US2010031323A1PendingUtilityA1

Network Interface Device

Assignee: BARRACUDA NETWORKS INCPriority: Mar 3, 2006Filed: Jan 27, 2009Published: Feb 4, 2010
Est. expiryMar 3, 2026(expired)· nominal 20-yr term from priority
H04L 63/029H04L 63/20
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

There are methods and apparatus, including computer program products, for defining a policy including a set of rules for a packet forwarding device by receiving information sufficient to enable a first rule related to one of security or traffic management to be defined, and based on the received information, enabling a corresponding second rule related to the other one of security or traffic management to be defined.

Claims

exact text as granted — not AI-modified
1 . A method for defining a policy including a set of rules for a packet forwarding device, the method comprising:
 receiving information sufficient to enable a first rule related to one of security or traffic management to be defined; and   based on the received information, enabling a corresponding second rule related to the other one of security or traffic management to be defined.   
   
   
       2 . The method of  claim 1 , wherein the second rule is defined without requiring any further information to be received. 
   
   
       3 . The method of  claim 1 , wherein the information sufficient to enable the first rule to be defined is received from a user, and the second rule is automatically defined without requiring any further input from the user. 
   
   
       4 . The method of  claim 1 , wherein the packet forwarding device is capable of processing data packets received from a local area network and bound for a wide area network in accordance with the defined policy. 
   
   
       5 . The method of  claim 1 , wherein the packet forwarding device is capable of processing data packets received from a wide area network and bound for a local area network in accordance with the defined policy. 
   
   
       6 . The method of  claim 1 , wherein receiving information sufficient to enable a first rule related to security or traffic management to be defined comprises:
 receiving first information identifying a service; and   receiving second information defining a set of actions to govern data traffic associated with the identified service.   
   
   
       7 . The method of  claim 6 , wherein the second information comprises one or more of the following: information related to attributes of IP address matching, information related to operation parameters, and information related to service parameters. 
   
   
       8 . The method of  claim 1 , wherein receiving information sufficient to enable a first rule related to security or traffic management to be defined comprises:
 receiving first information identifying a total amount of available bandwidth for a network link;   receiving second information identifying a class of service; and   determining a percentage of the total amount of available bandwidth to be guaranteed to the identified class of service.   
   
   
       9 . The method of  claim 1 , further comprising:
 accessing pre-stored information associating each of a set of services with a class of service and associating each of a set of classes of service with one or more services, wherein:
 the set of services comprises one or more of the following: a voice service, a video service, and a data service; and 
 the set of classes of service comprises one or more of the following: a premium class of service, a critical class of service, and a standard class of service. 
   
   
   
       10 . The method of  claim 9 , wherein automatically enabling a corresponding second rule related to the other one of security or traffic management to be defined comprises:
 examining the received information to identify a service the first rule related to one of security or traffic management is to be applied; and   enabling a second rule related to the other one or security or traffic management to be defined based on the class of service associated with the identified service.   
   
   
       11 . The method of  claim 10 , wherein when the service is identified as a voice service, the enabling comprises:
 identifying a number of calls to be simultaneously permitted per codec for the premium class of service associated with the voice service.   
   
   
       12 . The method of  claim 9 , wherein automatically enabling a corresponding second rule related to the other one of security or traffic management to be defined comprises:
 examining the received information to identify a class of service the first rule related to one of security or traffic management is to be applied; and   enabling a second rule related to the other one or security or traffic management to be defined based on the one or more services associated with the identified class of service.   
   
   
       13 . An apparatus comprising:
 management logic to:
 receive information sufficient to enable a first rule related to one of security or traffic management to be defined, 
 enable a corresponding second rule related to the other one of security or traffic management to be defined based on the received information, and 
 store attributes of the first rule and attributes of the second rule in a configuration database; and 
   coordination logic to:
 send a first signal to a first engine of a packet forwarding device to notify the first engine of the newly-stored attributes of the first rule, and 
 send a second signal to a second engine of the packet forwarding device to notify the second engine of the newly-stored attributes of the second rule. 
   
   
   
       14 . The apparatus of  claim 13 , wherein the information sufficient to enable the first rule related to one of security or traffic management to be defined is provided by a user using a graphical user interface. 
   
   
       15 . The apparatus of  claim 14 , wherein the second rule related to the other one of security or traffic management is automatically defined without requiring any further input to be received from the user. 
   
   
       16 . The apparatus of  claim 13 , wherein the second rule related to the other one of security or traffic management is defined without requiring any further information to be received by the management logic. 
   
   
       17 . The apparatus of  claim 13 , wherein:
 the first rule is related to security and the first engine is a security engine; and   the second rule is related to traffic management and the second engine is a quality of service engine.   
   
   
       18 . The apparatus of  claim 13 , wherein:
 the first rule is related to traffic management and the first engine is a quality of service engine; and   the second rule is related to security and the second engine is a security engine.   
   
   
       19 . The apparatus of  claim 13 , wherein the coordination logic is to configure a first engine and a second engine of a packet forwarding device that is capable of processing data packets passing between a local area network and a wide area network.

Join the waitlist — get patent alerts

Track US2010031323A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.