IP Library › Granted Patent US 12,120,022
Granted Patent B1
US 12,120,022 · App. 17/932,532 · Granted Oct 15, 2024

Traffic filtering based on destination address and incoming interface of a network device

Inventors: Shijo Thomas (Sunnyvale, CA); Zhaohui Zhang (Westford, MA)
Assignee: Juniper Networks, Inc.
H04L45/566H04L45/42H04L45/745
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,120,022
App. No.
17/932,532
Granted
Oct 15, 2024
Kind
B1
Abstract

In some implementations, a network device may receive one or more packets via an incoming interface of the network device. The network device may forward, or refraining from forwarding, based on a destination address associated with the one or more packets and the incoming interface of the network device, the one or more packets. The network device may receive, prior to receiving the one or more packets, route information indicating the destination address, and at least one of a set of one or more authorized incoming interfaces of the network device or a set of one or more authorized identifiers that are associated with the destination address and may save the route information in an entry of a data structure. Forwarding, or refraining from forwarding, the one or more packets may further be based on the entry of the data structure.

Claims (83)

1. A method, comprising:

receiving, by a network device, one or more packets via an incoming interface of the network device;

determining, by the network device, a destination address associated with one or more services and the one or more packets;

identifying, by the network device, the incoming interface of the network device;

searching, based on the destination address, a data structure to identify an entry that indicates a set of one or more authorized identifiers that are associated with the destination address,

wherein each authorized identifier, of the set of one or more authorized identifiers, is associated with a subscription related to the one or more services;

determining, by the network device, whether the destination address and the incoming interface of the network device are associated with the set of one or more authorized identifiers;

determining, by the network device and based on determining whether the destination address and the incoming interface of the network device are associated with the set of one or more authorized identifiers, whether the network device is to forward the one or more packets; and

forwarding, by the network device, or refraining from forwarding, based on determining whether the network device is to forward the one or more packets, the one or more packets.

2. The method of claim 1 , wherein determining whether the network device is to forward the one or more packets comprises:

searching, based on the destination address, the data structure to identify another entry that indicates a set of one or more authorized incoming interfaces of the network device that are associated with the destination address;

determining whether the incoming interface of the network device is included in the set of one or more authorized incoming interfaces; and

determining, based on determining whether the incoming interface of the network device is included in the set of one or more authorized incoming interfaces, whether the network device is to forward the one or more packets,

wherein the network device determines that the network device is to forward the one or more packets based on determining that the incoming interface of the network device is included in the set of one or more authorized incoming interfaces of the network device, and

wherein the network device determines that the network device is to refrain from forwarding the one or more packets based on determining that the incoming interface of the network device is not included in the set of one or more authorized incoming interfaces of the network device.

3. The method of claim 1 , further comprising:

advertising, prior to receiving the one or more packets, a prefix for the destination address to neighbor devices respectively connected to the network device by one or more interfaces of the network device; and

saving, based on advertising the prefix for the destination address, the prefix for the destination address and information associated with a set of the one or more interfaces of the network device connecting to the neighbor devices as authorized incoming interfaces of the network device in another entry of the data structure.

4. The method of claim 1 , wherein

the network device determines that the network device is to forward the one or more packets based on determining that the incoming interface of the network device is associated with the set of one or more authorized identifiers, and

wherein the network device determines that the network device is to refrain from forwarding the one or more packets based on determining that the incoming interface of the network device is not associated with the set of one or more authorized identifiers.

5. The method of claim 1 , further comprising:

advertising, prior to receiving the one or more packets, a prefix for the destination address to neighbor devices respectively connected to the network device by one or more interfaces of the network device; and

saving, based on advertising the prefix for the destination address, the prefix for the destination address and the set of one or more authorized identifiers that are associated with the prefix of the destination address in the entry of the data structure,

wherein each authorized identifier, of the set of one or more authorized identifiers, is associated with one or more interfaces connecting to the neighbor devices.

6. The method of claim 1 , wherein each authorized identifier, of the set of one or more authorized identifiers, is an external border gateway protocol group identifier.

7. The method of claim 1 , wherein determining whether the network device is to forward the one or more packets comprises:

searching, based on the destination address and the incoming interface, a forwarding information base (FIB) to identify another entry that indicates whether the network device is to forward the one or more packets; and

determining, based on the other entry, whether the network device is to forward the one or more packets,

wherein the network device determines that the network device is to forward the one or more packets when the entry indicates that the network device is to forward the one or more packets, and

wherein the network device determines that the network device is to refrain from forwarding the one or more packets when the entry indicates that the network device is to not forward the one or more packets.

8. The method of claim 7 , further comprising:

advertising, prior to receiving the one or more packets, a prefix of the destination address to neighbor devices respectively connected to the network device by one or more interfaces of the network device; and

saving, based on advertising the prefix of the destination address, for each of the interfaces connecting to the neighbor devices, the prefix and information associated with the interface in association with an entry of the FIB.

9. The method of claim 8 , wherein an identifier associated with the interface is an external border gateway protocol group identifier.

10. A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a network device, cause the network device to:

receive one or more packets via an incoming interface of the network device;

search, based on a destination address associated with one or more services and the one or more packets, a data structure to identify an entry that indicates a set of one or more authorized identifiers that are associated with the destination address,

wherein each authorized identifier of the set of one or more authorized identifiers is associated with a subscription related to the one or more services;

determine, based on determining whether the incoming interface of the network device is associated with the set of one or more authorized identifiers, whether the network device is to forward the one or more packets; and

forward, or refrain from forwarding, based on determining whether the network device is to forward the one or more packets, the one or more packets.

11. The non-transitory computer-readable medium of claim 10 , wherein the one or more instructions, that cause the network device to determine whether the network device is to forward the one or more packets, cause the network device to:

identify, based on the destination address, another entry in the data structure that indicates a set of one or more authorized incoming interfaces of the network device that are associated with the destination address; and

determine, based on the other entry and the incoming interface of the network device, whether the network device is to forward the one or more packets,

wherein the network device determines that the network device is to forward the one or more packets when the incoming interface of the network device is included in the set of one or more authorized incoming interfaces indicated by the other entry, and

wherein the network device determines that the network device is to refrain from forwarding the one or more packets when the incoming interface of the network device is not included in the set of one or more authorized incoming interfaces indicated by the other entry.

12. The non-transitory computer-readable medium of claim 10 , wherein the one or more instructions, when executed by the one or more processors, further cause the network device to:

advertise, prior to receiving the one or more packets, a prefix for the destination address to neighbor devices respectively connected to the network device by one or more interfaces of the network device; and

save, based on advertising the prefix for the destination address, the prefix for the destination address and information associated with a set of the one or more interfaces of the network device connecting to the neighbor devices as authorized incoming interfaces of the network device in another entry of the data structure.

13. The non-transitory computer-readable medium of claim 10 , wherein the one or more instructions, when executed by the one or more processors, further cause the network device to:

advertise, prior to receiving the one or more packets, a prefix for the destination address to neighbor devices respectively connected to the network device by one or more interfaces of the network device; and

save, based on advertising the prefix for the destination address, the prefix for the destination address and the set of one or more authorized identifiers that are associated with the prefix of the destination address in the entry of the data structure,

wherein each authorized identifier, of the set of one or more authorized identifiers, is associated with one or more interfaces connecting to the neighbor devices.

14. The non-transitory computer-readable medium of claim 10 , wherein the one or more instructions, that cause the network device to determine whether the network device is to forward the one or more packets, cause the network device to:

identify, based on the destination address and the incoming interface, another entry in the data structure that indicates whether the network device is to forward the one or more packets; and

determine, based on the other entry, whether the network device is to forward the one or more packets,

wherein the network device determines that the network device is to forward the one or more packets when the entry indicates that the network device is to forward the one or more packets, and

wherein the network device determines that the network device is to refrain from forwarding the one or more packets when the entry indicates that the network device is to not forward the one or more packets.

15. The non-transitory computer-readable medium of claim 10 , wherein the one or more instructions, when executed by the one or more processors, further cause the network device to:

advertise, prior to receiving the one or more packets, a prefix of the destination address to neighbor devices respectively connected to the network device by one or more interfaces of the network device; and

save, based on advertising the prefix of the destination address, for each of the interfaces connecting to the neighbor devices, the prefix and information associated with the interface or an identifier associated with the interface, in association with an entry of a forwarding information base (FIB).

16. A network device, comprising:

one or more memories; and

one or more processors to:

receive one or more packets via an incoming interface of the network device;

search, based on a destination address associated with one or more services and the one or more packets, a data structure to identify an entry that indicates a set of one or more authorized identifiers that are associated with the destination address,

wherein each authorized identifier of the set of one or more authorized identifiers is associated with a subscription related to the one or more services;

determine, based on determining whether the incoming interface of the network device is associated with the set of authorized identifiers, whether the network device is to forward the one or more packets; and

forward, or refrain from forwarding, based on determining whether the network device is to forward the one or more packets, the one or more packets.

17. The network device of claim 16 , wherein the one or more processors, to forward, or refrain from forwarding, the one or more packets, are to:

identify, based on the destination address, another entry in the data structure that indicates a set of one or more authorized incoming interfaces of the network device that are associated with the destination address; and

forward, or refrain from forwarding, based on the entry and the incoming interface of the network device, the one or more packets.

18. The network device of claim 16 , wherein the one or more processors, to forward, or refrain from forwarding, the one or more packets, are to:

identify, based on the destination address and the incoming interface, another entry in the data structure that indicates whether the network device is to forward the one or more packets; and

forward, or refrain from forwarding, based on the entry, the one or more packets.

19. The network device of claim 16 , wherein the one or more processors, to forward, or refrain from forwarding, the one or more packets, are to:

advertise, prior to receiving the one or more packets, a prefix of the destination address to neighbor devices respectively connected to the network device by one or more interfaces of the network device; and

save, based on advertising the prefix of the destination address, for each of the interfaces connecting to the neighbor devices, the prefix and information associated with the interface or an identifier associated with the interface, in association with an entry of a forwarding information base (FIB).

20. The network device of claim 16 , wherein the one or more processors are further to:

advertise, prior to receiving the one or more packets, a prefix for the destination address to neighbor devices respectively connected to the network device by one or more interfaces of the network device; and

save, based on advertising the prefix for the destination address, the prefix for the destination address and the set of one or more authorized identifiers that are associated with the prefix of the destination address in the entry of the data structure,

wherein each authorized identifier, of the set of one or more authorized identifiers, is associated with one or more interfaces connecting to the neighbor devices.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2025
From: THOMAS, SHIJO; ZHANG, ZHAOHUI
To: JUNIPER NETWORKS, INC.
Reel/Frame 070719/0986 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2022
From: THOMAS, SHIJO; ZHANG, ZHAOHUI
To: JUNIPER NETWORKS, INC.
Reel/Frame 061110/0803 →
Cited By (2)
US 12,245,036 US 12,574,322