IP Library Granted Patent US 7,660,259
Granted Patent B1
US 7,660,259 · App. 10/969,678 · Granted Feb 9, 2010

Methods and systems for hybrid hardware- and software-base media access control (MAC) address learning

Assignee: Extreme Networks, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,660,259
App. No.
10/969,678
Granted
Feb 9, 2010
Kind
B1
Abstract

Methods and systems for hybrid layer 2 address learning are disclosed. In one method, a packet with a layer 2 source address is received. Next, it is determined whether to implement hardware-based learning or software-based learning based on a classification of the received packet. In response to determining that software-based learning is required, the source address and corresponding forwarding information in the packet are learned using software. In response to determining that hardware-based learning is required, the source address and corresponding forwarding information are learned using hardware.

Claims (59)

1. A method for layer 2 address learning in a forwarding device, the method comprising:

(a) receiving a packet including a layer 2 source address at a forwarding device having software and hardware for learning the source address and forwarding information associated with the packet;

(b) at the forwarding device, classifying the packet and determining whether to implement software-based learning based on a classification determined for the packet;

(c) at the forwarding device, in response to determining to implement software-based learning, utilizing the software of the forwarding device for learning the source address of the received packet and the forwarding information associated with the packet using a software routine executed on a processor of the forwarding device; and, otherwise,

(d) at the forwarding device, utilizing the hardware of the forwarding device for learning the source address of the received packet and the forwarding information associated with the packet using learning operations implemented in hardware logic of the forwarding device.

2. The method of claim 1 wherein the layer 2 source address includes a media access control (MAC) source address.

3. The method of claim 1 wherein the forwarding information includes a port on which the packet was received.

4. The method of claim 1 wherein determining whether to implement software-based learning based on the classification includes determining whether to implement software-based learning based on a port on which the packet was received.

5. The method of claim 1 wherein determining whether to implement software-based learning based on the classification includes determining whether to implement software-based learning based on a virtual local area network (VLAN) associated with the received packet.

6. The method of claim 1 wherein utilizing the software of the forwarding device for learning the source address of the received packet includes:

(a) receiving the packet at an Input/Output (I/O) module;

(b) forwarding the packet to a management processor; and

(c) performing the software-based learning at the management processor.

7. The method of claim 1 wherein performing hardware-based learning includes receiving the packet at a hardware device located on an Input/Output (I/O) module and learning the source address of the received packet using the hardware device on the I/O module.

8. The method of claim 1 comprising, in response to determining to implement software-based learning, applying a layer 2 security policy to the received packet.

9. The method of claim 8 wherein utilizing the software of the forwarding device for learning the source address includes learning the source address of the received packet only in response to the received packet passing the security policy.

10. The method of claim 8 wherein applying a layer 2 security policy includes limiting learning of the source address in the received packet based on a predetermined condition.

11. The method of claim 10 wherein the predetermined condition includes at least one of a source port and source Virtual Local Area Network (VLAN) associated with the received packet.

12. The method of claim 10 wherein the predetermined condition includes the presence of the source address in an administratively defined table.

13. The method of claim 8 wherein applying a layer 2 security policy includes implementing an 802.1x security policy.

14. The method of claim 1 wherein utilizing the software of the forwarding device for learning the source address includes writing the source address to a hardware forwarding table.

15. The method of claim 14 wherein writing the source address to the hardware forwarding table includes overwriting a hardware-learned entry in the forwarding table with the source address and forwarding information associated with the received packet.

16. A layer 2 switch for implementing hybrid hardware- and software-based layer 2 address learning, the layer 2 switch comprising:

(a) a forwarding table in the layer 2 switch for storing layer 2 forwarding addresses and corresponding forwarding information;

(b) learning and forwarding logic in the layer 2 switch for performing hardware-based layer 2 address learning and updating the forwarding table with hardware-learned layer 2 addresses; and

(c) a processor in the layer 2 switch for performing software-based learning of layer 2 addresses by executing a software routine on the processor, wherein performing software-based learning includes classifying a received packet and determining whether to implement software-based layer 2 address learning for the received packet based on the classification determined for the received packet.

17. The layer 2 switch of claim 16 wherein the learning and forwarding logic classifies the received packet based on a port on which the packet was received.

18. The layer 2 switch of claim 16 wherein the learning and forwarding logic classifies the received packet based on a virtual local area network (VLAN) associated with the received packet.

19. The layer 2 switch of claim 16 wherein, in response to determining that software-based learning is required, the learning and forwarding logic forwards the packet to the processor and wherein the processor extracts the layer 2 source address from the packet.

20. The layer 2 switch of claim 16 wherein performing hardware-based layer 2 address learning includes using the learning and forwarding logic to learn the source address in the received packet and writes the source address to the hardware forwarding table.

21. The layer 2 switch of claim 16 wherein, in response to determining that software-based learning is required, the learning and forwarding logic forwards the packet to the processor, and wherein the processor applies a layer 2 security policy to the packet.

22. The layer 2 switch of claim 21 wherein the processor is performs the software-based learning only in response to determining that the packet passes the security policy.

23. The layer 2 switch of claim 21 wherein the security policy comprises a policy that limits learning of MAC addresses based on at least one of a port and Virtual Local Area Network (VLAN) basis.

24. The layer 2 switch of claim 21 wherein the layer 2 security policy comprises a policy that limits learning of MAC addresses based on an administratively defined table of MAC addresses.

25. The layer 2 switch of claim 21 wherein the layer 2 security policy comprises an 802.1x policy.

26. The layer 2 switch of claim 16 wherein, in response to determining that software-based learning is required, the processor writes the source address of the packet to the hardware forwarding table.

27. The layer 2 switch of claim 26 wherein the processor overwrites a hardware-learned entry in the hardware forwarding table.

28. A computer-readable medium encoded with computer-executable instructions for performing steps comprising:

(a) receiving a packet including a layer 2 source address at a forwarding device having software and hardware for learning the source address and forwarding information associated with the packet;

(b) at the forwarding device, classifying the packet and determining whether to implement software-based learning based on a classification determined for the packet;

(c) at the forwarding device, in response to determining to implement software-based learning, utilizing the software of the forwarding device for learning the source address of the received packet and the forwarding information associated with the packet using a software routine executed on a processor of the forwarding device; and, otherwise,

(d) at the forwarding device, in response to determining to implement hardware-based learning, utilizing the hardware of the forwarding device for learning the source address of the received packet and the forwarding information associated with the packet using learning operations implemented in hardware logic of the forwarding device.

29. The computer-readable medium of claim 28 wherein the layer 2 source address includes a media access control (MAC) source address.

30. The computer program product of claim 28 wherein the forwarding information includes a port on which the packet was received.

31. The computer-readable medium of claim 28 wherein determining whether to implement software-based learning based on the classification includes determining whether to implement software-based learning based on a port on which the packet was received.

32. The computer-readable medium of claim 28 wherein determining whether to implement software-based learning based on the classification includes determining whether to implement software-based learning based on a virtual local area network (VLAN) associated with the received packet.

33. The computer-readable medium of claim 28 wherein utilizing the software of the forwarding device for learning the source address of the received packet includes:

(a) receiving the packet at an Input/Output (I/O) module;

(b) forwarding the packet to a management processor; and

(c) performing the software-based learning at the management processor.

34. The computer-readable medium of claim 28 wherein performing hardware-based learning includes receiving the packet at a hardware device located on an Input/Output (I/O) module and learning the source address of the received packet using the hardware device on the I/O module.

35. The computer-readable medium of claim 28 comprising, in response to determining to implement software-based learning, applying a layer 2 security policy to the received packet.

36. The computer-readable medium of claim 35 wherein utilizing the software of the forwarding device for learning the source address includes learning the source address of the received packet only in response to the received packet passing the security policy.

37. The computer-readable medium of claim 35 wherein applying a layer 2 security policy includes limiting learning of the source address in the received packet based on a predetermined condition.

38. The computer-readable medium of claim 37 wherein the predetermined condition includes at least one of a source port and source VLAN associated with the received packet.

39. The computer-readable medium of claim 37 wherein the predetermined condition includes the presence of the source address in an administratively defined table.

40. The computer-readable medium of claim 35 wherein applying a layer 2 security policy includes implementing an 802.1x security policy.

41. The computer-readable medium of claim 28 wherein utilizing the software of the forwarding device for learning the source address includes writing the source address to a hardware forwarding table.

42. The computer-readable medium of claim 41 wherein writing the source address to the hardware forwarding table includes overwriting a hardware-learned entry in the forwarding table with the source address and forwarding information associated with the received packet.

Assignments (10)
RELEASE OF PATENT AND TRADEMARK SECURITY INTEREST AT REEL/FRAME NO. 46050/0546 Recorded Jul 30, 2026
From: BANK OF MONTREAL, AS AGENT
To: EXTREME NETWORKS, INC.
Reel/Frame 076081/0088 →
SECURITY INTEREST Recorded Jul 29, 2026
From: EXTREME NETWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 076078/0590 →
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2016
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 040521/0762 →
SECURITY AGREEMENT Recorded Jul 27, 2015
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 036189/0284 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2004
From: GROSSER, JR., DONALD B.; MROZ, MICHAEL D.
To: EXTREME NETWORKS, INC.
Reel/Frame 015439/0602 →