Determining security of local area network
US-2024372862-A1 · Nov 7, 2024 · US
US9838219B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9838219-B2 |
| Application number | US-201414266594-A |
| Country | US |
| Kind code | B2 |
| Filing date | Apr 30, 2014 |
| Priority date | Apr 30, 2014 |
| Publication date | Dec 5, 2017 |
| Grant date | Dec 5, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
The present disclosure discloses a method and network device for providing VLAN mismatch detection in networks. Specifically, a network device monitors a plurality of packets received by a first device from a second device to identify a first set of VLAN identifiers indicated by at least one of the plurality of packets. The network device receives from a third device at least one packet tagged with a particular VLAN identifier, whereas the at least one packet to be forwarded by the first device to the second device. The network device then determines whether the particular VLAN identifier is included in the first set of VLAN identifiers indicated by at least one of the plurality of packets received by the first device from the second device. If the particular VLAN identifier is not included in the first set of VLAN identifiers, the network device presents a notification.
Opening claim text (preview).
What is claimed is: 1. A method comprising: monitoring a plurality of packets received by a first device from a second device to identify a first set of Virtual Local Area Network (VLAN) identifiers indicated by at least one of the plurality of packets; receiving, by the first device from a third device, at least one packet tagged with a particular VLAN identifier, the at least one packet to be forwarded by the first device to the second device; determining that a response message was not received at the first device in response to a request message that comprises a Dynamic Host Configuration Protocol (DHCP) Discover message, wherein the request message is sent by the first device to the second device, and is tagged with the particular VLAN identifier; responsive to determining that the response message was not received at the first device, determining whether the particular VLAN identifier is included in the first set of VLAN identifiers; and responsive at least to determining that the particular VLAN identifier is not included in the first set of VLAN identifiers, presenting a notification. 2. The method of claim 1 , wherein the notification comprises a warning that the particular VLAN identifier may not be recognized by the second device. 3. The method of claim 1 , wherein the notification comprises a warning that the particular VLAN identifier may not be recognized on a port of the second device to which messages, tagged with the particular VLAN identifier, are being forwarded by the first device. 4. The method of claim 1 , further comprising: responsive to determining that the particular VLAN identifier is not included in the first set of VLAN identifiers, transmitting a message that causes the second device to be configured to accept messages tagged with the particular VLAN identifier. 5. A non-transitory computer readable medium comprising instructions which, when executed by one or more hardware processors, causes performance of operations comprising: monitoring a plurality of packets received by a first device from a second device to identify a first set of Virtual Local Area Network (VLAN) identifiers that are indicated by at least one of the plurality of packets and that are known to be recognized by the second device; comparing (a) the first set of VLAN identifiers to (b) a second set of VLAN identifiers that are configured for the first device; identifying a particular VLAN identifier included in the second set of VLAN identifiers and not included in the first set of VLAN identifiers; transmitting a first message, by the first device to the second device, that is a Dynamic Host Configuration Protocol (DHCP) Discover message, and that is tagged with the particular VLAN identifier; responsive to receiving, at the first device, a second message that is responsive to the first message, updating the first set of VLAN identifiers to include the particular VLAN identifier; determining that the second message was not received at the first device in response to first message; and responsive to not receiving the second message that is responsive to the first message, presenting a notification. 6. The medium of claim 5 , wherein the updating operation is performed responsive to the second message being tagged with the particular VLAN identifier. 7. The medium of claim 5 , wherein the notification comprises a warning that the particular VLAN identifier may not be recognized by the second device. 8. The medium of claim 5 , wherein the notification comprises a warning that the particular VLAN identifier may not be recognized on a port of the second device to which messages, tagged with the particular VLAN identifier, are being forwarded by the first device. 9. The medium of claim 5 , wherein the first message is a test for determining whether the second device recognizes the particular VLAN identifier. 10. The medium of claim 5 , wherein the operations further comprise: responsive to not receiving the second message that is responsive to the first message, transmitting a message that causes the second device to be configured to accept messages tagged with the particular VLAN identifier. 11. The medium of claim 5 , wherein the first message is of a particular type that is recognized by the second device as a VLAN detection message. 12. The medium of claim 5 , wherein the first message is generated by the first device to determine whether the second device recognizes the particular VLAN identifier. 13. A non-transitory computer readable medium comprising instructions which, when executed by one or more hardware processors, causes performance of operations comprising: identifying a plurality of Virtual Local Area Network (VLANs) identified by a plurality of Virtual Local Area Network (VLAN) identifiers configured for a first device; receiving at least one packet tagged with a particular VLAN identifier; and responsive to identifying the plurality of VLANs: determining whether the particular VLAN identifier is included in the plurality of VLANs; transmitting, by the first device to a second device, a request message that comprises at least one packet on each of the plurality of VLANs regardless of whether data is received for forwarding by the first device on each of the plurality of VLANs, wherein the request message comprises a Dynamic Host Configuration Protocol (DHCP) Discover message, and is tagged with the particular VLAN identifier; wherein the identifying and transmitting operations are performed by the first device, and wherein the first device includes a hardware processor; determining that a response message was not received at the first device in response to the request message; responsive to determining that the response message was not received at the first device, presenting a first notification; and responsive to determining that the particular VLAN identifier is not included in the plurality of VLANs, presenting a second notification. 14. The medium of claim 13 , wherein the transmission operation is performed by a primary access point and received by a set of one or more secondary access points. 15. The medium of claim 13 , wherein configuring the first device with the plurality of VLAN identifiers comprises configuring the first device to accept packets tagged with any of the plurality of VLAN identifiers. 16. The medium of claim 13 , wherein the transmission operation is performed periodically. 17. The medium of claim 13 , wherein the transmission operation is performed in response to one or more of: that a new VLAN identifier is configured for the first device; and that a new device is added in a system of devices. 18. The medium of claim 13 , wherein the first device is a controller that broadcasts the plurality of VLAN identifiers to other controllers.
Virtual LANs, VLANs, e.g. virtual private networks [VPN] (LAN interconnection over a bridge based backbone H04L12/462; encapsulation techniques H04L12/4633; routing of packets H04L45/00; packet switches H04L49/00; virtual private networks for security H04L63/0272) · CPC title
Checking configuration conflicts between network elements · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.