SYSTEMS, METHODS, AND DEVICES FOR SMART MAPPING AND VPN POLICY ENFORCEMENT
    52.
    发明申请
    SYSTEMS, METHODS, AND DEVICES FOR SMART MAPPING AND VPN POLICY ENFORCEMENT 审中-公开
    用于智能映射和VPN策略执行的系统,方法和设备

    公开(公告)号:US20170026417A1

    公开(公告)日:2017-01-26

    申请号:US15217154

    申请日:2016-07-22

    Abstract: Aspects of the embodiments are directed to systems, methods, and computer program products to program, via a northbound interface, a mapping between an endpoint identifier (EID) and a routing locator (RLOC) directly into a mapping database at a mapping system; receive, from a first tunneling router associated with a first virtual network, a mapping request to a second virtual network, the first router compliant with a Locator/ID Separation Protocol, the mapping request comprising an EID tuple that includes a source identifier and a destination identifier; identify an RLOC based, at least in part, on the destination identifier of the EID tuple from the mapping database; and transmit the RLOC to the first tunneling router implementing an high level policy that has been dynamically resolved into a state of the mapping database.

    Abstract translation: 实施例的方面涉及通过北向接口将端点标识符(EID)和路由定位器(RLOC)之间的映射直接编程到映射系统的映射数据库中的系统,方法和计算机程序产品; 从与第一虚拟网络相关联的第一隧道路由器接收对第二虚拟网络的映射请求,所述第一路由器符合定位符/ ID分离协议,所述映射请求包括包含源标识符和目的地的EID元组 标识符 至少部分地基于来自映射数据库的EID元组的目的地标识符来识别RLOC; 并将RLOC发送到实现已经被动态地解析成映射数据库的状态的高级策略的第一隧道路由器。

    Transparent network service header path proxies
    53.
    发明授权
    Transparent network service header path proxies 有权
    透明网络服务头路径代理

    公开(公告)号:US09548919B2

    公开(公告)日:2017-01-17

    申请号:US14522974

    申请日:2014-10-24

    Abstract: A controller that is in communication with the plurality of network nodes establishes a service path for a service chain defined by an ordered sequence of service functions to be performed at respective ones of one or more of the plurality of network nodes. The controller assigns a predetermined service path identifier and a predetermined service index value for a segment of the service chain that includes only one or more network nodes not capable of decapsulating packets to extract a network service header so as to designate the one or more network nodes determined not capable of decapsulating packets to extract the network service header as a single service hop segment in the service chain.

    Abstract translation: 与所述多个网络节点通信的控制器为由所述多个网络节点中的一个或多个网络节点中的一个或多个的相应的一个服务功能定义的服务链建立服务路径。 控制器为仅包括一个或多个不能解包分组的网络节点的服务链的段分配预定的服务路径标识符和预定的服务索引值,以提取网络服务头,以便指定一个或多个网络节点 确定不能解包分组,以将服务链中的单个服务跳段提取为网络服务头。

    DETERMINING THE OPERATIONS PERFORMED ALONG A SERVICE PATH/SERVICE CHAIN
    54.
    发明申请
    DETERMINING THE OPERATIONS PERFORMED ALONG A SERVICE PATH/SERVICE CHAIN 审中-公开
    确定在服务路径/服务链上执行的操作

    公开(公告)号:US20160337209A1

    公开(公告)日:2016-11-17

    申请号:US15223235

    申请日:2016-07-29

    Abstract: Presented herein are techniques performed in a network comprising a plurality of network nodes each configured to apply one or more service functions to traffic that passes the respective network nodes in a service path. At a network node, an indication is received of a failure or degradation of one or more service functions or applications applied to traffic at the network node. Data descriptive of the failure or degradation is generated. A previous service hop network node at which a service function or application was applied to traffic in the service path is determined. The data descriptive of the failure or degradation is communicated to the previous service hop network node.

    Abstract translation: 这里呈现的是在包括多个网络节点的网络中执行的技术,每个网络节点被配置为将一个或多个服务功能应用于通过服务路径中的相应网络节点的业务。 在网络节点处,接收到应用于网络节点处的业务的一个或多个服务功能或应用的故障或劣化的指示。 产生描述故障或退化的数据。 确定应用服务功能或应用程序到服务路径中的业务的先前服务跳网络节点。 将描述故障或劣化的数据传送到先前的服务跳网络节点。

    METADATA AUGMENTATION IN A SERVICE FUNCTION CHAIN
    55.
    发明申请
    METADATA AUGMENTATION IN A SERVICE FUNCTION CHAIN 有权
    服务功能链中的元数据补充

    公开(公告)号:US20160248685A1

    公开(公告)日:2016-08-25

    申请号:US14631595

    申请日:2015-02-25

    CPC classification number: H04L47/2441 H04L45/74 H04L47/18 H04L67/327 H04L69/22

    Abstract: A method for augmenting metadata of a network service header is disclosed. The method includes receiving, at a first service node, a packet or frame of a traffic flow, wherein the packet has a payload and the network service header including a first metadata and a first service path information for the traffic flow, classifying, by the first service node, at least one of the payload and the first metadata to generate a second metadata different from the first metadata, and augmenting, by the first service node, the first metadata using the second metadata before forwarding the packet or frame to a second service node.

    Abstract translation: 公开了一种用于增强网络服务头部的元数据的方法。 该方法包括在第一服务节点处接收业务流的分组或帧,其中所述分组具有有效载荷,并且所述网络服务报头包括所述业务流的第一元数据和第一服务路径信​​息, 第一服务节点,有效载荷和第一元数据中的至少一个,以生成不同于第一元数据的第二元数据,以及在将数据包或帧转发到第二元数据之前由第一服务节点使用第二元数据来扩充第一元数据 服务节点。

    NETWORK SERVICE HEADER METADATA FOR LOAD BALANCING
    57.
    发明申请
    NETWORK SERVICE HEADER METADATA FOR LOAD BALANCING 有权
    用于负载均衡的网络服务头元数据

    公开(公告)号:US20160173373A1

    公开(公告)日:2016-06-16

    申请号:US14664629

    申请日:2015-03-20

    Abstract: A method for load balancing based on metadata in a network service header. The method includes receiving a packet or frame of a traffic flow, wherein the packet or frame has a payload and the network service header including metadata and service path information for the traffic flow identifying the service path, and the metadata comprises classification information of the packet or frame, extracting, by a service header processor of the load balancer, the classification information of the metadata from the packet or frame, and applying, by a load balancing function of the load balancer, a load balancing policy on the packet or frame based on the classification information of the metadata.

    Abstract translation: 一种基于网络服务头部元数据的负载均衡方法。 所述方法包括接收业务流的分组或帧,其中所述分组或帧具有有效载荷,并且所述网络服务报头包括用于标识所述服务路径的业务流的元数据和服务路径信​​息,并且所述元数据包括所述分组的分类信息 或帧,由负载平衡器的服务头处理器从分组或帧中提取元数据的分类信息,并通过负载平衡器的负载平衡功能应用基于分组或帧的负载均衡策略 关于元数据的分类信息。

    Data plane learning of bi-directional service chains
    58.
    发明授权
    Data plane learning of bi-directional service chains 有权
    双向服务链的数据平面学习

    公开(公告)号:US09246799B2

    公开(公告)日:2016-01-26

    申请号:US13891245

    申请日:2013-05-10

    CPC classification number: H04L45/306 H04L41/0893 H04L47/2441 H04L69/22

    Abstract: Techniques are provided to decouple service chain structure from the underlying network forwarding state and allow for data plane learning of service chain forwarding requirements and any association between services function state requirements and the forward and reverse forwarding paths for a service chain. In a network comprising a plurality of network nodes each configured to apply a service function to traffic that passes through the respective network node, a packet is received at a network node. When the network node determines that the service function it applies is stateful, it updates context information in a network service header of the packet to indicate that the service function applied at the network node is stateful and that traffic for a reverse path matching the classification criteria is to be returned to the network node.

    Abstract translation: 提供了技术来将服务链结构与底层网络转发状态分离,并允许服务链转发要求的数据平面学习和服务功能状态要求与服务链的前向和后向转发路径之间的任何关联。 在包括多个网络节点的网络中,每个网络节点被配置为对通过相应网络节点的业务应用服务功能,在网络节点处接收分组。 当网络节点确定其应用的服务功能是有状态时,它更新分组的网络服务报头中的上下文信息,以指示在网络节点处应用的服务功能是有状态的,并且用于与分类标准匹配的反向路径的业务 将被返回到网络节点。

    SYSTEM AND METHOD FOR TRANSPORTING INFORMATION TO SERVICES IN A NETWORK ENVIRONMENT
    59.
    发明申请
    SYSTEM AND METHOD FOR TRANSPORTING INFORMATION TO SERVICES IN A NETWORK ENVIRONMENT 有权
    在网络环境中向服务运输信息的系统和方法

    公开(公告)号:US20150334595A1

    公开(公告)日:2015-11-19

    申请号:US14279724

    申请日:2014-05-16

    CPC classification number: H04L29/06 H04L41/0896 H04L41/5054 H04W28/0268

    Abstract: An example method is provided in one example embodiment and may include receiving a packet for a subscriber at a gateway, wherein the gateway includes a local policy anchor for interfacing with one or more policy servers and one or more classifiers for interfacing with one or more service chains, each service chain including one or more services accessible by the gateway; determining a service chain to receive the subscriber's packet; appending the subscriber's packet with a header, wherein the header includes, at least in part, identification information for the subscriber and an Internet Protocol (IP) address for the local policy anchor; and injecting the packet including the header into the service chain determined for the subscriber.

    Abstract translation: 在一个示例性实施例中提供了示例性方法,并且可以包括在网关处接收订户的分组,其中所述网关包括用于与一个或多个策略服务器进行接口的本地策略锚点以及用于与一个或多个服务 每个服务链包括由网关可访问的一个或多个服务; 确定服务链以接收订户的分组; 用标题附加订户的分组,其中该报头至少部分地包括用户的标识信息和用于本地策略锚的因特网协议(IP)地址; 以及将包括所述头部的分组注入到为所述用户确定的服务链中。

    Architecture for agentless service insertion
    60.
    发明授权
    Architecture for agentless service insertion 有权
    无代理服务插入架构

    公开(公告)号:US09178828B2

    公开(公告)日:2015-11-03

    申请号:US13872008

    申请日:2013-04-26

    CPC classification number: H04L47/2425 G06F9/45533 G06F2009/45562

    Abstract: An example method for service insertion in a network environment is provided in one example and includes configuring a service node by tagging one or more interface ports of a virtual switch function to which the service node is connected with one or more policy identifiers. When data traffic associated with a policy identifier is received on a virtual overlay path the virtual switch function may then terminate the virtual overlay path and direct raw data traffic to the interface port of the service node that is tagged to the policy identifier associated with the data traffic.

    Abstract translation: 在一个示例中提供了在网络环境中的服务插入的示例方法,并且包括通过标记服务节点与其连接的虚拟交换机功能的一个或多个接口端口与一个或多个策略标识符来配置服务节点。 当在虚拟覆盖路径上接收到与策略标识符相关联的数据流量时,虚拟交换机功能可以终止虚拟覆盖路径,并将原始数据流直接引导到标记为与数据相关联的策略标识符的服务节点的接口端口 交通。

Patent Agency Ranking