UNITED POLICY BROKER
Patent Information
- Application Number
- DE102022109180
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-10-11
- Filing Date
- 2022-04-14
- Publication Date
- 2025-09-11
- Estimated Expiration
- 2042-04-14
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
BACKGROUND
[0001] This disclosure generally relates to the field of network management and network policies. Generally, a network may comprise a plurality of interconnected network devices, with at least one or more network devices implementing a policy enforcement engine. In a typical network, a plurality of different policy enforcement engines may be present along a network path for enforcing network policies to manage network traffic. Each policy enforcement engine may be associated with different features and capabilities.
[0002] WO 2015 / 139724 A1 relates to an apparatus and method for managing policies and / or resources that can be used to configure one or more networks.
[0003] US 2020 / 0004742 A1 relates to network technologies, in particular to the configuration and management of network resources.
[0004] The present invention is defined by independent claims 1 and 11. Embodiments are subject to the respective dependent claims. BRIEF DESCRIPTION OF THE CHARACTERS Fig. 1 shows an example of a network environment including a computer system supporting a unified policy broker according to one aspect of the present application. Fig. 2 shows an example system architecture for supporting a unified policy broker according to one aspect of the present application. Fig. 3 shows a flowchart illustrating an example process for enabling a unified policy broker according to one aspect of the present application. Fig. 4 shows a flowchart illustrating an example process for configuring and managing policy enforcement engines based on a unified policy broker according to one aspect of the present application. Fig. 5 shows an exemplary user interface for selecting an enforcer from a list of enforcers, according to one aspect of the present application. Fig. 6 shows an example of a computer system enabling a unified policy broker according to one aspect of the present application.
[0005] In the figures, the same numbers refer to the same figure elements. DETAILED DESCRIPTION
[0006] The following description is intended to enable any person skilled in the art to make and use the examples and is provided in the context of a specific application and its requirements. Various modifications to the disclosed examples will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other examples and applications without departing from the spirit and scope of the present disclosure. Therefore, the scope of the present disclosure is not limited to the examples shown, but is to be as broad as possible consistent with the principles and features disclosed herein.
[0007] Various network devices in a network can be equipped with a policy enforcement engine. A policy enforcement engine can be a software component or a hardware component that can implement a set of network policies. For example, an access control list (ACL) can be a network policy that allows a user to specify rules through an application programming interface (API) to deny a specific type of traffic. In addition, network policies can also correspond to forwarding rules, such as Policy Based Forwarding (PBF), or firewall rules. Different policy enforcement engines can be connected to different types of APIs. For example, one API may support a specific way of describing or representing a policy, while another API may use a different language to represent policies.
[0008] Each policy enforcement engine can enforce one or more network policies to manage network traffic. For example, a policy enforcement engine in a first network device along a network traffic path can enforce network security policies, and another policy enforcement engine in a second network device along the network traffic path can enforce traffic management policies. In other words, ACLs in a network switch can correspond to the first policy enforcement engine, while firewall rules in firewall devices or distributed firewalls can correspond to the second policy enforcement engine.
[0009] Different types of policy enforcement engines can be connected to different application programming interfaces (APIs). Each type of API can represent policies using different terminology. For example, an API connected to a first policy enforcement engine can represent a policy function using specific terminology, while another API connected to a second policy enforcement engine can represent a similar policy function using different terminology. While having different types of policy enforcement engines along a network path can provide flexibility for network administrators, manually configuring these engines with different management APIs can be difficult and complex.This is because these "enforcers," or policy enforcement engines, can each have their own user interfaces and APIs and often use different terminology for the same functions. Therefore, it can be difficult and complex for a user to learn the various terminologies associated with the different policy enforcement systems and then manually configure them.
[0010] Some of the aspects described in this application offer a technical solution to the above-mentioned technical problems by providing a system and method for a unified policy broker that can provide a single user experience and a single API for configuring and managing various enforcement options. For example, the system can normalize different terminologies, workflows, and capabilities across different policy enforcement engines. The system can then provide a set of normalized workflows for the different policy enforcement engines, allowing the user to configure network policies on these engines that can interact and complement each other. In other words, a system can provide the user with the flexibility to create a policy rule using the same service group or qualifier, e.g., applications.The user can then simply change a policy type or enforcer to a network ACL type or a distributed firewall type enforcer. In response to the selection of the specific enforcer type, the system can ensure that the created policy rule is reflected with the correct implementation. In particular, if a consistent language or API for defining rules exists, the user can switch between different implementations, such as east-west firewalls, where a common set of capabilities exists. The system can also validate that the rule can be applied to a new target enforcer, enabling seamless migration between different enforcers.
[0011] Specifically, the system can automatically monitor the network to obtain configuration information associated with various policy models connected to the respective policy enforcement engines in the network. In other words, the system can obtain information about how each of the policy models creates policies, defines policies, defines policy rules, and so on. Based on this information, the system can create a mapping between a unified policy model and the various policy models. Such a unified policy model can provide a unified API for configuring and managing the various policy enforcement engines with different policy models through a user interface.
[0012] The term “policy enforcement engine” refers to a software and / or hardware component in a network device that can enforce a set of policy rules.
[0013] The terms “Policy Enforcement Engine” and “Enforcer” are used synonymously in this application. System architecture
[0014] Fig. 1 shows an example of a network environment with a computer system for supporting a Unified Policy Broker according to one aspect of the present application. In the Fig. In the example illustrated in Figure 1, environment 100 depicts a set of network devices or network facilities, e.g., network devices 110-114, located on a network 126. Network devices 110-114, e.g., network switches, may implement network policies based on a corresponding policy enforcement engine. These network policies may include a set of forwarding rules that may be applied to a network packet when certain matching criteria are met.
[0015] For example, one network device may support an ACL-type policy enforcement engine, while another network device may support a firewall-type policy enforcement engine. Furthermore, the firewall-based policy enforcement system may have similar policy-related functionality to the ACL-based policy enforcement system. However, each policy enforcement engine may be associated with its own API type, such as APIs 116–120. In other words, an API associated with a policy enforcement engine may contain different terminology and representations for a policy function than another API for a similar policy function. A policy function may be associated with policies, policy enforcement options (allow, deny, reject, etc.), policy rules, traffic specifications, and so on.
[0016] Manually managing and configuring these various policy enforcement engines connected to a specific API can be complex and difficult. This is because the user may need to be familiar with the different terminologies used in the various policy enforcement engines for different and similar policy functions. Furthermore, the user must understand the capabilities, available compute and memory resources of the network device, and the path efficiency along a network path to configure the appropriate policy enforcement engines to deliver the network flow efficiently and with the desired performance characteristics.
[0017] An aspect described in this application may provide a technical solution to the above-mentioned problems by providing a unified policy broker that can facilitate the configuration and management of policy enforcement engines with a single point of control. A unified policy broker 106 can facilitate the management of various policy enforcement engines with a unified API 122 via a user interface 104. For example, a computer system 102 implementing a unified policy broker 106 can provide a single point of control to configure different types of policies across the various policy enforcement engines using a unified or single set of policy definitions and structural elements.Furthermore, the unified policy broker 106 may not only provide a unified API, but may also account for differences in the capabilities of the various policy enforcement engines, such as performance characteristics, traffic enforcement options, resource availability, etc. The different capabilities may include, for example, the memory available on the particular network device, the capabilities of the processing resources on the network device, the number of policy rules supported by a policy enforcement engine associated with the network device, the latency added to a particular network traffic flow, the performance characteristics associated with the policy enforcement engine, the traffic enforcement options provided by the policy enforcement engine, etc.
[0018] Furthermore, the unified policy broker 106 may provide a unified API 122 via a user interface (UI) 104 connected to a display device 124 for configuring and managing the various policy enforcement engines. In one aspect of this application, the system 102 may provide a visualization to a user 108 via a graphical user interface that may include information about various policy enforcement engines in the network 126, information about how policies are enforced in a particular network traffic flow across multiple policy enforcement engines, etc. The operation of the unified policy broker 106 is described below with reference to the Fig. 2-6 described.
[0019] Fig. Figure 2 shows an example of a system architecture for enabling a Unified Policy Broker according to one aspect of the present application. Fig. 2, the system architecture 200 may include a computer system 202 with an integrated controller or unified policy broker 206 to provide a single user experience and a single API for configuring and managing various policy enforcement engines connected to network devices in a network 234. The network 234 may include a group of interconnected network devices, e.g., 216-220. At least two or more network devices in the network 234 may include a policy enforcement engine. For example, the network devices 216-220 may each include the policy enforcement engines 228-232.
[0020] The Unified Policy Broker (UPB) 206 may include a network monitoring module 210 that may implement a monitoring mechanism to provide comprehensive insight into various attributes associated with the network 234, such as the virtual network infrastructure running on servers; other types of data that may facilitate determining a path taken by network traffic; configuration information associated with a server, a network device, and other configuration information associated with the virtual network.
[0021] The network monitoring module 210 may also monitor and retrieve information related to the capabilities and resource availability of a network device located on the network; information related to the efficiency of a network path based on the various policy enforcement engines along that network path, etc. For example, a network switch supporting an ACL-type policy enforcement engine may offer limited resource capabilities, while a network device supporting a firewall-type policy enforcement engine may support a large number of policy rules, e.g., on the order of thousands or millions of policy rules, and therefore offer expanded resource capabilities. In addition, the network monitoring module 210 may retrieve network information that provides end-to-end visibility, e.g.,Monitoring a path taken by network traffic to enable UPB 206 to apply specific policy rules. For example, for a given network traffic flow, UPB 206 may determine the different types of Policy Enforcement Engines that exist along a path between a first virtual machine on a first host and a second virtual machine on a second host. UPB 206 may enable a user to apply a unified API to select, via user interface 204, one or more Policy Enforcement Engines along the network path to apply a specific policy rule to manage network traffic flowing from the first virtual machine to the second virtual machine.The network monitoring module 210 may not be limited to monitoring the above attributes, but may also provide insights into virtual network stacks and other network attributes that may provide an enhanced view of the network environment.
[0022] Each policy enforcement engine may have its own user interface and API. For example, policy enforcement engines 228, 230, and 232 may be connected to APIs 222, 224, and 226, respectively. The API 222 associated with a policy enforcement engine 226 may use a first representation or terminology to define a policy function, such as policy rules, traffic specifications, enforcement options (e.g., allow, deny, reject, etc.). The API 224 associated with policy enforcement engine 230 may use a second representation or terminology for a similar policy function. In existing systems, a user may apply a policy enforcement engine-specific API to configure the policy enforcement engine.In other words, a user is expected to know the different terminologies and definitions used in the different APIs for similar policy functions on the different policy enforcement engines in order to be able to configure the policy enforcement engines.
[0023] Furthermore, due to the diverse APIs, it can be difficult and complex for the user to understand how the various policy functions associated with the various policy enforcement engines interact and / or relate to each other. Understanding such interrelationships between different policy enforcement engines that exist along a network path can be important to ensure that the operations of the policy enforcement engines do not conflict with each other. In other words, a user can configure an ACL-type policy enforcement engine in a first network device to allow network traffic to be forwarded to a second network device. If the second network device is a firewall, the user must ensure that the firewall-type policy enforcement engine is not configured to block network traffic.
[0024] With the proliferation of different types of policy enforcement engines in a network environment, and with multiple policy enforcement engines each with their own interface and API, manually configuring and managing policy enforcement engines can become difficult and complex. For example, since different types of policy enforcement engines can exist along a physical or logical end-to-end network, the user may need to navigate to each of these infrastructures and understand which types of policies can be linked together to ensure uniform and consistent policy enforcement is applied along the network path associated with the network traffic.
[0025] One aspect described in this application is that the network monitoring module 210 may monitor and retrieve configuration information, which may include information about how a policy model associated with a policy enforcement engine is applied to create one or more policies and policy rules; information about how the policy model represents the one or more policies and policy rules; information about how the policy model represents one or more capabilities associated with the policy enforcement engine.
[0026] Based on the configuration information and other information retrieved from the network monitoring module 210, the UPB 206 may apply a unified policy model module 212 to translate the various descriptions or representations for similar policy functions into a unified description. In other words, the unified policy model module 212 may apply the configuration information and other information retrieved from the network monitoring module 210 to provide a unified API. A user may apply the unified API via a user interface 204 to configure and manage the various types of policy enforcement engines deployed in the network environment. Therefore, the UPB 206 may provide a unified API with a single user experience for configuring, managing, and monitoring various enforcers.
[0027] In other words, with the unified API and a single user interface, the user can configure and manage the various types of policy enforcement engines without having to learn and understand the different terminologies used in the various APIs. In particular, based on the configuration information received from the network monitoring module 210, the unified policy model module 212 can convert the various terminologies associated with the various policy enforcement engines and their respective APIs into a unified terminology, i.e., translate the various terminologies into a unified representation. Furthermore, the unified policy model module 212 can normalize the various terminologies, workflows, and capabilities of the enforcers 228-232 in the network 234.
[0028] The set of normalized workflows between Enforcers 228-232 can allow the user to configure network policies on Enforcers that can interact and complement each other. For example, an ACL-style Enforcer on a switch can provide a filter for traffic allowed on a specific path, which can then be further inspected and modified later by additional Enforcers on that path, such as a firewall device.
[0029] In one aspect of this application, the unified policy model module 212 may retrieve the existing policy definitions configured for various network devices in the network environment (each network device providing a different policy enforcement engine) and create a mapping between a unified policy model and various policy models associated with the respective policy enforcement engines. Such a unified policy model may be used to provide a unified API for configuring and managing the various policy enforcement engines through a user interface. In other words, the unified policy model module 212 may create a unified object model for the various policy enforcement devices that perform similar policy functions.In addition, the unified policy model module 212 may also consider and maintain some of the relevant differences between the various policy enforcement engines, such as performance characteristics, traffic enforcement options, capabilities, etc.
[0030] The configuration module 214 can configure policy enforcement engines, i.e., 228-232, on network devices 216-220 based on the unified API 208. For example, a user can apply the unified API 208 via the user interface 204 to select a policy enforcement engine, e.g., the policy enforcement engine 232 associated with the network device 220, to enforce a particular policy. In one aspect, the user interface 204 can provide a visualization that can include information about various policy enforcement engines in the network 234, information about how policies are enforced for a particular network traffic flow across multiple enforcers. In response to receiving user input via the user interface, e.g.,If the user input may include the selection of one or more policy enforcement engines to enforce the given policy rules, the configuration module 214 may send one or more API commands to a corresponding selected policy enforcement engine. The API commands may include a request to configure the selected policy enforcement engine to enforce one or more predetermined policy rules. The configuration module 214 may send API commands based on the unified API 208 to the corresponding network device to add a given policy to a policy lookup table maintained on the network device.
[0031] In another example, when a user deselects a policy enforcement engine using Unified API 208 via user interface 204, configuration module 214 may send API commands to edit or remove entries in the corresponding policy lookup table so that the network device containing that policy enforcement engine no longer functions as an enforcement point for applying the given policy. An enforcement point may correspond to a network device interface at which a particular policy can be enforced by a policy enforcement engine.
[0032] In one aspect of this application, the UPB 206 may apply the unified policy model module 212 to convert a unified API command into policy-specific API commands. For example, if a user selects the Policy Enforcement Engine 228 using the unified API 208 via the user interface 204 to enforce a particular policy, the unified policy model module 212 may convert a unified representation of a policy function into a Policy Enforcement Engine API 222-specific representation of the policy function. Based on this conversion, the configuration module 214 may send one or more API-specific commands to the Policy Enforcement Engine 228 to enforce the given policy.
[0033] Fig. 3 shows a flowchart illustrating an exemplary process for enabling a unified policy broker according to one aspect of the present application. Referring to flowchart 300 in Fig. 3, a system implementing the Unified Policy Broker may dynamically monitor a network during operation (operation 402) to collect information associated with various Policy Enforcement Engines. Based on the monitoring, the system may receive configuration information associated with various Policy Enforcement Engines in the network (operation 404). This configuration information may include information about how a policy model associated with a Policy Enforcement Engine is applied to create one or more policies and policy rules; information about how the policy model represents the one or more policies and policy rules; and information about how the policy model represents one or more capabilities associated with the Policy Enforcement Engine.
[0034] Based on the configuration information, the system can learn different representations corresponding to a set of similar policy definitions in the different policy enforcement engines in the network (operation 306). The system can also learn different representations corresponding to a set of different capabilities associated with a respective policy enforcement engine. The system can transform or translate the different representations of the set of policy rules into a unified representation (operation 308). In other words, the system can map the different representations associated with the set of similar policy definitions into a unified representation.For example, based on the configuration information, the system may determine a first representation and a second representation of the similar policy function, corresponding to a first and a second policy enforcement engine, respectively. The system may then apply a unified policy model to perform a first mapping from a unified representation of the similar policy function to the first representation and the second representation. The unified representation may provide a unified definition of the similar policy function.
[0035] The system may also map the various representations corresponding to a set of different capabilities to multiple unified representations, thereby preserving the useful differences between the various policy enforcement engines. For example, based on the configuration information, the system may also determine a third representation of a first capability associated with the first policy enforcement engine and a fourth representation of a second capability associated with the second policy enforcement engine. The system may then apply the unified policy model to perform a second mapping from the third representation and the fourth representation to a corresponding first unified representation and a second unified representation, thereby preserving differences in the capabilities associated with the first and second policy enforcement engines.The system may then add the second mapping to the unified API and configure the first and second policy enforcement engines accordingly. The system may create or deploy a unified policy model based on the various mappings, thus providing a unified API to a user through a user interface. This unified policy model may enable a user to apply the unified API through a user interface to configure the various policy enforcement engines (operation 310), thereby providing a single user experience and a single point of control with a unified API. The operation then returns.
[0036] Fig. Figure 4 shows a flowchart illustrating an example process for configuring and managing policy enforcement engines based on a unified policy broker, according to one aspect of the present application. An aspect described in the present application may provide a user interface that enables a user to apply the unified API to select one or more policy enforcement engines existing along a network path for enforcing one or more predetermined policies based on the configuration information and other information (retrieved during a monitoring process).
[0037] The system may receive user input via a user interface based on a unified API (operation 402). The user input may include a selection of one or more policy enforcement engines for enforcing one or more given policy rules. In response to receiving the user input, the system may determine whether the user input includes a selection of a policy enforcement engine (operation 404). If the user input includes a selection of at least one policy enforcement engine, the system may, based on a unified policy model, transform a unified representation of a policy function into the selected policy enforcement-specific API representation of the policy function (operation 406).The system may then, based on the transformation in operation 406, send one or more API commands to the selected policy enforcement engine to enforce the given policy rule (operation 408), then the operation returns.
[0038] If user input indicates that at least one policy enforcement engine is not selected, the system may, based on the unified policy model, convert a unified representation of a policy function into the unselected policy enforcement-specific API representation of the policy function (operation 410). The system may then, based on the conversion in operation 410, send one or more API commands to the unselected policy enforcement engine to remove the given policy rule from a policy lookup table (operation 412), and then the operation returns.
[0039] Fig. 5 shows an example of a user interface for selecting an executor from a list of executors according to one aspect of the present application. In the Fig. 5, the system may provide a user interface 500 that allows a user to select from a list of enforcers. For example, user interface 500 lists two different enforcers, namely an ACL-type enforcer and a distributed firewall-type enforcer. In other words, a system may provide the user with the flexibility to create a policy rule using a same service group or qualifiers, e.g., applications. The user can then simply change the policy type or enforcer to be either a network ACL-type enforcer or a distributed firewall-type enforcer. In response to the selection of the specific enforcement type, the system may ensure that the created policy rule is reflected with the correct implementation.For example, user interface 502 indicates that the user has selected an ACL type Enforcer, and user interface 504 indicates that the user has selected a distributed firewall type Enforcer. Although both Enforcers can implement a similar policy, the user has the flexibility to choose between the two Enforcers. Therefore, with a unified language or API for defining rules, the user can switch between different implementations, such as east-west firewalls, as long as they share a common set of capabilities. The system can also verify that the rule can be applied to a new target Enforcer, enabling seamless migration between different Enforcers. Computer system for enabling automatic selection of policy engines
[0040] Fig.6 illustrates an example of a computer system enabling a unified policy broker according to one aspect of the present application. In this example, computer system 600 may include a processor 602, a memory 604, and a storage device 606. Computer system 600 may be coupled to peripheral input / output (I / O) user devices 616, such as a display device 608, a keyboard 610, and a pointing device 612. Storage device 606 may store instructions for an operating system 618, a unified policy broker system 620, and data 630. Data 630 may include any data desired as input or generated as output by the methods and / or processes described in this disclosure. Computer system 600 may be connected to a network 614 via one or more network interfaces.
[0041] In one aspect of this application, the unified policy broker system 620 may include instructions that, when executed by the processor 602, may cause the computer system 600 to perform the methods and / or processes described in this disclosure. The unified policy broker system 620 may include a communications module 622 for sending network packets to other nodes in the network 614 via one or more network interfaces. The communications module 622 may also receive network packets from other network nodes in the network 614 via one or more network interfaces. The unified policy broker system 620 may further include instructions for implementing a network monitor module 624 for monitoring the network 614 and the network devices located on the network 614.Additionally, the network monitoring module 624 may utilize the communications module 624 to receive configuration information and a set of attributes associated with the monitored network 614.
[0042] The unified policy broker system 620 may include a unified policy model module 626 to determine a unified representation of a set of policy definitions. In other words, policy enforcement engines associated with a respective network device in the network 614 may be configured using a particular API, meaning different policy enforcement engines may be configured with different APIs. Each API may contain a different representation or description of a set of policy definitions. For example, a first API associated with a first policy enforcement engine may provide a first representation of a policy definition, e.g., a policy rule, while a second API associated with a second policy enforcement engine may provide a second representation of a similar policy rule. Often, a network may include multiple policy enforcement engines and multiple APIs.Configuring such policy enforcement engines with different APIs can be complex and difficult.
[0043] The unified policy broker system 620 may employ the unified policy model module 626 to transform these different representations of policy definitions in different policy enforcement engines in the network into a unified representation or a unified API. In other words, the unified policy model module 626 may generate a first type of mapping between different representations of similar policy definitions and a unified policy representation; and a second type of mapping between a set of different representations of different policy enforcement engine capabilities and a set of unified representations, rather than mapping such capability differences into a single unified representation.The first mapping provides a unified representation for the various representations of similar policy functions, while the second mapping preserves the differences in capabilities, such as performance characteristics, traffic enforcement options, etc., that exist between the various policy enforcement engines. Such a unified API can be used for configuring the various policy enforcement engines.
[0044] The configuration module 628 may configure one or more selected policy enforcement engines to enforce the assigned policy rules. If a policy enforcement engine along a network path is not selected, the configuration module 628 may, in one aspect, configure it so that the policy enforcement engine does not enforce the unassigned subset of the given policy rules.
[0045] An aspect described in this application may provide a system and method for enabling a unified policy broker. During operation, the system may receive configuration information from the set of network devices. At least two network devices in the network may be equipped with a first policy enforcement engine and a second policy enforcement engine, respectively, to enforce one or more given policy rules. Each policy enforcement engine may be connected to a different API providing a different representation of a similar policy function. The system may determine, based on the configuration information, a first representation and a second representation of the similar policy function corresponding to the first and second policy enforcement engines, respectively.Furthermore, the system may apply a unified policy model to perform a first mapping from a unified representation of the similar policy function to the first representation and the second representation. The unified representation may provide a unified definition of the similar policy function. Based on the first mapping, the system may create a unified API by representing the first and second representations of the similar policy function with the unified representation. The system may then apply the unified API via a user interface to configure the similar policy function in the first and second policy enforcement engines.
[0046] In a variation of this aspect, the system may determine, based on the configuration information, a third representation of a first capability associated with the first policy enforcement engine and a fourth representation of a second capability associated with the second policy enforcement engine. The system may then apply the unified policy model to perform a second mapping from the third representation and the fourth representation to a corresponding first unified representation and a second unified representation, thereby maintaining differences in the capabilities associated with the first and second policy enforcement engines. Further, the system may add the second mapping to the unified API and configure the first and second policy enforcement engines based on the unified API.
[0047] In a variation of this aspect, the first capability and the second capability comprise one or more of the following elements: the amount of memory available in a corresponding network device; the capabilities of the processing resources in the network device; the number of policy rules supported by a policy enforcement engine associated with the network device; the latency added to a given network traffic flow; the performance characteristics associated with the policy enforcement engine; and the traffic enforcement options provided by the policy enforcement engine.
[0048] In a variation of this aspect, the third representation differs from the fourth representation.
[0049] In a variation of this aspect, the user interface may include a visualization of the various policy enforcement engines in the network, as well as information about how policies are enforced for a given network traffic flow across multiple policy enforcement engines.
[0050] In a variation of this aspect, the system may, via the user interface, apply the unified API to configure the similar policy function in the first and second policy enforcement engines by, in response to determining that a user has selected the first policy enforcement engine to enforce the one or more given policy rules, converting the unified representation of the similar policy function to the first representation and, based on the conversion, sending one or more API commands to a network device implementing the first policy enforcement engine to enforce the one or more given policy rules.
[0051] In a variation of this aspect, the system may, via the user interface, apply the unified API to configure the similar policy function across the first and second policy enforcement engines by, in response to determining that a user has deselected the first policy enforcement engine to enforce the one or more given policy rules, converting the unified representation of the similar policy function to the first representation and, based on the conversion, sending one or more API commands to a network device implementing the first policy enforcement engine to remove the one or more given policy rules from a policy lookup table.
[0052] In a variation of this aspect, the similar policy function may include one or more of the following elements: a policy rule, a policy, a traffic specification, and a set of enforcement options.
[0053] In another variant, the first representation may differ from the second representation.
[0054] In a further variation, the configuration information may include information about how a policy model associated with a policy enforcement engine is applied to create one or more policies and policy rules; information about how the policy model represents the one or more policies and policy rules; and information about how the policy model represents one or more capabilities associated with the policy enforcement engine.
[0055] The methods and processes described in the "Detailed Description" section may be embodied as code and / or data that may be stored in a computer-readable storage medium, as described above. When a computer system reads and executes the code and / or data stored on the computer-readable storage medium, the computer system executes the methods and processes embodied as data structures and code stored in the computer-readable storage medium.
[0056] Furthermore, the methods and processes described above can be integrated into hardware modules or devices. The hardware modules or devices can include, but are not limited to, ASIC chips, field-programmable gate arrays (FPGAs), dedicated or shared processors that execute a specific software module or piece of code at a specific time, and other known or later developed programmable logic devices. When activated, the hardware modules or devices execute the methods and processes contained therein.
[0057] The foregoing descriptions of aspects have been presented for purposes of illustration and description. They are not intended to be exhaustive or to limit the scope of this disclosure to the forms disclosed. Accordingly, many modifications and variations will be apparent to those skilled in the art.
Claims
[1] A computer-implemented method comprising: Receiving configuration information from a set of network devices (110-114, 216-220) at a controller, wherein at least two network devices are equipped with a first policy enforcement engine and a second policy enforcement engine, respectively, to enforce one or more given policy rules, wherein each policy enforcement engine (228-232) is connected to a different application programming interface (API) (116-120, 222-226), and wherein the API provides a different representation of a similar policy function; Determining, based on the configuration information, a first representation and a second representation of the similar policy function corresponding to the first and second policy enforcement engines, respectively; applying a unified policy model to perform a first mapping from a unified representation of the similar policy function to the first representation and the second representation, the unified representation providing a unified definition of the similar policy function; Creating a unified API (122, 208) based on the first mapping by representing the first and second representations of the similar policy function with the unified representation; and Applying the unified API via a user interface (104, 204) to configure the similar policy function in the first and second policy enforcement engines. [2] The computer-implemented method of claim 1, further comprising: Determining a third representation of a first capability associated with the first policy enforcement engine and a fourth representation of a second capability associated with the second policy enforcement engine based on the configuration information; Applying the unified policy model to perform a second mapping from the third representation and the fourth representation to a corresponding first unified representation and a second unified representation, thereby maintaining differences in the capabilities associated with the first and second policy enforcement engines; Adding the second mapping to the unified API and Configure the first and second policy enforcement engines based on the unified API. [3] The computer-implemented method of claim 2, wherein the first capability and the second capability comprise one or more of the following elements: the amount of memory available in a particular network device; Capabilities of the processing resources in the network device; Number of policy rules supported by a policy enforcement engine connected to the network device; Latency added to a particular network traffic flow; Performance characteristics associated with the Policy Enforcement Engine; and Traffic enforcement options provided by the Policy Enforcement Engine. [4] The computer-implemented method of claim 2, wherein the third representation is different from the fourth representation. [5] The computer-implemented method of claim 1, wherein the user interface includes a visualization of: various policy enforcement engines in the network and Information about how policies are enforced for a specific network traffic flow across multiple policy enforcement engines. [6] The computer-implemented method of claim 1, wherein applying the unified API via the user interface to configure the similar policy function via the first and second policy enforcement engines comprises: in response to determining that a user has selected the first policy enforcement engine to enforce the one or more given policy rules, converting the unified representation of the similar policy function to the first representation; and Sending one or more API commands based on the transformation to a network device implementing the first policy enforcement engine to enforce the one or more specified policy rules. [7] The computer-implemented method of claim 1, wherein applying the unified API via the user interface to configure the similar policy function in the first and second policy enforcement engines comprises: in response to determining that a user has deselected the first policy enforcement engine for enforcing the one or more given policy rules, converting the unified representation of the similar policy function to the first representation; and Sending one or more API commands based on the transformation to a network device implementing the first policy enforcement engine to remove the one or more given policy rules from a policy lookup table. [8] The computer-implemented method of claim 1, wherein the similar policy function comprises one or more of the following elements: a policy rule; a policy; Traffic specification and a set of enforcement options. [9] The computer-implemented method of claim 1, wherein the first representation is different from the second representation. [10] The computer-implemented method of claim 1, wherein the configuration information includes: Information about how a policy model associated with a policy enforcement engine is applied to create one or more policies and policy rules; Information about how the policy model represents the one or more policies and policy rules; and Information about how the policy model represents one or more capabilities associated with the Policy Enforcement Engine. [11] A computer system (102, 202, 600) comprising: a processor (602); a memory (604, 606) coupled to the processor and storing instructions that, when executed by the processor, cause the processor to perform a method, the method comprising: Receiving configuration information from a set of network devices (110-114, 216-220) at a controller, wherein at least two network devices are equipped with a first policy enforcement engine and a second policy enforcement engine, respectively, to enforce one or more given policy rules, wherein each policy enforcement engine (228-232) is connected to a different application programming interface (API) (116-120, 222-226), and wherein the API provides a different representation of a similar policy function; Determining, based on the configuration information, a first representation and a second representation of a similar policy function corresponding to the first and second policy enforcement engines, respectively; Applying a unified policy model to create a first mapping from a unified representation of the similar policy function to the first representation and perform the second representation, the unified representation providing a unified definition of the similar policy function; Creating a unified API (122, 208) based on the first mapping by representing the first and second representations of the similar policy function with the unified representation; and Applying the unified API via a user interface (104, 204) to configure the similar policy function in the first and second policy enforcement engines. [12] The computer system of claim 11, wherein the method further comprises: Determining a third representation of a first capability associated with the first policy enforcement engine and a fourth representation of a second capability associated with the second policy enforcement engine based on the configuration information; Applying the unified policy model to perform a second mapping from the third representation and the fourth representation to a corresponding first unified representation and a second unified representation, thereby maintaining differences in the capabilities associated with the first and second policy enforcement engines; Adding the second mapping to the unified API and Configure the first and second policy enforcement engines based on the unified API. [13] The computer system of claim 12, wherein the first capability and the second capability comprise one or more of the following elements: the amount of memory available in a particular network device; Capabilities of the processing resources in the network device; Number of policy rules supported by a policy enforcement engine connected to the network device; Latency added to a particular network traffic flow; Performance characteristics associated with the Policy Enforcement Engine; and Traffic enforcement options provided by the Policy Enforcement Engine. [14] The computer system of claim 12, wherein the third representation is different from the fourth representation. [15] The computer system of claim 11, wherein the user interface includes a visualization of: various policy enforcement engines in the network and Information about how policies are enforced for a specific network traffic flow across multiple policy enforcement engines. [16] The computer system of claim 11, wherein applying the unified API via the user interface to configure the similar policy function via the first and second policy enforcement engines comprises: in response to determining that a user has selected the first policy enforcement engine to enforce the one or more given policy rules, converting the unified representation of the similar policy function to the first representation; and Sending one or more API commands based on the transformation to a network device implementing the first policy enforcement engine to enforce the one or more specified policy rules. [17] The computer system of claim 11, wherein applying the unified API via the user interface to configure the similar policy function in the first and second policy enforcement engines comprises: in response to determining that a user has deselected the first policy enforcement engine for enforcing the one or more given policy rules, converting the unified representation of the similar policy function to the first representation; and Sending one or more API commands based on the transformation to a network device implementing the first policy enforcement engine to remove the one or more given policy rules from a policy lookup table. [18] The computer system of claim 11, wherein the similar policy function comprises one or more of the following elements: a policy rule; a policy; traffic specification; and a range of enforcement options. [19] The computer system of claim 11, wherein the first representation is different from the second representation. [20] The computer system of claim 11, wherein the configuration information comprises: Information about how a policy model associated with a policy enforcement engine is applied to create one or more policies and policy rules; Information about how the policy model represents the one or more policies and policy rules; and Information about how the policy model represents one or more capabilities associated with the Policy Enforcement Engine.
Citation Information
Patent Citations
Epoch comparison for network policy differences
US20200004742A1
Device and method for managing policies and / or resources used for configuring a network
WO2015139724A1