IP Library Granted Patent US 12,476,903
Granted Patent B2
US 12,476,903 · App. 18/113,240 · Granted Nov 18, 2025

Network partition filter

Inventors: Michael Avimelech Gandelman Milgrom (Aventura, FL); Lior Hodaya Bezen (Tel-Aviv, IL); Alex Netes (Rehovot, IL); Yoav Menes (Tel Aviv, IL); Guy Rozenberg Kunievsky (Rehovot, IL); Vladimir Koushnir (Rishon Le Zion, IL); Lion Levi (Yavne, IL); Eitan Zahavi (Zichron Yaakov, IL)
Assignee: MELLANOX TECHNOLOGIES, LTD.
H04L45/26H04L45/745H04L47/2416H04L49/111
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,476,903
App. No.
18/113,240
Granted
Nov 18, 2025
Kind
B2
Abstract

A networking device and system are described, among other things. An illustrative system is disclosed to include a switch programmed to route a received packet to an egress port based on a combination of a destination address associated with the received packet and an identification of an ingress port from which the packet was received by the switch.

Claims (31)

1 . A system for providing dynamic logical port isolation, the system comprising:

a processor; and

a memory device coupled with the processor, wherein the memory device comprises data stored thereon that, when processed by the processor, enables the processor to:

receive a packet via an ingress port, wherein the packet is associated with a destination address;

determine, based on the ingress port and the destination address associated with the packet, one or more egress ports are authorized to transmit packets both received via the ingress port and associated with the destination address; and

in response to determining the one or more egress ports are authorized to transmit packets both received via the ingress port and associated with the destination address, forward the packet to the destination address via at least one of the one or more egress ports.

2 . The system of claim 1 , wherein the processor is provided in a flow manager of a switch.

3 . The system of claim 1 , wherein the packet is received from a switch.

4 . The system of claim 1 , wherein a filter table is referenced to determine that the one or more egress ports are authorized to transmit the packet.

5 . The system of claim 4 , wherein the filter table lists, for each of a plurality of destination addresses, one or more pairs of ingress ports and egress ports authorized for transmission.

6 . The system of claim 5 , wherein determining the one or more egress ports are authorized to transmit packets both received via the ingress port and associated with the destination address comprises determining the ingress port and the destination address match a pair of ingress ports and egress ports.

7 . The system of claim 4 , wherein the filter table is modified based at least in part on traffic data received by the system.

8 . The system of claim 1 , wherein determining the one or more egress ports are authorized to transmit packets both received via the ingress port and associated with the destination address is based at least in part on traffic data received by the system.

9 . The system of claim 1 , wherein for packets associated with a particular destination address, one or more ingress ports are isolated from one or more egress ports.

10 . The system of claim 1 , wherein a second one or more egress ports are not authorized to transmit packets both received via the ingress port and associated with the destination address.

11 . A switch, comprising a processor to perform:

receiving a packet via an ingress port, wherein the packet is associated with a destination address;

determining, based on the ingress port and a destination address associated with the packet, one or more egress ports are authorized to transmit packets both received via the ingress port and associated with the destination address; and

in response to determining the one or more egress ports are authorized to transmit packets received via the ingress port and associated with the destination address, forwarding the packet to the destination address via at least one of the one or more egress ports.

12 . The switch of claim 11 , wherein the processor is provided in a flow manager of the switch.

13 . The switch of claim 11 , wherein the packet is received from a second switch.

14 . The switch of claim 11 , wherein a filter table is referenced to determine that the one or more egress ports are authorized to transmit the packet.

15 . The switch of claim 14 , wherein the filter table lists, for each of a plurality of destination addresses, one or more pairs of ingress ports and egress ports authorized for transmission.

16 . The method of claim 15 , wherein determining the one or more egress ports are authorized to transmit packets both received via the ingress port and associated with the destination address comprises determining the ingress port and the destination address match a pair of ingress ports and egress ports.

17 . The switch of claim 11 , wherein for packets associated with a particular destination address, one or more ingress ports are isolated from one or more egress ports.

18 . A networking device, comprising a processor to perform:

receiving a packet via an ingress port, wherein the packet is associated with a destination address;

determining, based on the ingress port and a destination address associated with the packet, one or more egress ports are authorized to transmit packets both received via the ingress port and associated with the destination address; and

in response to determining the one or more egress ports are authorized to transmit packets received via the ingress port and associated with the destination address, forwarding the packet to the destination address via at least one of the one or more egress ports.

19 . The networking device of claim 18 , wherein a filter table is referenced to determine that the one or more egress ports are authorized to transmit the packet.

20 . The networking device of claim 19 , wherein the filter table lists, for each of a plurality of destination addresses, one or more pairs of ingress ports and egress ports authorized for transmission.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2023
From: GANDELMAN MILGROM, MICHAEL AVIMELECH; BEZEN, LIOR HODAYA; NETES, ALEX; MENES, YOAV; KUNIEVSKY, GUY ROZENBERG; KOUSHNIR, VLADIMIR; LEVI, LION; ZAHAVI, EITAN
To: MELLANOX TECHNOLOGIES, LTD.
Reel/Frame 062793/0421 →
Continuity (1)
Related Publication 20240291749A1 · Aug 29, 2024
References Cited (8)
US 20080240106A1 · Schlenk · 2008 [cited by examiner]
US 20130272135A1 · Leong · 2013 [cited by examiner]
US 20140195666A1 · Dumitriu · 2014 [cited by examiner]
US 20150063364A1 · Thakkar · 2015 [cited by examiner]
US 20160080261A1 · Koponen · 2016 [cited by examiner]
US 20160352637A1 · Wakumoto · 2016 [cited by examiner]
US 20180109441A1 · Meyer · 2018 [cited by examiner]
US 20220353174A1 · Kfir et al. · 2022 [cited by applicant]