US2021234812A1PendingUtilityA1
Traffic broker for routing data packets through sequences of in-line tools
Est. expiryNov 11, 2035(~9.3 yrs left)· nominal 20-yr term from priority
H04L 49/30
58
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Embodiments are disclosed for a network switch appliance with a traffic broker that facilitates routing of network traffic between pairs of end nodes on a computer network through a configurable sequence of in-line tools.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
associating at least one packet dispatch scheme, of a plurality of packet dispatch schemes, with each of a plurality of network ingress ports of a network switching device, such that a packet dispatch scheme associated with at least one network ingress port of the plurality of network ingress ports includes separate packet forwarding information for each of a plurality of different packet flows; receiving, at the network switching device, a packet at a first network ingress port of the network switching device, the packet having originated at a source node on a network and being destined for a destination node on the network; determining, for the packet, a packet dispatch scheme associated with the first network ingress port, based on a flow with which the packet is associated; and forwarding, by the network switching device, the packet to a second port of the network switching device according to the determined packet dispatch scheme.
2 . The method of claim 1 , further comprising:
transmitting the packet, via the second port, to the destination node in response to determining that, according to the packet dispatch scheme, the second port is a network port of the network switching device, wherein the second port is communicatively coupled to the destination node.
3 . The method of claim 1 , further comprising:
transmitting the packet, via the second port, to an in-line tool in response to determining that, according to the packet dispatch scheme specific to the first port, the second port is an instrument port of the network switching device, wherein the second port is communicatively coupled to the in-line tool, and the in-line tool is associated with one of the plurality of specified sequences of in-line tools.
4 . The method of claim 1 , wherein the network switching device includes a plurality of instrument ports, each of the plurality of instrument ports communicatively coupled with one of a plurality of in-line tools.
5 . The method of claim 1 , wherein each of a plurality of in-line tools is communicatively coupled with two of a plurality of instrument ports of the network switching device.
6 . The method of claim 1 , further comprising:
receiving first user input that specifies:
a first traffic flow; and
a first sequential order of in-line tools through which to route packets associated with the first traffic flow;
receiving second user input that specifies:
a second traffic flow; and
a second sequential order of in-line tools through which to route packets associated with the second traffic flow;
wherein the second sequential order is different from the first sequential order.
7 . The method of claim 6 , further comprising:
in response to at least one of the first user input or the second user input, generating the plurality of packet dispatch schemes.
8 . The method of claim 6 , wherein the first traffic flow is a first segment of network traffic comprising packets that satisfy a specified first criterion and wherein the second traffic flow is a second segment of network traffic comprising packets that satisfy a specified second criterion, and wherein the specified first criterion is different from the specified second criterion.
9 . The method of claim 6 , wherein the specified first criterion and specified second criterion are based on one or more of: a source node identifier, a destination node identifier, a unique packet identifier, a packet length, a transmission protocol, a priority level identifier, payload data, or an application port setting.
10 . The method of claim 6 , wherein each of a plurality of in-line tools is included no more than one time in each of the first sequential order of in-line tools and the second sequential order of in-line tools.
11 . The method of claim 1 , wherein the forwarding is performed via a programmable switching fabric in the network switching device.
12 . The method of claim 1 , further comprising:
determining that the packet is associated with a first traffic flow by determining that the packet includes a tag indicative of the first traffic flow.
13 . The method of claim 12 , further comprising:
after forwarding the packet to the second port, removing the tag from the packet in response to determining that, according to the packet dispatch scheme, the second port is a network port of the network switching device, the network port communicatively coupled to the destination node; and transmitting the packet without the tag, via the second port, to the destination node.
14 . The method of claim 1 , further comprising:
receiving user input specifying:
a traffic flow; and
a sequential order of in-line tools through which to route packets associated with the traffic flow; and
in response to receiving the user input, generating a new packet dispatch scheme for each of the plurality of ports of the network switching device based on the user input.
15 . The method of claim 14 , further comprising:
configuring a switching fabric of the network switching device based on the new packet dispatch scheme.
16 . A system comprising:
a processor, and memory accessible to the processor and having instructions stored therein, execution of which by the processor causes the system to perform operations including:
associating at least one packet dispatch scheme, of a plurality of packet dispatch schemes, with each of a plurality of network ingress ports of a network switching device, such that a packet dispatch scheme associated with at least one network ingress port of the plurality of network ingress ports includes separate packet forwarding information for each of a plurality of different packet flows;
receiving, at the network switching device, a packet at a first network ingress port of the network switching device, the packet having originated at a source node on a network and being destined for a destination node on the network;
determining, for the packet, a packet dispatch scheme associated with the first network ingress port, based on a flow with which the packet is associated; and
forwarding, by the network switching device, the packet to a second port of the network switching device according to the determined packet dispatch scheme.
17 . The system of claim 16 , wherein the operations further comprise at least one of:
transmitting the packet, via the second port, to the destination node in response to determining that, according to the packet dispatch scheme, the second port is a network port of the network switching device, wherein the second port is communicatively coupled to the destination node; or transmitting the packet, via the second port, to an in-line tool in response to determining that, according to the packet dispatch scheme specific to the first port, the second port is an instrument port of the network switching device, wherein the instrument port is communicatively coupled to the in-line tool, and the in-line tool is associated with one of the plurality of specified sequences of in-line tools.
18 . The system of claim 16 , wherein the operations further comprise generating the plurality of packet dispatch schemes.
19 . A network switching device comprising:
a plurality of network ports for communication with a plurality of nodes on a computer network; a plurality of instrument ports for communication with a plurality of in-line tools; a switching fabric; a processor configured to perform or to cause the network switching device to perform operations comprising: associating at least one packet dispatch scheme, of a plurality of packet dispatch schemes, with each of a plurality of network ingress ports of a network switching device, such that a packet dispatch scheme associated with at least one network ingress port of the plurality of network ingress ports includes separate packet forwarding information for each of a plurality of different packet flows; receiving a packet at a first network ingress port of the network switching device, the packet having originated at a source node on a network and being destined for a destination node on the network; determining, for the packet, a packet dispatch scheme associated with the first network ingress port, based on a flow with which the packet is associated; and forwarding, by the network switching device, the packet to a second port of the network switching device according to the determined packet dispatch scheme.
20 . The network switching device of claim 19 , wherein the operations further comprise at least one of:
transmitting the packet, via the second port, to the destination node in response to determining that, according to the packet dispatch scheme, the second port is a network port of the network switching device, wherein the second port is communicatively coupled to the destination node; or transmitting the packet, via the second port, to an in-line tool in response to determining that, according to the packet dispatch scheme specific to the first port, the second port is an instrument port of the network switching device, wherein the instrument port is communicatively coupled to the in-line tool, and the in-line tool is associated with one of the plurality of specified sequences of in-line tools.Join the waitlist — get patent alerts
Track US2021234812A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.