IP Library Granted Patent US 10,355,930
Granted Patent B2
US 10,355,930 · App. 14/210,069 · Granted Jul 16, 2019

System and method of subnetting a virtual network identifier

Inventors: Kelly Ann Wanser (San Francisco, CA); Andreas Markos Antonopoulos (San Francisco, CA)
Assignee: Fortinet, Inc.
H04L41/0866H04L12/4633H04L12/4645H04L41/0893
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,355,930
App. No.
14/210,069
Granted
Jul 16, 2019
Kind
B2
Abstract

A method and apparatus that determines a plurality of matching policies for a segment of a dynamic virtualized network is described. A device retrieves a virtual network identifier of the segment, where the virtual network identifier includes a plurality of bits and a plurality of subnets and each of the plurality of subnets is a different subset of the plurality of bits. In addition, the dynamic virtualized network is a virtualized layer 2 network that is overlaid on a layer 3 physical network, where the layer 3 physical network includes a plurality of network access devices, and the segment includes a plurality of endpoints. The device further determines the plurality of matching policies for the segment from the plurality of subnets of the virtual network identifier, where each of the plurality of subnets corresponds to one of the plurality of matching policies. The device additionally applies the plurality of matching policies to each network access device that corresponds to one of the plurality of matching endpoints.

Claims (44)

1. A method comprising:

maintaining, by a network policy module of a network automation engine associated with a dynamic virtualized network, a set of hierarchical policies, wherein each policy of the set of hierarchical policies specifies how network data for a corresponding segment of a plurality of segments of the dynamic virtualized network is to be processed and wherein the set of hierarchical policies include a top-level root policy that is applicable to all of the plurality of segments and sub-policies that are additionally applicable to corresponding tenants of a plurality of tenants or to corresponding categories of a plurality of categories of computer systems associated with the corresponding segments;

retrieving, by the network policy module, a virtual network identifier of a segment of the plurality of segments of the dynamic virtualized network, wherein the virtual network identifier includes a plurality of bits defining a plurality of hierarchical subnets of the virtual network identifier, each of the plurality of hierarchical subnets is represented by a different subset of the plurality of bits, the dynamic virtualized network is a virtualized layer 2 network that is overlaid on a layer 3 physical network, the layer 3 physical network includes a plurality of network access devices, and the segment includes a plurality of tunnel endpoints;

determining, by the network policy module, a plurality of matching policies for the segment based on the plurality of hierarchical subnets of the virtual network identifier by identifying and aggregating those of the set of hierarchical policies applicable to each of the plurality of hierarchical subnets, wherein each of the plurality of hierarchical subnets corresponds to at least one of the plurality of matching policies; and

applying, by the network policy module, the plurality of matching policies to each network access device of the plurality of network access devices that corresponds to one of the plurality of tunnel endpoints.

2. The method of claim 1 , wherein the dynamic virtualized network is a Virtual eXtensible Local Area Network.

3. The method of claim 1 , wherein the virtual network identifier is represented by a dotted collection of the plurality of subnets.

4. The method of claim 1 , wherein one of the plurality of subnets is a top-level net and others of the plurality of subnets are subnets of the top-level net.

5. The method of claim 1 , wherein the determining the plurality of matching policies comprises:

determining a policy match for each of the plurality of subnets from a set of possible policies.

6. The method of claim 5 , wherein the determining the policy match comprises:

for each of the plurality of subnets,

applying a policy mask that corresponds to one of set of possible policies to the virtual network identifier, wherein the set of possible policies correspond to that subnet, and

adding the one of the set of possible policies to the plurality of matching policies if the policy mask indicates a match.

7. The method of claim 5 , wherein the set of possible policies is a set of sub-policies of one of the plurality of matching policies.

8. The method of claim 1 , wherein the virtual network identifier is a Virtual eXtensible Local Area Network Network Identifier.

9. The method of claim 1 , wherein a network access device is selected from the group consisting of a switch and a router.

10. A non-transitory machine-readable medium having executable instructions to cause one or more processing units to perform a method of determining a plurality of matching policies for a segment of a plurality of segments of a dynamic virtualized network, the method comprising:

maintaining, by a network policy module of a network automation engine associated with the dynamic virtualized network, a set of hierarchical policies, wherein each policy of the set of hierarchical policies specifies how network data for a corresponding segment of the plurality of segments is to be processed and wherein the set of hierarchical policies include a top-level root policy that is applicable to all of the plurality of segments and sub-policies that are additionally applicable to corresponding tenants of a plurality of tenants or to corresponding categories of a plurality of categories of computer systems associated with the corresponding segments;

retrieving, by the network policy module, a virtual network identifier of the segment of the dynamic virtualized network, wherein the virtual network identifier includes a plurality of bits defining a plurality of hierarchical subnets of the virtual network identifier, each of the plurality of hierarchical subnets is represented by a different subset of the plurality of bits, the dynamic virtualized network is a virtualized layer 2 network that is overlaid on a layer 3 physical network, the layer 3 physical network includes a plurality of network access devices, and the segment includes a plurality of tunnel endpoints;

determining, by the network policy module, a plurality of matching policies for the segment based on the plurality of hierarchical subnets of the virtual network identifier by identifying and aggregating those of the set of hierarchical policies applicable to each of the plurality of hierarchical subnets, wherein each of the plurality of hierarchical subnets corresponds to at least one of the plurality of matching policies; and

applying, by the network policy module, the plurality of matching policies to each network access device of the plurality of network access devices that corresponds to one of the plurality of tunnel endpoints.

11. The non-transitory machine-readable medium of claim 10 , wherein the dynamic virtualized network is a Virtual eXtensible Local Area Network.

12. The non-transitory machine-readable medium of claim 10 , wherein the virtual network identifier is represented by a dotted collection of the plurality of subnets.

13. The non-transitory machine-readable medium of claim 10 , wherein one of the plurality of subnets is a top-level net and others of the plurality of subnets are subnets of the top-level net.

14. The non-transitory machine-readable medium of claim 10 , wherein the determining the plurality of matching policies comprises:

determining a policy match for each of the plurality of subnets from a set of possible policies.

15. The non-transitory machine-readable medium of claim 14 , wherein the determining the policy match comprises:

for each of the plurality of subnets,

applying a policy mask that corresponds to one of set of possible policies to the virtual network identifier, wherein the set of possible policies correspond to that subnet, and

adding the one of the set of possible policies to the plurality of matching policies if the policy mask indicates a match.

16. A system to determine a plurality of matching policies for a segment of a plurality of segments of a dynamic virtualized network, the system comprising:

a plurality of network access devices;

a layer 3 physical network interconnecting the plurality of network access devices;

the dynamic virtualized network, wherein the dynamic virtualized network is a virtualized layer 2 network that is overlaid on the layer 3 physical network and the segment includes a plurality of tunnel endpoints; and

a network automation element, coupled to the plurality of network access elements, wherein the network automation element:

maintains a set of hierarchical policies, wherein each policy of the set of hierarchical policies specifies how network data for a corresponding segment of the plurality of segments is to be processed and wherein the set of hierarchical policies include a top-level root policy that is applicable to all of the plurality of segments and sub-policies that are additionally applicable to corresponding tenants of a plurality of tenants or to corresponding categories of a plurality of categories of computer systems associated with the corresponding segments,

retrieves a virtual network identifier of the segment of the dynamic virtualized network, wherein the virtual network identifier includes a plurality of bits defining a plurality of hierarchical subnets of the virtual network identifier, each of the plurality of hierarchical subnets is represented by a different subset of the plurality of bits,

determines the plurality of matching policies for the segment based on the plurality of hierarchical subnets of the virtual network identifier by identifying and aggregating those of the set of hierarchical policies applicable to each of the plurality of hierarchical subnets, and

applies the plurality of matching policies to each network access device of the plurality of network access devices that corresponds to at least one of the plurality of tunnel endpoints, wherein each of the plurality of subnets corresponds to a different one of the plurality of matching policies.

17. The system of claim 16 , wherein the dynamic virtualized network is a Virtual eXtensible Local Area Network.

18. The system of claim 16 , wherein the virtual network identifier is represented by a dotted collection of the plurality of subnets.

19. The system of claim 16 , wherein one of the plurality of subnets is a top-level net and others of the plurality of subnets are subnets of the top-level net.

20. The system of claim 16 , wherein the virtual network identifier is a Virtual eXtensible Local Area Network Network Identifier.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2016
From: LUMINUS NETWORKS, INC.
To: FORTINET, INC.
Reel/Frame 039774/0396 →
CHANGE OF NAME Recorded Mar 21, 2016
From: STATELESS NETWORKS INC.
To: LUMINUS NETWORKS INC.
Reel/Frame 038190/0333 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 6, 2014
From: WANSER, KELLY; ANTONOPOULOS, ANDREAS MARKOS
To: STATELESS NETWORKS, INC.
Reel/Frame 033481/0028 →
Continuity (2)
Provisional Application 61783757 · Mar 14, 2013
Related Publication 20140337497A1 · Nov 13, 2014
Cited By (1)
US 12,683,884