US2020106773A1PendingUtilityA1

Device integration for a network access control server based on device mappings and testing verification

Assignee: FORTINET INCPriority: Sep 29, 2018Filed: Oct 9, 2018Published: Apr 2, 2020
Est. expirySep 29, 2038(~12.2 yrs left)· nominal 20-yr term from priority
H04L 43/50H04L 41/0853H04L 41/0843H04W 12/08H04L 63/20H04L 41/145G06F 16/86H04L 63/0876H04L 63/10G06F 17/30917H04W 12/71H04W 12/088H04L 63/0236
44
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods for facilitating self-service device integration for a network access control (NAC) server are provided. An enforcement engine running on a NAC server initializes modeling of a network device by reading a system object identifier associated with the network device and queries a device information database for the system object identifier to determine whether a mapping for the system object identifier exists in the database. When a match of the system object identifier is not found, the enforcement engine retrieves a list of network devices from the database based on the system object identifier to enable a user to select a potential network device from the list. Furthermore, the enforcement engine, maps implementation details of the potential network device against the system object identifier and stores the mapping as an entry in the database in order to access the network device using implementation details of the potential network device.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 initializing, by an enforcement engine running on a network access control (NAC) server protecting a private network, modeling of a network device that is operatively coupled with the NAC server by reading a system object identifier associated with said network device;   querying, by the enforcement engine, a device information database maintained by the NAC server for said system object identifier, to determine if mapping for said system object identifier exists in the database, wherein the database includes mappings of each of one or more system object identifiers with corresponding implementation details of associated network devices; and   identifying, by the enforcement engine, a matching system object identifier stored in said database to access the network device based on implementation details stored corresponding to said matched system object identifier, wherein in response to match of the system object identifier not being found:
 retrieving, by the enforcement engine, a list of one or more network devices from said database based on the system object identifier in order to enable a user to select a potential network device from the list of one or more network devices; and 
 mapping, by the enforcement engine, implementation details of the potential network device against the system object identifier and storing said mapping as an entry in said database in order to access the network device using said implementation details of said potential network device. 
   
     
     
         2 . The method of  claim 1 , wherein on storing of said entry, the enforcement engine tests successful modeling of the network device by reading device information of said network device. 
     
     
         3 . The method of  claim 2 , wherein said device information comprises any or a combination of Media Access Control (MAC) address information, port information, Internet Protocol (IP) address information, Virtual Local Area Network (VLAN) information, host information, Service Set Identifier (SSID) information and Access Point (AP) information. 
     
     
         4 . The method of  claim 2 , wherein on failing said test, the enforcement engine removes said entry pertaining to the system object identifier responsive to input from the user in order to enable the user to select another potential network device from the list of one or more network devices. 
     
     
         5 . The method of  claim 1 , wherein the network device comprises any of a switch, a router, an access device, or a network gateway device. 
     
     
         6 . The method of  claim 1 , wherein the list of one or more network devices is retrieved based on a vendor identifier extracted from the system object identifier. 
     
     
         7 . The method of  claim 1 , wherein the enforcement engine enables the user to search the potential network device from the list of one or more network devices based on a model name of the network device. 
     
     
         8 . The method of  claim 1 , wherein the enforcement engine maintains the database by extracting device mapping information from one or more property files stored in the NAC server. 
     
     
         9 . The method of  claim 1 , wherein the method further comprises notifying a NAC development team of the NAC server regarding creation of the entry. 
     
     
         10 . The method of  claim 1 , wherein the list of one or more network devices includes any or a combination of system object identifier, model name, firmware version and mapping information of each of the one or more network devices. 
     
     
         11 . A non-transitory computer-readable storage medium embodying a set of instructions, which when executed by one or more processors of a network access control (NAC) server protecting a private network, causes the one or more processors to perform a method comprising:
 initializing, by an enforcement engine running on the NAC server, modeling of a network device that is operatively coupled with the NAC server by reading a system object identifier associated with said network device;   querying, by the enforcement engine, a device information database maintained by the NAC server for said system object identifier, to determine whether a mapping for said system object identifier exists in said database, wherein said database includes mappings of each of one or more system object identifiers with corresponding implementation details of associated network devices; and   identifying, by the enforcement engine, a matching system object identifier stored in said database to access the network device based on implementation details stored corresponding to said matched system object identifier, wherein in response to match of the system object identifier not being found:
 retrieving, by the enforcement engine, a list of one or more network devices from said database based on the system object identifier in order to enable a user to select a potential network device from the list of one or more network devices; and 
 mapping, by the enforcement engine, implementation details of the potential network device against the system object identifier and storing said mapping as an entry in said database in order to access the network device using said implementation details of said potential network device. 
   
     
     
         12 . The non-transitory computer-readable storage medium of  claim 11 , wherein on storing of said entry, the enforcement engine tests successful modeling of the network device by reading device information of said network device. 
     
     
         13 . The non-transitory computer-readable storage medium of  claim 12 , wherein said device information comprises any or a combination of Media Access Control (MAC) address information, port information, Internet Protocol (IP) address information, Virtual Local Area Network (VLAN) information, host information, Service Set Identifier (SSID) information and Access Point (AP) information. 
     
     
         14 . The non-transitory computer-readable storage medium of  claim 12 , wherein on failing said test, the enforcement engine removes said entry pertaining to the system object identifier responsive to input from the user in order to enable the user to select another potential network device from the list of one or more network devices. 
     
     
         15 . The non-transitory computer-readable storage medium of  claim 11 , wherein the network device is any of a switch, a router, an access device, or a network gateway device. 
     
     
         16 . The non-transitory computer-readable storage medium of  claim 11 , wherein the list of one or more network devices is retrieved based on a vendor identifier extracted from the system object identifier. 
     
     
         17 . The non-transitory computer-readable storage medium of  claim 11 , wherein the enforcement engine enables the user to search the potential network device from the list of one or more network devices based on model name of the network device. 
     
     
         18 . The non-transitory computer-readable storage medium of  claim 11 , wherein the enforcement engine maintains the database by extracting device mapping information from one or more property files stored in the NAC server. 
     
     
         19 . The non-transitory computer-readable storage medium of  claim 11 , wherein the method further comprises notifying a NAC development team of the NAC server regarding creation of the entry. 
     
     
         20 . The non-transitory computer-readable storage medium of  claim 11 , wherein the list of one or more network devices includes any or a combination of system object identifier, model name, firmware version and mapping information of each of the one or more network devices.

Join the waitlist — get patent alerts

Track US2020106773A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.