首页> 外国专利> MICROSEGMENTATION IN HETEROGENEOUS SOFTWARE DEFINED NETWORKING ENVIRONMENTS

MICROSEGMENTATION IN HETEROGENEOUS SOFTWARE DEFINED NETWORKING ENVIRONMENTS

机译:异构软件定义的网络环境中的微粉化

摘要

Microsegmentation in a heterogeneous software-defined network can be performed by classifying endpoints associated with a first virtualized environment into respective endpoint groups based on respective attributes, and classifying endpoints associated with a second virtualized environment into respective security groups based on respective attributes. Each respective endpoint group can correspond to a respective security group having the same attribute. Each respective endpoint group and corresponding security group can be associated with a respective policy model defining rules for processing associated traffic. Each of the respective security groups can be used to generate a respective network attribute endpoint group, which can include the network addresses of those endpoints in the respective security group. Each respective network attribute endpoint group can inherit the policy model of the respective endpoint group corresponding to the respective security group. Traffic between the endpoints can then be processed based on the various classifications and associated rules.
机译:可以通过基于各自的属性将与第一虚拟化环境相关联的端点分类为各个端点组,并基于各自的属性将与第二虚拟化环境相关联的端点分类为各自的安全组,来执行异构软件定义网络中的微细分。每个相应端点组可以对应于具有相同属性的相应安全组。每个相应的端点组和相应的安全组可以与相应的策略模型关联,该策略模型定义用于处理关联流量的规则。各个安全组中的每个可用于生成各个网络属性端点组,该网络属性端点组可包括各个安全组中那些端点的网络地址。每个相应的网络属性端点组可以继承与相应的安全组相对应的相应端点组的策略模型。然后可以基于各种分类和关联规则来处理端点之间的流量。

著录项

  • 公开/公告号WO2017201264A1

    专利类型

  • 公开/公告日2017-11-23

    原文格式PDF

  • 申请/专利权人 CISCO TECHNOLOGY INC.;

    申请/专利号WO2017US33297

  • 申请日2017-05-18

  • 分类号H04L12/931;G06F9/455;H04L29/06;H04L12/713;

  • 国家 WO

  • 入库时间 2022-08-21 12:47:03

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号