Method for defining a set of rules for a packet forwarding device
View Patent ↗There are methods and apparatus, including computer program products, for defining a policy including a set of rules for a packet forwarding device by receiving information sufficient to enable a first rule related to one of security or traffic management to be defined, and based on the received information, enabling a corresponding second rule related to the other one of security or traffic management to be defined.
1. A method for defining a policy including a set of rules for a packet forwarding device which integrates security and traffic management, the method implemented on a computer system, comprising:
presenting a graphical user interface (GUI) through which a user can specify and/or modify a new traffic management class of data flows, whether rate shaping applies to this class of data flows, burst bandwidth, priority, and type of service; and a traffic management service class selection screen on which the user can select traffic management services, the selection screen comprising a “Basic Web Utilities” service type, a “Voice Applications” service type, and a “Gaming” service type; and
presenting a GUI through which a user specifies a new security rule for the selected traffic management service class.
2. The method of claim 1 wherein presenting a GUI through which a user specifies a new security rule comprises:
presenting a screen for determining a match of source and destination IP addresses with a specified source IP address and/or a specified destination IP address;
presenting a selection screen for specifying an action to be taken upon determination of a match of the source and destination IP addresses of a packet with the specified source IP address and/or the specified destination IP address, wherein the action is selected from one of “drop”“reject” and “accept”.
3. A method for defining a policy including a set of rules for a packet forwarding device which integrates security and traffic management, the method implemented on a computer system, comprising:
presenting a graphical user interface (GUI) through which a user can specify and/or modify a policy for the device;
presenting a network map screen from which the user can add a new security rule or a new traffic management rule to the policy;
bringing up a security settings screen that allows the user to enter various pieces of information to enable a new security rule to be defined,
wherein the information comprises attributes of IP address matching parameters, operation parameters, and service parameters;
presenting a screen for specifying “Source IP address” and/or “Destination IP address” attributes;
presenting a selection screen for specifying an action to be taken on a packet upon determination of a match of said packet's source IP address and/or destination IP address with the specified Source IP address attributes and/or the specified Destination IP address attributes wherein the action is selected from one of “drop”,“reject”, and “accept”; and
presenting a class selection screen on which the user can also select a traffic management class to which a security rule is to be linked comprising a drop down menu of the existing traffic management classes and a new traffic management class settings screen that allows the user to enter various pieces of information to customize a traffic management rule, wherein the information comprises a total amount of bandwidth that is guaranteed to this class of data flows, whether rate shaping applies to this class of data flows, burst bandwidth, priority, and type of service.