Abstract: The present technology provides intercloud connectivity as a service by discovering components of the organization's deployment in various sites, irrespective of the cloud provider, such that two sites can merely be selected along with a few standard options, and the controller can handle the complexity of instantiating a tunnel between the cloud sites automatically. Further, the controller can monitor the health of one or more tunnels between the cloud sites to automatically scale bandwidth up or down.
-
公开(公告)号:US10931629B2
公开(公告)日:2021-02-23
申请号:US16236757
申请日:2018-12-31
Applicant: Cisco Technology, Inc.
Inventor: Vijay Chander , Yibin Yang , Praveen Jain , Munish Mehta
IPC: H04L29/12 , H04L12/46 , H04L12/751
Abstract: According to one or more embodiments of this disclosure, a network controller in a data center network establishes a translation table for in-band traffic in a data center network, the translation table resolves ambiguous network addresses based on one or more of a virtual network identifier (VNID), a routable tenant address, or a unique loopback address. The network controller device receives packets originating from applications and/or an endpoints operating in a network segment associated with a VNID. The network controller device translates, using the translation table, unique loopback addresses and/or routable tenant addresses associated with the packets into routable tenant addresses and/or unique loopback addresses, respectively.
-
15.
公开(公告)号:US20190141010A1
公开(公告)日:2019-05-09
申请号:US16236757
申请日:2018-12-31
Applicant: Cisco Technology, Inc.
Inventor: Vijay Chander , Yibin Yang , Praveen Jain , Munish Mehta
IPC: H04L29/12 , H04L12/751 , H04L12/46
Abstract: According to one or more embodiments of this disclosure, a network controller in a data center network establishes a translation table for in-band traffic in a data center network, the translation table resolves ambiguous network addresses based on one or more of a virtual network identifier (VNID), a routable tenant address, or a unique loopback address. The network controller device receives packets originating from applications and/or an endpoints operating in a network segment associated with a VNID. The network controller device translates, using the translation table, unique loopback addresses and/or routable tenant addresses associated with the packets into routable tenant addresses and/or unique loopback addresses, respectively.
-
公开(公告)号:US20180063003A1
公开(公告)日:2018-03-01
申请号:US15792650
申请日:2017-10-24
Applicant: Cisco Technology, Inc.
Inventor: Joji Thomas Mekkattuparamban , Vijay Chander
IPC: H04L12/813 , H04L12/18 , H04L12/46 , H04L12/721 , H04L12/775 , H04L12/24 , H04L12/931
CPC classification number: H04L47/20 , H04L12/185 , H04L12/4633 , H04L41/00 , H04L45/32 , H04L45/58 , H04L49/70
Abstract: Systems, methods, and computer-readable media are provided for enforcing policy for upstream (e.g., traffic from an endpoint to the physical network layer or hardware fabric of a data center) flood traffic (e.g., broadcast, unknown unicast, or multicast traffic) originating from a virtual endpoint via a network fabric. In one embodiment, upstream flood traffic can be transmitted using a special multicast group to which only elements of the data center fabric (e.g., physical switches, routers) are subscribed. That is, upstream flood traffic is assigned to the special multicast group, resulting in unintended endpoints not receiving the flood traffic. However, the hardware fabric receives the flood traffic and will then enforce applicable policies to route the packets to intended endpoints.
-
17.
公开(公告)号:US20170346736A1
公开(公告)日:2017-11-30
申请号:US15208018
申请日:2016-07-12
Applicant: Cisco Technology, Inc.
Inventor: Vijay Chander , Yibin Yang , Praveen Jain , Munish Mehta
IPC: H04L12/741 , H04L12/46
CPC classification number: H04L45/745 , H04L12/4633 , H04L12/4641 , H04L45/74
Abstract: According to one or more embodiments of this disclosure, a network controller in a data center network establishes a translation table for in-band traffic in a data center network, the translation table resolves ambiguous network addresses based on one or more of a virtual network identifier (VNID), a routable tenant address, or a unique loopback address. The network controller device receives packets originating from applications and/or an endpoints operating in a network segment associated with a VNID. The network controller device translates, using the translation table, unique loopback addresses and/or routable tenant addresses associated with the packets into routable tenant addresses and/or unique loopback addresses, respectively.
-
公开(公告)号:US09674107B2
公开(公告)日:2017-06-06
申请号:US14206579
申请日:2014-03-12
Applicant: Cisco Technology, Inc.
Inventor: Marco Di Benedetto , Dante Malagrino , Alessandro Salvatori , Arthur Lihder Chang , Vijay Chander , Thomas Vincent Flynn
IPC: G06F15/173 , H04L12/26 , H04L12/911 , H04L12/64 , H04L12/713
CPC classification number: H04L47/70 , H04L12/6418 , H04L45/586
Abstract: A distributed virtual appliance is disclosed, including: determining a classification type associated with the first flow; and determining an allocation of the first flow to the first data plane compute unit of the distributed virtual appliance based at least in part on the determined classification type and at least a subset of information of a first flow identifier, wherein the distributed virtual appliance includes a plurality of compute units, including the first data plane compute.
-
-
-
-
-
-
-