IP Library › Granted Patent US 12,580,891
Granted Patent B2
US 12,580,891 · App. 18/401,089 · Granted Mar 17, 2026

Group based policy for non-virtual extensible local area network deployments

Inventors: Balaji Palanisamy (Tiruppur, IN); Samatha Madhusudan Punja (Bangalore, IN); Veera Srinivas Kamana (Bangalore, IN)
Assignee: Juniper Networks, Inc.
H04L63/0245H04L63/0876H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,580,891
App. No.
18/401,089
Filed
Dec 29, 2023
Granted
Mar 17, 2026
Kind
B2
Art Unit
2449
USPC
726/11
Abstract

A network device may receive, from a server device, a first tag assigned to a first host device, and may generate a first filter based on the first tag. The network device may receive a second filter generated based on a second tag assigned to a second host device, and may generate a policy based on the first filter and the second filter. The network device may propagate the first filter and the second filter to one or more other network devices, and may receive a packet. The network device may derive a source tag and a destination tag associated with the packet, and may determine an action for the packet based on the policy, the source tag, and the destination tag. The network device may perform the action.

Claims (71)

1 . A method, comprising:

receiving, by a network device and from a server device, a first tag assigned to a first host device;

generating, by the network device, a first filter based on the first tag;

receiving, by the network device, a second filter generated based on a second tag assigned to a second host device;

generating, by the network device, a policy based on the first filter and the second filter; and

propagating, by the network device, the first filter and the second filter to one or more other network devices using a BGP update message, wherein an extended communities field within the BGP update message is set to indicate the first tag or the second tag, and one or more actions associated with the policy.

2 . The method of claim 1 , further comprising:

receiving a packet;

deriving a source tag and a destination tag associated with the packet;

determining an action of the one or more actions for the packet based on the policy, the source tag, and the destination tag; and

performing the action.

3 . The method of claim 2 ,

wherein performing the action comprises dropping the packet.

4 . The method of claim 2 ,

wherein performing the action comprises causing the packet to be provided to a destination based on the destination tag and via the one or more other network devices.

5 . The method of claim 2 ,

wherein the source tag corresponds to the first tag and the destination tag corresponds to the second tag.

6 . The method of claim 1 ,

wherein the server device is to authenticate the first host device and assign the first tag to the first host device.

7 . The method of claim 1 ,

wherein the server device is to authenticate the second host device and assign the second tag to the second host device.

8 . A network device, comprising:

one or more memories; and

one or more processors to:

receive, from a server device, a first tag assigned to a first host device;

generate a first filter based on the first tag;

receive a second filter generated based on a second tag assigned to a second host device;

generate a policy based on the first filter and the second filter;

propagate the first filter and the second filter to one or more other network devices using a BGP update message, wherein an extended communities field within the BGP update message is set to indicate the first tag or the second tag, and one or more actions associated with the policy;

receive a packet;

derive a source tag and a destination tag associated with the packet;

determine an action of the one or more actions for the packet based on the policy, the source tag, and the destination tag; and

perform the action.

9 . The network device of claim 8 ,

wherein the network device and the one or more other network devices are associated with a non-virtual extensible local area network.

10 . The network device of claim 8 ,

wherein each of the first filter and the second filter is a border gateway protocol flow specification filter.

11 . The network device of claim 8 ,

wherein the one or more processors, to propagate the first filter and the second filter to the one or more other network devices, are to:

generate border gateway protocol (BGP) network layer reachability information (NLRI) that includes the first filter and the second filter; and

propagate the BGP NLRI to the one or more other network devices.

12 . The network device of claim 8 ,

wherein each of the first tag and the second tag is a group based policy tag.

13 . The network device of claim 8 ,

wherein the network device is an ingress device for the first host device.

14 . The network device of claim 8 ,

wherein one of the one or more other network devices is an egress device for the second host device.

15 . A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a network device, cause the network device to:

receive, from a server device, a first tag assigned to a first host device;

generate a first filter based on the first tag;

receive a second filter generated based on a second tag assigned to a second host device;

generate a policy based on the first filter and the second filter;

propagate the first filter and the second filter to one or more other network devices using a BGP update message, wherein an extended communities field within the BGP update message is set to indicate the first tag or the second tag, and one or more actions associated with the policy;

receive a packet;

derive a source tag and a destination tag associated with the packet; and

determine an action of the one or more actions for the packet based on the policy, the source tag, and the destination tag.

16 . The non-transitory computer-readable medium of claim 15 ,

wherein the one or more instructions further cause the network device to one of:

drop the packet based on the action; or

cause, based on the action, the packet to be provided to a destination based on the destination tag and via the one or more other network devices.

17 . The non-transitory computer-readable medium of claim 15 ,

wherein the source tag corresponds to the first tag and the destination tag corresponds to the second tag.

18 . The non-transitory computer-readable medium of claim 15 ,

wherein the network device and the one or more other network devices are associated with a non-virtual extensible local area network.

19 . The non-transitory computer-readable medium of claim 15 ,

wherein each of the first filter and the second filter is a border gateway protocol flow specification filter.

20 . The non-transitory computer-readable medium of claim 15 ,

wherein the one or more instructions, that cause the network device to propagate the first filter and the second filter to the one or more other network devices, cause the network device to:

generate border gateway protocol (BGP) network layer reachability information (NLRI) that includes the first filter and the second filter; and

propagate the BGP NLRI to the one or more other network devices.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2023
From: PALANISAMY, BALAJI; PUNJA, SAMATHA MADHUSUDAN; KAMANA, VEERA SRINIVAS
To: JUNIPER NETWORKS, INC.
Reel/Frame 065985/0423 →
Continuity (1)
Related Publication 20250219997A1 · Jul 3, 2025
References Cited (7)
US 20100271954A1 · Eswaran · 2010 [cited by examiner]
US 20150012998A1 · Nellikar et al. · 2015 [cited by applicant]
US 20160261638A1 · Xu et al. · 2016 [cited by applicant]
US 20220045971A1 · Lu · 2022 [cited by examiner]
US 20230093278A1 · Majila · 2023 [cited by examiner]
Extended European Search Report for European Application No. EP24160136.8 dated Jul. 15, 2024, 10 pages. [cited by applicant]
Lin, W., et al., “Group Policy ID Bgp Draft-wlin-bess-group-policy-id-extended-community 03: Draft-wlin-bess-group-policy-id-extended-community 03.Txt”, Group Policy Id Bgp Extended Community Drapt Wlin Bess Group-polic… [cited by applicant]