首页> 外国专利> DEVICE AND METHOD OF FORWARDING DATA PACKETS IN A VIRTUAL SWITCH OF A SOFTWARE-DEFINED WIDE AREA NETWORK ENVIRONMENT

DEVICE AND METHOD OF FORWARDING DATA PACKETS IN A VIRTUAL SWITCH OF A SOFTWARE-DEFINED WIDE AREA NETWORK ENVIRONMENT

机译:在软件定义的广域网环境的虚拟交换机中转发数据分组的设备和方法

摘要

The invention relates to a method of forwarding data packets in a virtual switch (120) of a software-defined wide area network (SD-WAN) environment (100), wherein the virtual switch (120) comprises at least one first virtual port (122) for receiving outbound LAN traffic (T) from and transmitting inbound LAN traffic (T) to at least one physical local area network (LAN) port (112), at least one second virtual port (124) for receiving inbound secured traffic (T) from and transmitting outbound secured traffic (T) to at least one physical secured traffic port (114), and at least one third virtual port (126) for receiving inbound Internet traffic (T) from and transmitting outbound Internet traffic (T) to at least one physical Internet port (116), the method comprising the steps of: determining, for each or at least selected data packets of the outbound LAN traffic (T) directed to the at least one first virtual port (122), a dedicated signature information based on the bits of the data packet; storing the signature information and, if appropriate, information identifying the packet to which the signature information has been assigned; if appropriate, outputting the outbound LAN traffic (T) at the first virtual port (122) for processing by a virtual machine (134); receiving at least a portion of the outbound LAN traffic (T), as the case may be after having been further processed by the virtual machine (134), at the second virtual port (124) as an outbound secured traffic (T) that is to be supplied to the at least one physical secured traffic port (114); examining each data packet of the outbound secure traffic (T) as to whether it matches the dedicated signature information and using the result of this check for controlling the forwarding of the respective data packet as part of the outbound secured traffic (T) to the at least one physical secured traffic port (114) and/or for creating a SUSPICIOUS SOURCE alarm if a predetermined alarm condition is met. Further, the invention relates to a network interface device (110) which is configured to implement the method as well as to a computer program product stored which is configured to cause a computer to perform the method.
机译:本发明涉及一种在软件定义的广域网(SD-WAN)环境(100)的虚拟交换机(120)中转发数据分组的方法,其中虚拟交换机(120)包括至少一个第一虚拟端口( 122),用于从至少一个物理局域网(LAN)端口(112)接收出站LAN流量(T)并向其发送入站LAN流量(T),至少一个第二虚拟端口(124)用于接收入站安全流量(T) T)从至少一个物理安全流量端口(114)发送出站安全流量(T)并将其传输到至少一个物理安全流量端口(114),以及至少一个第三虚拟端口(126),用于从中接收入站Internet流量(T)并发送出站Internet流量(T)到至少一个物理互联网端口(116)的方法,该方法包括以下步骤:为定向到至少一个第一虚拟端口(122)的出站LAN流量(T)的每个或至少选定的数据包确定一个基于数据包的位的专用签名信息;存储签名信息,以及在适当时存储标识已分配签名信息的数据包的信息;如果合适,在第一虚拟端口(122)上输出出站LAN业务(T),以供虚拟机(134)处理;在第二虚拟端口(124)处接收至少一部分出站LAN流量(T),作为出站安全流量(T),视情况在经过虚拟机(134)进一步处理之后,供给至少一个物理安全交通端口(114);检查出站安全流量(T)的每个数据包是否与专用签名信息匹配,并使用此检查的结果来控制将相应数据包作为出站安全流量(T)的一部分转发到至少一个物理安全通信端口(114)和/或用于在满足预定警报条件的情况下创建可疑源警报。此外,本发明涉及被配置为实现该方法的网络接口设备(110)以及被配置为使计算机执行该方法的所存储的计算机程序产品。

著录项

  • 公开/公告号EP3525407B1

    专利类型

  • 公开/公告日2020-09-23

    原文格式PDF

  • 申请/专利权人 ADVA OPTICAL NETWORKING SE;

    申请/专利号EP20180155798

  • 发明设计人 SERGEEV ANDREW;ANGEL ELI;

    申请日2018-02-08

  • 分类号H04L12/931;H04L29/06;

  • 国家 EP

  • 入库时间 2022-08-21 11:41:37

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号