IP Library Patent Application 13196782
Patent Application
App. No. 13/196,782

EGRESS PROCESSING OF INGRESS VLAN ACLs

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/196,782
Abstract

A network packet processing system includes source and destination virtual local area networks (VLANs) that are indirectly connected through a network routing device. Additionally, the network packet processing system includes a metadata generator connected to provide metadata for a network packet to be routed between the source and destination VLANS, wherein the metadata captures pre-routing source VLAN information from the network packet. The network packet processing system also includes an access control list (ACL) for specifying routing of the network packet between the source and destination VLANs that employs the pre-routing source VLAN information from the metadata and post-routing destination VLAN information from the network packet. A method of network packet processing is also included.

Claims (27)

1 . A method of network packet processing, comprising:

providing indirectly linked source and destination virtual local area networks (VLANs) that are connected through a network routing device;

defining an access control list (ACL) specifying network traffic between the source and destination VLANs;

generating metadata for a network packet to be routed between the source and destination VLANS, wherein the metadata captures pre-routing source VLAN information from the network packet; and

applying the ACL for routing the network packet employing the pre-routing source VLAN information from the metadata and post-routing destination VLAN information from the network packet.

2 . The method as recited in claim 1 wherein the network packet is an internet protocol (IP) packet.

3 . The method as recited in claim 1 wherein the metadata is included in an additional header that is mapped onto the packet.

4 . The method as recited in claim 3 wherein the additional header is a HiGig header.

5 . The method as recited in claim 1 wherein the metadata exists for at least a portion of an ingress-to-egress period of the network packet.

6 . The method as recited in claim 1 wherein the pre-routing source and post-routing destination VLAN information includes respective source and destination VLAN identification (ID) numbers.

7 . The method as recited in claim 6 wherein the source VLAN ID number is stored in a classification tag of a HiGig header.

8 . The method as recited in claim 6 wherein the destination VLAN ID number is stored in a VLAN tag.

9 . The method as recited in claim 6 wherein the source and destination VLAN ID numbers range from one to 4094.

10 . The method as recited in claim 1 wherein the metadata and the ACL conform to the IEEE 802.1Q specification.

11 . A network packet processing system, comprising:

source and destination virtual local area networks (VLANs) that are indirectly connected through a network routing device;

a metadata generator connected to provide metadata for a network packet to be routed between the source and destination VLANS, wherein the metadata captures pre-routing source VLAN information from the network packet; and

an access control list (ACL) for specifying routing of the network packet between the source and destination VLANs that employs the pre-routing source VLAN information from the metadata and post-routing destination VLAN information from the network packet.

12 . The system as recited in claim 11 wherein the network packet is an internet protocol (IP) packet.

13 . The system as recited in claim 11 wherein the metadata is included in an additional header that is mapped onto the packet.

14 . The system as recited in claim 13 wherein the additional header is a HiGig header.

15 . The system as recited in claim 11 wherein the metadata exists for at least a portion of an ingress-to-egress period of the network packet.

16 . The system as recited in claim 11 wherein the pre-routing source and post-routing destination VLAN information includes respective source and destination VLAN identification (ID) numbers.

17 . The system as recited in claim 16 wherein the source VLAN ID number is stored in a classification tag of a HiGig header.

18 . The system as recited in claim 16 wherein the destination VLAN ID number is stored in a VLAN tag.

19 . The system as recited in claim 16 wherein the source and destination VLAN ID numbers range from one to 4094.

20 . The system as recited in claim 11 wherein the metadata and the ACL conform to the IEEE 802.1Q specification.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Oct 9, 2014
From: CREDIT SUISSE AG
To: ALCATEL-LUCENT USA INC.
Reel/Frame 033949/0016 →
SECURITY INTEREST Recorded Mar 7, 2013
From: ALCATEL-LUCENT USA INC.
To: CREDIT SUISSE AG
Reel/Frame 030510/0627 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2012
From: ALCATEL-LUCENT USA INC.
To: ALCATEL LUCENT
Reel/Frame 028969/0884 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2011
From: OLAKANGIL, JOSEPH F.
To: ALCATEL-LUCENT USA INC.
Reel/Frame 026785/0287 →