Distributed node processing of network traffic

    公开(公告)号:US11516136B2

    公开(公告)日:2022-11-29

    申请号:US17132171

    申请日:2020-12-23

    摘要: A first network device may receive first traffic of a session that involves a service. The first network device may identify that the service is configured for distributed node processing. The first network device may identify a second network device that is configured for distributed node processing. The first network device may identify a state machine that is associated with the service. The first network device may determine, based on the state machine, a first function and a second function, wherein the first function is identified by a first label and the second function is identified by a second label. The first network device may process the first traffic based on the first function. The first network device may provide, to the second network device, the first traffic and the second label to permit the second network device to process second traffic in association with the second function.

    NETWORK TRAFFIC SWITCHING FOR VIRTUAL MACHINES

    公开(公告)号:US20200252437A1

    公开(公告)日:2020-08-06

    申请号:US16854056

    申请日:2020-04-21

    IPC分类号: H04L29/06 G06F9/455

    摘要: A cloud network may include a distributed security switch (DSS). The DSS may be to receive configuration information from the hypervisor. The configuration information may include a set of access mode attributes and a security policy. The DSS may be to determine that a packet is to be directed from a source virtual machine to a target virtual machine. The DSS may be to identify an egress interface of the source virtual machine and an ingress interface of the target virtual machine. The egress interface may be associated with a first access mode attribute and the ingress interface being associated with a second access mode attribute. The DSS may be to selectively route the packet, using the shared memory, based on the first access mode attribute, the second access mode attribute, and the security policy.

    Rule enforcement based on network address requests

    公开(公告)号:US10560480B1

    公开(公告)日:2020-02-11

    申请号:US15205717

    申请日:2016-07-08

    IPC分类号: H04L29/06

    摘要: A first device may include one or more processors. The first device may receive a network address request to obtain a network address that is associated with an application. The network address request may include application information that identifies the application. The first device may determine that the application is associated with a rule. The first device may store the application information and information identifying the network address request. The first device may obtain the network address based on the network address request. The first device may determine that the network address is associated with the rule. The first device may provide the network address, the rule, and/or the application information to a second device, to permit the second device to enforce the rule, based on determining that the application is associated with the rule and determining that the network address is associated with the rule.

    Distributed node processing of network traffic

    公开(公告)号:US11818051B2

    公开(公告)日:2023-11-14

    申请号:US18050188

    申请日:2022-10-27

    摘要: A first network device may receive first traffic of a session that involves a service. The first network device may identify that the service is configured for distributed node processing. The first network device may identify a second network device that is configured for distributed node processing. The first network device may identify a state machine that is associated with the service. The first network device may determine, based on the state machine, a first function and a second function, wherein the first function is identified by a first label and the second function is identified by a second label. The first network device may process the first traffic based on the first function. The first network device may provide, to the second network device, the first traffic and the second label to permit the second network device to process second traffic in association with the second function.

    Network traffic switching for virtual machines

    公开(公告)号:US11323485B2

    公开(公告)日:2022-05-03

    申请号:US16854056

    申请日:2020-04-21

    IPC分类号: G06F9/455 H04L29/06

    摘要: A cloud network may include a distributed security switch (DSS). The DSS may be to receive configuration information from the hypervisor. The configuration information may include a set of access mode attributes and a security policy. The DSS may be to determine that a packet is to be directed from a source virtual machine to a target virtual machine. The DSS may be to identify an egress interface of the source virtual machine and an ingress interface of the target virtual machine. The egress interface may be associated with a first access mode attribute and the ingress interface being associated with a second access mode attribute. The DSS may be to selectively route the packet, using the shared memory, based on the first access mode attribute, the second access mode attribute, and the security policy.

    Efficient transmission control protocol (TCP) reassembly for HTTP/2 streams

    公开(公告)号:US10291682B1

    公开(公告)日:2019-05-14

    申请号:US15272930

    申请日:2016-09-22

    IPC分类号: G06F15/16 H04L29/06 H04L29/08

    摘要: A device may determine that a received transmission control protocol (TCP) segment includes data for a hypertext transfer protocol (HTTP) version N stream, where N is greater than or equal to 2. The device may identify, from the received TCP segment, a stream identifier for the HTTP version N stream. The device may determine that a condition is satisfied for releasing one or more TCP segments, associated with the stream identifier, from a TCP reassembly queue. The device may release the one or more TCP segments from the TCP reassembly queue based on determining that the condition is satisfied.