IP Library Granted Patent US 11,438,384
Granted Patent B2
US 11,438,384 · App. 17/153,072 · Granted Sep 6, 2022

Aggregated networking subsystem station move control system

Inventors: Saye Balasubramaniam Subramanian (Chennai, IN); Damodharan Sreenivasagaperumal (Chennai, IN)
Assignee: Dell Products L.P.
H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,438,384
App. No.
17/153,072
Granted
Sep 6, 2022
Kind
B2
Abstract

An aggregated networking device subsystem station move control system includes first and second aggregated networking devices connected via an ICL. The first aggregated networking device receives a MAC address from the second aggregated networking device that was learned on an orphan port that has port security enabled and a station-move-deny configuration, and generates a static MAC address entry in its MAC address table that associates the MAC address with the ICL. The static MAC address entry causes data packets received on non-ICL ports on the first aggregated networking device that include the MAC address to generate a static MAC move violation. The first aggregated networking device also programs rule(s) that, in response to data packets being received on its non-ICL ports that have port security disabled and generating a static MAC move violation, causes the association of the MAC address with that non-ICL port.

Claims (54)

1. An aggregated networking device subsystem station move control system, comprising:

a second aggregated networking device; and

a first aggregated networking device that is coupled to the second networking device via an Inter-Chassis Link (ICL) and aggregated with the second networking device to provide an aggregated networking device subsystem, wherein the first aggregated networking device is configured to:

receive, from the second aggregated networking device, a Media Access Control (MAC) address that was learned on an orphan port that is included on the second aggregated networking device, that has port security enabled, and that is configured as a station-move-deny port;

generate, in a MAC address table associated with the first aggregated networking device, a static MAC address entry that associates the MAC address with the ICL, wherein the static MAC address entry is configured to cause data packets that are received on non-ICL ports on the first aggregated networking device and that include the MAC address to generate a static MAC move violation; and

program, in the first aggregated networking device, at least one rule that, in response to a data packet being received on a non-ICL port on the first aggregated networking device that has port security disabled and generating a static MAC move violation, causes the association of the MAC address with that non-ICL port.

2. The system of claim 1 , wherein the first aggregated networking device includes a network processing subsystem that is configured to:

receive a first data packet that includes the MAC address on a first non-ICL port on the first aggregated networking device;

determine that the first data packet has generated a static MAC move violation based on the static MAC address entry; and

drop the first data packet.

3. The system of claim 2 , wherein the first non-ICL port on the first aggregated networking device has port security enabled.

4. The system of claim 2 , wherein the first aggregated networking device includes at least one hardware device that is configured to:

determine, based on the at least one rule, that the first non-ICL port on the first aggregated networking device has port security disabled; and

forward, based on the at least one rule, information associated with the first data packet to a central processing subsystem included in the first aggregated networking device.

5. The system of claim 4 , wherein the central processing subsystem is configured to:

receive the information associated with first data packet from the at least one hardware device; and

associate the MAC address with the first non-ICL port on the first aggregated networking device.

6. The system of claim 1 , wherein the aggregated networking device subsystem utilizes a Virtual Link Trunking (VLT) protocol.

7. An Information Handling System (IHS), comprising:

a processing system; and

a memory system that is coupled to the processing system and that includes instructions that, when executed by the processing system, cause the processing system to provide a station move control engine that is configured to:

receive, from an aggregated networking device, a Media Access Control (MAC) address that was learned on an orphan port that is included on the aggregated networking device, that has port security enabled, and that is configured as a station-move-deny port;

generate, in a MAC address table, a static MAC address entry that associates the MAC address with an ICL that connects the processing system to the aggregated networking device, wherein the static MAC address entry is configured to cause data packets that are received on non-ICL ports connected to the processing system and that include the MAC address to generate a static MAC move violation; and

program at least one rule that, in response to a data packet being received on a non-ICL port connected to the processing system that has port security disabled and generating a static MAC move violation, causes the association of the MAC address with that non-ICL port.

8. The IHS of claim 7 , wherein the processing system includes a network processing subsystem that is configured to:

receive a first data packet that includes the MAC address on a first non-ICL port connected to the processing system;

determine that the first data packet has generated a static MAC move violation based on the static MAC address entry; and

drop the first data packet.

9. The IHS of claim 8 , wherein the first non-ICL port connected to the processing system has port security enabled.

10. The IHS of claim 8 , wherein the processing system includes at least one hardware device that is configured to:

determine, based on the at least one rule, that the first non-ICL port connected to the processing system has port security disabled; and

forward, based on the at least one rule, information associated with the first data packet to a central processing subsystem included in the processing system.

11. The IHS of claim 10 , wherein the central processing subsystem is configured to:

receive the information associated with the first data packet from the at least one hardware device; and

associate the MAC address with the first non-ICL port connected to the processing system.

12. The IHS of claim 10 , wherein the at least one hardware device includes a field processor, and wherein the at least one rule includes a field processor entry.

13. The IHS of claim 7 , wherein the aggregated networking device utilizes a Virtual Link Trunking (VLT) protocol.

14. A method for providing station move control in an aggregated networking device subsystem, comprising:

receiving, by a first aggregated networking device from a second aggregated networking device that is aggregated with the first networking device to provide an aggregated networking device subsystem, a Media Access Control (MAC) address that was learned on an orphan port that is included on the second aggregated networking device, that has port security enabled, and that is configured as a station-move-deny port;

generating, in a MAC address table associated with the first aggregated networking device, a static MAC address entry that associates the MAC address with an Inter-Chassis Link (ICL) that couples the first aggregated networking device to the second aggregated networking device, wherein the static MAC address entry is configured to cause data packets that are received on non-ICL ports on the first aggregated networking device and that include the MAC address to generate a static MAC move violation; and

programming, by the first aggregated networking device, at least one rule that, in response to a data packet being received on a non-ICL port on the first aggregated networking device that has port security disabled and generating a static MAC move violation, causes the association of the MAC address with that non-ICL port.

15. The method of claim 14 , further comprising:

receiving, by a network processing subsystem in the first aggregated networking device, a first data packet that includes the MAC address on a first non-ICL port on the first aggregated networking device;

determining, by the network processing subsystem, that the first data packet has generated a static MAC move violation based on the static MAC address entry; and

dropping, by the network processing subsystem, the first data packet.

16. The method of claim 15 , wherein the first non-ICL port on the first aggregated networking device has port security enabled.

17. The method of claim 15 , further comprising:

determining, by at least one hardware device in the first aggregated networking device based on the at least one rule, that the first non-ICL port on the first aggregated networking device has port security disabled; and

forwarding, by the at least one hardware device based on the at least one rule, information associated with the first data packet to a central processing subsystem included in the first aggregated networking device.

18. The method of claim 17 , further comprising:

receiving, by the central processing subsystem, the information associated with the first data packet from the at least one hardware device; and

associating, by the central processing subsystem, the MAC address with the first non-ICL port on the first aggregated networking device.

19. The method of claim 17 , wherein the at least one hardware device includes a field processor, and wherein the at least one rule includes a field processor entry.

20. The method of claim 14 , wherein the aggregated networking device utilizes a Virtual Link Trunking (VLT) protocol.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0342) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0460 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0051) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0663 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056136/0752) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0771 →
RELEASE OF SECURITY INTEREST AT REEL 055408 FRAME 0697 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0553 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056136/0752 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0051 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0342 →
SECURITY AGREEMENT Recorded Feb 25, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 055408/0697 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 20, 2021
From: SUBRAMANIAN, SAYE BALASUBRAMANIAM; SREENIVASAGAPERUMAL, DAMODHARAN
To: DELL PRODUCTS L.P.
Reel/Frame 054971/0019 →