SHORTEST PATH BRIDGING (SPB) SECURITY GROUP POLICY
Disclosed herein are system, method, and computer program product aspects for implementing a security group policy. Some aspects of this disclosure relate to a method for applying a security group policy. The method includes receiving a first frame from a source device and assigning a source security group identifier (ID) to the first frame. The method further includes generating a second frame based on the first frame and the source security group ID and identifying a target security group ID for the second frame. The method also includes applying one or more forwarding decisions to the second frame based on the source security group ID and the target security group ID.
1 . A method for applying a security group policy in a Shortest Path Bridging (SPB) network, the method comprising:
assigning a source security group identifier (ID) to a first frame from a source device based on a first Instance Service Identifiers (I-SID) or a first virtual local area network (VLAN);
generating a second frame based on the first frame and the source security group ID;
identifying a target security group ID for the second frame based on a second I-SID or a second VLAN; and
applying one or more forwarding decisions to the second frame based on the source security group ID and the target security group ID.
2 . The method of claim 1 , wherein the assigning the source security group ID comprises:
determining a port on which the first frame is received; and
assigning the source security group ID further based on the determined port.
3 . The method of claim 1 , wherein the assigning the source security group ID comprises:
determining a client Media Access Control (MAC) (C-MAC) address associated with the source device; and
assigning the source security group ID further based on the determined C-MAC address.
4 . The method of claim 1 , wherein the identifying the target security group ID comprises:
determining a port on which the second frame is to be transmitted to a destination device; and
identifying the target security group ID further based on the determined port.
5 . The method of claim 1 , wherein the identifying the target security group ID comprises:
determining a client Media Access Control (MAC) (C-MAC) address associated with a destination device; and
identifying the target security group ID further based on the determined C-MAC address.
6 . The method of claim 1 , wherein the generating the second frame based on the first frame and the source security group ID comprises:
adding a tag protocol identifier (TPID) field to the first frame; and
adding a source security group ID field to the first frame,
7 . The method of claim 6 , wherein the source security group ID field is immediately after the TPID field and wherein a value of the TPID field indicates that the source security group ID field includes the source security group ID.
8 . The method of claim 1 , wherein the applying one or more forwarding decisions to the second frame based on the source security group ID and the target security group ID comprises:
using a communication matrix to determine whether the source security group ID and the target security group ID are allowed to communicate; and
in response to determining that the source security group ID and the target security group ID are allowed to communicate, forwarding the second frame to a destination device associated with the target security group ID.
9 . A system for applying a security group policy in a Shortest Path Bridging (SPB) network, the system comprising:
a memory; and
at least one processor coupled to the memory and configured to:
assign a source security group identifier (ID) to a first frame from a source device based on a first Instance Service Identifiers (I-SID) or a first virtual local area network (VLAN);
generate a second frame based on the first frame and the source security group ID;
identify a target security group ID for the second frame based on a second I-SID or a second VLAN; and
apply one or more forwarding decisions to the second frame based on the source security group ID and the target security group ID.
10 . The system of claim 9 , wherein to assign the source security group ID, the at least one processor is further configured to:
determine a port on which the first frame is received; and
assign the source security group ID further based on the determined port.
11 . The system of claim 9 , wherein to assign the source security group ID, the at least one processor is configured to:
determine a client Media Access Control (MAC) (C-MAC) address associated with the source device; and
assign the source security group ID further based on the determined C-MAC address.
12 . The system of claim 9 , wherein to identify the target security group ID, the at least one processor is configured to:
determine a port on which the second frame is to be transmitted to a destination device; and
identify the target security group ID further based on the determined port.
13 . The system of claim 9 , wherein to identify the target security group ID, the at least one processor is configured to:
determine a client Media Access Control (MAC) (C-MAC) address associated with a destination device; and
identify the target security group ID further based on the determined C-MAC address.
14 . The system of claim 9 , wherein to generate the second frame based on the first frame and the source security group ID, the at least one processor is further configured to:
add a tag protocol identifier (TPID) field to the first frame; and
add a source security group ID field to the first frame.
15 . The system of claim 14 , wherein the source security group ID field is immediately after the TPID field and a value of the TPID field indicates that the source security group ID field includes the source security group ID.
16 . The system of claim 9 , wherein to apply one or more forwarding decisions to the second frame based on the source security group ID and the target security group ID, the at least one processor is further configured to:
use a communication matrix to determine whether the source security group ID and the target security group ID are allowed to communicate; and
in response to determining that the source security group ID and the target security group ID are allowed to communicate, forward the second frame to a destination device associated with the target security group ID.
17 . A tangible computer-readable device having instructions stored thereon that, when executed by at least one processor, cause the at least one processor to perform operations for applying a security group policy in a Shortest Path Bridging (SPB) network, the operations comprising:
receiving a first frame from a source device;
assigning a source security group identifier (ID) to the first frame based on a first Instance Service Identifiers (I-SID) or a first virtual local area network (VLAN);
generating a second frame based on the first frame and the source security group ID;
identifying a target security group ID for the second frame based on a second I-SID or a second VLAN; and
applying one or more forwarding decisions to the second frame based on the source security group ID and the target security group ID.
18 . The computer-readable device of claim 17 , wherein the generating the second frame based on the first frame and the source security group ID comprises:
adding a tag protocol identifier (TPID) field to the first frame; and
adding a source security group ID field to the first frame,
wherein the source security group ID field is immediately after the TPID field, and
wherein a value of the TPID field indicates that the source security group ID field includes the source security group ID.
19 . The computer-readable device of claim 17 , wherein the applying one or more forwarding decisions to the second frame based on the source security group ID and the target security group ID comprises:
using a communication matrix to determine whether the source security group ID and the target security group ID are allowed to communicate; and
in response to determining that the source security group ID and the target security group ID are allowed to communicate, forwarding the second frame to a destination device associated with the target security group ID.
20 . The computer-readable device of claim 17 , wherein:
the assigning the source security group ID comprises:
determining a first client Media Access Control (MAC) (C-MAC) address associated with the source device; and
assigning the source security group ID further based on the determined first C-MAC address, and
the identifying the target security group ID comprises:
determining a second C-MAC address associated with a destination device; and
assigning the target security group ID further based on the determined second C-MAC address.