IP Library › Granted Patent US 12,244,560
Granted Patent B2
US 12,244,560 · App. 18/478,942 · Granted Mar 4, 2025

Enforcement of inter-segment traffic policies by network fabric control plane

Inventors: Prakash C. Jain (Fremont, CA); Sanjay Kumar Hooda (Pleasanton, CA); Satish Kumar Kondalam (Milpitas, CA); Vikram Vikas Pendharkar (San Jose, CA); Anoop Vetteth (Fremont, CA); Solomon T Lucas (Sunnyvale, CA)
Assignee: Cisco Technology, Inc.
H04L63/0227H04L47/825H04L2212/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,244,560
App. No.
18/478,942
Filed
Sep 29, 2023
Granted
Mar 4, 2025
Kind
B2
Art Unit
2454
USPC
726/13
Abstract

This disclosure describes techniques to operate a control plane in a network fabric. The techniques include determining a stateless rule corresponding to communication between a first segment of the network fabric and a second segment of the network fabric. The techniques further include configuring the control plane to enforce the stateless rule.

Claims (47)

1. A method comprising:

determining a stateless rule corresponding to communication between a first virtual forwarding and routing (VRF) segment of a network fabric and a second VRF segment of the network fabric, the stateless rule being usable to enforce network policy on communications between the first and second VRF segments;

receiving first network layer prefixes associated with first subscriber devices in the first VRF segment and second network layer prefixes associated with second subscriber devices in the second VRF segment;

receiving a packet sent from a first subscriber device of the first VRF, the packet having a source address that is included in the first network layer prefixes and a destination address included in the second network layer prefixes; and

determining, using the stateless rule, the source address, and the destination address, that the packet is allowed to be communicated from the first VRF and to the second VRF.

2. The method of claim 1 , wherein the network fabric is of a BGP EVPN type.

3. The method of claim 1 , wherein:

the first network layer prefixes and second network layer prefixes are received at a network device of the network fabric;

the first network layer prefixes and second network layer prefixes are pushed to the network device according to push model of communication; and

the first network layer prefixes and second network layer prefixes are received at the network device prior to the packet being received.

4. The method of claim 1 , wherein the first network layer prefixes and second network layer prefixes are received, from a centralized router reflector, at a network device of the network fabric that is of a BGP EVPN type.

5. The method of claim 1 , further comprising:

determining an overlap between the source address associated with the first VRF segment and the destination address associated with the second VRF segment; and

enabling communication between the first VRF segment and the second VRF segment based at least in part on the overlap.

6. The method of claim 1 , wherein stateless rule is enforced by a firewall device, further comprising sending, from the firewall device, an advertisement message indicating routes associated with at least one of the first network layer prefixes or the second network layer prefixes.

7. The method of claim 6 , wherein the advertisement message includes an indication of a specific prefix, to attract inter-VRF segment communication from at least one subscriber associated with the specific prefix.

8. A network device comprising:

one or more processors; and

one or more computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving a stateless rule corresponding to communication between a first virtual forwarding and routing (VRF) segment of a network fabric and a second VRF segment of the network fabric, the stateless rule being usable to enforce network policy on communications between the first and second VRF segments;

receiving first network layer prefixes associated with first subscriber devices in the first VRF segment and second network layer prefixes associated with second subscriber devices in the second VRF segment;

receiving a packet sent from a first subscriber device of the first VRF, the packet having a source address that is included in the first network layer prefixes and a destination address included in the second network layer prefixes; and

determining, using the stateless rule, the source address, and the destination address, that the packet is allowed to be communicated from the first VRF and to the second VRF.

9. The network device of claim 8 , wherein the network fabric is of a BGP EVPN type.

10. The network device of claim 8 , wherein:

the first network layer prefixes and second network layer prefixes are pushed to the network device according to push model of communication; and

the first network layer prefixes and second network layer prefixes are received at the network device prior to the packet being received.

11. The network device of claim 8 , wherein the first network layer prefixes and second network layer prefixes are received, from a centralized router reflector, at a network device of the network fabric that is of a BGP EVPN type.

12. The network device of claim 8 , the operations further comprising:

determining an overlap between the source address associated with the first VRF segment and the destination address associated with the second VRF segment; and

enabling communication between the first VRF segment and the second VRF segment based at least in part on the overlap.

13. The network device of claim 8 , wherein network device is a4 firewall device, the operations further comprising sending, from the firewall device, an advertisement message indicating routes associated with at least one of the first network layer prefixes or the second network layer prefixes.

14. The network device of claim 13 , wherein the advertisement message includes an indication of a specific prefix, to attract inter-VRF segment communication from at least one subscriber associated with the specific prefix.

15. A system comprising:

one or more processors; and

one or more computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving a stateless rule corresponding to communication between a first virtual forwarding and routing (VRF) segment of a network fabric and a second VRF segment of the network fabric, the stateless rule being usable to enforce network policy on communications between the first and second VRF segments;

receiving first network layer prefixes associated with first subscriber devices in the first VRF segment and second network layer prefixes associated with second subscriber devices in the second VRF segment;

receiving a packet sent from a first subscriber device of the first VRF, the packet having a source address that is included in the first network layer prefixes and a destination address included in the second network layer prefixes; and

determining, using the stateless rule, the source address, and the destination address, that the packet is allowed to be communicated from the first VRF and to the second VRF.

16. The system of claim 15 , wherein the network fabric is of a BGP EVPN type.

17. The system of claim 15 , wherein:

the first network layer prefixes and second network layer prefixes are pushed to a network device of the system according to push model of communication; and

the first network layer prefixes and second network layer prefixes are received at the network device prior to the packet being received.

18. The system of claim 15 , wherein the first network layer prefixes and second network layer prefixes are received, from a centralized router reflector, at a network device of the system in the network fabric that is of a BGP EVPN type.

19. The system of claim 15 , wherein system includes a firewall device, the operations further comprising sending, from the firewall device, an advertisement message indicating routes associated with at least one of the first network layer prefixes or the second network layer prefixes.

20. The system of claim 19 , wherein the advertisement message includes an indication of a specific prefix, to attract inter-VRF segment communication from at least one subscriber associated with the specific prefix.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2023
From: JAIN, PRAKASH C.; HOODA, SANJAY KUMAR; KONDALAM, SATISH KUMAR; PENDHARKAR, VIKRAM VIKAS; VETTETH, ANOOP; LUCAS, SOLOMON T
To: CISCO TECHNOLGY, INC.
Reel/Frame 065080/0323 →
Continuity (2)
Continuation 17084453 · Oct 29, 2020
Related Publication 20240031333A1 · Jan 25, 2024
References Cited (27)
US 10015132B1 · Qin · 2018 [cited by examiner]
US 10152604B1 · Diaz · 2018 [cited by examiner]
US 10742512B2 · Steinhauer · 2020 [cited by examiner]
US 11089064B1 · Sarukkai · 2021 [cited by examiner]
US 11201854B2 · Valluri · 2021 [cited by examiner]
US 11818096B2 · Jain · 2023 [cited by examiner]
US 20040003070A1 · Fernald · 2004 [cited by examiner]
US 20040131059A1 · Ayyakad · 2004 [cited by examiner]
US 20180359151A1 · Akhavain Mohammadi · 2018 [cited by examiner]
US 20180367337A1 · Jain et al. · 2018 [cited by applicant]
US 20190020489A1 · Moreno · 2019 [cited by examiner]
US 20190116119A1 · Chu · 2019 [cited by examiner]
US 20190132360A1 · Shin et al. · 2019 [cited by applicant]
US 20200036593A1 · Sethi · 2020 [cited by examiner]
US 20200076769A1 · Mishra · 2020 [cited by applicant]
US 20200177550A1 · Valluri · 2020 [cited by examiner]
US 20200204520A1 · Pan · 2020 [cited by examiner]
US 20210168125A1 · Vemulpali · 2021 [cited by examiner]
US 20210320899A1 · Homma · 2021 [cited by examiner]
US 20220141181A1 · Jain et al. · 2022 [cited by applicant]
CN 110381025B · 2020 [cited by applicant]
WO WO2020112345 · 2020 [cited by applicant]
WO WO2020112345A1 · 2020 [cited by applicant]
Indian Office Action mailed Dec. 20, 2023 for Indian Application No. 202347030315, a foreign counterpart to U.S. Pat. No. 11,818,096, 6 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/084,453, mailed on Mar. 6, 2023, Inventor #1 Prakash C. Jain, “Enforcement of Inter-Segment Traffic Policies by Network Fabric Control Plane”, 11 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/084,453, mailed Jul. 11, 2022, Jain, Enforcement of Inter-Segment Traffic Policies by Network Fabric Control Plane, 9 pages. [cited by applicant]
International Search Report and Written Opinion for PCT Application No. PCT/US21/57074, mailed Feb. 14, 2022. [cited by applicant]