首页> 外国专利> Dynamically defining encryption spaces across multiple data centers

Dynamically defining encryption spaces across multiple data centers

机译:动态定义跨多个数据中心的加密空间

摘要

Described herein are systems, methods, and software to enhance the management of encryption addressing across multiple virtual computing sites. In one implementation, a first edge gateway at a first computing site may obtain, via border gateway protocol (BGP), one or more internet protocol (IP) address prefixes from a second edge gateway of a second computing site. The first edge gateway may further update an access control list (ACL) at the first edge gateway based on the one or more prefixes, wherein the ACL provides permissions in IPSec communications between a plurality of virtual nodes at the first computing site and a plurality of virtual nodes at the second site. Once the ACL is updated, the first edge gateway may forward communications based on the ACL using IPSec protocol.
机译:本文描述了用于增强跨多个虚拟计算站点的加密寻址的管理的系统,方法和软件。在一个实现中,第一计算站点处的第一边缘网关可以经由边界网关协议(BGP)从第二计算站点的第二边缘网关获得一个或多个互联网协议(IP)地址前缀。第一边缘网关可以进一步基于一个或多个前缀在第一边缘网关处更新访问控制列表(ACL),其中,该ACL在第一计算站点处的多个虚拟节点与多个计算节点之间的IPSec通信中提供许可。第二个站点上的虚拟节点。一旦更新了ACL,第一边缘网关就可以使用IPSec协议基于ACL转发通信。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号