Secure mode VLANs systems and methods

US9537827B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-9537827-B1
Application numberUS-201514977021-A
CountryUS
Kind codeB1
Filing dateDec 21, 2015
Priority dateDec 21, 2015
Publication dateJan 3, 2017
Grant dateJan 3, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method includes binding, using a plurality of processors, a process to a wildcard address and a port on each of a plurality of nodes. The process receives, on a redirector node, a first request for a first address of a first volume located on the cluster from a first client. The first request is sent to the port and a first address associated with a first virtual local area network (VLAN) that is not the wildcard address. The process determines the first address from the first request and a name of the first VLAN based on the first address. The process determines a first node that contains information regarding the first volume and an address of the first node that is part of the first VLAN. The process determines that a volume identifier associated with the first volume of the first request is present on a volume list.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: binding, using a plurality of processors, a process to a wildcard address and a port on each of a plurality of nodes that are part of a cluster; receiving, by the process on a redirector node, a first request for a first address of a first volume located on the cluster from a first client, wherein the first request is sent to the port and a first address associated with a first virtual local area network (VLAN) that is not the wildcard address; determining, by the process on the redirector node, the first address from the first request; determining, by the process on the redirector node, a name of the first VLAN based on the first address; determining, by the process on the redirector node, a first node that contains information regarding the first volume; determining, by the process on the redirector node, an address of the first node that is part of the first VLAN based upon the name of the first VLAN; determining, by the process on the redirector node, that a volume identifier (ID) associated with the first volume of the first request is present on a volume list; and returning, by the process on the redirector node, the address of the first node to the first client. 2. The method of claim 1 , wherein determining that the volume ID is present on the volume list occurs before returning the address of the first node to the first client. 3. The method of claim 1 , further comprising grouping, by the plurality of processors, a plurality of clients into a security domain. 4. The method of claim 3 , wherein any client included in the security domain is authorized to receive addresses associated with volumes located on the cluster. 5. The method of claim 3 , wherein grouping the plurality of clients occurs before determining that the volume ID associated with the first volume of the first request is present on the volume list. 6. The method of claim 1 , wherein the first volume is accessible only by the first client. 7. The method of claim 1 , wherein the first volume is accessible by the first client and at least a second client. 8. The method of claim 1 , wherein the volume list comprises a plurality of volume IDs that indicate that the first client is authorized to access volumes associated with the plurality of volume IDs. 9. The method of claim 1 , further comprising receiving, at the process on the first node, a request from a first client to access the first volume. 10. The method of claim 9 , wherein the redirector node is the first node. 11. The method of claim 9 , wherein the redirector node is different from the first node. 12. The method of claim 1 , further comprising initiating an iSCSI discovery request for the first volume based on the address of the first node. 13. The method of claim 1 , where the first address is an internet protocol address. 14. A system comprising: a cluster comprising a plurality of nodes, including a redirector node, wherein each node comprises: a process bound to a wildcard address and a port; the redirector node, wherein the process on the redirector node is configured to: receive a first request for a first address of a first volume located on the cluster from a first client, wherein the first request is sent to the port and a first address associated with a first virtual local area network (VLAN) that is not the wildcard address; determine the first address from the first request; determine a name of the first VLAN based on the first address; determine a first node that contains information regarding the first volume; determine an address of the first node that is part of the first VLAN based upon the name of the first VLAN; determine that a volume identifier (ID) associated with the first volume of the first request is present on a volume list; and return the address of the first node to the first client. 15. The system of claim 14 , wherein the volume list comprises a plurality of volume lists corresponding to a plurality of security domains. 16. The system of claim 15 , wherein the plurality of volume lists corresponding to the plurality of security domains authorize the first client to access a plurality of volumes associated with the plurality of security domains. 17. The system of claim 14 , wherein the determination that the volume ID is present on the volume list occurs before returning the address of the first node to the first client. 18. A non-transitory computer-readable storage medium containing instructions for controlling a computer system to perform operations comprising: binding a process to a wildcard address and a port on a redirector node that is part of a cluster; receiving a first request for a first address of a first volume located on the cluster from a first client, wherein the first request is sent to the port and a first address associated with a first virtual local area network (VLAN) that is not the wildcard address; determining the first address from the first request; determining a name of the first VLAN based on the first address; determining a first node that contains information regarding the first volume; determining an address of the first node that is part of the first VLAN based upon the name of the first VLAN; determining that a volume identifier (ID) associated with the first volume of the first request is present on a volume list; and returning, by the process on the redirector node, the address of the first node to the first client. 19. The non-transitory computer-readable storage medium of claim 18 , wherein the determination that the volume ID is present on the volume list occurs before returning the address of the first node to the first client. 20. The non-transitory computer-readable storage medium of claim 18 , wherein the operations further comprise receiving a request from a first client to access the first volume, and wherein the first request is an iSCSI discovery request.

Assignees

Inventors

Classifications

  • Virtual LANs, VLANs, e.g. virtual private networks [VPN] (LAN interconnection over a bridge based backbone H04L12/462; encapsulation techniques H04L12/4633; routing of packets H04L45/00; packet switches H04L49/00; virtual private networks for security H04L63/0272) · CPC title

  • Entity profiles · CPC title

  • Filtering policies (mail message filtering H04L51/212) · CPC title

  • Electricity · mapped topic

  • Virtual private networks · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9537827B1 cover?
A method includes binding, using a plurality of processors, a process to a wildcard address and a port on each of a plurality of nodes. The process receives, on a redirector node, a first request for a first address of a first volume located on the cluster from a first client. The first request is sent to the port and a first address associated with a first virtual local area network (VLAN) tha…
Who is the assignee on this patent?
Netapp Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/0227. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 03 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).