首页> 外国专利> SUPPORTING ACCESS CONTROL LIST RULES THAT APPLY TO TCP SEGMENTS BELONGING TO 'ESTABLISHED' CONNECTION

SUPPORTING ACCESS CONTROL LIST RULES THAT APPLY TO TCP SEGMENTS BELONGING TO 'ESTABLISHED' CONNECTION

机译:支持适用于“已建立”连接的TCP段的访问控制列表规则

摘要

Embodiments presented herein provide a TCAM-based access control list that supports disjunction operations in rules. According to one embodiment, a numeric range table is tied to the access control list. Each entry in the numeric range table includes an encode field that provides for scanning TCP flags in a TCP header of an incoming Ethernet frame. Further, each entry provides a first mask and a second mask used to test for desired set and unset TCP flags in a given frame. Each entry also provides an operation field that performs a disjunction operation that compares the first mask, the second mask, and set TCP flags in a given frame.
机译:本文提出的实施例提供了基于TCAM的访问控制列表,该列表支持规则中的析取操作。根据一个实施例,数字范围表被绑定到访问控制列表。数字范围表中的每个条目都包含一个编码字段,该字段用于扫描传入以太网帧的TCP标头中的TCP标志。此外,每个条目提供用于测试给定帧中所需的设置和未设置的TCP标志的第一掩码和第二掩码。每个条目还提供一个执行分离操作的操作字段,该操作对第一掩码,第二掩码进行比较,并在给定帧中设置TCP标志。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号