IP Library Granted Patent US 9,479,415
Granted Patent B2
US 9,479,415 · App. 15/043,421 · Granted Oct 25, 2016

Duplicating network traffic through transparent VLAN flooding

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,479,415
App. No.
15/043,421
Granted
Oct 25, 2016
Kind
B2
Abstract

Provided are methods, non-transitory computer-readable medium, and network devices for duplicating network traffic through transparent VLAN flooding. In some implementations, a network device comprises a plurality of ports. The plurality of ports may include a first port configured as a receiving port for a VLAN configured for the network device. The plurality of ports may further include a set of ports configured as I/O ports of the VLAN. MAC learning may be disabled for the receiving port. In some implementations, the network device is configured to determine, based on contents of a packet received at the receiving port, that the packet is to be sent to one or more monitoring devices. The network device may further be configure to, upon receiving the packet at the receiving port of the VLAN, cause a copy of the packet to be sent to each of one or more I/O ports of the VLAN.

Claims (30)

1. A method comprising:

determining, based on contents of a packet received at a network device, that the received packet is to be sent to one or more monitoring devices, wherein the network device includes a virtual local area network (VLAN), the VLAN including a receiving port and a plurality of I/O ports, the receiving port and the plurality of I/O ports of the VLAN corresponding to ports of the network device, wherein Media Access Control (MAC) learning has been disabled for the receiving port, and wherein the packet is received at the receiving port of the VLAN; and

upon receiving the packet at the receiving port of the VLAN, causing a copy of the packet to be sent to each of one or more of the plurality of I/O ports of the VLAN.

2. The method of claim 1 , wherein the packet is a duplicate packet received from an in-line tap.

3. The method of claim 1 , wherein the packet is received from a network traffic source.

4. The method of claim 1 , wherein determining that the packet is to be monitored includes determining that information included in the packet matches a defined parameter.

5. The method of claim 1 , wherein causing a copy of the packet to be sent to each of one or more of the plurality of I/O ports includes selecting one or more ports from the plurality of I/O ports, wherein the one or more selected ports are determined using an access control list.

6. The method of claim 1 , wherein each of the plurality of I/O ports is configured to connect to a corresponding monitoring device.

7. The method of claim 1 , wherein causing a copy of the packet to be sent to each of one or more of the plurality of I/O ports includes causing a copy of the packet to be sent to each of the plurality of I/O ports.

8. A non-transitory computer-readable medium storing a plurality of instructions executable by one or more processors of a network device, the network device including a virtual local area network (VLAN), the VLAN including a receiving port and a plurality of I/O ports, the receiving port and the plurality of I/O ports of the VLAN corresponding to ports of the network device, wherein Media Access Control (MAC) learning has been disabled for the receiving port; and

wherein the plurality of instructions comprise:

instructions for causing at least one processor from the one or more processors to determine, based on contents of a packet received at the receiving port of the VLAN, that the packet is to be sent to one or more monitoring devices; and

upon receiving the packet at the receiving port of the VLAN:

instructions for causing at least one processor from the one or more processors to cause a copy of the packet to be sent to each of one or more of the plurality of I/O ports of the VLAN.

9. The non-transitory computer-readable medium of claim 8 , wherein the packet is a duplicate packet received from an in-line tap.

10. The non-transitory computer-readable medium of claim 8 , wherein the packet is received from a network traffic source.

11. The non-transitory computer-readable medium of claim 8 , wherein the instructions for causing at least one processor from the one or more processors to cause a copy of the packet to be sent to each of one or more of the plurality of I/O ports includes instructions for causing at least one processor from the one or more processors to select one or more ports from the plurality of I/O ports, wherein the one or more selected ports are determined using an access control list.

12. The non-transitory computer-readable medium of claim 8 , wherein each of the plurality of I/O ports is configured to connect to a monitoring device.

13. The non-transitory computer-readable medium of claim 8 , wherein the instructions for causing at least one processor from the one or more processors to cause a copy of the packet to be sent to one or more of the plurality of I/O ports includes instructions for causing at least one processor from the one or more processors to send a copy to each of the plurality of I/O ports.

14. A network device, comprising:

a plurality of ports, comprising a first port configured as a receiving port for a VLAN configured for the network device, the plurality of ports further comprising a set of ports configured as I/O ports of the VLAN, wherein Media Access Control (MAC) learning has been disabled for the receiving port;

wherein the network device is configured to:

determine, based on contents of a packet received at the receiving port of the VLAN, that the packet is to be sent to one or more monitoring devices; and

upon receiving the packet at the receiving port of the VLAN, cause a copy of the packet to be sent to each of one or more of the I/O ports of the VLAN.

15. The network device of claim 14 , wherein the packet is a duplicate packet received from an in-line tap.

16. The network device of claim 14 , wherein the packet is received from a network traffic source.

17. The network device of claim 14 , wherein the network device is configured to determine that the packet is to be sent to one or more monitoring devices by determining that information included in the packet matches a defined parameter.

18. The network device of claim 14 , wherein the network device is further configured to cause a copy of the packet to be sent to each of one or more of the plurality of I/O ports includes selecting one or more ports from the plurality of I/O ports, wherein the one or more I/O ports are determined using an access control list.

19. The network device of claim 14 , wherein each of the plurality of I/O ports is configured to connect to a corresponding monitoring device.

20. The network device of claim 14 , wherein the network device is configured to cause a copy of the packet to be sent to each of the plurality of I/O ports.

Assignments (5)
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2016
From: NATARAJAN, HARI; SAHLE, ESKINDER; HELFINSTINE, CHARLES; OSKUIE, CHRIS
To: FOUNDRY NETWORKS, INC.
Reel/Frame 040331/0707 →