IP Library Granted Patent US 9,917,842
Granted Patent B2
US 9,917,842 · App. 15/230,458 · Granted Mar 13, 2018

Inheritance based network management

Inventors: Michael Xie (Palo Alto, CA); Langtian Du (Fremont, CA); Jun Li (San Jose, CA)
Assignee: Fortinet, Inc.
H04L63/102H04L41/0816H04L41/22H04L63/0227H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,917,842
App. No.
15/230,458
Granted
Mar 13, 2018
Kind
B2
Abstract

Systems and methods for normalization of physical interfaces having different physical attributes are provided. According to one embodiment, information regarding multiple network devices is presented to a network manager. The network devices have one or more different physical attributes. Two physical attributes of two network devices that are to be normalized and that are among the one or more different physical attributes are identified. The physical attributes are normalized by creating a virtual attributes to which both correspond. A policy applicable to the virtual attribute is received. Configuration files, in which policies or rules contained therein are implemented in terms of the virtual attribute, are created for the network devices while they are offline. Physical attribute configurations for the physical attributes are resolved during installation of the network devices by resolving references to the virtual attribute in the configuration files into the respective physical attributes.

Claims (28)

1. A method comprising:

presenting to a network manager, via a graphical user interface (GUI) of a network management system, information regarding a plurality of network devices managed by the network management system, wherein the plurality of network devices have one or more different physical attributes are associated with a private computer network and are logically interposed between client systems of the private computer network and an external computer network;

receiving, via the GUI, from the network manager information indicative of a first physical attribute of a first network device of the plurality of network devices and a second physical attribute of a second network device of the plurality of network devices that are to be normalized, wherein the first physical attribute and the second physical attribute are among the one or more different physical attributes;

normalizing, by the network management system, the first physical attribute and the second physical attribute by creating a virtual attribute to which both the first physical attribute and the second physical attribute correspond;

receiving, via the GUI, from the network manager information regarding a policy applicable to the virtual attribute;

responsive to said receiving, creating or modifying, by the network management system, a first configuration file for the first network device while the first network device is in an offline state and creating or modifying a second configuration file for the second network device while the second network device is in the offline state, wherein one or more policies or rules contained within the first configuration file and the second configuration file are implemented in terms of the virtual attribute; and

applying policy configurations, by the network management system, to the first network device and the second network device and resolving physical attribute configurations for the first physical attribute and the second physical attribute during installation of the first network device and the second network device by resolving references to the virtual attribute in the first configuration file into the first physical attribute and resolving references to the virtual attribute in the second configuration file into the second physical attribute.

2. The method of claim 1 , further comprising:

creating a first policy group having a group policy applicable to all members of the first policy group;

adding the first network device and the second network device to the first policy group; and

wherein said receiving, via the GUI, from the network manager information regarding a policy applicable to the virtual attribute is responsive to said adding the first network device and the second network device to the first policy group.

3. The method of claim 1 , wherein the first network device and the second network device comprise network security devices, web filters, spam firewalls, gateways, routers, load balancers or wireless devices.

4. The method of claim 3 , wherein the first network device and the second network device comprise Unified Threat Management (UTM) devices.

5. The method of claim 1 , wherein the first physical attribute and the second physical attribute comprise a first physical interface and a second physical interface, respectively.

6. A non-transitory program storage device readable by a network management system, embodying a program of instructions executable by one or more processors of the network management system to perform a method of managing a plurality of network devices having one or more different physical attributes, wherein the plurality of network devices are associated with a private computer network and are logically interposed between client systems of the private computer network and an external computer network, the method comprising:

presenting to a network manager, via a graphical user interface (GUI) of the network management system, information regarding the plurality of network devices;

receiving, via the GUI, from the network manager information indicative of a first physical attribute of a first network device of the plurality of network devices and a second physical attribute of a second network device of the plurality of network devices that are to be normalized, wherein the first physical attribute and the second physical attribute are among the one or more different physical attributes;

normalizing, by the network management system, the first physical attribute and the second physical attribute by creating a virtual attribute to which both the first physical attribute and the second physical attribute correspond;

receiving, via the GUI, from the network manager information regarding a policy applicable to the virtual attribute;

responsive to said receiving, creating or modifying, by the network management system, a first configuration file for the first network device while the first network device is in an offline state and creating or modifying a second configuration file for the second network device while the second network device is in the offline state, wherein one or more policies or rules contained within the first configuration file and the second configuration file are implemented in terms of the virtual attribute; and

applying policy configurations, by the network management system, to the first network device and the second network device and resolving physical attribute configurations for the first physical attribute and the second physical attribute during installation of the first network device and the second network device by resolving references to the virtual attribute in the first configuration file into the first physical attribute and resolving references to the virtual attribute in the second configuration file into the second physical attribute.

7. The non-transitory program storage device of claim 6 , wherein the method further comprises:

creating a first policy group having a group policy applicable to all members of the first policy group;

adding the first network device and the second network device to the first policy group; and

wherein said receiving, via the GUI, from the network manager information regarding a policy applicable to the virtual interface is responsive to said adding the first network device and the second network device to the first policy group.

8. The non-transitory program storage device of claim 6 , wherein the first network device and the second network device comprise network security devices, web filters, spam firewalls, gateways, routers, load balancers or wireless devices.

9. The non-transitory program storage device of claim 6 , wherein the first network device and the second network device comprise Unified Threat Management (UTM) devices.

10. The non-transitory program storage device of claim 6 , wherein the first physical attribute and the second physical attribute comprise a first physical interface and a second physical interface, respectively.

Continuity (3)
Continuation 14670323 · Mar 26, 2015
Continuation 11084071 · Mar 16, 2005
Related Publication 20160344588A1 · Nov 24, 2016