IP Library Granted Patent US 8,751,650
Granted Patent B2
US 8,751,650 · App. 13/468,739 · Granted Jun 10, 2014

Method and apparatus for supporting access control lists in a multi-tenant environment

Inventors: Anuraag Mittal (San Jose, CA); Maithili Narasimha (Sunnyvale, CA); Ashwin Deepak Swaminathan (San Jose, CA); Badhri Madabusi Vijayaraghavan (Sunnyvale, CA)
Assignee: Cisco Technology, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,751,650
App. No.
13/468,739
Granted
Jun 10, 2014
Kind
B2
Abstract

In one embodiment, a method includes identifying common access control list (ACL) parameters and variable ACL parameters among a plurality of tenants in a network, mapping parameter values for the variable ACL parameters to the tenants, generating a multi-tenant access control list for the tenants, storing the multi-tenant access control list and mapping at a network device, and applying the multi-tenant access control list to ports at the network device. The multi-tenant access control list includes the common ACL parameters and variable ACL parameters.

Claims (33)

1. A method comprising:

identifying common access control list (ACL) parameters and variable ACL parameters among a plurality of tenants in a network;

mapping parameter values for said variable ACL parameters to said tenants;

generating a multi-tenant access control list for said plurality of tenants, the multi-tenant access control list comprising said common ACL parameters and said variable ACL parameters;

storing the multi-tenant access control list and said mapping at a network device; and

applying the multi-tenant access control list to ports at the network device.

2. The method of claim 1 wherein the network device comprises a virtual switch in communication with virtual machines and the ports comprise virtual ports.

3. The method of claim 1 wherein each of said plurality of tenants is associated with one or more virtual networks or virtual network segments.

4. The method of claim 1 further comprising performing a lookup in a table comprising said mapping.

5. The method of claim 1 further comprising programming said mapping into a port entry.

6. The method of claim 1 wherein said parameter values comprise Internet Protocol (IP) address ranges.

7. The method of claim 1 wherein said parameter values comprise virtual machine attributes.

8. The method of claim 7 wherein the virtual machine attributes comprise addresses for the virtual machines.

9. The method of claim 1 wherein the ports comprise port profiles defined within a virtual switch.

10. The method of claim 1 wherein said parameter values comprise values learned on the network.

11. The method of claim 1 wherein said parameter values comprise user defined values.

12. The method of claim 1 wherein mapping parameter values to said tenants comprises mapping said parameter values to networks or virtual machines associated with said tenants.

13. An apparatus comprising:

a processor for identifying common access control list (ACL) parameters and variable ACL parameters among a plurality of tenants in a network, mapping parameter values for said variable ACL parameters to said tenants, and generating a multi-tenant access control list for said plurality of tenants, the multi-tenant access control list comprising said common ACL parameters and said variable ACL parameters; and

memory for storing the multi-tenant access control list and said mapping;

wherein the multi-tenant access control list is configured for use at a virtual switch.

14. The apparatus of claim 13 wherein each of said plurality of tenants is associated with one or more virtual networks or virtual network segments.

15. The apparatus of claim 13 wherein the processor is further configured to perform a lookup in a table comprising said mapping.

16. The apparatus of claim 13 wherein said mapping is programmed into a port entry.

17. The apparatus of claim 13 wherein said parameter values comprise Internet Protocol (IP) address ranges.

18. The apparatus of claim 13 wherein said parameter values comprise virtual machine attributes.

19. The apparatus of claim 13 wherein mapping parameter values to said tenants comprises mapping said parameter values to networks or virtual machines associated with said tenants.

20. Logic encoded on one or more non-transitory computer readable media for execution and when executed operable to:

identify common access control list (ACL) parameters and variable ACL parameters among a plurality of tenants in a network;

map parameter values for said variable ACL parameters to said tenants;

generate a multi-tenant access control list for said plurality of tenants, the multi-tenant access control list comprising said common ACL parameters and said variable ACL parameters;

store the multi-tenant access control list and said mapping; and

apply the multi-tenant access control list to ports at a network device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2012
From: MITTAL, ANURAAG; NARASIMHA, MAITHILI; SWAMINATHAN, ASHWIN DEEPAK; VIJAYARAGHAVAN, BADHRI MADABUSI
To: CISCO TECHNOLOGY, INC.
Reel/Frame 028190/0717 →
Continuity (1)
Related Publication 20130304917A1 · Nov 14, 2013