CN109314706B - 网络隔离 - Google Patents
网络隔离 Download PDFInfo
- Publication number
- CN109314706B CN109314706B CN201780035216.3A CN201780035216A CN109314706B CN 109314706 B CN109314706 B CN 109314706B CN 201780035216 A CN201780035216 A CN 201780035216A CN 109314706 B CN109314706 B CN 109314706B
- Authority
- CN
- China
- Prior art keywords
- packet
- routing
- node
- gateway
- downstream
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000002955 isolation Methods 0.000 title claims abstract description 69
- 238000011144 upstream manufacturing Methods 0.000 claims abstract description 56
- 238000000034 method Methods 0.000 claims abstract description 20
- 230000004044 response Effects 0.000 claims description 11
- 230000000903 blocking effect Effects 0.000 claims description 6
- 238000004891 communication Methods 0.000 description 34
- 238000010586 diagram Methods 0.000 description 9
- 230000003287 optical effect Effects 0.000 description 4
- 238000005516 engineering process Methods 0.000 description 3
- 238000011156 evaluation Methods 0.000 description 3
- 230000006870 function Effects 0.000 description 3
- 238000012986 modification Methods 0.000 description 3
- 230000004048 modification Effects 0.000 description 3
- 230000004075 alteration Effects 0.000 description 2
- 230000008901 benefit Effects 0.000 description 2
- 238000001914 filtration Methods 0.000 description 2
- 230000000977 initiatory effect Effects 0.000 description 2
- 238000004519 manufacturing process Methods 0.000 description 2
- 230000008569 process Effects 0.000 description 2
- 230000000644 propagated effect Effects 0.000 description 2
- 239000004065 semiconductor Substances 0.000 description 2
- 238000004590 computer program Methods 0.000 description 1
- 230000001419 dependent effect Effects 0.000 description 1
- 230000002093 peripheral effect Effects 0.000 description 1
- 239000007787 solid Substances 0.000 description 1
- 230000003068 static effect Effects 0.000 description 1
- 230000001360 synchronised effect Effects 0.000 description 1
- 230000002123 temporal effect Effects 0.000 description 1
- 230000007723 transport mechanism Effects 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0227—Filtering policies
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/28—Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
- H04L12/46—Interconnection of networks
- H04L12/4641—Virtual LANs, VLANs, e.g. virtual private networks [VPN]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L45/00—Routing or path finding of packets in data switching networks
- H04L45/22—Alternate routing
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L45/00—Routing or path finding of packets in data switching networks
- H04L45/24—Multipath
- H04L45/247—Multipath using M:N active or standby paths
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L49/00—Packet switching elements
- H04L49/35—Switches specially adapted for specific applications
- H04L49/354—Switches specially adapted for specific applications for supporting virtual local area networks [VLAN]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/20—Network architectures or network communication protocols for network security for managing network security; network security policies in general
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L69/00—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
- H04L69/30—Definitions, standards or architectural aspects of layered protocol stacks
- H04L69/32—Architecture of open systems interconnection [OSI] 7-layer type protocol stacks, e.g. the interfaces between the data link level and the physical level
- H04L69/322—Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions
- H04L69/325—Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions in the network layer [OSI layer 3], e.g. X.25
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/28—Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
- H04L12/44—Star or tree networks
- H04L2012/445—Star or tree networks with switching in a hub, e.g. ETHERNET switch
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L45/00—Routing or path finding of packets in data switching networks
- H04L45/74—Address processing for routing
- H04L45/745—Address table lookup; Address filtering
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims (20)
Applications Claiming Priority (3)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US15/175,100 | 2016-06-07 | ||
US15/175,100 US10148618B2 (en) | 2016-06-07 | 2016-06-07 | Network isolation |
PCT/US2017/036080 WO2017214097A1 (en) | 2016-06-07 | 2017-06-06 | Network isolation |
Publications (2)
Publication Number | Publication Date |
---|---|
CN109314706A CN109314706A (zh) | 2019-02-05 |
CN109314706B true CN109314706B (zh) | 2022-03-08 |
Family
ID=59054335
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201780035216.3A Active CN109314706B (zh) | 2016-06-07 | 2017-06-06 | 网络隔离 |
Country Status (4)
Country | Link |
---|---|
US (1) | US10148618B2 (zh) |
EP (1) | EP3466027A1 (zh) |
CN (1) | CN109314706B (zh) |
WO (1) | WO2017214097A1 (zh) |
Families Citing this family (7)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20190141616A1 (en) * | 2017-11-08 | 2019-05-09 | Carrier Corporation | Mesh networking using peer to peer messages |
CN110009767B (zh) | 2017-11-08 | 2023-04-28 | 开利公司 | 使用对等消息用于接待实体的网状联网 |
US10855581B2 (en) * | 2017-11-10 | 2020-12-01 | Fabriscale Technologies AS | System and method of computing ethernet routing paths |
US11212224B1 (en) | 2019-01-23 | 2021-12-28 | Palantir Technologies Inc. | Systems and methods for isolating network traffic of multiple users across networks of computing platforms |
CN109981462B (zh) * | 2019-03-28 | 2021-06-22 | 新华三技术有限公司 | 一种报文处理方法及装置 |
CN111586041A (zh) * | 2020-05-07 | 2020-08-25 | 英赛克科技(北京)有限公司 | 工业单向隔离网闸系统和数据传输方法 |
CN112631804B (zh) * | 2020-12-25 | 2024-05-24 | 杭州涂鸦信息技术有限公司 | 基于隔离环境的服务调用请求处理方法及计算机设备 |
Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2004090741A2 (en) * | 2001-08-14 | 2004-10-21 | Riverhead Networks Inc. | Selective diversion and injection of communication traffic |
WO2012015410A1 (en) * | 2010-07-29 | 2012-02-02 | Hewlett-Packard Development Company, L. P. | A device and method for egress packet forwarding using mesh tagging |
CN104348723A (zh) * | 2013-07-30 | 2015-02-11 | 华为技术有限公司 | 生成路由表项的方法和边界网关协议演讲者 |
Family Cites Families (22)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US5920699A (en) | 1996-11-07 | 1999-07-06 | Hewlett-Packard Company | Broadcast isolation and level 3 network switch |
US6741592B1 (en) | 2000-05-22 | 2004-05-25 | Cisco Technology, Inc. | Private VLANs |
US7200145B1 (en) | 2000-05-22 | 2007-04-03 | Cisco Technology, Inc. | Private VLANs |
US6914905B1 (en) | 2000-06-16 | 2005-07-05 | Extreme Networks, Inc. | Method and system for VLAN aggregation |
US7095741B1 (en) | 2000-12-20 | 2006-08-22 | Cisco Technology, Inc. | Port isolation for restricting traffic flow on layer 2 switches |
US7660292B2 (en) | 2002-06-27 | 2010-02-09 | Broadcom Corporation | System and method for isolating network clients |
US6996659B2 (en) * | 2002-07-30 | 2006-02-07 | Lsi Logic Corporation | Generic bridge core |
JP4444834B2 (ja) | 2002-10-04 | 2010-03-31 | テレフオンアクチーボラゲット エル エム エリクソン(パブル) | アクセスネットワークに接続されるホストの分離 |
WO2005112390A1 (en) | 2004-05-12 | 2005-11-24 | Alcatel | Automated containment of network intruder |
US7808992B2 (en) | 2004-12-30 | 2010-10-05 | Cisco Technology, Inc. | Platform independent implementation of private VLANS |
US7953089B1 (en) | 2006-05-16 | 2011-05-31 | Cisco Technology, Inc. | Systems and methods for multicast switching in a private VLAN |
US20070274230A1 (en) * | 2006-05-23 | 2007-11-29 | Werber Ryan A | System and method for modifying router firmware |
EP1998505B1 (en) | 2007-05-29 | 2010-05-12 | PacketFront Systems AB | Method of connecting VLAN systems to other networks via a router |
RU2540017C2 (ru) | 2008-07-24 | 2015-01-27 | Мейдзи Сейка Фарма Ко,Лтд.,Jp | Выделенный полинуклеотид, кодирующий полипептид, вовлеченный в биосинтез пирипиропена а, вектор и клетка-хозяин содержащие такой полинуклеотид и способ получения предшественника пирипиропена а (варианты) |
US8737398B2 (en) | 2008-12-31 | 2014-05-27 | Schneider Electric USA, Inc. | Communication module with network isolation and communication filter |
US8369344B1 (en) | 2009-03-18 | 2013-02-05 | Extreme Networks, Inc. | Customer isolation using a common forwarding database with hardware learning support |
US8341725B2 (en) | 2009-07-30 | 2012-12-25 | Calix, Inc. | Secure DHCP processing for layer two access networks |
CN101883160B (zh) * | 2010-07-09 | 2013-03-20 | 杭州华三通信技术有限公司 | 多接口网络设备和多接口网络设备的报文发送方法 |
US9363207B2 (en) | 2011-06-24 | 2016-06-07 | Cisco Technology, Inc. | Private virtual local area network isolation |
IN2014DN06766A (zh) * | 2012-01-24 | 2015-05-22 | L3 Comm Corp | |
CN104205943B (zh) * | 2012-03-05 | 2018-03-09 | 富士通株式会社 | 通信系统和通信方法 |
CN103001877A (zh) * | 2012-12-11 | 2013-03-27 | 太仓市同维电子有限公司 | 一种用于家庭网关产品上的数据绑定方法 |
-
2016
- 2016-06-07 US US15/175,100 patent/US10148618B2/en active Active
-
2017
- 2017-06-06 CN CN201780035216.3A patent/CN109314706B/zh active Active
- 2017-06-06 WO PCT/US2017/036080 patent/WO2017214097A1/en unknown
- 2017-06-06 EP EP17729738.9A patent/EP3466027A1/en active Pending
Patent Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2004090741A2 (en) * | 2001-08-14 | 2004-10-21 | Riverhead Networks Inc. | Selective diversion and injection of communication traffic |
WO2012015410A1 (en) * | 2010-07-29 | 2012-02-02 | Hewlett-Packard Development Company, L. P. | A device and method for egress packet forwarding using mesh tagging |
CN104348723A (zh) * | 2013-07-30 | 2015-02-11 | 华为技术有限公司 | 生成路由表项的方法和边界网关协议演讲者 |
Also Published As
Publication number | Publication date |
---|---|
WO2017214097A1 (en) | 2017-12-14 |
EP3466027A1 (en) | 2019-04-10 |
US10148618B2 (en) | 2018-12-04 |
US20170353431A1 (en) | 2017-12-07 |
CN109314706A (zh) | 2019-02-05 |
WO2017214097A8 (en) | 2019-02-07 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN109314706B (zh) | 网络隔离 | |
CN110113291B (zh) | 用于在业务功能链域之间进行互通的方法和设备 | |
US8874789B1 (en) | Application based routing arrangements and method thereof | |
US9686194B2 (en) | Adaptive multi-interface use for content networking | |
US9992106B2 (en) | Generating a host route | |
US10263808B2 (en) | Deployment of virtual extensible local area network | |
US10567345B2 (en) | Verifying firewall filter entries using rules associated with an access control list (ACL) template | |
US10461958B2 (en) | Packet transmission method and apparatus | |
US20140230044A1 (en) | Method and Related Apparatus for Authenticating Access of Virtual Private Cloud | |
US20150326528A1 (en) | Enforcement of Network-Wide Context Aware Policies | |
US20130223287A1 (en) | Layer two extensions | |
US10122548B2 (en) | Services execution | |
US11483379B2 (en) | Enhancing network services based on edge clouds | |
CN107948150A (zh) | 报文转发方法及装置 | |
CN115380516B (zh) | 基于lisp的软件定义网络中策略更改的通信 | |
CN109218182B (zh) | 一种路由信息的同步方法及装置 | |
US10333830B2 (en) | Passive routing in mesh network | |
US9231862B2 (en) | Selective service based virtual local area network flooding | |
CN107483334B (zh) | 一种报文转发的方法及装置 | |
WO2015100644A1 (zh) | 一种处理报文的方法和装置 | |
JP6256471B2 (ja) | 通信装置、通信方法、及びプログラム | |
WO2023232071A1 (zh) | 一种源地址验证的方法、网络设备及通信系统 | |
EP4191965A1 (en) | Preserving consistency of redundant border gateway protocol link state topology information | |
CN111083144B (zh) | 一种服务质量策略配置方法及装置 | |
US20220045956A1 (en) | Policy based routing in extranet networks |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
TA01 | Transfer of patent application right | ||
TA01 | Transfer of patent application right |
Effective date of registration: 20210517 Address after: Baden, Switzerland Applicant after: ABB grid Switzerland AG Address before: Baden, Switzerland Applicant before: ABB Switzerland Co.,Ltd. |
|
CB02 | Change of applicant information | ||
CB02 | Change of applicant information |
Address after: Swiss Baden Applicant after: Hitachi energy Switzerland AG Address before: Swiss Baden Applicant before: ABB grid Switzerland AG |
|
GR01 | Patent grant | ||
GR01 | Patent grant | ||
TR01 | Transfer of patent right | ||
TR01 | Transfer of patent right |
Effective date of registration: 20240104 Address after: Zurich, SUI Patentee after: Hitachi Energy Co.,Ltd. Address before: Swiss Baden Patentee before: Hitachi energy Switzerland AG |