首页> 外国专利> System and method for supporting at least one of sub-management packet (SMP) firewall restrictions and traffic protection in a middleware machine environment

System and method for supporting at least one of sub-management packet (SMP) firewall restrictions and traffic protection in a middleware machine environment

机译:在中间件机器环境中支持子管理包(SMP)防火墙限制和流量保护中至少一项的系统和方法

摘要

The system and method can provide firewall restrictions for subnet management packets (SMP) in a middleware machine environment. A secure firmware implementation may be provided by a Host Channel Adapter (HCA), which is associated with a host in a middleware machine environment. The secure firmware implementation operates to receive at least one SMP from or destined for the host, or to prevent the host from transmitting or receiving at least one SMP. . Furthermore, the secure firmware implementation may include a proxy function that can communicate with an external management component on behalf of the host. The system and method can provide protection of switch-based subnet management packet (SMP) traffic in a middleware machine environment. The middleware machine environment includes a network switch that operates to receive at least one SMP addressed to a subnet management agent (SMA) component. The network switch can check if at least one SMP contains the correct management key, and if at least one SMP does not contain the correct management key, at least one SMP is forwarded to the designated SMA To prevent that. In addition, the network switch can specify different management keys for each external port, and can enforce separate restrictions on ingress and egress SMP traffic on unique external ports.
机译:该系统和方法可以为中间件机器环境中的子网管理包(SMP)提供防火墙限制。主机通道适配器(HCA)可以提供安全的固件实现,该主机通道适配器与中间件机器环境中的主机相关联。安全固件实现用于从主机接收或发往主机的至少一个SMP,或防止主机发送或接收至少一个SMP。 。此外,安全固件实现可以包括代理功能,该代理功能可以代表主机与外部管理组件进行通信。该系统和方法可以在中间件机器环境中提供对基于交换机的子网管理分组(SMP)流量的保护。中间件机器环境包括网络交换机,该网络交换机用于接收至少一个寻址到子网管理代理(SMA)组件的SMP。网络交换机可以检查至少一个SMP是否包含正确的管理密钥,并且如果至少一个SMP不包含正确的管理密钥,则将至少一个SMP转发到指定的SMA以防止这种情况。此外,网络交换机可以为每个外部端口指定不同的管理密钥,并且可以对唯一外部端口上的入口和出口SMP流量实施单独的限制。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号