System and method for management of network-based services
US-9450836-B2 · Sep 20, 2016 · US
US9736185B1 · US · B1
| Field | Value |
|---|---|
| Publication number | US-9736185-B1 |
| Application number | US-201514806476-A |
| Country | US |
| Kind code | B1 |
| Filing date | Jul 22, 2015 |
| Priority date | Apr 21, 2015 |
| Publication date | Aug 15, 2017 |
| Grant date | Aug 15, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Techniques for configuring a network based on a Domain Name System (DNS) or network metadata policy for network control are disclosed. In some embodiments, a system, process, and/or computer program product for a DNS or network metadata policy for network control includes receiving a DNS or network metadata update at a DNS server (e.g., an authoritative or recursive DNS server) or an IP Address Management (IPAM) server, in which the DNS or network metadata update is determined to be relevant to the DNS or network metadata policy for network control; and sending the DNS or network metadata update to a network controller for a network, in which the network controller configures a plurality of network devices on the network based on the DNS or network metadata policy for network control.
Opening claim text (preview).
What is claimed is: 1. A system for a Domain Name System (DNS) or network metadata policy for network control, comprising: a processor of a DNS or an IP Address Management (IPAM) server configured to: receive a DNS or network metadata update at the DNS or IPAM server, wherein the DNS or network metadata update is determined to be relevant to the DNS or network metadata policy for network control, and wherein the DNS or network metadata policy for network control includes a policy based on Domain Name System (DNS) zones, subzones, DNS wildcards, or any combination thereof or metadata associated with network configuration data including network CIDR blocks, network ranges, IP addresses, DNS records, or any combination thereof; send the DNS or network metadata update to a network controller for a network, wherein the network controller configures a plurality of network devices on the network based on the DNS or network metadata policy for network control, and wherein the sending of the DNS or network metadata update to the network controller to: perform one or more of the following: add an IP address to a set of IP addresses relevant to the policy or the metadata; remove an IP address from the set of IP addresses relevant to the policy or the metadata; add the set of IP addresses relevant to the policy or the metadata to an access control list; or move an IP address from a first set of IP addresses relevant to the policy or the metadata to a second set of IP addresses relevant to the policy or the metadata; and a memory coupled to the processor and configured to provide the processor with instructions. 2. The system of claim 1 , wherein the network controller is a Software Defined Networking (SDN) network controller, and wherein the plurality of network devices includes physical, virtual, or SDN based routers and/or switches. 3. The system of claim 1 , wherein the plurality of network devices includes physical, virtual, or Software Defined Networking (SDN) based routers and/or switches, and wherein the network includes network devices from a plurality of different vendors. 4. The system of claim 1 , wherein the DNS server is an authoritative DNS server or a recursive DNS server. 5. The system of claim 1 , wherein the network controller subscribes to DNS or network metadata updates from the DNS or IPAM server. 6. The system of claim 1 , wherein the DNS or IPAM server publishes DNS or network metadata updates to the network controller. 7. The system of claim 1 , wherein the DNS or IPAM server communicates with the network controller via an Application Programming Interface (API). 8. The system of claim 1 , wherein the DNS or IPAM server communicates with the network controller via a messaging protocol. 9. The system of claim 1 , wherein the processor is further configured to: determine whether the DNS or network metadata update is relevant to the DNS or network metadata policy for network control. 10. The system of claim 1 , wherein the sending of the DNS or network metadata update to the network controller to: perform two or more of the following: add an IP address to a set of IP addresses relevant to the policy or the metadata; remove an IP address from the set of IP addresses relevant to the policy or the metadata; add the set of IP addresses relevant to the policy or the metadata to an access control list; or move an IP address from a first set of IP addresses relevant to the policy or the metadata to a second set of IP addresses relevant to the policy or the metadata. 11. The system of claim 1 , wherein the sending of the DNS or network metadata update to the network controller to: perform three or more of the following: add an IP address to a set of IP addresses relevant to the policy or the metadata; remove an IP address from the set of IP addresses relevant to the policy or the metadata; add the set of IP addresses relevant to the policy or the metadata to an access control list; or move an IP address from a first set of IP addresses relevant to the policy or the metadata to a second set of IP addresses relevant to the policy or the metadata. 12. A method for a Domain Name System (DNS) or network metadata policy for network control, comprising: receiving a DNS or network metadata update at a DNS or IP Address Management (IPAM) server, wherein the DNS or network metadata update is determined to be relevant to the DNS or network metadata policy for network control, and wherein the DNS or network metadata policy for network control includes a policy based on Domain Name System (DNS) zones, subzones, DNS wildcards, or any combination thereof or metadata associated with network configuration data including network CIDR blocks, network ranges, IP addresses, DNS records, or any combination thereof; sending the DNS or network metadata update to a network controller for a network, wherein the network controller configures a plurality of network devices on the network based on the DNS or network metadata policy for network control, and wherein the sending of the DNS or network metadata update to the network controller to: perform one or more of the following: add an IP address to a set of IP addresses relevant to the policy or the metadata; remove an IP address from the set of IP addresses relevant to the policy or the metadata; add the set of IP addresses relevant to the policy or the metadata to an access control list; or move an IP address from a first set of IP addresses relevant to the policy or the metadata to a second set of IP addresses relevant to the policy or the metadata. 13. The method of claim 12 , wherein the DNS server is an authoritative DNS server or a recursive DNS server. 14. The method of claim 12 , wherein the network controller is a Software Defined Networking (SDN) network controller, wherein the plurality of network devices includes physical, virtual, or SDN based routers and/or switches, and wherein the network includes network devices from a plurality of different vendors. 15. The method of claim 12 , further comprising: determining whether the DNS or network metadata update is relevant to the DNS or network metadata policy for network control. 16. A computer program product for a Domain Name System (DNS) or network metadata policy for network control, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for: receiving a DNS or network metadata update for a DNS or IP Address Management (IPAM) server, wherein the DNS or network metadata update is determined to be relevant to the DNS or network metadata policy for network control, and wherein the DNS or network metadata policy for network control includes a policy based on Domain Name System (DNS) zones, subzones, DNS wildcards, or any combination thereof or metadata associated with network configuration data including network CIDR blocks, network ranges, IP addresses, DNS records, or any combination thereof; sending the DNS or network metadata update to a network controller for a network, wherein the network controller configures a plurality of network devices on the network based on the DNS or network metadata policy for network control, and wherein the sending of the DNS or network metadata update to the network controller to: perform one or more of the following: add an IP address to a set of IP addresses relevant to the policy or the metadata; remove an IP address from the set of IP addresses relevant to the policy or the metadata; add the set of IP addresses relevant to the policy or the m
Network management software packages · CPC title
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
Multiple levels of security · CPC title
Electricity · mapped topic
using domain name system [DNS] · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.