JP4332033B2 - L2装置でのレイヤ3/レイヤ7・ファイアウォール実施方法及び装置 - Google Patents
L2装置でのレイヤ3/レイヤ7・ファイアウォール実施方法及び装置 Download PDFInfo
- Publication number
- JP4332033B2 JP4332033B2 JP2003533141A JP2003533141A JP4332033B2 JP 4332033 B2 JP4332033 B2 JP 4332033B2 JP 2003533141 A JP2003533141 A JP 2003533141A JP 2003533141 A JP2003533141 A JP 2003533141A JP 4332033 B2 JP4332033 B2 JP 4332033B2
- Authority
- JP
- Japan
- Prior art keywords
- packet
- zone
- layer
- security
- packets
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Lifetime
Links
- 238000000034 method Methods 0.000 title claims description 38
- 238000004891 communication Methods 0.000 claims description 58
- 238000007689 inspection Methods 0.000 claims description 39
- VYMDGNCVAMGZFE-UHFFFAOYSA-N phenylbutazonum Chemical compound O=C1C(CCCC)C(=O)N(C=2C=CC=CC=2)N1C1=CC=CC=C1 VYMDGNCVAMGZFE-UHFFFAOYSA-N 0.000 claims description 26
- 238000012216 screening Methods 0.000 claims description 16
- 238000001914 filtration Methods 0.000 claims description 11
- 230000008569 process Effects 0.000 claims description 9
- 230000007246 mechanism Effects 0.000 claims description 4
- 230000000717 retained effect Effects 0.000 claims description 4
- 238000012546 transfer Methods 0.000 claims description 4
- 238000013507 mapping Methods 0.000 claims description 2
- 239000000523 sample Substances 0.000 description 9
- 238000012545 processing Methods 0.000 description 8
- 230000004044 response Effects 0.000 description 4
- 230000008901 benefit Effects 0.000 description 3
- 238000012805 post-processing Methods 0.000 description 2
- 238000012360 testing method Methods 0.000 description 2
- 230000005540 biological transmission Effects 0.000 description 1
- 230000008859 change Effects 0.000 description 1
- 238000010586 diagram Methods 0.000 description 1
- 239000000284 extract Substances 0.000 description 1
- 230000002452 interceptive effect Effects 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 230000008520 organization Effects 0.000 description 1
- 238000007781 pre-processing Methods 0.000 description 1
- 238000003672 processing method Methods 0.000 description 1
- 230000011218 segmentation Effects 0.000 description 1
- 238000000638 solvent extraction Methods 0.000 description 1
- 230000001960 triggered effect Effects 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0227—Filtering policies
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/16—Implementing security features at a particular protocol layer
- H04L63/162—Implementing security features at a particular protocol layer at the data link layer
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/102—Entity profiles
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Small-Scale Networks (AREA)
Description
パケットの流れ
Claims (20)
- 第1のセキュリティゾーンに含まれる端末ユニットに連結される少なくとも1つのポートと、
前記第1のセキュリティゾーンとは異なる第2のセキュリティゾーンに含まれる端末ユニットに連結される少なくとも1つのポートと、
前記第1及び第2のセキュリティゾーンのうち一方のセキュリティゾーンから受信した各パケットに対して、該受信したパケットが他方のセキュリティゾーンに向かうインターゾーンパケットであるか否かを判定するコントローラと、
インターゾーンパケットをゾーン固有のポリシーを使用して検査しフィルタリングするファイアウォールエンジンと、
受信したイントラゾーンパケットを、前記ファイアウォールエンジンによる検査をすることなく、MACアドレスと対応するポートのテーブルを使用してイントラゾーン転送に関連するポートへと転送し、前記ファイアウォールエンジンによる検査後も保持されているインターゾーンパケットをインターゾーン転送に関連するポートへ転送するレイヤ2スイッチングエンジンと、
を備えるレイヤ2装置。 - 受信した各パケットに対して、それぞれが別々のセキュリティドメインを表し、関連するゾーンを出入りするパケットの検査に用いられる関連するポリシーを有するイントラゾーン又はインターゾーンのどちらへ前記受信パケットを転送するかを判定するコントローラと、
受信したインターゾーンパケットをゾーン固有のポリシーを使用して検査しフィルタリングするファイアウォールエンジンと、
レイヤ2スイッチングエンジンとを備え、前記レイヤ2スイッチングエンジンは、
受信したイントラゾーンパケットを、前記ファイアウォールエンジンによる検査をすることなく、MACアドレスと対応するポートのテーブルを使用してイントラゾーンポートへとルートし、
前記ファイアウォールエンジンによる検査後も保持されている検査されたインターゾーンパケットをインターゾーンポートへルートするように動作可能である、
レイヤ2装置。 - 受信した各パケットに対して、前記受信パケットを、複数のゾーンの間にあるインターゾーン又は一のゾーン内にあるイントラゾーンのどちらに転送するかどうかを判定するコントローラであって、各ゾーンが別々のセキュリティドメインを表す、コントローラと、
インターゾーンパケットを、レイヤ2プロトコルを使用してルートすることを許可する前に、ゾーン固有のポリシーを使用して検査しフィルタリングするファイアウォールエンジンと、
を備え、
イントラゾーンパケットが前記ファイアウォールエンジンにより検査されない、
レイヤ2装置。 - 受信した各パケットに対して、前記受信パケットが、セキュリティ検査に基づいて第1のセキュリティドメインから第2のセキュリティドメインへの転送が許可されているインターゾーンパケットであるか、セキュリティ検査をすることなく前記第1及び第2セキュリティドメインの少なくとも一つの内での転送が許可されているイントラゾーンパケットであるかを判定するコントローラと、
インターゾーンパケットを、レイヤ2プロトコルを使用してゾーン間をルートする前に、ゾーン固有のポリシーを使用して検査しフィルタリングする検査装置と、
を備えるレイヤ2装置。 - それぞれが別々のセキュリティドメインを表す複数のゾーンを有するパケット交換通信システムにおけるレイヤ2装置であって、
受信した各パケットに対して、前記受信パケットをセキュリティポリシーに照らして検査するかどうかを判定するコントローラと、
前記コントローラによって検査が必要であると識別されたパケットのみをゾーン固有のポリシーに基づいて検査しフィルタリングする検査装置と、
検査したパケットを、レイヤ2プロトコルを使用してレイヤ2ヘッダ情報にしたがって第1のセキュリティゾーンから第2のセキュリティゾーンへ転送し、検査されなかったパケットを前記第1又は第2のセキュリティゾーン内で転送するレイヤ2コントローラと、
を備えるレイヤ2装置。 - 前記検査装置がファイアウォールである、請求項5記載の装置。
- 前記検査装置がレイヤ3ファイアウォール装置である、請求項5記載の装置。
- 前記検査装置がレイヤ4ファイアウォール装置である、請求項5記載の装置。
- 前記検査装置がレイヤ7ファイアウォール装置である、請求項5記載の装置。
- 前記検査装置が、レイヤ2ヘッダ情報以外のレイヤ情報に基づいてフィルタリングするファイアウォールである、請求項5記載の装置。
- 前記コントローラはセキュリティゾーン間を渡される各パケットを判定し、前記検査装置はインターゾーントラフィックのみを処理する、請求項5記載の装置。
- 前記コントローラは単一のセキュリティゾーンに留まる各パケットを判定し、イントラゾーンパケットを前記検査装置を経由させずに前記レイヤ2コントローラに転送する、請求項5記載の装置。
- 前記装置は、所与のパケットのレイヤ2ヘッダのMACアドレスを使用して、そのパケットを転送する前記装置の出口を決定する、請求項12記載の装置。
- 検査されるパケットを記憶する記憶要素と、
装置を通過するようにパケットを転送するレイヤ2コントローラとをさらに備え、前記レイヤ2コントローラは、
所与のパケットを転送するための出口を、前記所与のパケット中のその宛先MACアドレスを使用して決定するステップと、
MACアドレスと関連する出口ノードのマッピングを含むMACアドレステーブルと、
を含む、請求項5記載の装置。 - 前記記憶要素は第1の部分及び第2の部分を含み、前記第1の部分は前記装置を通過するように転送されるパケットを記憶し、前記第2の部分は検査待ちのパケットを記憶する、請求項14記載の装置。
- 前記装置がレイヤ2スイッチである、請求項5記載の装置。
- 前記装置がレイヤ2ブリッジである、請求項5記載の装置。
- 通信ネットワークにおいてパケットを転送する方法であって、
レイヤ2装置でパケットを受信するステップと、
前記受信パケットが単一のゾーン内で転送されるイントラゾーンパケットであるか、ゾーン間で転送されるインターゾーンパケットであるかを判定するステップであって、各ゾーンが別々のセキュリティドメインを表す、ステップと、
レイヤ2プロトコルを使用してインターゾーンパケットをゾーン間でルートする前に、ゾーン固有のポリシーを使用して前記インターゾーンパケットを検査しフィルタリングするステップと、
セキュリティ検査及びフィルタリングを行うことなく前記イントラゾーンパケットを転送するステップと、
を含む方法。 - 通信ネットワークにおいてパケットを転送する方法であって、
レイヤ2装置でパケットを受信するステップと、
前記受信パケットをセキュリティポリシーに照らして検査するかどうかを判定するステップと、
識別したパケットを、第1のセキュリティゾーンから前記レイヤ2装置を経由して前記第1のセキュリティゾーンと異なる第2のセキュリティゾーンに転送する前に、ゾーン固有のポリシーを使用して検査しフィルタリングするステップと、
検査されなかったパケットを前記第1又は第2のセキュリティゾーン内で転送するステップと、
を含む方法。 - 各ユーザ側に暗号化サービス及び解読サービスを必要とせずに、ユーザ間の安全な通信を提供する仮想プライベートネットワークであって、
通信ネットワークにわたって第1のユーザと第2のユーザとを連結する第1のレイヤ2装置及び第2のレイヤ2装置を備え、前記第1のレイヤ2装置及び第2のレイヤ2装置のそれぞれは、
受信パケットが前記仮想プライベートネットワークに関連付けられるかどうかを判定するスクリーニングメカニズムと、
レイヤ2プロトコルを使用して、信頼された前記第1及び第2のレイヤ2装置のうち一の装置を通過するようにパケットを転送する前に、前記仮想プライベートネットワークに関連付けられたこのパケットに対して作動する暗号化サービス及び解読サービスと、を含む
仮想プライベートネットワーク。
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US09/967,878 US7302700B2 (en) | 2001-09-28 | 2001-09-28 | Method and apparatus for implementing a layer 3/layer 7 firewall in an L2 device |
PCT/US2002/030835 WO2003030004A1 (en) | 2001-09-28 | 2002-09-26 | Method and apparatus for implementing a layer 3/layer 7 firewall in an l2 device |
Publications (2)
Publication Number | Publication Date |
---|---|
JP2005505175A JP2005505175A (ja) | 2005-02-17 |
JP4332033B2 true JP4332033B2 (ja) | 2009-09-16 |
Family
ID=25513451
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
JP2003533141A Expired - Lifetime JP4332033B2 (ja) | 2001-09-28 | 2002-09-26 | L2装置でのレイヤ3/レイヤ7・ファイアウォール実施方法及び装置 |
Country Status (8)
Country | Link |
---|---|
US (5) | US7302700B2 (ja) |
EP (2) | EP1438670B1 (ja) |
JP (1) | JP4332033B2 (ja) |
CN (1) | CN100437543C (ja) |
AU (1) | AU2002327757B2 (ja) |
CA (1) | CA2461866A1 (ja) |
IL (2) | IL161112A0 (ja) |
WO (1) | WO2003030004A1 (ja) |
Families Citing this family (111)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
GB2362482A (en) * | 2000-05-15 | 2001-11-21 | Ridgeway Systems & Software Lt | Direct slave addressing to indirect slave addressing |
GB2365256A (en) | 2000-07-28 | 2002-02-13 | Ridgeway Systems & Software Lt | Audio-video telephony with port address translation |
GB2369746A (en) * | 2000-11-30 | 2002-06-05 | Ridgeway Systems & Software Lt | Communications system with network address translation |
CA2439692A1 (en) * | 2001-03-01 | 2002-09-12 | Storeage Networking Technologies | Storage area network (san) security |
US7302700B2 (en) | 2001-09-28 | 2007-11-27 | Juniper Networks, Inc. | Method and apparatus for implementing a layer 3/layer 7 firewall in an L2 device |
US7571239B2 (en) * | 2002-01-08 | 2009-08-04 | Avaya Inc. | Credential management and network querying |
US20030163692A1 (en) * | 2002-01-31 | 2003-08-28 | Brocade Communications Systems, Inc. | Network security and applications to the fabric |
US8201252B2 (en) * | 2002-09-03 | 2012-06-12 | Alcatel Lucent | Methods and devices for providing distributed, adaptive IP filtering against distributed denial of service attacks |
US8185652B2 (en) * | 2002-11-15 | 2012-05-22 | Lantiq Deutschland Gmbh | Data switch and method of operating the data switch |
US7660980B2 (en) * | 2002-11-18 | 2010-02-09 | Liquidware Labs, Inc. | Establishing secure TCP/IP communications using embedded IDs |
US7549159B2 (en) * | 2004-05-10 | 2009-06-16 | Liquidware Labs, Inc. | System, apparatuses, methods and computer-readable media for determining the security status of a computer before establishing connection thereto |
US7386889B2 (en) * | 2002-11-18 | 2008-06-10 | Trusted Network Technologies, Inc. | System and method for intrusion prevention in a communications network |
US20060098649A1 (en) * | 2004-11-10 | 2006-05-11 | Trusted Network Technologies, Inc. | System, apparatuses, methods, and computer-readable media for determining security realm identity before permitting network connection |
US7591001B2 (en) * | 2004-05-14 | 2009-09-15 | Liquidware Labs, Inc. | System, apparatuses, methods and computer-readable media for determining the security status of a computer before establishing a network connection |
US20040123130A1 (en) * | 2002-12-20 | 2004-06-24 | Inrange Technologies Corporation | Method and apparatus for distributing and activating security parameters |
MY141160A (en) * | 2003-01-13 | 2010-03-31 | Multimedia Glory Sdn Bhd | System and method of preventing the transmission of known and unknown electronic content to and from servers or workstations connected to a common network |
US7697568B1 (en) * | 2003-03-03 | 2010-04-13 | Cisco Technology, Inc. | Method and system for automatic modem bandwidth detection in a router |
WO2004090675A2 (en) * | 2003-04-03 | 2004-10-21 | Commvault Systems, Inc. | System and method for performing storage operations through a firewall |
US20040210754A1 (en) * | 2003-04-16 | 2004-10-21 | Barron Dwight L. | Shared security transform device, system and methods |
US7523485B1 (en) | 2003-05-21 | 2009-04-21 | Foundry Networks, Inc. | System and method for source IP anti-spoofing security |
US7516487B1 (en) | 2003-05-21 | 2009-04-07 | Foundry Networks, Inc. | System and method for source IP anti-spoofing security |
EP1634175B1 (en) * | 2003-05-28 | 2015-06-24 | Citrix Systems, Inc. | Multilayer access control security system |
US20040255154A1 (en) * | 2003-06-11 | 2004-12-16 | Foundry Networks, Inc. | Multiple tiered network security system, method and apparatus |
KR100503422B1 (ko) * | 2003-06-13 | 2005-07-22 | 한국전자통신연구원 | 이더넷 스위치, 포트다중화장치 및 방법 |
US7426577B2 (en) * | 2003-06-19 | 2008-09-16 | Avaya Technology Corp. | Detection of load balanced links in internet protocol netwoks |
US7876772B2 (en) * | 2003-08-01 | 2011-01-25 | Foundry Networks, Llc | System, method and apparatus for providing multiple access modes in a data communications network |
US7735114B2 (en) * | 2003-09-04 | 2010-06-08 | Foundry Networks, Inc. | Multiple tiered network security system, method and apparatus using dynamic user policy assignment |
US7774833B1 (en) | 2003-09-23 | 2010-08-10 | Foundry Networks, Inc. | System and method for protecting CPU against remote access attacks |
US7606916B1 (en) * | 2003-11-10 | 2009-10-20 | Cisco Technology, Inc. | Method and apparatus for load balancing within a computer system |
US7844731B1 (en) * | 2003-11-14 | 2010-11-30 | Symantec Corporation | Systems and methods for address spacing in a firewall cluster |
US8146148B2 (en) * | 2003-11-19 | 2012-03-27 | Cisco Technology, Inc. | Tunneled security groups |
US8528071B1 (en) | 2003-12-05 | 2013-09-03 | Foundry Networks, Llc | System and method for flexible authentication in a data communications network |
ATE413761T1 (de) * | 2004-03-02 | 2008-11-15 | Alcatel Lucent | Ein verfahren zur zugriffserteilung auf ein kommunikationsnetzwerk und entsprechende einrichtung |
CN1298141C (zh) * | 2004-05-20 | 2007-01-31 | 中国科学院软件研究所 | 实现安全交换网络数据的方法 |
US7624435B1 (en) * | 2004-07-26 | 2009-11-24 | Trend Micro Incorporated | Method and apparatus for managing digital assets |
US7636841B2 (en) | 2004-07-26 | 2009-12-22 | Intercall, Inc. | Systems and methods for secure data exchange in a distributed collaborative application |
GB2418110B (en) * | 2004-09-14 | 2006-09-06 | 3Com Corp | Method and apparatus for controlling traffic between different entities on a network |
US8261337B1 (en) | 2004-11-17 | 2012-09-04 | Juniper Networks, Inc. | Firewall security between network devices |
US8631450B1 (en) * | 2004-12-02 | 2014-01-14 | Entropic Communications, Inc. | Broadband local area network |
JP4381448B2 (ja) * | 2005-03-16 | 2009-12-09 | 富士通株式会社 | Ipネットワークにおけるマルチキャストツリー監視方法およびシステム |
US7881325B2 (en) * | 2005-04-27 | 2011-02-01 | Cisco Technology, Inc. | Load balancing technique implemented in a storage area network |
US7647434B2 (en) | 2005-05-19 | 2010-01-12 | Cisco Technology, Inc. | Technique for in order delivery of traffic across a storage area network |
KR100719118B1 (ko) * | 2005-10-27 | 2007-05-17 | 삼성전자주식회사 | 특정 영역에서의 디바이스 기능 제한 방법 및 시스템 |
WO2007055684A2 (en) * | 2005-11-09 | 2007-05-18 | Trusted Network Technologies, Inc. | Determining security realm identity before permitting network connection |
JP4482630B2 (ja) * | 2005-11-21 | 2010-06-16 | インターナショナル・ビジネス・マシーンズ・コーポレーション | 通信装置および通信方法 |
US7649875B2 (en) * | 2005-12-23 | 2010-01-19 | Beecher Phillip E | Networking layer extension |
US20070214502A1 (en) * | 2006-03-08 | 2007-09-13 | Mcalister Donald K | Technique for processing data packets in a communication network |
JP4823728B2 (ja) * | 2006-03-20 | 2011-11-24 | 富士通株式会社 | フレーム中継装置及びフレーム検査装置 |
US9001645B2 (en) * | 2006-05-17 | 2015-04-07 | Rajant Corporation | System and method for packet delivery backtracking |
JP4813970B2 (ja) * | 2006-05-29 | 2011-11-09 | 日本電信電話株式会社 | ブリッジ装置 |
US7522595B2 (en) * | 2006-06-16 | 2009-04-21 | Cisco Technology, Inc. | Communicating packets between forwarding contexts using virtual interfaces |
US8009566B2 (en) | 2006-06-26 | 2011-08-30 | Palo Alto Networks, Inc. | Packet classification in a network security device |
US8281360B2 (en) * | 2006-11-21 | 2012-10-02 | Steven Adams Flewallen | Control of communication ports of computing devices using policy-based decisions |
US8594085B2 (en) * | 2007-04-11 | 2013-11-26 | Palo Alto Networks, Inc. | L2/L3 multi-mode switch including policy processing |
US8341277B2 (en) * | 2007-07-03 | 2012-12-25 | International Business Machines Corporation | System and method for connecting closed, secure production network |
US8040888B1 (en) * | 2007-12-17 | 2011-10-18 | Integrated Device Technology, Inc. | Packet switch with port route tables |
US8640143B2 (en) * | 2008-02-12 | 2014-01-28 | International Business Machines Corporation | Method and system for providing preemptive response routing |
US8307422B2 (en) * | 2008-08-14 | 2012-11-06 | Juniper Networks, Inc. | Routing device having integrated MPLS-aware firewall |
US8316435B1 (en) * | 2008-08-14 | 2012-11-20 | Juniper Networks, Inc. | Routing device having integrated MPLS-aware firewall with virtual security system support |
US8713627B2 (en) | 2008-08-14 | 2014-04-29 | Juniper Networks, Inc. | Scalable security services for multicast in a router having integrated zone-based firewall |
US8175101B2 (en) * | 2008-08-15 | 2012-05-08 | Raytheon Company | Multicasting in a network using neighbor information |
US8873556B1 (en) | 2008-12-24 | 2014-10-28 | Palo Alto Networks, Inc. | Application based packet forwarding |
US20100265955A1 (en) * | 2009-04-17 | 2010-10-21 | Park Sung I | Cross layer routing (xrp) protocol |
CN102035821A (zh) * | 2009-09-29 | 2011-04-27 | 凹凸电子(武汉)有限公司 | 防火墙/虚拟专用网集成系统以及电路 |
US8127365B1 (en) | 2009-11-16 | 2012-02-28 | Trend Micro Incorporated | Origination-based content protection for computer systems |
US8424091B1 (en) | 2010-01-12 | 2013-04-16 | Trend Micro Incorporated | Automatic local detection of computer security threats |
JP5382451B2 (ja) | 2010-01-29 | 2014-01-08 | 日本電気株式会社 | フロントエンドシステム、フロントエンド処理方法 |
JP5454399B2 (ja) * | 2010-07-15 | 2014-03-26 | パナソニック株式会社 | ラージスケールnat検出装置、アプリケーション切替装置、ラージスケールnat検出方法およびアプリケーション切替方法 |
US8687649B2 (en) * | 2011-03-08 | 2014-04-01 | International Business Machines Corporation | Message forwarding toward a source end node in a converged network environment |
US9047441B2 (en) | 2011-05-24 | 2015-06-02 | Palo Alto Networks, Inc. | Malware analysis system |
US8695096B1 (en) | 2011-05-24 | 2014-04-08 | Palo Alto Networks, Inc. | Automatic signature generation for malicious PDF files |
US8516241B2 (en) | 2011-07-12 | 2013-08-20 | Cisco Technology, Inc. | Zone-based firewall policy model for a virtualized data center |
US8640251B1 (en) | 2011-12-14 | 2014-01-28 | Trend Micro Incorporated | Methods and systems for classifying computer documents into confidential levels using log information |
US8826452B1 (en) | 2012-01-18 | 2014-09-02 | Trend Micro Incorporated | Protecting computers against data loss involving screen captures |
US9419941B2 (en) * | 2012-03-22 | 2016-08-16 | Varmour Networks, Inc. | Distributed computer network zone based security architecture |
WO2013189059A1 (zh) | 2012-06-21 | 2013-12-27 | 华为技术有限公司 | 报文处理方法、装置、主机和网络系统 |
JP5445626B2 (ja) * | 2012-06-25 | 2014-03-19 | 横河電機株式会社 | ネットワーク管理システム |
US9100366B2 (en) | 2012-09-13 | 2015-08-04 | Cisco Technology, Inc. | Early policy evaluation of multiphase attributes in high-performance firewalls |
US11301514B2 (en) | 2013-03-02 | 2022-04-12 | Leon Guzenda | System and method to identify islands of nodes within a graph database |
US10789294B2 (en) * | 2013-03-02 | 2020-09-29 | Leon Guzenda | Method and system for performing searches of graphs as represented within an information technology system |
US9083732B2 (en) | 2013-04-12 | 2015-07-14 | Lenovo Enterprise Solutions (Singapore) Pte. Ltd. | Establishing communication between entities in a shared network |
US9917849B2 (en) * | 2013-05-01 | 2018-03-13 | Fortinet, Inc. | Security system for physical or virtual environments |
WO2015041706A1 (en) * | 2013-09-23 | 2015-03-26 | Mcafee, Inc. | Providing a fast path between two entities |
US9973472B2 (en) | 2015-04-02 | 2018-05-15 | Varmour Networks, Inc. | Methods and systems for orchestrating physical and virtual switches to enforce security boundaries |
US9560081B1 (en) | 2016-06-24 | 2017-01-31 | Varmour Networks, Inc. | Data network microsegmentation |
US20170006082A1 (en) * | 2014-06-03 | 2017-01-05 | Nimit Shishodia | Software Defined Networking (SDN) Orchestration by Abstraction |
DE102015002574B4 (de) * | 2015-02-27 | 2018-06-21 | Audi Ag | Kraftfahrzeug- Kommunikationsnetzwerk mit Switchvorrichtung |
US9467476B1 (en) | 2015-03-13 | 2016-10-11 | Varmour Networks, Inc. | Context aware microsegmentation |
US9438634B1 (en) | 2015-03-13 | 2016-09-06 | Varmour Networks, Inc. | Microsegmented networks that implement vulnerability scanning |
US10178070B2 (en) | 2015-03-13 | 2019-01-08 | Varmour Networks, Inc. | Methods and systems for providing security to distributed microservices |
US9609026B2 (en) | 2015-03-13 | 2017-03-28 | Varmour Networks, Inc. | Segmented networks that implement scanning |
US9756015B2 (en) * | 2015-03-27 | 2017-09-05 | International Business Machines Corporation | Creating network isolation between virtual machines |
US9525697B2 (en) | 2015-04-02 | 2016-12-20 | Varmour Networks, Inc. | Delivering security functions to distributed networks |
US10171507B2 (en) * | 2016-05-19 | 2019-01-01 | Cisco Technology, Inc. | Microsegmentation in heterogeneous software defined networking environments |
US9892622B2 (en) | 2016-05-27 | 2018-02-13 | At&T Intellectual Property I, L.P. | Emergency event virtual network function deployment and configuration |
US9787639B1 (en) | 2016-06-24 | 2017-10-10 | Varmour Networks, Inc. | Granular segmentation using events |
US10972437B2 (en) * | 2016-08-08 | 2021-04-06 | Talari Networks Incorporated | Applications and integrated firewall design in an adaptive private network (APN) |
US10298491B2 (en) * | 2016-08-25 | 2019-05-21 | Cisco Technology, Inc. | Efficient path detection and validation between endpoints in large datacenters |
US10645123B1 (en) * | 2016-12-28 | 2020-05-05 | Juniper Networks, Inc. | Network traffic switching for virtual machines |
US10791091B1 (en) * | 2018-02-13 | 2020-09-29 | Architecture Technology Corporation | High assurance unified network switch |
DE102018216959B4 (de) * | 2018-10-02 | 2020-11-12 | Continental Automotive Gmbh | Verfahren zur Absicherung eines Datenpakets durch eine Vermittlungsstelle in einem Netzwerk, Vermittlungsstelle und Kraftfahrzeug |
US11201854B2 (en) * | 2018-11-30 | 2021-12-14 | Cisco Technology, Inc. | Dynamic intent-based firewall |
DE102019210224A1 (de) * | 2019-07-10 | 2021-01-14 | Robert Bosch Gmbh | Vorrichtung und Verfahren für Angriffserkennung in einem Rechnernetzwerk |
US11336694B2 (en) * | 2019-08-05 | 2022-05-17 | Cisco Technology, Inc. | Scalable security policy architecture with segregated forwarding and security plane and hierarchical classes |
CN110830301B (zh) * | 2019-11-11 | 2022-04-22 | 国网江苏省电力有限公司检修分公司 | 基于安全加密的电力二次系统站控层拓扑扫描方法及装置 |
US11343234B2 (en) * | 2019-12-10 | 2022-05-24 | Cisco Technology, Inc. | Multi-domain extension to cloud security |
US11777993B2 (en) | 2021-01-30 | 2023-10-03 | Netskope, Inc. | Unified system for detecting policy enforcement issues in a cloud-based environment |
US11848949B2 (en) * | 2021-01-30 | 2023-12-19 | Netskope, Inc. | Dynamic distribution of unified policies in a cloud-based policy enforcement system |
US12015619B2 (en) | 2021-01-30 | 2024-06-18 | Netskope, Inc. | Dynamic routing of access request streams in a unified policy enforcement system |
US11831605B2 (en) * | 2021-03-29 | 2023-11-28 | Nokia Solutions And Networks Oy | Router firewall |
US20240179125A1 (en) * | 2022-11-30 | 2024-05-30 | Cisco Technology, Inc. | Service optimization in networks and cloud interconnects |
Family Cites Families (66)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JPH06311161A (ja) | 1993-04-23 | 1994-11-04 | Matsushita Electric Works Ltd | Lan用ハブ装置 |
US5485455A (en) * | 1994-01-28 | 1996-01-16 | Cabletron Systems, Inc. | Network having secure fast packet switching and guaranteed quality of service |
US5544322A (en) * | 1994-05-09 | 1996-08-06 | International Business Machines Corporation | System and method for policy-based inter-realm authentication within a distributed processing system |
US5617421A (en) | 1994-06-17 | 1997-04-01 | Cisco Systems, Inc. | Extended domain computer network using standard links |
US5608726A (en) * | 1995-04-25 | 1997-03-04 | Cabletron Systems, Inc. | Network bridge with multicast forwarding table |
US5889953A (en) * | 1995-05-25 | 1999-03-30 | Cabletron Systems, Inc. | Policy management and conflict resolution in computer networks |
US5684800A (en) * | 1995-11-15 | 1997-11-04 | Cabletron Systems, Inc. | Method for establishing restricted broadcast groups in a switched network |
US5781550A (en) * | 1996-02-02 | 1998-07-14 | Digital Equipment Corporation | Transparent and secure network gateway |
US5918018A (en) * | 1996-02-09 | 1999-06-29 | Secure Computing Corporation | System and method for achieving network separation |
US5768501A (en) * | 1996-05-28 | 1998-06-16 | Cabletron Systems | Method and apparatus for inter-domain alarm correlation |
US5842040A (en) * | 1996-06-18 | 1998-11-24 | Storage Technology Corporation | Policy caching method and apparatus for use in a communication device based on contents of one data unit in a subset of related data units |
CA2214911C (en) | 1996-09-11 | 2001-12-25 | Nippon Telegraph And Telephone Corporation | Contents transmission control method with user authentication functions and recording medium with the method recorded thereon |
US6101170A (en) * | 1996-09-27 | 2000-08-08 | Cabletron Systems, Inc. | Secure fast packet switch having improved memory utilization |
US5708654A (en) * | 1996-11-27 | 1998-01-13 | Arndt; Manfred R. | Method for detecting proxy ARP replies from devices in a local area network |
US5905859A (en) * | 1997-01-09 | 1999-05-18 | International Business Machines Corporation | Managed network device security method and apparatus |
US6591303B1 (en) * | 1997-03-07 | 2003-07-08 | Sun Microsystems, Inc. | Method and apparatus for parallel trunking of interfaces to increase transfer bandwidth |
US6301257B1 (en) * | 1997-03-19 | 2001-10-09 | Nortel Networks Limited | Method and apparatus for transmitting data frames between switches in a meshed data network |
US6212558B1 (en) * | 1997-04-25 | 2001-04-03 | Anand K. Antur | Method and apparatus for configuring and managing firewalls and security devices |
US5968176A (en) * | 1997-05-29 | 1999-10-19 | 3Com Corporation | Multilayer firewall system |
US5909686A (en) * | 1997-06-30 | 1999-06-01 | Sun Microsystems, Inc. | Hardware-assisted central processing unit access to a forwarding database |
US6049528A (en) * | 1997-06-30 | 2000-04-11 | Sun Microsystems, Inc. | Trunking ethernet-compatible networks |
US6088356A (en) * | 1997-06-30 | 2000-07-11 | Sun Microsystems, Inc. | System and method for a multi-layer network element |
US6775692B1 (en) * | 1997-07-31 | 2004-08-10 | Cisco Technology, Inc. | Proxying and unproxying a connection using a forwarding agent |
US6104700A (en) * | 1997-08-29 | 2000-08-15 | Extreme Networks | Policy based quality of service |
US6041058A (en) * | 1997-09-11 | 2000-03-21 | 3Com Corporation | Hardware filtering method and apparatus |
US6170012B1 (en) * | 1997-09-12 | 2001-01-02 | Lucent Technologies Inc. | Methods and apparatus for a computer network firewall with cache query processing |
US7143438B1 (en) * | 1997-09-12 | 2006-11-28 | Lucent Technologies Inc. | Methods and apparatus for a computer network firewall with multiple domain support |
US6141749A (en) * | 1997-09-12 | 2000-10-31 | Lucent Technologies Inc. | Methods and apparatus for a computer network firewall with stateful packet filtering |
US6098172A (en) * | 1997-09-12 | 2000-08-01 | Lucent Technologies Inc. | Methods and apparatus for a computer network firewall with proxy reflection |
US6154775A (en) * | 1997-09-12 | 2000-11-28 | Lucent Technologies Inc. | Methods and apparatus for a computer network firewall with dynamic rule processing with the ability to dynamically alter the operations of rules |
US6131120A (en) | 1997-10-24 | 2000-10-10 | Directory Logic, Inc. | Enterprise network management directory containing network addresses of users and devices providing access lists to routers and servers |
US6172981B1 (en) * | 1997-10-30 | 2001-01-09 | International Business Machines Corporation | Method and system for distributing network routing functions to local area network stations |
US6182226B1 (en) * | 1998-03-18 | 2001-01-30 | Secure Computing Corporation | System and method for controlling interactions between networks |
US6141755A (en) * | 1998-04-13 | 2000-10-31 | The United States Of America As Represented By The Director Of The National Security Agency | Firewall security apparatus for high-speed circuit switched networks |
US6456597B1 (en) * | 1998-05-04 | 2002-09-24 | Hewlett Packard Co. | Discovery of unknown MAC addresses using load balancing switch protocols |
JP4080599B2 (ja) * | 1998-06-17 | 2008-04-23 | 富士通株式会社 | 通信制御装置およびマルチキャスト対応lanに適用される通信制御方法 |
US6233688B1 (en) | 1998-06-30 | 2001-05-15 | Sun Microsystems, Inc. | Remote access firewall traversal URL |
US6430188B1 (en) * | 1998-07-08 | 2002-08-06 | Broadcom Corporation | Unified table for L2, L3, L4, switching and filtering |
US6304973B1 (en) * | 1998-08-06 | 2001-10-16 | Cryptek Secure Communications, Llc | Multi-level security network system |
US6438133B1 (en) * | 1998-09-09 | 2002-08-20 | Cisco Technology, Inc. | Load balancing mechanism for a translational bridge environment |
US6556541B1 (en) * | 1999-01-11 | 2003-04-29 | Hewlett-Packard Development Company, L.P. | MAC address learning and propagation in load balancing switch protocols |
IL128814A (en) * | 1999-03-03 | 2004-09-27 | Packet Technologies Ltd | Local network security |
US6993027B1 (en) * | 1999-03-17 | 2006-01-31 | Broadcom Corporation | Method for sending a switch indicator to avoid out-of-ordering of frames in a network switch |
US7643481B2 (en) * | 1999-03-17 | 2010-01-05 | Broadcom Corporation | Network switch having a programmable counter |
US6704278B1 (en) * | 1999-07-02 | 2004-03-09 | Cisco Technology, Inc. | Stateful failover of service managers |
US7051066B1 (en) * | 1999-07-02 | 2006-05-23 | Cisco Technology, Inc. | Integrating service managers into a routing infrastructure using forwarding agents |
US6742045B1 (en) * | 1999-07-02 | 2004-05-25 | Cisco Technology, Inc. | Handling packet fragments in a distributed network service environment |
US6633560B1 (en) * | 1999-07-02 | 2003-10-14 | Cisco Technology, Inc. | Distribution of network services among multiple service managers without client involvement |
US6549516B1 (en) * | 1999-07-02 | 2003-04-15 | Cisco Technology, Inc. | Sending instructions from a service manager to forwarding agents on a need to know basis |
US6650641B1 (en) * | 1999-07-02 | 2003-11-18 | Cisco Technology, Inc. | Network address translation using a forwarding agent |
US6606315B1 (en) * | 1999-07-02 | 2003-08-12 | Cisco Technology, Inc. | Synchronizing service instructions among forwarding agents using a service manager |
US6970913B1 (en) * | 1999-07-02 | 2005-11-29 | Cisco Technology, Inc. | Load balancing using distributed forwarding agents with application based feedback for different virtual machines |
US6735169B1 (en) * | 1999-07-02 | 2004-05-11 | Cisco Technology, Inc. | Cascading multiple services on a forwarding agent |
US6684253B1 (en) * | 1999-11-18 | 2004-01-27 | Wachovia Bank, N.A., As Administrative Agent | Secure segregation of data of two or more domains or trust realms transmitted through a common data channel |
US6754716B1 (en) * | 2000-02-11 | 2004-06-22 | Ensim Corporation | Restricting communication between network devices on a common network |
US7263719B2 (en) * | 2000-05-15 | 2007-08-28 | Hewlett-Packard Development Company, L.P. | System and method for implementing network security policies on a common network infrastructure |
US7031297B1 (en) | 2000-06-15 | 2006-04-18 | Avaya Communication Israel Ltd. | Policy enforcement switching |
US20020053020A1 (en) * | 2000-06-30 | 2002-05-02 | Raytheon Company | Secure compartmented mode knowledge management portal |
US7047561B1 (en) * | 2000-09-28 | 2006-05-16 | Nortel Networks Limited | Firewall for real-time internet applications |
JP3474548B2 (ja) * | 2001-04-09 | 2003-12-08 | アライドテレシス株式会社 | 集合建築物 |
US7212534B2 (en) * | 2001-07-23 | 2007-05-01 | Broadcom Corporation | Flow based congestion control |
US20030033463A1 (en) * | 2001-08-10 | 2003-02-13 | Garnett Paul J. | Computer system storage |
US7302700B2 (en) | 2001-09-28 | 2007-11-27 | Juniper Networks, Inc. | Method and apparatus for implementing a layer 3/layer 7 firewall in an L2 device |
JP2005215935A (ja) * | 2004-01-29 | 2005-08-11 | Vodafone Kk | ファイアウォール |
US7895431B2 (en) * | 2004-09-10 | 2011-02-22 | Cavium Networks, Inc. | Packet queuing, scheduling and ordering |
US7535907B2 (en) * | 2005-04-08 | 2009-05-19 | Oavium Networks, Inc. | TCP engine |
-
2001
- 2001-09-28 US US09/967,878 patent/US7302700B2/en not_active Expired - Lifetime
-
2002
- 2002-09-26 EP EP02763764.4A patent/EP1438670B1/en not_active Expired - Lifetime
- 2002-09-26 IL IL16111202A patent/IL161112A0/xx unknown
- 2002-09-26 EP EP13155632.6A patent/EP2595357B1/en not_active Expired - Lifetime
- 2002-09-26 WO PCT/US2002/030835 patent/WO2003030004A1/en active Application Filing
- 2002-09-26 CA CA002461866A patent/CA2461866A1/en not_active Abandoned
- 2002-09-26 JP JP2003533141A patent/JP4332033B2/ja not_active Expired - Lifetime
- 2002-09-26 CN CNB028213874A patent/CN100437543C/zh not_active Expired - Lifetime
- 2002-09-26 AU AU2002327757A patent/AU2002327757B2/en not_active Ceased
-
2004
- 2004-03-25 IL IL161112A patent/IL161112A/en active IP Right Grant
-
2007
- 2007-10-09 US US11/869,287 patent/US7779459B2/en not_active Expired - Lifetime
-
2010
- 2010-07-08 US US12/832,347 patent/US8291114B2/en not_active Expired - Lifetime
-
2012
- 2012-09-14 US US13/615,780 patent/US8689316B2/en not_active Expired - Fee Related
-
2014
- 2014-03-31 US US14/230,210 patent/US9407605B2/en not_active Expired - Fee Related
Also Published As
Publication number | Publication date |
---|---|
CN1575462A (zh) | 2005-02-02 |
EP1438670A1 (en) | 2004-07-21 |
US7302700B2 (en) | 2007-11-27 |
US20080034414A1 (en) | 2008-02-07 |
EP1438670A4 (en) | 2010-12-15 |
US7779459B2 (en) | 2010-08-17 |
US20140215600A1 (en) | 2014-07-31 |
EP2595357B1 (en) | 2018-08-29 |
IL161112A0 (en) | 2004-08-31 |
EP2595357A2 (en) | 2013-05-22 |
EP1438670B1 (en) | 2017-06-14 |
CN100437543C (zh) | 2008-11-26 |
US20100281533A1 (en) | 2010-11-04 |
EP2595357A3 (en) | 2014-08-20 |
AU2002327757B2 (en) | 2008-11-06 |
CA2461866A1 (en) | 2003-04-10 |
US8689316B2 (en) | 2014-04-01 |
US20030065944A1 (en) | 2003-04-03 |
US20130007839A1 (en) | 2013-01-03 |
IL161112A (en) | 2010-06-16 |
WO2003030004A1 (en) | 2003-04-10 |
US8291114B2 (en) | 2012-10-16 |
JP2005505175A (ja) | 2005-02-17 |
US9407605B2 (en) | 2016-08-02 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
JP4332033B2 (ja) | L2装置でのレイヤ3/レイヤ7・ファイアウォール実施方法及び装置 | |
US10701034B2 (en) | Intelligent sorting for N-way secure split tunnel | |
AU2002327757A1 (en) | Method and apparatus for implementing a layer 3/layer 7 firewall in an L2 device | |
US9385994B2 (en) | Network security device | |
US7496955B2 (en) | Dual mode firewall | |
US20100100616A1 (en) | Method and apparatus for controlling traffic between different entities on a network | |
US20050257256A1 (en) | Firewall load balancing using a single physical device | |
US20040030765A1 (en) | Local network natification | |
US7567522B2 (en) | Suppression of router advertisement | |
Loibl et al. | RFC 8955: Dissemination of flow specification rules | |
KR20030018018A (ko) | 패킷 컨트롤 시스템과 방법 | |
Miroshnichenko | Design and configuration of a company network: Case study AstraZeneca Russia | |
Jiang et al. | Measuring and evaluating the current BGP policy model | |
Donohue | Ccnp Switch 642-813 Quick Reference | |
Ee et al. | Simplifying Access Control in Enterprise Networks |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
A621 | Written request for application examination |
Free format text: JAPANESE INTERMEDIATE CODE: A621 Effective date: 20050916 |
|
A711 | Notification of change in applicant |
Free format text: JAPANESE INTERMEDIATE CODE: A712 Effective date: 20050916 |
|
RD03 | Notification of appointment of power of attorney |
Free format text: JAPANESE INTERMEDIATE CODE: A7423 Effective date: 20050916 |
|
A521 | Request for written amendment filed |
Free format text: JAPANESE INTERMEDIATE CODE: A821 Effective date: 20050916 |
|
A977 | Report on retrieval |
Free format text: JAPANESE INTERMEDIATE CODE: A971007 Effective date: 20080121 |
|
A131 | Notification of reasons for refusal |
Free format text: JAPANESE INTERMEDIATE CODE: A131 Effective date: 20080129 |
|
A521 | Request for written amendment filed |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20080430 |
|
RD03 | Notification of appointment of power of attorney |
Free format text: JAPANESE INTERMEDIATE CODE: A7423 Effective date: 20080430 |
|
A521 | Request for written amendment filed |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20080630 |
|
A521 | Request for written amendment filed |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20080820 |
|
A131 | Notification of reasons for refusal |
Free format text: JAPANESE INTERMEDIATE CODE: A131 Effective date: 20081021 |
|
A521 | Request for written amendment filed |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20081219 |
|
TRDD | Decision of grant or rejection written | ||
A01 | Written decision to grant a patent or to grant a registration (utility model) |
Free format text: JAPANESE INTERMEDIATE CODE: A01 Effective date: 20090609 |
|
A01 | Written decision to grant a patent or to grant a registration (utility model) |
Free format text: JAPANESE INTERMEDIATE CODE: A01 |
|
A61 | First payment of annual fees (during grant procedure) |
Free format text: JAPANESE INTERMEDIATE CODE: A61 Effective date: 20090619 |
|
R150 | Certificate of patent or registration of utility model |
Ref document number: 4332033 Country of ref document: JP Free format text: JAPANESE INTERMEDIATE CODE: R150 Free format text: JAPANESE INTERMEDIATE CODE: R150 |
|
FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20120626 Year of fee payment: 3 |
|
FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20130626 Year of fee payment: 4 |
|
R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
EXPY | Cancellation because of completion of term |