Method and system for policy-based networking
By leveraging SD-WAN architecture and policy header processing technology, the problems of SaaS application access latency and bandwidth congestion are resolved, enabling efficient and secure network traffic management and simplifying the configuration and security policy management of large networks.
Patent Information
- Application Number
- CN202410281154.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-05-06
- Filing Date
- 2021-01-28
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2041-01-28
AI Technical Summary
In the existing network architecture, the migration of SaaS applications from enterprise data centers to the Internet cloud has led to increased access latency and bandwidth congestion, as well as complex management, making it difficult to implement access control and security configuration for hundreds or thousands of segments.
It adopts a software-defined wide area network (SD-WAN) architecture, centrally manages policy configuration through a network device coordinator, generates and processes WAN packets containing network segmentation, application and security information, and simplifies network traffic management by utilizing policy headers and address translation.
It enables low-latency, low-bandwidth network access, simplifies the configuration of large networks, reduces human error, and provides unified security policy management and rapid update capabilities.
Smart Images

Figure CN117978535B_ABST
Abstract
Description
[0001] This application is a divisional application of the original Chinese invention patent application entitled "Method, Apparatus and System for Policy-Based Grouping Processing", in which the application number of the original application is 202110119141.5 and the application date of the original application is January 28, 2021. Technical Field
[0002] This application generally relates to computer networking, and more specifically to systems and methods for generating and processing network packets using network policy information. Background Technology
[0003] In the previous network architecture, the branch office network was connected to the data center via a WAN (Wide Area Network) connection through routers. The leased WAN lines could use Multiprotocol Label Translation (MPLS) as the connection protocol, and this was a viable architecture because all applications resided in the data center. Access control to the data center and applications was distributed across routers in each back office, and each router had to be configured individually. Furthermore, other security measures also had to be configured individually.
[0004] Currently, networked architectures include SaaS (Software as a Service) applications. These applications have moved from enterprise data centers to the internet cloud. Examples of such cloud applications include Google Cloud, Amazon AWS, Dropbox, and Salesforce. Routing back to these applications through a central data center has a drawback: it adds extra latency and can potentially clog the bandwidth of leased lines back to the data center. To leverage internet access to route data to these SaaS applications, the architecture needs to utilize direct access to the internet.
[0005] This has driven the demand for Software-Defined Networking (SD-WAN) for traffic between segmented WANs and direct internet access. Furthermore, managing access control for hundreds or thousands of segments, tunneling between segments, and the security of these segments can be complex and prone to human error. A networking architecture is needed where WAN packets comprise network segments, application, and security information. Summary of the Invention
[0006] This summary is provided to present a selection of concepts in a simplified form, which will be further described in the detailed description section below. This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used to help determine the scope of the claimed subject matter.
[0007] Generally, this disclosure relates to a method, apparatus, and system for generating and processing wide area network (WAN) packets containing policy information. Policy information may include, but is not limited to, network segmentation information and security information. In one aspect of the invention, a packet is received and prepared for transmission over the WAN. Based on the packet's source and destination, it is associated with a policy configuration. If the packet has a valid policy configuration, a policy header is added to the packet, which may contain security information. Further, the packet may include network segmentation information, application information, tunneling, and address translation information. Received or incoming packets are associated with a policy configuration and are verified according to the policy configuration. If the packet conforms to the policy configuration, then the payload is forwarded to the interface indicated by its destination address. Further, the packet payload may be encrypted, and network address translation is performed on the packet payload. Attached Figure Description
[0008] Exemplary embodiments are illustrated by way of example and are not limited to the figures in the accompanying drawings, wherein the same reference numerals indicate the same elements.
[0009] Figure 1 The diagram illustrates an existing wide area network architecture where SaaS application traffic is backhauled through a public server.
[0010] Figure 2 An exemplary wide area network (WAN) architecture is illustrated, which has multiple network devices that are directly connected to the Internet and WAN network resources.
[0011] Figure 3A This is a block diagram of a network device.
[0012] Figure 3B This is an example table for policy configuration.
[0013] Figure 4 This is a flowchart illustrating the process of generating outgoing WAN packets based on a shared policy configuration.
[0014] Figure 5 This is a flowchart illustrating the process of handling incoming WAN packets according to a shared policy configuration.
[0015] Figure 6A It is an exemplary user interface for configuring route coverage, firewall zones, and address translation.
[0016] Figure 6B This is an example user interface for configuring network segmentation.
[0017] Figure 6C This is an exemplary user interface for configuring firewall zone segmentation.
[0018] Figure 6DThis is an exemplary user interface for configuring inter-segment routing.
[0019] Figure 7A It is an example wide-area group that includes the strategy header.
[0020] Figure 7B It is an example encrypted wide-area packet that includes a policy header. Detailed Implementation
[0021] The following detailed description includes reference to the accompanying drawings, which form a part of the detailed description. The drawings illustrate exemplary embodiments. These exemplary embodiments, also referred to herein as “examples,” are described in sufficient detail to enable those skilled in the art to practice the subject matter. Embodiments may be combined, other embodiments may be utilized, or structural, logical, and electrical changes may be made without departing from the scope of the claims. Therefore, the following detailed description is not to be considered limiting, and the scope is defined by the appended claims and their equivalents. In this document, the terms “a” and “an,” as are common in patent documents, are used to include one or more. In this document, unless otherwise stated, the term “or” is used to refer to a non-exclusive “or,” such that “A or B” includes “A but not B,” “B but not A,” and “A and B.”
[0022] The embodiments disclosed herein can be implemented using various techniques. For example, the methods described herein can be implemented in software executing on a computer system comprising one or more computers, or in hardware utilizing application-specific integrated circuits (ASICs), programmable logic devices, or various combinations thereof, using a combination of microprocessors or other specially designed components. In particular, the methods described herein may be implemented by a series of computer-executable instructions residing on a storage medium, such as a disk drive or a computer-readable medium.
[0023] The embodiments described herein relate to wide area networks that use policy-based configuration for packet generation and processing. Figure 1 The illustration depicts a prior art network architecture 100. In this architecture, several branch offices 10 are connected to a central office 20, which may include a data center. All data from the branch offices 10 is transmitted back to the central office for processing via router 15, WAN 30, and other networking equipment. WAN 30 may be a leased communication link or a network of other service providers.
[0024] When applications in branch offices 10 utilize SaaS (Software as a Service) 50 (office software (MS Office), cloud storage, etc.), they are accessed via the Internet 40 through router 15 back to the central office. However, routing all data via WAN 30 can slow down the performance of SaaS applications 50. Furthermore, such an architecture lacks centralized security and a unified management system for configuration.
[0025] Figure 2 The diagram illustrates a new architecture using SD-WAN (Software-Defined Wide Area Network) architecture 200, which can be used to provide access between remote offices 10, data centers 20, and SaaS applications 50. Several branch offices 10 are bound to data center 20 via WAN network 30 using network devices 250. SaaS / cloud applications 50 can be accessed at each branch office 10 via the Internet 40 using communication links 127. The advantage of this architecture is that it requires fewer WAN links and less bandwidth. Each remote office 10 can directly access SaaS / cloud applications 50 using the low-cost and high-speed Internet 40 service.
[0026] However, access to the WAN needs to be controlled based on the type of application, the company policy for segmenting the office network, and security. This control can be referred to as network policy or policy configuration. Furthermore, it is beneficial to have a central coordinator that centrally and uniformly uses the policy configuration information to configure each network device in network device 250, and includes this security information for each WAN packet.
[0027] WAN bandwidth can be divided into segments, where different parts of the corporate network are effectively separated from the others. For example, there could be segments for real-time data, audio, or video, with guaranteed quality of service. For SD-WAN (Software-Defined Wide Area Network), these network segments are software-defined, centrally created on the coordinator, and provisioned on network devices.
[0028] Policy configuration specifies the rules for network traffic segmentation. Different network traffic segments can be viewed as having different business intents. Therefore, different network segments can be managed based on required quality of service, bandwidth, applications, and their security requirements. These business intents can be referred to as business intent overlay.
[0029] Policy configuration can be orchestrated via a computer or server communicating with all network devices 250, typically on a management plane known as the network. Each network device 250 can have a unique identifier, allowing them to apply these rules to their incoming and outgoing network traffic. Network devices 250 know which interface they receive packets on and are application-aware. Policy configuration constrains network traffic based on specified rules and relationships. These rules and relationships are based on network segmentation, application data transmission and reception, and security configurations. Each network device can receive the same policy configuration so that security configurations are uniformly enforced across the network.
[0030] Figure 3A A block diagram of a network device 250 in an exemplary embodiment of the present invention is illustrated. Device 250 includes a processor 310, a memory 320, a WAN communication interface 330, a LAN communication interface 340, and a database and storage device 350. A system bus 380 links the processor 310, memory 320, WAN communication interface 330, LAN communication interface 340, and database 350. When deployed in a branch location, line 360 links the WAN communication interface 330 to WAN 127 (in... Figure 2 (in the middle), and line 370 connects the LAN communication interface 11 to Figure 2 Computer 140 in the middle.
[0031] Database and storage device 350 includes hardware and / or software elements configured to store data in an organized format to allow processor 310 to create, modify, and retrieve data. This includes software programs for processing incoming and outgoing data and configuring storage policies. Database and storage device 350 may include policy configuration 390 (also as...) Figure 3B (As shown). During operation of network device 250, policy configurations can be stored in memory 320. Hardware and / or software elements of database 350 may include storage devices such as RAM, hard disk drives, optical drives, flash memory, and magnetic tape.
[0032] In some embodiments, some network devices 250 include the same hardware and / or software elements. Alternatively, in other embodiments, some network devices 250, such as a second device, may include hardware and / or software elements that provide additional processing, communication, and storage capacity. Furthermore, routing functions relating to configuring networking policies can be performed within the network device 250.
[0033] Figure 3BThis is an exemplary embodiment of a table representing policy configuration 390 information. Policy configuration 390 is shown as a table, but may be represented in other data structures, including but not limited to database entries, linked lists, or flat files, and is not limited to... Figure 3B The diagram illustrates this. Furthermore, the network segmentation and security information shown is not exhaustive and may include any other information relating to network segmentation, network tunneling, firewalls, and address translation. Although policy configuration 390... Figure 3A It is shown as part of the database and storage device 350, but it can be loaded into the computer memory 320 when the network device 250 is processing incoming and outgoing packets according to the policy configuration 390.
[0034] Policy configuration 390 can be distributed to multiple network devices 250 via a single server, which may be referred to as an orchestrator (not shown). In one embodiment, the setting of policy configuration 390 is executed at a single location. The same policy configuration 390 can be sent to all network devices 250. It is also contemplated that policy configuration 390 can be modified for each network device 250 or for truncated policy configurations. Advantageously, centralized management of policy configuration 390 simplifies the configuration process, minimizes the possibility of errors, and provides a rapid method for updating security policies.
[0035] Table 392 defines the relationships between network segments, referred to as segments or VRFs (Virtual Routing and Forwarding) and BIOs (Service Intent Overlays). A Service Intent Overlay (BIO) specifies how traffic with specific characteristics is handled within the network. Multiple BIOs can be created for different types of traffic. Which traffic matches a particular BIO is determined either by a tag on the interface through which it enters the device or by matching traffic to an access list. A BIO controls things like the WAN port and network type used to transmit traffic, and what to do if a preferred link degrades or fails to meet specified performance thresholds. Therefore, Table 392 provides policies or rules for generating and forwarding packets. For further information, patent publication US2016 / 0255542 A1, “Virtual Wide Area Network Overlays,” provides more information on network overlays, and is incorporated herein by reference.
[0036] Table 394 defines the relationship between VRF and other policies, including but not limited to overlay policies for applicable segmented firewall zones, and the network addresses that will use D-NAT (Destination Network Address Translation) and S-NAT (Source Network Address Translation). Network device 250 can use the configuration in this table when generating, authenticating, and processing incoming and outgoing WAN packets.
[0037] Table 396 defines which network addresses and network protocols are allowed through firewall zones and between firewall zones. Figures 6A-6D A description of a sample user interface is provided for accessing the parameters of policy configuration 250.
[0038] Figure 4 Depicting network devices (such as Figure 2 An exemplary method for network-based policies (device 250). Packet data is processed and generated according to policy configuration 390. Further, the method appends associated policy configuration 390 information, including but not limited to network segmentation, application data, and security-related information, to outgoing packets for verification by the receiving network device 250 according to policy configuration 390.
[0039] In step 405, one or more network devices 250 are configured with policy settings. In one embodiment, all network devices 250 are configured with the same policy settings. Therefore, large-scale network configurations can be uniformly implemented without the possibility of human intervention or human input errors. Each network device 250 will need an identifier to know its relationship within the network in configuration policy 390.
[0040] In step 410, network device 250 receives an outgoing packet that includes a destination address on a WAN network. Network device 250 may be configured with one or more WAN networks, including but not limited to the Internet, MPLS, or private network lines. The outgoing packet may originate from a source, including but not limited to a LAN network, VoIP system, and video system.
[0041] In step 415, the outgoing packet is associated with policy configuration 390, which relates to the network device 250 receiving the packet. This association includes the classification of the packet by the port on which it is received, and the determination of the application from which the packet originated. Those skilled in network programming and design should know how to examine and classify the packet. This information is matched against the policy configuration parameters 390 for the port and application. The policy configuration can then be examined to determine which network segment the port and application are assigned to.
[0042] In step 420, the outgoing packet is validated against the policy configuration. Validation may include verifying that the outgoing packet's destination and source are within the same network segment. The outgoing packet may also be validated for security to verify that the destination address is within the firewall zone specified in policy configuration 390.
[0043] Furthermore, if the outgoing packets are destined for different network segments, policy configuration checks can be performed on the packet tunnels between network segments.
[0044] Authentication can include security policies. These can include granular application visibility matching criteria. For example, a wireless guest user (guest Wi-Fi) in one network segment might be allowed to browse the internet but not access social media sites or play online games, while users in other network segments might only be able to access enterprise SaaS applications but not browse the internet, access social media sites, or play online games. In one embodiment, when a specific application is denied, the user's browser session will time out.
[0045] Other policy checks are included, such as whether outgoing packets are encrypted and which encryption protocol should be used.
[0046] Furthermore, policy configuration 390 can instruct address translation for outgoing packets. Different address translation protocols can be used, including but not limited to S-NAT and D-NAT.
[0047] In step 425, a policy header is added to the outgoing packet. The policy header may include, but is not limited to, network segmentation information, firewall zone information, tunneling information for networking between network segments, and address translation information. The outgoing packet with the added policy header forms the packet payload.
[0048] In optional step 430, the outgoing packet payload may be encrypted. The encryption protocol may include, but is not limited to, UDP-IPsec (RFC 3948), IKE-IPsec (Internet Key Exchange Protocol), and GRE-IPsec (Generic Routing Encapsulation). This step may include adding an IPsec header depending on the protocol's purpose.
[0049] In step 435, a WAN header is added to the outgoing payload to form a WAN packet. The format of the WAN header is selected to be compatible with the WAN interface indicated by the network segment identified by the policy configuration.
[0050] In step 440, the WAN packet is forwarded to the WAN interface for transmission on the selected network.
[0051] Method 400 may further include method 500 for receiving and processing incoming WAN packets, decrypting them, verifying WAN packets, and providing network address translation if necessary. Figure 5 Describes network devices (such as Figure 2 and Figure 3A An exemplary method for the device 250 to process incoming packets according to policy configuration 390.
[0052] In step 505, the incoming WAN packet is received from one of the WAN interfaces on the network device. This can include WAN packets from the Internet, MPLS services, or other leased network lines.
[0053] In step 510, the WAN header is removed from the WAN packet. This results in the remaining payload of the incoming packet. The payload of this packet includes the second policy header.
[0054] In optional step 515, if the encrypted packet payload is decrypted and any security protocol headers are removed, the encryption protocol may include, but is not limited to, UDP-IPsec, IKE-IPsec, or GRE-IPsec.
[0055] In step 520, the second policy header is associated with policy configuration 390, which relates to the network device 250 that receives the incoming packet. This association includes classifying the incoming packet by the port on which it was received and determining which application the packet originated from. Those skilled in network programming and design should know which fields to examine to classify the incoming packet. This information is matched with the policy configuration 390 parameters for the port and application.
[0056] In step 525, the second policy header is verified. The network device knows which network segment the received incoming packet belongs to. Incoming packet routing can be verified based on the label of the network interface, the second policy header, or a more complex policy using various packet inspection techniques. For example, incoming traffic may have been mixed, and the device needs to use a combination of traffic statistics and packet content to separate it into traffic categories (e.g., voice, video, and data). Further, verification may include verifying that the policy configuration allows the incoming packet to be forwarded to the destination address. Security verification may also be performed, where firewall zones for the port and destination network address are verified. If the packet does not meet the policy configuration for network segmentation, allowed applications, and security, the packet may be dropped.
[0057] In step 530, the second policy header is removed from the incoming WAN packet. The second policy header is added to conform to and validate that the incoming packet meets the policy configuration. It must be removed before forwarding the packet to other destinations to ensure compatibility with the destination network, typically a LAN.
[0058] In optional step 535, the destination address is translated if indicated by the second policy header. Multiple branch offices may be using the same IP address, and therefore, this would cause a conflict. IP address translation can be performed using standard NAT protocols, including but not limited to D-NAT and S-NAT.
[0059] In step 540, the incoming packet is forwarded to the interface, with the packet's destination address located thereon. This step may include appending a network protocol header associated with the destination address of the incoming packet.
[0060] Figure 6A The diagram illustrates an embodiment of the routing segment user interface 610 for configuring network segments (routing segments) for policy configuration 390. This interface page can create and label network segment names 612. Overlay and interruption policies can be specified for each segment. Overlay is a logical tunnel created for different traffic types and policies (such as VoIP). Interruption specifies policy configurations for Internet SaaS applications or for guest WiFi traffic.
[0061] The routing segmentation user interface 610 also provides fields for specifying firewall zone policies 616. A firewall zone is a collection of interfaces and network segments attached to those interfaces. It can have physical interfaces, logical interfaces, sub-interfaces, and interfaces with VLAN tags. Interfaces belong to a single zone, but a zone can have multiple interfaces. In SD-WAN embodiments, the zone-based firewall extends the concept of zones to the WAN and includes coverage separated by LAN segments. This zone information can be stored in policy configuration 390 and includes the generation, authentication, and processing of SD-WAN packets.
[0062] The segmentation user interface 610 includes fields for specifying policy configurations for segmentation routing and D-NAT 618. Some network traffic may need to be transmitted across network segments or VRFs, and these exceptions can be configured in this field. Packet transmission from one network segment to another is often blocked due to network segmentation. Exceptions for cross-segment traffic can be specified in this field 618. Another potential problem is network address conflicts. Two computers on different network segments may have the same destination address. The inter-segment routing and D-NAT field 618 provides destination address translation for packets. Furthermore, this inter-segment routing and D-NAT can be part of policy configuration 390.
[0063] Figure 6B The illustration shows an embodiment of a user interface 630 for configuring the association between VRFs and BIOs. For a given BIO, this includes which VRF is designated as part of the BIO. Furthermore, these user configurations are stored as part of policy configurations and used for packet generation, validation, and processing.
[0064] Figure 6C The illustration shows an embodiment of a user interface 650 for configuring firewall zone policies. A firewall zone is a collection of interfaces and network segments attached to those interfaces. Rule 652 can specify which IP addresses can receive data and which IP addresses are allowed to transmit between zones.
[0065] Figure 6D The illustration shows an embodiment of a user interface 670 for configuring network addresses, which may have tunnels between different network segments and address translation between network segments or VRFs. For each VRF 672, 676, address translation is performed, and the IP address 674 to be translated can be specified.
[0066] Figure 7A and Figure 7B Two embodiment headers, 700A and 700B, with policy headers embedded in the packets are shown. The packets are generated and processed by network device 250. Data from local area network 11 can be received by network device 250 and used to generate WAN packets if the destination address is outside the local area network.
[0067] Figure 7A The diagram illustrates a simplified unencrypted WAN packet. The packet may include a WAN header 710, a policy header 720, and a payload 730. The payload 730 is data received from the LAN. It may include a packet header from the LAN (not shown). Furthermore, the payload 730 can be modified if Network Address Translation (NAT) is applied to the packet.
[0068] WAN header 710 is the header that needs to be... Figure 2 The header of communication on WAN link 125 is where network devices communicate. These WANs can be specified by the service provider or determined by the equipment used for connections over leased lines between central offices and data centers.
[0069] The policy header 720 may include, but is not limited to, network segmentation, information about the application that generates and sends packets, firewall zone 724, and other information 726. The segment ID 722 identifies which segment or VRF the WAN packet should be sent from or originate from. A person skilled in network configuration will know how to configure the system for network device 250 to select the segment that matches the desired policy configuration. Firewall zone 724 restricts communication to other network addresses within the firewall zone specified in policy configuration 390. Other information 726 may include information about the security protocols used or equipment identifiers. Equipment identifiers may include the identifier of the equipment manufacturer that generated the WAN packet or the identifier of the individual network device 250.
[0070] When WAN packet 700A is generated, a policy header is generated to match policy configuration 390. When WAN packet 700A is verified, the policy header is used to verify that the packet matches policy configuration 390.
[0071] Figure 7B An alternative embodiment utilizing encrypted WAN packets is illustrated. Three encrypted packet formats 750, 770, and 790 are encrypted according to three different encryption protocols: UDP-IPsec, IKE-IPsec, and GRE. A policy header 760 is added to the secure packet payload. This header is added to every packet sent over SD-WAN and is found on every packet received over SD-WAN. The policy header 760 may include, but is not limited to, identifier 763, area identifier 764, and route segment identifier 765.
Claims
1. A method for policy-based networking, comprising the following steps: Utilize policy configuration to configure multiple network devices, where each network device is coupled to at least one wide area network (WAN); Receive outgoing packets having a destination address on at least one WAN; The outgoing packets are associated with the policy configuration using the following steps: The outgoing packets are classified based on the port on which the outgoing packets are received by the network device receiving them. Determine the application from which the outgoing packet originates; as well as Based on the policy configuration, network segments are determined to be assigned to the port and the application; Verify the outgoing packets according to the policy configuration; A policy header configured based on the policy is appended to the outgoing packet, wherein the policy header includes the network segment; A WAN header compatible with at least one WAN interface associated with the network segment is attached to form an outgoing WAN packet; as well as The outgoing WAN packet is forwarded to at least one WAN interface of the network device, and the location of the destination address is located on the corresponding WAN interface.
2. The method of claim 1, wherein the policy configuration defines the relationship between network segmentation and service intent coverage, wherein the service intent coverage specifies the processing of packets based on at least one of a tag or access list associated with the port through which the outgoing packet enters the network device.
3. The method of claim 2, wherein the service intent coverage is associated with network segmentation, and wherein appending a policy header configured based on the policy to the outgoing packet comprises: An identifier is attached for the network segment associated with the service intent coverage.
4. The method of claim 1, wherein the policy configuration definition includes at least one security policy for the network segment that covers or interrupts service intent, wherein the service intent coverage specifies a logical tunnel based on different traffic types accessing the network segment, and wherein the interruption specifies a policy configuration for Internet Software as a Service (SaaS) applications or wireless guest user traffic for the network segment.
5. The method of claim 1, wherein the policy configuration defines at least one firewall zone policy applicable to the network segment, wherein the firewall zone policy defines a relationship between a first firewall zone associated with the network segment and a second firewall zone associated with a different network segment, and wherein the method comprises: The at least one firewall zone policy is determined to allow the outgoing WAN packets to be forwarded from the network segment to the different network segments.
6. The method of claim 1, wherein the policy configuration is defined to at least one tunnel for different network segments, and wherein the method comprises: Determine that the destination address is located on a different network segment compared to the network segment; as well as The destination address is translated into a different address associated with the different network segments.
7. The method according to claim 1, further comprising: It is determined that the outgoing packets were received via a local area network (LAN). as well as The destination address is determined to be outside the LAN.
8. The method of claim 1, wherein the policy header includes at least one of a network segment identifier associated with the network segment, information about the application, or a firewall zone associated with the network segment.
9. The method of claim 8, wherein the network segment identifier identifies from which network segment the outgoing packet is received or sent to which network segment.
10. A method for policy-based networking, comprising the following steps: Multiple network devices are configured using policy settings, where each network device is coupled to at least one wide area network (WAN) and local area network (LAN). Receive an incoming packet from a WAN interface associated with the at least one WAN, the incoming packet including a WAN header and a policy header; Remove the WAN header from the incoming packet, wherein removing the WAN header leaves the incoming packet payload including the policy header; The policy header is associated with the policy configuration, and the association includes classifying the incoming packets by the port on which the packets are received and determining which application the incoming packets originated from. Verify the policy configuration to allow the incoming packet to be forwarded to the destination address; Remove the policy header from the incoming packet payload to generate a modified packet; Append a network protocol header associated with the destination address; as well as The packet with the network protocol header attached is forwarded to the interface associated with the LAN.
11. The method of claim 10, wherein associating the policy header comprises: The incoming packets are classified based on the port on which they are received; Determine the application from which the incoming packet originates; as well as Match the port and the application with the parameters in the policy configuration.
12. The method according to claim 10, further comprising: Decrypt the incoming packet payload; as well as Remove at least one security protocol header from the policy header.
13. The method of claim 12, wherein the incoming packet payload is encrypted using at least one of UDP-IPsec, IKE-IPsec, and GRE-IPsec.
14. The method of claim 10, further comprising: Verify the policy header based on the tag associated with the WAN interface; as well as The policy configuration is determined to allow the incoming packet to be forwarded to the destination address.
15. The method of claim 10, further comprising: Determine that the policy header indicates the translation of the destination address; as well as Convert the destination address.
16. The method of claim 10, further comprising: Receive a second incoming packet from the WAN interface; Determine whether the second incoming packet satisfies the policy configuration for the network segment associated with the network device; as well as Based on the determination that the second incoming packet does not satisfy the policy configuration for network segmentation, the second incoming packet is discarded and not forwarded.
17. The method of claim 10, wherein the incoming packet is received from the Multiprotocol Label Transform (MPLS) service.
18. A system for policy-based networking, the system being configured to perform the method of any one of claims 1-9, the system comprising: Multiple network devices, each of which has a port connected to a wide area network (WAN); as well as A coordinator device that communicates with each of the plurality of network devices, wherein the coordinator device is configured to distribute policy configurations to the plurality of network devices, wherein: The policy configuration defines the relationship between network segmentation and service intent coverage, which is matched with network traffic entering through the ports of the network device and is determined based on tags associated with the ports. The policy configuration is used to determine the network segments assigned to the port and the applications from which outgoing packets originate.
19. The system of claim 18, wherein the policy configuration includes at least one association between the network segment and the second network segment, and the network traffic will be forwarded to the second network segment in inter-segment routing.
20. The system of claim 18, wherein the policy configuration includes firewall zone policies for the network segmentation.
Citation Information
Patent Citations
Virtual wide area network overlays
US20160255542A1
Methods and systems for processing network data packets
AU2003221853A1
Method and device for realizing different IP data packet repeating using strategic flow
CN1612562A