IP Library › Granted Patent US 12,457,197
Granted Patent B2
US 12,457,197 · App. 18/335,933 · Granted Oct 28, 2025

Supporting a vendor-neutral policy configuration on a network device with a vendor-specific policy configuration

Inventors: Rajat Rastogi (Alwar, IN); Sandeep Hassan Ramanna (Fremont, CA); Vikas G (Udupi, IN)
Assignee: Juniper Networks, Inc.
H04L63/0245H04L63/101H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,457,197
App. No.
18/335,933
Granted
Oct 28, 2025
Kind
B2
Abstract

A network device may receive a vendor-neutral policy configuration, and may translate the vendor-neutral policy configuration to a first family filter and a second family filter. The network device may associate each of the first family filter and the second family filter with a routing instance and an interface, and may generate a policy configuration supported by the network device based on the first family filter, the second family filter, the routing instance, and the interface.

Claims (55)

1. A method, comprising:

receiving, by a network device, a vendor-neutral policy configuration;

translating, by the network device, the vendor-neutral policy configuration to a first family filter and a second family filter;

associating, by the network device, each of the first family filter and the second family filter with a routing instance and an interface;

generating, by the network device, a policy configuration supported by the network device based on the first family filter, the second family filter, the routing instance, and the interface;

processing, by the network device, packets with the policy configuration to generate first operational state data associated with the first family filter and second operational state data associated with the second family filter;

receiving, by the network device, a request for operational state data associated with the vendor-neutral policy configuration;

aggregating, by the network device, the first operational state data and the second operational state data to generate the operational state data associated with the vendor-neutral policy configuration; and

returning, by the network device, the operational state data associated with the vendor-neutral policy configuration.

2. The method of claim 1 , further comprising:

receiving the packets.

3. The method of claim 2 , wherein each of the first operational state data and the second operational state data is monitoring data or telemetry data.

4. The method of claim 2 , further comprising:

storing the first operational state data in a first data structure; and

storing the second operational state data in a second data structure.

5. The method of claim 1 , wherein the vendor-neutral policy configuration is an openconfig network instance policy configuration.

6. The method of claim 1 , wherein the vendor-neutral policy configuration is an openconfig access control list policy configuration.

7. A network device, comprising:

one or more memories; and

one or more processors, coupled to the one or more memories, configured to:

receive a vendor-neutral policy configuration;

translate the vendor-neutral policy configuration to a first family filter and a second family filter;

associate each of the first family filter and the second family filter with a routing instance and an interface;

generate a policy configuration supported by the network device based on the first family filter, the second family filter, the routing instance, and the interface;

receive packets;

process the packets with the policy configuration to generate first operational state data associated with the first family filter and second operational state data associated with the second family filter;

receive a request for operational state data associated with the vendor-neutral policy configuration;

aggregate the first operational state data and the second operational state data to generate the operational state data associated with the vendor-neutral policy configuration; and

return the operational state data associated with the vendor-neutral policy configuration.

8. The network device of claim 7 , wherein the vendor-neutral policy configuration includes vendor-neutral data models.

9. The network device of claim 7 , wherein each of the first family filter and the second family filter is a Layer-3 filter.

10. The network device of claim 7 , wherein the first family filter is for family Internet protocol version 4 address match conditions.

11. The network device of claim 7 , wherein the second family filter is for family Internet protocol version 6 address match conditions.

12. The network device of claim 7 , wherein the first family filter includes a first set of terms and the second family filter includes a second set of terms.

13. The network device of claim 7 , wherein the policy configuration is for a firewall component of the network device.

14. A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a network device, cause the network device to:

receive a vendor-neutral policy configuration;

translate the vendor-neutral policy configuration to a first family filter and a second family filter;

associate each of the first family filter and the second family filter with a routing instance and an interface;

generate a policy configuration supported by the network device based on the first family filter, the second family filter, the routing instance, and the interface,

wherein the policy configuration is for a firewall component of the network device;

process packets with the policy configuration to generate first operational state data associated with the first family filter and second operational state data associated with the second family filter;

receive a request for operational state data associated with the vendor-neutral policy configuration;

aggregate the first operational state data and the second operational state data to generate the operational state data associated with the vendor-neutral policy configuration; and

return the operational state data associated with the vendor-neutral policy configuration.

15. The non-transitory computer-readable medium of claim 14 , wherein the one or more instructions further cause the network device to:

receive packets;

store the first operational state data in a first data structure; and

store the second operational state data in a second data structure.

16. The non-transitory computer-readable medium of claim 14 , wherein the vendor-neutral policy configuration is an openconfig network instance policy configuration or an openconfig access control list policy configuration.

17. The non-transitory computer-readable medium of claim 14 , wherein each of the first family filter and the second family filter is a Layer-3 filter.

18. The non-transitory computer-readable medium of claim 14 , wherein the first family filter is for family Internet protocol version 4 address match conditions, and the second family filter is for family Internet protocol version 6 address match conditions.

19. The method of claim 1 , wherein the policy configuration is for a firewall component of the network device.

20. The non-transitory computer-readable medium of claim 14 , wherein each of the first operational state data and the second operational state data is monitoring data or telemetry data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2023
From: RASTOGI, RAJAT; RAMANNA, SANDEEP HASSAN; G, VIKAS
To: JUNIPER NETWORKS, INC.
Reel/Frame 063967/0985 →
Continuity (1)
Related Publication 20240422130A1 · Dec 19, 2024
References Cited (15)
US 9369431B1 · Kirby · 2016 [cited by examiner]
US 10212138B1 · Diamant · 2019 [cited by examiner]
US 10558542B1 · A. et al. · 2020 [cited by applicant]
US 20170131980A1 · Velandy · 2017 [cited by examiner]
US 20170187577A1 · Nevrekar et al. · 2017 [cited by applicant]
US 20200366575A1 · Rajendran · 2020 [cited by examiner]
US 20220166717A1 · Pfosi · 2022 [cited by examiner]
US 20220197876A1 · Sterne · 2022 [cited by examiner]
US 20220329489A1 · Nayyar et al. · 2022 [cited by applicant]
US 20220382611A1 · Kapish · 2022 [cited by examiner]
US 20230009328A1 · Ding · 2023 [cited by examiner]
US 20230179525A1 · Pai · 2023 [cited by examiner]
EP 3672157B1 · 2021 [cited by applicant]
Extended European Search Report for Application No. EP231917634 mailed on Feb. 7, 2024, 08 pages. [cited by applicant]
Yang, J., et al., “An Automata-based Security Policy Translation for Network Security Functions, ”International Conference on Information and Communication Technology Convergence, 2018, pp. 268-272. [cited by applicant]