IP Library Granted Patent US 10,341,203
Granted Patent B2
US 10,341,203 · App. 14/588,850 · Granted Jul 2, 2019

Policy tracking in a network that includes virtual devices

Inventors: Dennis Drangula (Sparta, NJ); Veniamin Bourakov (Fremont, CA)
Assignee: Gigamon Inc.
H04L43/062H04L41/0816H04L43/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,341,203
App. No.
14/588,850
Granted
Jul 2, 2019
Kind
B2
Abstract

A method performed by a network device includes: receiving an input indicating a change in an auxiliary network from a first configuration to a second configuration, wherein the auxiliary network is configured to obtain copies of packets from a traffic production network; determining a first network policy, wherein the first network policy is for application in the auxiliary network when the auxiliary network is in the first configuration; and determining a second network policy by the network device based on the received input and the first network policy, wherein the second network policy is for application in the auxiliary network when the auxiliary network is in the second configuration.

Claims (42)

1. A method performed by a network device, the method comprising:

receiving, by the network device, an input signal from a device other than the network device, the input signal including an indication that the device other than the network device detected a change in a configuration of a first node or a second node of an auxiliary network from a first configuration to a second configuration, wherein the first node of the auxiliary network is configured to obtain copies of traffic production packets from a traffic production network, the first node is at a boundary between the auxiliary network and the traffic production network, the auxiliary network is not a part of the traffic production network, the second node of the auxiliary network is configured to obtain at least some of the copies of traffic production packets from the first node, and each of the first node and the second node is configured to provide at least one of a packet filtering service, a packet manipulation service, or a packet forwarding service for the copies of traffic production packets;

determining, by the network device, a first network policy including at least one of a rule or criterion that prescribes a first type of packet of the traffic production packets for processing in accordance with a first network objective and precludes from processing another type of packet of the traffic production packets, wherein the first network policy is for application on the copies of traffic production packets in the first node or the second node of the auxiliary network when the first node or the second node of the auxiliary network is in the first configuration;

determining, by the network device, a second network policy that is independent of and distinct from the first network policy and prescribes a second type of packet of the traffic production packets for processing in accordance with a second network objective and precludes from processing another type of packet of the traffic production packets, wherein the second network objective is distinct from the first network objective, is based on the change in the configuration of the first node or the second node of the auxiliary network as indicated in the input signal received from the device other than the network device, and is for application on the copies of traffic production packets in the first node or the second node of the auxiliary network when the first node or the second node of the auxiliary network is in the second configuration; and

deploying, by the network device, the second network policy for application on the copies of traffic production packets in the first node or the second node of the auxiliary network such that the network device automatically adjusts the at least one of a rule or a criterion for processing the copies of traffic production packets by the auxiliary network in accordance with the second network objective as a result of the change in the configuration of the first node or the second node of the auxiliary network as detected by the device other than the network device, wherein the second network policy is for replacing the first network policy, and the second network policy is configured to achieve an objective previously desired to be achieved by the first network policy.

2. The method of claim 1 , wherein the first network policy prescribes the copies of traffic production packets to be forwarded to an instrument port for transmission to a network monitoring instrument.

3. The method of claim 1 , wherein the determining of the second network policy is performed by the network device automatically in response to the received input signal.

4. The method of claim 1 , wherein the input signal is received from a virtual machine management layer.

5. The method of claim 1 , wherein the input signal is received from a controller that is communicatively coupled to the network device.

6. The method of claim 1 , wherein the network device comprises a fabric manager configured to manage the first node or the second node in the auxiliary network.

7. The method of claim 1 , wherein the auxiliary network comprises a virtual machine, and wherein the change in the auxiliary network comprises a movement of the virtual machine from a first host to a second host.

8. The method of claim 1 , wherein the auxiliary network comprises a virtual network interface card, and wherein the change in the auxiliary network comprises a movement of the virtual network interface card.

9. The method of claim 1 , wherein the change in the auxiliary network comprises a change in a configuration of a physical switch device in the auxiliary network.

10. The method of claim 1 , wherein the second network policy is the same as the first network policy.

11. The method of claim 1 , wherein the network device is implemented in a computer, a laptop, a server, a tablet computer, or a phone.

12. The method of claim 1 , wherein the network device comprises multiple appliances that are stacked together or that are communicatively coupled.

13. The method of claim 1 , wherein at least one of the first type of packet or second type of packet defines for processing by a particular virtual switch, a particular virtual machine, or a particular switch device configured to forward packets to a tool that monitors any packet of the first type of packet or the second type of packet.

14. The method of claim 1 , wherein at least one of the first type of packet or second type of packet defines a type of packet received by a node of the auxiliary network, and causes any matching packet to be dropped.

15. The method of claim 1 , wherein at least one of the first type of packet or second type of packet defines a type of packet received by a node of the auxiliary network, and causes header stripping, tagging, payload removal, or insertion of information in any matching packet.

16. A network device, comprising:

a communication interface for receiving an input signal from a device other than the network device, the input signal including an indication that the device other than the network device detected a change in a configuration of a first node or a second node of an auxiliary network from a first configuration to a second configuration, wherein the first node of the auxiliary network is configured to obtain copies of traffic production packets from a traffic production network, the first node is at a boundary between the auxiliary network and the traffic production network, the auxiliary network is not a part of the traffic production network, the second node of the auxiliary network is configured to obtain at least some of the copies of traffic production packets from the first node, and each of the first node and the second node is configured to provide at least one of a packet filtering service, a packet manipulation service, or a packet forwarding service for the copies of traffic production packets;

a processor coupled to the communication interface; and

memory containing instructions that, when executed by the processor, cause the network device to:

determine a first network policy that is configured to achieve a first network objective and that includes at least one of a rule or a criterion for processing the copies of traffic production packets in accordance with the first network objective, wherein the first network policy is for application on the copies of traffic production packets in the first node or the second node of the auxiliary network when the first node or the second node of the auxiliary network is in the first configuration;

determine a second network policy that is configured to achieve a second network objective distinct from the first network objective and that is based on the change in the configuration of the first node or the second node of the auxiliary network as indicated in the input signal received from the device other than the network device and the first network policy, wherein the second network policy is independent of and distinct from the first network policy and is for application on the copies of traffic production packets in the first node or the second node of the auxiliary network when the first node or the second node of the auxiliary network is in the second configuration; and

deploy the second network policy for application on the copies of traffic production packets in the first node or the second node of the auxiliary network such that the network device automatically adjusts the at least one of a rule or a criterion for processing the copies of traffic production packets by the auxiliary network in accordance with the second network objective as a result of the change in the configuration of the first node or the second node of the auxiliary network as detected by the device other than the network device, wherein the second network policy is for replacing the first network policy, and wherein the second network policy is configured to achieve an objective previously desired to be achieved by the first network policy.

17. The network device of claim 16 , wherein the first network policy prescribes the copies of traffic production packets to be forwarded to an instrument port for transmission to a network monitoring instrument.

18. The network device of claim 16 , wherein the processor is configured to determine the second network policy automatically in response to the received input signal.

19. The network device of claim 16 , wherein the communication interface is configured to receive the input signal from a virtual machine management layer.

20. The network device of claim 16 , wherein the communication interface is configured to receive the input signal from a controller that is communicatively coupled to the network device.

21. The network device of claim 16 , wherein the network device comprises a fabric manager configured to manage the first node or the second node in the auxiliary network.

22. The network device of claim 16 , wherein the auxiliary network comprises a virtual machine, and wherein the change in the auxiliary network comprises a movement of the virtual machine from a first host to a second host.

23. The network device of claim 16 , wherein the auxiliary network comprises a virtual network interface card, and wherein the change in the auxiliary network comprises a movement of the virtual network interface card.

24. The network device of claim 16 , wherein the change in the auxiliary network comprises a change in a configuration of a physical switch device in the auxiliary network.

25. The network device of claim 16 , wherein the second network policy is the same as the first network policy.

26. The network device of claim 16 , wherein the network device is implemented in a computer, a laptop, a server, a tablet computer, or a phone.

27. The network device of claim 16 , wherein the network device comprises multiple appliances that are stacked together or that are communicatively coupled.

28. A computer product having a non-transitory medium storing a set of instruction, an execution of which by a processor in a network device causes a method to be performed, the method comprising:

receiving, by the network device, an input signal from a device other than the network device, the input signal including an indication that the device other than the network device detected a change in a configuration of a first node or a second node of an auxiliary network from a first configuration to a second configuration, wherein the first node of the auxiliary network is configured to obtain copies of traffic production packets from a traffic production network, the first node is at a boundary between the auxiliary network and the traffic production network, the auxiliary network is not a part of the traffic production network, the second node of the auxiliary network is configured to obtain at least some of the copies of traffic production packets from the first node, and each of the first node and the second node is configured to provide at least one of a packet filtering service, a packet manipulation service, or a packet forwarding service for the copies of traffic production packets;

determining, by the network device, a first network policy that is configured to achieve a first network objective and that includes at least one of a rule or a criterion for processing the copies of traffic production packets in accordance with the first network objective, wherein the first network policy is for application on the copies of traffic production packets in the first node or the second node of the auxiliary network when the first node or the second node of the auxiliary network is in the first configuration;

determining, by the network device, a second network policy that is configured to achieve a second network objective distinct from the first network objective and that is based on the change in the configuration of the first node or the second node of the auxiliary network as indicated in the input signal received from the device other than the network device and the first network policy, wherein the second network policy is independent of and distinct from the first network policy and is for application on the copies of traffic production packets in the first node or the second node of the auxiliary network when the first node or the second node of the auxiliary network is in the second configuration; and

deploying, by the network device, the second network policy for application on the copies of traffic production packets in the first node or the second node of the auxiliary network such that the network device automatically adjusts the at least one of a rule or a criterion for processing the copies of traffic production packets by the auxiliary network in accordance with the second network objective as a result of the change in the configuration of the first node or the second node of the auxiliary network as detected by the device other than the network device, wherein the second network policy is for replacing the first network policy, and wherein the second network policy is configured to achieve an objective previously desired to be achieved by the first network policy.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Mar 11, 2022
From: JEFFERIES FINANCE LLC
To: GIGAMON INC.
Reel/Frame 059362/0491 →
SECURITY INTEREST Recorded Mar 11, 2022
From: GIGAMON INC.; ICEBRG LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 059362/0717 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Feb 11, 2020
From: GIGAMON INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 051898/0559 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2017
From: DRANGULA, DENNIS; BOURAKOV, VENIAMIN
To: GIGAMON INC.
Reel/Frame 042656/0015 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 14, 2016
From: DRANGULA, DENNIS; BOURAKOV, VENIAMIN
To: GIGAMON INC.
Reel/Frame 038287/0650 →
Continuity (1)
Related Publication 20160197936A1 · Jul 7, 2016