VxLAN security implemented using VxLAN membership information at VTEPs

    公开(公告)号:US10171559B2

    公开(公告)日:2019-01-01

    申请号:US14549915

    申请日:2014-11-21

    Abstract: A network device stores a Virtual Extensible Local Area Network (VxLAN) Tunnel Endpoint (VTEP) membership information that associates VxLANs each with a corresponding set of VTEPs authorized to originate VxLAN packets on that VxLAN. The network device receives from a communication network a VxLAN packet that identifies a VxLAN and an originating VTEP. The VTEP compares the originating VTEP to the set of VTEPs associated with the VxLAN in the VTEP membership information that matches the identified VxLAN. If the comparison indicates that the originating VTEP is not included in the set of VTEPs authorized to originate VxLAN packets, the VTEP discards the received VxLAN packet. Otherwise the VTEP further processes the VxLAN packet.

    VxLAN Security Implemented using VxLAN Membership Information at VTEPs
    2.
    发明申请
    VxLAN Security Implemented using VxLAN Membership Information at VTEPs 审中-公开
    VxLAN Security在VTEP中使用VxLAN成员身份信息实现

    公开(公告)号:US20160149808A1

    公开(公告)日:2016-05-26

    申请号:US14549915

    申请日:2014-11-21

    CPC classification number: H04L67/10 H04L12/4633

    Abstract: A network device stores a Virtual Extensible Local Area Network (VxLAN) Tunnel Endpoint (VTEP) membership information that associates VxLANs each with a corresponding set of VTEPs authorized to originate VxLAN packets on that VxLAN. The network device receives from a communication network a VxLAN packet that identifies a VxLAN and an originating VTEP. The VTEP compares the originating VTEP to the set of VTEPs associated with the VxLAN in the VTEP membership information that matches the identified VxLAN. If the comparison indicates that the originating VTEP is not included in the set of VTEPs authorized to originate VxLAN packets, the VTEP discards the received VxLAN packet. Otherwise the VTEP further processes the VxLAN packet.

    Abstract translation: 网络设备存储虚拟可扩展局域网(VxLAN)隧道端点(VTEP)成员身份信息,该信息将VxLANs与授权在该VxLAN上创建VxLAN数据包的对应的一组VTEP相关联。 网络设备从通信网络接收识别VxLAN和始发VTEP的VxLAN分组。 VTEP将起始VTEP与与所识别的VxLAN匹配的VTEP成员资格信息中与VxLAN相关联的VTEP集合进行比较。 如果比较表明发起VTEP不包含在授权发起VxLAN数据包的VTEP集合中,则VTEP将丢弃接收的VxLAN数据包。 否则,VTEP进一步处理VxLAN数据包。

Patent Agency Ranking