Implementing PVLANs in a large-scale distributed virtual switch
    1.
    发明授权
    Implementing PVLANs in a large-scale distributed virtual switch 有权
    在大规模分布式虚拟交换机中实现PVLAN

    公开(公告)号:US09331872B2

    公开(公告)日:2016-05-03

    申请号:US13477605

    申请日:2012-05-22

    摘要: In one embodiment, a list of source identifiers is maintained at a virtual switch. These source identifiers are allowed to send packets through the virtual switch to ports in a private virtual local area network (PVLAN). When a packet is received at the virtual switch from a particular source destined for a particular port in the PVLAN, the virtual switch determines whether a particular identifier associated with the particular source matches one of the source identifiers in the list. If that particular source identifier is not on the list, the packet is prevented from being forwarded to the particular port in the PVLAN.

    摘要翻译: 在一个实施例中,在虚拟交换机上维护源标识符的列表。 允许这些源标识符通过虚拟交换机发送到私有虚拟局域网(PVLAN)中的端口。 当虚拟交换机从虚拟交换机接收目的地为PVLAN中的特定端口的分组时,虚拟交换机确定与特定源相关联的特定标识符是否与列表中的一个源标识符匹配。 如果该特定源标识符不在列表中,则阻止该数据包转发到PVLAN中的特定端口。

    Location independent dynamic IP address assignment
    2.
    发明申请
    Location independent dynamic IP address assignment 审中-公开
    位置独立的动态IP地址分配

    公开(公告)号:US20130024553A1

    公开(公告)日:2013-01-24

    申请号:US13135918

    申请日:2011-07-18

    IPC分类号: G06F15/177

    摘要: In one embodiment, a method includes receiving at a network device operating as a relay agent, a Dynamic Host Configuration Protocol (DHCP) request from an end host, inserting a group identifier into the DHCP request and forwarding the DHCP request to a DHCP server, the end host associated with a group identified by the group identifier, receiving a response from the DHCP server, and forwarding the response to the end host. The response includes configuration information for the end host, at least some of the configuration information selected based on the group identifier. An apparatus is also disclosed.

    摘要翻译: 在一个实施例中,一种方法包括在作为中继代理工作的网络设备处接收来自终端主机的动态主机配置协议(DHCP)请求,将组标识符插入到DHCP请求中并将DHCP请求转发给DHCP服务器, 与由组标识符标识的组相关联的终端主机,从DHCP服务器接收响应,并将响应转发到终端主机。 响应包括终端主机的配置信息,基于组标识符选择的至少一些配置信息。 还公开了一种装置。

    ERSPAN dynamic session negotiation
    3.
    发明申请
    ERSPAN dynamic session negotiation 有权
    ERSPAN动态会话协商

    公开(公告)号:US20100054152A1

    公开(公告)日:2010-03-04

    申请号:US12231635

    申请日:2008-09-04

    IPC分类号: H04L12/26

    摘要: A method and network device to generate a remote traffic monitoring session using an automated technique to configure the source and destination devices of the monitoring system is disclosed. The method includes discovering a Layer 3 (L3) source device and an L3 destination device and automatically configuring the devices. The L3 source device passes target traffic that will be monitored via the L3 destination device in a remote traffic monitoring session. The method verifies configurations of the L3 source device and the L3 destination device, and determines remote monitoring capabilities common to the L3 source device and the L3 destination device. The method negotiates relevant parameters for the remote traffic monitoring session and establishes the remote traffic monitoring session between the L3 source device and the L3 destination device.

    摘要翻译: 公开了一种使用自动化技术来生成远程流量监控会话的方法和网络设备来配置监控系统的源和目的设备。 该方法包括发现三层(L3)源设备和L3目的设备,并自动配置设备。 L3源设备通过远程流量监控会话中将通过L3目标设备进行监控的目标流量。 该方法验证L3源设备和L3目的设备的配置,并确定L3源设备和L3目的设备通用的远程监控功能。 该方法协商远程流量监控会话的相关参数,并建立L3源设备与L3目的设备之间的远程流量监控会话。

    System and method for running a multiple spanning tree protocol with a very large number of domains
    4.
    发明授权
    System and method for running a multiple spanning tree protocol with a very large number of domains 有权
    用于运行具有非常大数量域的多生成树协议的系统和方法

    公开(公告)号:US08565123B2

    公开(公告)日:2013-10-22

    申请号:US11416559

    申请日:2006-05-03

    IPC分类号: H04L12/28

    摘要: A system and method runs a multiple spanning tree protocol (MSTP) in a computer network having a very large number of bridge domains. The computer network includes a plurality of intermediate network devices, each having a plurality of ports for forwarding network messages. Within each device, a plurality of bridge domains are defined, each bridge domain is identified by a Virtual Local Area Network (VLAN) Identifier (VID), and one or more device ports. For each port, a separate mapping of VIDs to Multiple Spanning Tree Instances (MSTIs), based on the bridge domains defined at the port, is established. Each mapping is converted to a port-based configuration digest, which is entered into Spanning Tree Protocol (STP) control messages sent from the respective port. Ports receiving STP control messages whose configuration digest values that match the configuration digests values computed for the ports are said to be in the same Multiple Spanning Tree region. Ports whose configuration digests differ from the configuration digests of received STP control messages are said to be in different regions.

    摘要翻译: 系统和方法在具有非常大数量的网桥域的计算机网络中运行多生成树协议(MSTP)。 计算机网络包括多个中间网络设备,每个中间网络设备具有用于转发网络消息的多个端口。 在每个设备中,定义了多个桥接域,每个网桥域由虚拟局域网(VLAN)标识符(VID)和一个或多个设备端口来标识。 对于每个端口,建立基于端口定义的桥接域的VID到多生成树实例(MSTI)的单独映射。 每个映射被转换为基于端口的配置摘要,它被输入到从相应端口发送的生成树协议(STP)控制消息。 接收STP控制消息的端口的配置摘要值与配置摘要值计算的端口称为处于相同的“多生成树”区域。 其配置摘要与接收的STP控制消息的配置摘要不同的端口据说在不同的区域。

    Technique for sharing a physical port among a plurality of virtual bridges on a switch in a computer network
    5.
    发明授权
    Technique for sharing a physical port among a plurality of virtual bridges on a switch in a computer network 有权
    用于在计算机网络中的交换机上的多个虚拟网桥之间共享物理端口的技术

    公开(公告)号:US07639699B2

    公开(公告)日:2009-12-29

    申请号:US11499556

    申请日:2006-08-04

    IPC分类号: H04L12/28

    摘要: A technique shares a port (e.g., a physical port) among a plurality of virtual bridges on a switch in a computer network. According to the novel technique, two or more virtual bridges are established on the switch, and are each assigned respective sets of Virtual Local Area Networks (VLANs). Each virtual bridge has a virtual interface corresponding to the physical port (a “shared trunk”), the virtual bridges regarding the virtual interfaces as though they were physical ports. Control messages transmitted by the virtual bridges on the virtual interfaces are sent over the physical port and to each other virtual interface of the port (the shared trunk), such as, e.g., by a virtual hub of the shared trunk. Also, control messages received on the physical port are sent over each virtual interface to each virtual bridge (e.g., by the virtual hub).

    摘要翻译: 技术在计算机网络中的交换机上的多个虚拟网桥中共享端口(例如,物理端口)。 根据该技术,交换机上建立了两个或多个虚拟网桥,并分别分配了各自的虚拟局域网(VLAN)。 每个虚拟桥具有与物理端口(“共享中继”)对应的虚拟接口,虚拟接口的虚拟桥接就像物理端口一样。 由虚拟接口上的虚拟网桥发送的控制消息通过物理端口和端口(共享中继线)的彼此虚拟接口(例如由共享中继线的虚拟集线器)发送。 此外,物理端口上接收的控制消息通过每个虚拟接口发送到每个虚拟网桥(例如,由虚拟集线器)。

    IMPLEMENTING PVLANs IN A LARGE-SCALE DISTRIBUTED VIRTUAL SWITCH
    6.
    发明申请
    IMPLEMENTING PVLANs IN A LARGE-SCALE DISTRIBUTED VIRTUAL SWITCH 有权
    在大规模分布式虚拟交换机中实现PVLAN

    公开(公告)号:US20130315252A1

    公开(公告)日:2013-11-28

    申请号:US13477605

    申请日:2012-05-22

    IPC分类号: H04L12/56

    摘要: In one embodiment, a list of source identifiers is maintained at a virtual switch. These source identifiers are allowed to send packets through the virtual switch to ports in a private virtual local area network (PVLAN). When a packet is received at the virtual switch from a particular source destined for a particular port in the PVLAN, the virtual switch determines whether a particular identifier associated with the particular source matches one of the source identifiers in the list. If that particular source identifier is not on the list, the packet is prevented from being forwarded to the particular port in the PVLAN.

    摘要翻译: 在一个实施例中,在虚拟交换机上维护源标识符的列表。 允许这些源标识符通过虚拟交换机发送到私有虚拟局域网(PVLAN)中的端口。 当虚拟交换机从虚拟交换机接收目的地为PVLAN中的特定端口的分组时,虚拟交换机确定与特定源相关联的特定标识符是否与列表中的一个源标识符匹配。 如果该特定源标识符不在列表中,则阻止该数据包转发到PVLAN中的特定端口。

    Remote traffic monitoring through a network
    7.
    发明授权
    Remote traffic monitoring through a network 有权
    通过网络进行远程流量监控

    公开(公告)号:US08520540B1

    公开(公告)日:2013-08-27

    申请号:US12847350

    申请日:2010-07-30

    IPC分类号: G01R31/08

    摘要: Techniques are provided for receiving one or more packets at a network device in a network. The one or more packets are part of normal network communication traffic. Device specific information associated with the one or more packets is generated that is unique to or available at the network device. One or more duplicate packets corresponding to the one or more packets are generated. The device specific information is encapsulated within the one or more duplicate packets for transmission over the network. The one or more duplicate packets are received at a network analyzer in the network. The device specific information associated with the one or more packets that is unique to the network device is extracted from the one or more duplicate packets and analyzed to determine network metrics for the one or more packets.

    摘要翻译: 提供了用于在网络中的网络设备处接收一个或多个分组的技术。 一个或多个分组是正常网络通信业务的一部分。 生成与一个或多个分组相关联的设备特定信息,其在网络设备上是唯一的或可用的。 生成与一个或多个分组对应的一个或多个重复分组。 设备特定信息被封装在一个或多个重复分组内,以便通过网络进行传输。 在网络中的网络分析器处接收一个或多个重复分组。 从一个或多个重复分组中提取与网络设备唯一的一个或多个分组相关联的设备特定信息,并进行分析以确定一个或多个分组的网络度量。

    Efficient pruning of virtual services in bridged computer networks
    8.
    发明授权
    Efficient pruning of virtual services in bridged computer networks 有权
    桥接计算机网络中虚拟服务的有效修剪

    公开(公告)号:US07894342B2

    公开(公告)日:2011-02-22

    申请号:US12394924

    申请日:2009-02-27

    IPC分类号: G01R31/08 G06F15/173

    CPC分类号: H04L12/4625

    摘要: In one embodiment, a bridge in a computer network may execute a spanning tree protocol (STP) for network topology and a registration protocol for traffic control of virtual connections (e.g., EVCs) at the bridge. For any gateway ports of the bridge inter-connected with a provider network, the bridge may generate “fake” received registration protocol join messages for a particular virtual connection at the gateway port. The bridge may then either i) propagate the join messages, in response to the gateway port being in a forwarding state according to the STP, on other forwarding ports of the bridge, or ii) in response to the gateway port not being in a forwarding state, block propagation of the join messages to other ports of the bridge.

    摘要翻译: 在一个实施例中,计算机网络中的网桥可以执行用于网络拓扑的生成树协议(STP)和用于桥上虚拟连接(例如,EVC)的业务控制的注册协议。 对于与提供商网络相互连接的桥的任何网关端口,桥接器可以在网关端口处针对特定虚拟连接生成“假的”接收的注册协议加入消息。 桥接器然后可以i)响应于网关端口处于根据STP的转发状态在网桥的其他转发端口上传播加入消息,或者ii)响应于网关端口不处于转发 状态,将连接消息块传播到网桥的其他端口。

    EFFICIENT PRUNING OF VIRTUAL SERVICES IN BRIDGED COMPUTER NETWORKS
    9.
    发明申请
    EFFICIENT PRUNING OF VIRTUAL SERVICES IN BRIDGED COMPUTER NETWORKS 有权
    桥梁计算机网络虚拟服务的有效修复

    公开(公告)号:US20100220730A1

    公开(公告)日:2010-09-02

    申请号:US12394924

    申请日:2009-02-27

    IPC分类号: H04L12/56

    CPC分类号: H04L12/4625

    摘要: In one embodiment, a bridge in a computer network may execute a spanning tree protocol (STP) for network topology and a registration protocol for traffic control of virtual connections (e.g., EVCs) at the bridge. For any gateway ports of the bridge inter-connected with a provider network, the bridge may generate “fake” received registration protocol join messages for a particular virtual connection at the gateway port. The bridge may then either i) propagate the join messages, in response to the gateway port being in a forwarding state according to the STP, on other forwarding ports of the bridge, or ii) in response to the gateway port not being in a forwarding state, block propagation of the join messages to other ports of the bridge.

    摘要翻译: 在一个实施例中,计算机网络中的网桥可以执行用于网络拓扑的生成树协议(STP)和用于桥上虚拟连接(例如,EVC)的业务控制的注册协议。 对于与提供商网络相互连接的桥的任何网关端口,桥接器可以在网关端口处针对特定虚拟连接生成“假的”接收的注册协议加入消息。 桥接器然后可以i)响应于网关端口处于根据STP的转发状态在网桥的其他转发端口上传播加入消息,或者ii)响应于网关端口不处于转发 状态,将连接消息块传播到网桥的其他端口。

    Technique for sharing a physical port among a plurality of virtual bridges on a switch in a computer network
    10.
    发明申请
    Technique for sharing a physical port among a plurality of virtual bridges on a switch in a computer network 有权
    用于在计算机网络中的交换机上的多个虚拟网桥之间共享物理端口的技术

    公开(公告)号:US20080031266A1

    公开(公告)日:2008-02-07

    申请号:US11499556

    申请日:2006-08-04

    IPC分类号: H04L12/56

    摘要: A technique shares a port (e.g., a physical port) among a plurality of virtual bridges on a switch in a computer network. According to the novel technique, two or more virtual bridges are established on the switch, and are each assigned respective sets of Virtual Local Area Networks (VLANs). Each virtual bridge has a virtual interface corresponding to the physical port (a “shared trunk”), the virtual bridges regarding the virtual interfaces as though they were physical ports. Control messages transmitted by the virtual bridges on the virtual interfaces are sent over the physical port and to each other virtual interface of the port (the shared trunk), such as, e.g., by a virtual hub of the shared trunk. Also, control messages received on the physical port are sent over each virtual interface to each virtual bridge (e.g., by the virtual hub).

    摘要翻译: 技术在计算机网络中的交换机上的多个虚拟网桥中共享端口(例如,物理端口)。 根据该技术,交换机上建立了两个或多个虚拟网桥,并分别分配了各自的虚拟局域网(VLAN)。 每个虚拟桥具有与物理端口(“共享中继”)对应的虚拟接口,虚拟接口的虚拟桥接就像物理端口一样。 由虚拟接口上的虚拟网桥发送的控制消息通过物理端口和端口(共享中继线)的彼此虚拟接口(例如由共享中继线的虚拟集线器)发送。 此外,物理端口上接收的控制消息通过每个虚拟接口发送到每个虚拟网桥(例如,由虚拟集线器)。