IP Library Granted Patent US 9,509,700
Granted Patent B2
US 9,509,700 · App. 14/249,173 · Granted Nov 29, 2016

Access control list lockout prevention system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,509,700
App. No.
14/249,173
Granted
Nov 29, 2016
Kind
B2
Abstract

An access control list lockout prevention system includes a network. A first administrator Information Handling System (IHS) is coupled to the network. A networking device is communicatively connected to the first administrator IHS through the network. The networking device is configured to receive an access control list instruction from the first administrator IHS. The networking device then determines that at least one administrator IHS that is communicatively connected to the networking device will lose access to the networking device in response to execution of the access control list instruction. In response to determining that the at least one administrator IHS will lose access to the networking device in response to execution of the access control list instruction, the networking device provides a warning message for display on the first administrator IHS.

Claims (44)

1. An access control list lockout prevention system, comprising:

a network;

a first administrator Information Handling System (IHS) that is coupled to the network; and

a networking device that is communicatively connected to the first administrator IHS through the network, wherein the networking device is configured to:

receive an access control list instruction from the first administrator IHS through the network;

determine that at least one administrator IHS Internet Protocol (IP) address of a respective administrator IHS that is communicatively connected to the networking device is subject to an access control list deny statement in the access control list instruction and is not subject to an access control list permit statement in the access control list instruction; and

send a warning message through the network to the first administrator IHS in response to determining that the at least one administrator IHS IP address is subject to the access control list deny statement in the access control list instruction and is not subject to the access control list permit statement in the access control list instruction, wherein the warning message is configured to display a warning on the first administrator IHS that each respective administrator IHS having the at least one administrator IHS IP address will lose access to the networking device if the access control list instruction is executed.

2. The access control list lockout prevention system of claim 1 , wherein the determining that the at least one administrator IHS IP address is subject to the access control list deny statement in the access control list instruction and is not subject to the access control list permit statement in the access control list instruction further includes:

determining that an address of the networking device is included as a destination address in the access control list instruction.

3. The access control list lockout prevention system of claim 1 , wherein determining that the at least one administrator IHS IP address is subject to the access control list deny statement in the access control list instruction and is not subject to the access control list permit statement in the access control list instruction further includes:

determining that the at least one administrator IHS IP address is included in a routing table of the networking device in association with an interface on the networking device to which the access control list instruction applies.

4. The access control list lockout prevention system of claim 1 , wherein the at least one administrator IHS IP address is a first administrator IHS IP address of the first administrator IHS.

5. The access control list lockout prevention system of claim 1 , wherein determining that the at least one administrator IHS IP address is subject to the access control list deny statement in the access control list instruction and is not subject to the access control list permit statement in the access control list instruction further includes:

determining that the at least one administrator IHS IP address is subject to an implicit access control list deny statement in the access control list instruction.

6. The access control list lockout prevention system of claim 1 , wherein the at least one administrator IHS IP address is a second administrator IHS IP address of a second administrator IHS that is communicatively connected to the networking device through the network.

7. An information handling system (IHS), comprising:

a communication system that is configured to couple to a network;

a processing system that is coupled to the communication system;

a memory system that is coupled to the processing system and that includes instructions that, when executed by the processing system, cause the processing system to provide an access control list engine that is configured to:

receive an access control list through the network that is directed to a networking device and that is provided by a first administrator IHS that is coupled to the communication system;

determine that at least one administrator IHS Internet Protocol (IP) address of a respective administrator IHS that is communicatively connected to the networking device is subject to an access control list deny statement in the access control list and is not subject to an access control list permit statement in the access control list; and

send a warning message through the network via the communication system to the first administrator IHS in response to determining that the at least one administrator IHS IP address is subject to the access control list deny statement in the access control list and is not subject to the access control list permit statement in the access control list, wherein the warning message is configured to display a warning on the first administrator IHS that each respective administrator IHS having the at least one administrator IHS IP address will lose access to the networking device if the access control list is applied.

8. The IHS of claim 7 , wherein the determining that the at least one administrator IHS IP address is subject to the access control list deny statement in the access control list and is not subject to the access control list permit statement in the access control list further includes:

determining that an address of the networking device is included as a destination address in the access control list.

9. The IHS of claim 7 , wherein the determining that the at least one administrator IHS IP address is subject to the access control list deny statement in the access control list and is not subject to the access control list permit statement in the access control list further includes:

determining that the at least one administrator IHS IP address is included in a routing table of the networking device in association with an interface on the networking device to which the access control list applies.

10. The IHS of claim 7 , wherein the at least one administrator IHS IP address is a first administrator IHS IP address of the first administrator IHS.

11. The IHS of claim 7 , wherein the determining that the at least one administrator IHS IP address is subject to the access control list deny statement in the access control list and is not subject to the access control list permit statement in the access control list further includes:

determining that the at least one administrator IHS IP address is subject to an implicit access control list deny statement in the access control list.

12. The IHS of claim 7 , wherein the at least one administrator IHS IP address is a second administrator IHS IP address of a second administrator IHS that is communicatively connected to the networking device.

13. The IHS of claim 7 , wherein the warning message is configured to display a request to confirm or deny the application of the access control list.

14. A method for providing access control lists, comprising:

receiving, by an access control list engine through a network, an access control list that is directed to a networking device;

determining, by the access control list engine, that at least one administrator information handling system (IHS) Internet Protocol (IP) address of a respective administrator IHS that is communicatively connected to the networking device through the network is subject to an access control list deny statement in the access control list and is not subject to an access control list permit statement in the access control list; and

sending, by the access control list engine through the network, a warning message in response to determining that the at least one administrator IHS IP address is subject to the access control list deny statement in the access control list and is not subject to the access control list permit statement in the access control list, wherein the warning message is configured to display a warning on a warning display device that each respective administrator IHS having the at least one administrator IHS IP address will lose access to the networking device if the access control list is applied.

15. The method of claim 14 , wherein the determining that the at least one administrator IHS IP address is subject to the access control list deny statement in the access control list and is not subject to the access control list permit statement in the access control list further includes:

determining, by the access control list engine, that an address of the networking device is included as a destination address in the access control list.

16. The method of claim 14 , wherein determining that the at least one administrator IHS IP address is subject to the access control list deny statement in the access control list and is not subject to the access control list permit statement in the access control list further includes:

determining, by the access control list engine, that the at least one administrator IHS IP address is included in a routing table of the networking device in association with an interface on the networking device to which the access control list applies.

17. The method of claim 14 , wherein the at least one administrator IHS IP address is a first administrator IHS IP address of a first administrator IHS that provided the access control list to the access control list engine.

18. The method of claim 14 , wherein determining that the at least one administrator IHS IP address is subject to the access control list deny statement in the access control list and is not subject to the access control list permit statement in the access control list further includes:

determining, by the access control list engine, that the at least one administrator IHS IP address is subject to an implicit access control list deny statement in the access control list.

19. The method of claim 14 , wherein the at least one administrator IHS IP address is a second administrator IHS IP address of a second administrator IHS that is communicatively connected to the networking device and that did not provide the access control list to the access control list engine.

20. The method of claim 14 , wherein the warning message is configured to display a request to confirm or deny the application of the access control list.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL USA L.P.; ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 033625 FRAME 0688 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040027/0757 →
RELEASE OF REEL 033625 FRAME 0748 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040027/0050 →
RELEASE OF REEL 033625 FRAME 0711 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040016/0903 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 033625/0748 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 033625/0711 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 033625/0688 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 10, 2014
From: DAVIS, KEVIN EUGENE; STONE, PATRICIA TIMS
To: DELL PRODUCTS L.P.
Reel/Frame 032644/0687 →