-
公开(公告)号:US12069051B2
公开(公告)日:2024-08-20
申请号:US17743758
申请日:2022-05-13
Applicant: Cisco Technology, Inc.
Inventor: Roberto Mitsuo Kobo , Zheng Li , Gopala Krishna Andagunda , Einar Nilsen-Nygaard , Shree Murthy , Parthiv Shah
IPC: H04L29/06 , G06F9/455 , H04L9/40 , H04L61/5014
CPC classification number: H04L63/0876 , G06F9/45558 , H04L61/5014 , H04L63/101 , H04L63/20 , G06F2009/45587 , G06F2009/45595
Abstract: Techniques for authenticating and enforcing differentiated policies for a virtual machine (VM) executing in bridge mode on a wireless host device in a media access control (MAC)-based authentication network are described. In an example method a wireless host device is authorized to join a fabric enabled wireless network. A VM executes in bridge mode on the wireless host device. At the fabric edge, a source MAC address of the VM is determined. A session is created between the VM and an authentication server. The VM is authenticated. A policy for the VM is determined. A source internet protocol (IP) address is assigned to the VM to create a MAC-IP binding. A data-plane device in the fabric enabled wireless network is programmed to apply the policy to traffic communicated with the VM. Finally, the data-plane device applies the policy for the VM based at least in part on the MAC-IP binding.
-
公开(公告)号:US20240340283A1
公开(公告)日:2024-10-10
申请号:US18746555
申请日:2024-06-18
Applicant: Cisco Technology, Inc.
Inventor: Roberto Mitsuo Kobo , Zheng Li , Gopala Krishna Andagunda , Einar Nilsen-Nygaard , Shree Murthy , Parthiv Shah
IPC: H04L9/40 , G06F9/455 , H04L61/5014
CPC classification number: H04L63/0876 , G06F9/45558 , H04L61/5014 , H04L63/101 , H04L63/20 , G06F2009/45587 , G06F2009/45595
Abstract: Techniques for authenticating and enforcing differentiated policies for a virtual machine (VM) executing in bridge mode on a host device are described. In an example method a fabric edge device determines a MAC address of the VM executing on the host device. The fabric edge device transmits an access request to create a session for the VM to an authentication server. The fabric edge device receives an indication that the VM is authenticated and a session for the VM has been created from the authentication server. The authentication server determines a policy to apply to packets communicated from the VM and assigns an IP address to the VM to create a MAC-IP binding for the VM. The fabric edge device applies the policy for the VM to packets with a source IP address corresponding to an IP address assigned to the VM.
-
公开(公告)号:US20230370453A1
公开(公告)日:2023-11-16
申请号:US17743758
申请日:2022-05-13
Applicant: Cisco Technology, Inc.
Inventor: Roberto Mitsuo Kobo , Zheng Li , Gopala Krishna Andagunda , Einar Nilsen-Nygaard , Shree Murthy , Parthiv Shah
IPC: H04L9/40 , H04L61/5014 , G06F9/455
CPC classification number: H04L63/0876 , H04L63/101 , H04L63/20 , H04L61/5014 , G06F9/45558 , G06F2009/45595 , G06F2009/45587
Abstract: Techniques for authenticating and enforcing differentiated policies for a virtual machine (VM) executing in bridge mode on a wireless host device in a media access control (MAC)-based authentication network are described. In an example method a wireless host device is authorized to join a fabric enabled wireless network. A VM executes in bridge mode on the wireless host device. At the fabric edge, a source MAC address of the VM is determined. A session is created between the VM and an authentication server. The VM is authenticated. A policy for the VM is determined. A source internet protocol (IP) address is assigned to the VM to create a MAC-IP binding. A data-plane device in the fabric enabled wireless network is programmed to apply the policy to traffic communicated with the VM. Finally, the data-plane device applies the policy for the VM based at least in part on the MAC-IP binding.
-
-