IP Library Granted Patent US 9,455,957
Granted Patent B2
US 9,455,957 · App. 14/272,410 · Granted Sep 27, 2016

Map sharing for a switch device

Inventors: Shehzad Merchant (Los Altos, CA); Hung Nguyen (San Jose, CA); Hoang Nguyen Bao Nguyen (San Jose, CA); Patrick Allen Riley (San Jose, CA); Jay Han Yu (San Jose, CA)
Assignee: Gigamon Inc.
H04L63/0236H04L12/6418H04L45/02H04L45/742H04L47/20H04L49/25H04L49/3054H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,455,957
App. No.
14/272,410
Granted
Sep 27, 2016
Kind
B2
Abstract

A method of implementing map sharing for a network switch appliance, the network switch appliance having a plurality of network ports and a plurality of instrument ports, the method includes: receiving a first input for creating a map for the network switch appliance, wherein the map comprises one or more packet processing rules, and wherein the act of receiving the first input is performed by a processing unit; receiving a second input for prescribing a map sharing privilege for the map; and storing the map and the map sharing privilege in association with the map in a non-transitory medium.

Claims (71)

1. A method of implementing map sharing for a network switch appliance, the network switch appliance having a plurality of network ports and a plurality of instrument ports, the method comprising:

receiving a first input for creating a map for the network switch appliance, wherein the map comprises one or more packet processing rules, and wherein the act of receiving the first input is performed by a processor;

receiving a second input for prescribing a map sharing privilege for the map, wherein at least one of the first input or the second input is from a first user;

storing the map and the map sharing privilege in association with the map in a machine-readable non-transitory storage medium;

receiving a third input from a second user representing a request to access the map;

determining a role of the second user; and

determining whether to allow the second user to access the map based on the role of the second user.

2. The method of claim 1 , wherein the first input comprises one or more parameters for defining the one or more packet processing rules.

3. The method of claim 2 , wherein the first input also comprises a network port identifier of one of the network ports, and/or an instrument port identifier of one of the instrument ports.

4. The method of claim 1 , wherein one of the one or more packet processing rules comprises data for matching against header information of a packet to be received at the network switch appliance.

5. The method of claim 1 , wherein one of the one or more packet processing rules comprises data for matching against non-header information of a packet to be received at the network switch appliance.

6. The method of claim 1 , wherein the first input for creating the map is received from the first user.

7. The method of claim 6 , wherein the first user and the second user belong to different respective roles.

8. The method of claim 1 , wherein the second input includes a parameter for setting a level of the map sharing privilege.

9. The method of claim 8 , wherein the level is selected from at least two levels that include a first level and a second level;

wherein the map is viewable by a user to which the map is shared if the map sharing privilege is set to be the first level; and

wherein the map is viewable, editable, and deletable by a user to which the map is shared if the map sharing privilege is set to be the second level.

10. The method of claim 9 , wherein the level is selected from at least three levels that include the first level, the second level, and a third level; and

wherein the map is viewable by a user to which the map is shared, and the user to which the map is shared may assign an instrument port to the map in a listening mode, if the map sharing privilege is set to be the third level.

11. The method of claim 8 , wherein the parameter is for setting the level of the map sharing privilege on a per-role basis.

12. The method of claim 1 , wherein the first input and the second input are from the first user.

13. The method of claim 12 , further comprising determining whether to allow the second user to perform a task on the map based on a level of the map sharing privilege assigned for the role of the second user.

14. The method of claim 1 , further comprising determining whether to allow a user to assign one or more of the network ports and/or one or more of the instrument ports to the map based on a privilege level of a role to which the user belongs.

15. The method of claim 1 , wherein the non-transitory medium is located in the network switch appliance.

16. The method of claim 1 , wherein the non-transitory medium is located at a location that is remote from the network switch appliance.

17. The method of claim 1 , wherein the processor is a part of the network switch appliance.

18. An apparatus for implementing map sharing for a network switch appliance, the network switch appliance having a plurality of network ports and a plurality of instrument ports, the apparatus comprising:

a processor configured for:

receiving a first input for creating a map for the network switch appliance, wherein the map comprises one or more packet processing rules;

receiving a second input for prescribing a map sharing privilege for the map, wherein at least one of the first input or the second input is from a first user;

receiving a third input from a second user representing a request to access the map;

determining a role of the second user; and

determining whether to allow the second user to access the map based on the role of the second user; and

a machine-readable non-transitory storage medium to store the map and the map sharing privilege.

19. The apparatus of claim 18 , wherein the first input comprises one or more parameters for defining the one or more packet processing rules.

20. The apparatus of claim 19 , wherein the first input also comprises a network port identifier of one of the network ports, and/or an instrument port identifier of one of the instrument ports.

21. The apparatus of claim 18 , wherein one of the one or more packet processing rules comprises data for matching against header information of a packet to be received at the network switch appliance.

22. The apparatus of claim 18 , wherein one of the one or more packet processing rules comprises data for matching against non-header information of a packet to be received at the network switch appliance.

23. The apparatus of claim 18 , wherein the first input for creating the map is received from the first user.

24. The apparatus of claim 23 , wherein the first user and the second user belong to different respective roles.

25. The apparatus of claim 18 , wherein the second input includes a parameter for setting a level of the map sharing privilege.

26. The apparatus of claim 25 , wherein the level is one of at least two levels that include a first level and a second level;

wherein the map is viewable by a user to which the map is shared if the map sharing privilege is set to be the first level; and

wherein the map is viewable, editable, and deletable by a user to which the map is shared if the map sharing privilege is set to be the second level.

27. The apparatus of claim 26 , wherein the level is one of at least three levels that include the first level, the second level, and a third level; and

wherein the map is viewable by a user to which the map is shared, and the user to which the map is shared may assign an instrument port to the map in a listening mode, if the map sharing privilege is set to be the third level.

28. The apparatus of claim 25 , wherein the parameter is for setting the level of the map sharing privilege on a per-role basis.

29. The apparatus of claim 18 , wherein the first input and the second input are from the first user.

30. The apparatus of claim 29 , wherein the processor is further configured for determining whether to allow the second user to perform a task on the map based on a level of the map sharing privilege assigned for the role of the second user.

31. The apparatus of claim 18 , wherein the processor is further configured for determining whether to allow a user to assign one or more of the network ports and/or one or more of the instrument ports to the map based on a privilege level of a role to which the user belongs.

32. The apparatus of claim 18 , wherein the non-transitory medium is located in the network switch appliance.

33. The apparatus of claim 18 , wherein the non-transitory medium is located at a location that is remote from the network switch appliance.

34. The apparatus of claim 18 , wherein the processor is a part of the network switch appliance.

35. A method of implementing map sharing for a network switch appliance, the network switch appliance having a plurality of network ports and a plurality of instrument ports, the method comprising: receiving a first input for creating a map for the network switch appliance, wherein the map includes one or more packet processing rules, and wherein the act of receiving the first input is performed by a processor; receiving a second input for prescribing a map sharing privilege for the map, wherein: the second input includes a parameter for setting a level of the map sharing privilege; the level is selected from at least two levels that include a first level and a second level; the map is viewable by a user to which the map is shared if the map sharing privilege is set to be the first level; and the map is viewable, editable, and deletable by a user to which the map is shared if the map sharing privilege is set to be the second level; and storing the map and the map sharing privilege in association with the map in a machine-readable non-transitory storage medium;

receiving a third input representing a request to access the map; and

determining whether to allow the access to the map based on the level of the map sharing privilege.

36. The method of claim 35 , wherein the level is selected from at least three levels that include the first level, the second level, and a third level; and

wherein the map is viewable by a user to which the map is shared, and the user to which the map is shared may assign an instrument port to the map in a listening mode, if the map sharing privilege is set to be the third level.

37. The method of claim 35 , wherein the parameter is for setting the level of the map sharing privilege on a per-role basis.

38. An apparatus for implementing map sharing for a network switch appliance, the network switch appliance having a plurality of network ports and a plurality of instrument ports, the apparatus comprising:

a processor configured for:

receiving a first input for creating a map for the network switch appliance, wherein the map includes one or more packet processing rules; and

receiving a second input for prescribing a map sharing privilege for the map, wherein:

the second input includes a parameter for setting a level of the map sharing privilege;

the level is one of at least two levels that include a first level and a second level; the map is viewable by a user to which the map is shared if the map sharing privilege is set to be the first level; and

the map is viewable, editable, and deletable by a user to which the map is shared if the map sharing privilege is set to be the second level;

a machine-readable non-transitory storage medium to store the map and the map sharing privilege;

receiving a third input representing a request to access the map; and determining whether to allow the access to the map based on the level of the map sharing privilege.

39. The apparatus of claim 38 , wherein the level is one of at least three levels that include the first level, the second level, and a third level; and

wherein the map is viewable by a user to which the map is shared, and the user to which the map is shared may assign an instrument port to the map in a listening mode, if the map sharing privilege is set to be the third level.

40. The apparatus of claim 38 , wherein the parameter is for setting the level of the map sharing privilege on a per-role basis.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Mar 11, 2022
From: JEFFERIES FINANCE LLC
To: GIGAMON INC.
Reel/Frame 059362/0491 →
SECURITY INTEREST Recorded Mar 11, 2022
From: GIGAMON INC.; ICEBRG LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 059362/0717 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Feb 11, 2020
From: GIGAMON INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 051898/0559 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 10, 2016
From: MERCHANT, SHEHZAD; NGUYEN, HUNG; NGUYEN, HOANG NGUYEN BAO; RILEY, PATRICK ALLEN; YU, JAY HAN
To: GIGAMON INC.
Reel/Frame 037950/0074 →
Continuity (1)
Related Publication 20150326503A1 · Nov 12, 2015