首页> 外国专利> Micro and macro segmentation in enterprise networks without a per segment layer-3 domain

Micro and macro segmentation in enterprise networks without a per segment layer-3 domain

机译:企业网络中的微观和宏观细分,没有每段第3层域

摘要

Secure network segmentation using logical subnet segments is described. A single network segment or subnet provided by a third party is mapped into multiple layer-3 virtual or logical segments without requiring separate subnets. This mapping is accomplished by using virtual routing functions (VRFs) per logical subnet segment while retaining a single subnet across the segments. The logical subnet segments interact with the single network segment provided by the third party (ISP). The layer-3 VRF instances are created without the need for separate IP subnet pools per layer-3 segment. Each VRF instance for the various logical subnet segments is mapped to a Virtual Network Identifier (VNI) and Scalable Group Tag (SGT).
机译:描述了使用逻辑子网分段的安全网络分段。第三方提供的单个网段或子网映射到多个第三层虚拟或逻辑网段,而不需要单独的子网。这种映射是通过在每个逻辑子网段中使用虚拟路由功能(VRF),同时在这些段中保留一个子网来实现的。逻辑子网段与第三方(ISP)提供的单个网段交互。创建第三层VRF实例时,每个第三层网段不需要单独的IP子网池。各个逻辑子网段的每个VRF实例都映射到虚拟网络标识符(VNI)和可伸缩组标签(SGT)。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号