首页> 外国专利> Packet induced revalidation of connection tracker

Packet induced revalidation of connection tracker

机译:数据包引起的连接跟踪器的重新验证

摘要

A method of revalidating a connection tracking table of a flow-based managed forwarding element (MFE) that stores a set of firewall rules associated with each of a set of network connections and a connection table that stores a firewall rule identification and a set of state values associated with each of said network connections. The method receives a change in one or more firewall rules stored at the MFE. The method receives a packet that requires stateful firewall rule check on a particular connection after the change in the firewall rules. When the rule identification retrieved from the connection table is not the same as the new firewall rule associated with the particular connection, the method updates the firewall rule identification and the set of state values associated the particular connection using the new firewall rule identification associated with the particular connection.
机译:一种重新验证基于流的受管转发元素(MFE)的连接跟踪表的方法,该方法存储与一组网络连接中的每一个相关联的一组防火墙规则,以及一个连接表,该表存储防火墙规则标识和一组状态与每个所述网络连接相关联的值。该方法接收存储在MFE的一个或多个防火墙规则的更改。该方法接收更改防火墙规则后需要对特定连接进行状态防火墙规则检查的数据包。当从连接表中检索到的规则标识与与特定连接相关联的新防火墙规则不同时,该方法将使用与特定连接相关联的新防火墙规则标识来更新防火墙规则标识和与特定连接相关联的状态值集。特定的连接。

著录项

  • 公开/公告号US10708229B2

    专利类型

  • 公开/公告日2020-07-07

    原文格式PDF

  • 申请/专利权人 NICIRA INC.;

    申请/专利号US201715814272

  • 发明设计人 SONER SEVINC;YANG SONG;JONATHAN STRINGER;

    申请日2017-11-15

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 11:29:01

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号