摘要:
A method for selectively redirecting a data packet to a port on a switching device which is associated with a corresponding network service. In one embodiment, the data packet is redirected to an intrusion prevention service (IPS) for security analysis of the data packet. In another embodiment, the switching device performs a data link layer redirecting of the data packet based at least in part on whether the data packet is to be flooded from the switching device.
摘要:
A method for selectively redirecting a data packet to a port on a switching device which is associated with a corresponding network service. In one embodiment, the data packet is redirected to an intrusion prevention service (IPS) for security analysis of the data packet. In another embodiment, the switching device performs a data link layer redirecting of the data packet based at least in part on whether the data packet is to be flooded from the switching device.
摘要:
Techniques and architectures to dynamically modify policies used to determine how data in switched network traffic is selected for security inspection. One embodiment of the invention modifies policies used to determine how data in network traffic is redirected from a switch to an intrusion prevention system, without the policy modifications interrupting the handling of network traffic by the switch.
摘要:
Path information is obtained in a VPLS-based network by generating special Layer 2 frames (referred to herein as “trace-request frames”), performing source MAC filtering to identify the trace-request frames, and generating a special frame (referred to herein as a “trace-reply frame”) when the source MAC filtering identifies a trace-request frame. Upon identifying a trace-request frame, path information is collected and embedded into the trace-reply frame. The trace-reply frame is then sent to the originating node where the path information is used to learn the path that the trace-request frame traversed. By sending multiple trace-request frames with different source MAC addresses, path information received from source MAC filtering at different nodes in the VPLS-based network can be collected and used to learn an entire path of interest.