Policy tracking in a network that includes virtual devices

US2016197936A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016197936-A1
Application numberUS-201514588850-A
CountryUS
Kind codeA1
Filing dateJan 2, 2015
Priority dateJan 2, 2015
Publication dateJul 7, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method performed by a network device includes: receiving an input indicating a change in an auxiliary network from a first configuration to a second configuration, wherein the auxiliary network is configured to obtain copies of packets from a traffic production network; determining a first network policy, wherein the first network policy is for application in the auxiliary network when the auxiliary network is in the first configuration; and determining a second network policy by the network device based on the received input and the first network policy, wherein the second network policy is for application in the auxiliary network when the auxiliary network is in the second configuration.

First claim

Opening claim text (preview).

What is claimed: 1 . A method performed by a network device, comprising: receiving an input indicating a change in an auxiliary network from a first configuration to a second configuration, wherein the auxiliary network is configured to obtain copies of packets from a traffic production network; determining a first network policy, wherein the first network policy is for application in the auxiliary network when the auxiliary network is in the first configuration; and determining a second network policy by the network device based on the received input and the first network policy, wherein the second network policy is for application in the auxiliary network when the auxiliary network is in the second configuration. 2 . The method of claim 1 , wherein the first network policy prescribes the copies of the packets to be forwarded to one or more instrument ports for transmission to one or more network monitoring instruments. 3 . The method of claim 1 , wherein the act of determining the second network policy is performed by the network device automatically in response to the received input. 4 . The method of claim 1 , wherein the second network policy is for replacing the first network policy, and wherein the second network policy is configured to achieve an objective previously desired to be achieved by the first network policy. 5 . The method of claim 1 , wherein the input is received from a vCenter. 6 . The method of claim 1 , wherein the input is received from a controller that is communicatively coupled to the network device. 7 . The method of claim 1 , wherein the network device comprises a fabric manager configured to manage one or more service nodes in the auxiliary network. 8 . The method of claim 1 , wherein the auxiliary network comprises a virtual machine, and wherein the change in the auxiliary network comprises a movement of the virtual machine from a first host to a second host. 9 . The method of claim 1 , wherein the auxiliary network comprises a vNIC, and wherein the change in the auxiliary network comprises a movement of the vNIC. 10 . The method of claim 1 , wherein the change in the auxiliary network comprises a change in a configuration of a physical switch device in the auxiliary network. 11 . The method of claim 1 , wherein the second network policy is the same as the first network policy. 12 . The method of claim 1 , wherein the network device is implemented in a computer, a laptop, a server, a tablet, an iPad, or a phone. 13 . The method of claim 1 , wherein the network device comprises multiple appliances that are stacked together or that are communicatively coupled. 14 . The method of claim 1 , further comprising deploying the second network policy for application in the auxiliary network. 15 . A network device, comprising: a communication component for receiving an input indicating a change in an auxiliary network from a first configuration to a second configuration, wherein the auxiliary network is configured to obtain copies of packets from a traffic production network; and a processing unit coupled to the communication component, wherein the processing unit is configured for determining a first network policy, wherein the first network policy is for application in the auxiliary network when the auxiliary network is in the first configuration; and determining a second network policy by the network device based on the received input and the first network policy, wherein the second network policy is for application in the auxiliary network when the auxiliary network is in the second configuration. 16 . The network device of claim 15 , wherein the first network policy prescribes the copies of the packets to be forwarded to one or more instrument ports for transmission to one or more network monitoring instruments. 17 . The network device of claim 15 , wherein the processing unit is configured to determine the second network policy automatically in response to the received input. 18 . The network device of claim 15 , wherein the second network policy is for replacing the first network policy, and wherein the second network policy is configured to achieve an objective previously desired to be achieved by the first network policy. 19 . The network device of claim 15 , wherein the communication component is configured to receive the input from a vCenter. 20 . The network device of claim 15 , wherein the communication component is configured to receive the input from a controller that is communicatively coupled to the network device. 21 . The network device of claim 15 , wherein the network device comprises a fabric manager configured to manage one or more service nodes in the auxiliary network. 22 . The network device of claim 15 , wherein the auxiliary network comprises a virtual machine, and wherein the change in the auxiliary network comprises a movement of the virtual machine from a first host to a second host. 23 . The network device of claim 15 , wherein the auxiliary network comprises a vNIC, and wherein the change in the auxiliary network comprises a movement of the vNIC. 24 . The network device of claim 15 , wherein the change in the auxiliary network comprises a change in a configuration of a physical switch device in the auxiliary network. 25 . The network device of claim 15 , wherein the second network policy is the same as the first network policy. 26 . The network device of claim 15 , wherein the network device is implemented in a computer, a laptop, a server, a tablet, an iPad, or a phone. 27 . The network device of claim 15 , wherein the network device comprises multiple appliances that are stacked together or that are communicatively coupled. 28 . The network device of claim 15 , wherein the processing unit is further configure to deploy the second network policy for application in the auxiliary network. 29 . A computer product having a non-transitory medium storing a set of instruction, an execution of which by a processing unit in a network device causes a method to be performed, the method comprising: receiving an input indicating a change in an auxiliary network from a first configuration to a second configuration, wherein the auxiliary network is configured to obtain copies of packets from a traffic production network; determining a first network policy, wherein the first network policy is for application in the auxiliary network when the auxiliary network is in the first configuration; and determining a second network policy based on the received input and the first network policy, wherein the second network policy is for application in the auxiliary network when the auxiliary network is in the second configuration.

Assignees

Inventors

Classifications

  • Network monitoring probes · CPC title

  • H04L43/062Primary

    related to network traffic · CPC title

  • the condition being an adaptation, e.g. in response to network events · CPC title

  • H04L63/107Primary

    wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals · CPC title

  • based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016197936A1 cover?
A method performed by a network device includes: receiving an input indicating a change in an auxiliary network from a first configuration to a second configuration, wherein the auxiliary network is configured to obtain copies of packets from a traffic production network; determining a first network policy, wherein the first network policy is for application in the auxiliary network when the au…
Who is the assignee on this patent?
Gigamon Inc
What technology area does this patent fall under?
Primary CPC classification H04L43/062. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Jul 07 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).