US2023336477A1PendingUtilityA1

Centralized management and distributed enforcement of policies for network segmentation

Assignee: ARISTA NETWORKS INCPriority: May 11, 2020Filed: Apr 27, 2023Published: Oct 19, 2023
Est. expiryMay 11, 2040(~13.8 yrs left)· nominal 20-yr term from priority
H04L 45/02H04L 45/74H04L 45/38H04L 63/101H04L 45/04H04L 45/64H04L 63/20H04L 63/0236
62
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A central controller in a data network can maintain a set of access control list (ACL) rules that represent traffic and data policies of the data network. The controller can autonomously propagate the set of ACL rules to switches in the data network. Each switch that receives the set of ACL rules can selectively install rules from the set based on criteria such as whether or not a given rule in the set is close to the source and device class.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A network device comprising:
 one or more computer processors;   a memory; and   a computer-readable storage medium comprising instructions for controlling the one or more computer processors to:
 receive a plurality of ACL rules from a controller that is separate from the network device; 
 selectively program the plurality of ACL rules in the memory of the network device, wherein an ACL rule in the plurality of ACL rules is programmed when the ACL rule targets data packets sent from a computer that is deemed to be local to the network device; and 
 send at least some of the ACL rules in the plurality of ACL rules to a peer network device. 
   
     
     
         2 . The network device of  claim 1 , wherein the computer is deemed to be local to the network device when the computer is on a route that is directly connected to the network device. 
     
     
         3 . The network device of  claim 1 , wherein the computer-readable storage medium further comprises instructions for controlling the one or more computer processors to communicate with a spine switch, the spine switch having stored therein the plurality of ACL rules from the controller, wherein the network device receives the plurality of ACL rules from the controller via the spine switch. 
     
     
         4 . The network device of  claim 1 , wherein the computer-readable storage medium further comprises instructions for controlling the one or more computer processors to:
 determine whether a source address in the ACL rule identifies a directly connected route;   determine whether the source address in the ACL rule is local to the network device; and   program the ACL rule in the memory of the network device when the source address identifies a directly connected route and is local to the network device.   
     
     
         5 . The network device of  claim 1 , wherein the computer-readable storage medium further comprises instructions for controlling the one or more computer processors to delete the ACL rule from the memory of the network device when the ACL rule is already programmed in the memory of the network device and the computer targeted by the ACL rule is no longer connected to the network device. 
     
     
         6 . The network device of  claim 1 , wherein the computer-readable storage medium further comprises instructions for controlling the one or more computer processors to collect information relating to ACL rules programmed in the memory of the network device that have been triggered and providing the collected information to the controller, the network device receiving updated ACL rules from the controller in response to providing the collected information to the controller. 
     
     
         7 . The network device of  claim 1 , wherein at least some of the ACL rules in the plurality of ACL rules are based on device classes of computers connected to the network device. 
     
     
         8 . A network device comprising:
 one or more computer processors;   a memory; and   a computer-readable storage medium comprising instructions for controlling the one or more computer processors to:
 receive a plurality of ACL rules, the plurality of ACL rules stored in a data store of a controller that is separate from the network device; and 
 process each ACL rule in the plurality of ACL rules, wherein an ACL rule is programmed in the memory of the network device when the ACL is associated with a route that is directly connected to the network device. 
   
     
     
         9 . The network device of  claim 8 , wherein the computer-readable storage medium further comprises instructions for controlling the one or more computer processors to send at least some of the ACL rules in the plurality of ACL rules to a peer network device. 
     
     
         10 . The network device of  claim 8 , wherein the computer-readable storage medium further comprises instructions for controlling the one or more computer processors to:
 determine whether a source address in the ACL rule identifies a directly connected route;   determine whether the source address in the ACL rule is local to the network device; and   program the ACL rule in the memory of the network device when the source address identifies a directly connected route and is local to the network device.   
     
     
         11 . The network device of  claim 8 , wherein the computer-readable storage medium further comprises instructions for controlling the one or more computer processors to communicate with a spine switch that contains the plurality of ACL rules from the controller, wherein the network device receives the plurality of ACL rules from the controller via the spine switch. 
     
     
         12 . The network device of  claim 8 , wherein the computer-readable storage medium further comprises instructions for controlling the one or more computer processors to delete the ACL rule from the memory of the network device when the ACL rule is already programmed in the memory of the network device and the ACL rule is no longer local to the network device. 
     
     
         13 . The network device of  claim 8 , wherein the computer-readable storage medium further comprises instructions for controlling the one or more computer processors to determine that the computer targeted by the ACL rule is no longer connected to the network device and, in response, deleting the ACL rule from the memory of the network device. 
     
     
         14 . A method in a network switch comprising:
 receiving a plurality of ACL rules from a controller that is separate from the network switch;   for each ACL rule in the plurality of ACL rules, autonomously programming the ACL rule in a memory of the network switch when the ACL rule targets data packets sent from a computer that is deemed to be local to the network switch; and   sending at least some of the ACL rules in the plurality of ACL rules to a peer network switch.   
     
     
         15 . The method of  claim 14 , wherein the computer is deemed to be local to the network switch when the computer is on a route that is directly connected to the network switch. 
     
     
         16 . The method of  claim 14 , wherein the computer is deemed to be local to the network switch when the computer is connected to a physical port of the network switch. 
     
     
         17 . The method of  claim 14 , further comprising:
 determining whether a source address in the ACL rule identifies a directly connected route;   determining whether the source address in the ACL rule is local to the network switch; and   programming the ACL rule in the memory of the network switch when the source address identifies a directly connected route and is local to the network switch.   
     
     
         18 . The method of  claim 14 , further comprising deleting the ACL rule from the memory of the network switch when the ACL rule is already programmed in the memory of the network switch and the ACL rule is no longer local to the network switch. 
     
     
         19 . The method of  claim 14 , further comprising determining that the computer targeted by the ACL rule is no longer connected to the network switch and, in response, deleting the ACL rule from the memory of the network switch. 
     
     
         20 . The method of  claim 14 , further comprising the network switch collecting information relating to ACL rules programmed in the memory of the network switch that have been triggered and providing the collected information to the controller, the network switch receiving updated ACL rules from the controller in response to providing the collected information to the controller.

Join the waitlist — get patent alerts

Track US2023336477A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.