IP Library Granted Patent US 9,609,021
Granted Patent B2
US 9,609,021 · App. 14/555,441 · Granted Mar 28, 2017

System and method for securing virtualized networks

Inventors: Kelly Wanser (Thornton, CO); Andreas Markos Antonopoulos (San Francisco, CA)
Assignee: FORTINET, INC.
H04L63/20H04L63/10H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,609,021
App. No.
14/555,441
Granted
Mar 28, 2017
Kind
B2
Abstract

A method and apparatus that secures a dynamic virtualized network is described. In an exemplary embodiment, a device receives a current network policy of the dynamic virtualized network. In addition, the current network policy includes multiple network policy elements, where each of the multiple network policy elements identifies an authorized endpoint in the dynamic virtualized network. The device further determines a network security policy for the dynamic virtualized network from the current network policy. The network security policy includes one or more second network policy elements that are a different network policy element than one of the multiple network policy elements of the current network policy. In addition, each of the one or more second network policy network elements adds an additional policy on how network traffic is processed in the dynamic virtualized network by a port of one of the plurality of network access devices. The device further applies the network security policy to each network access device that is affected by the network security policy.

Claims (33)

1. A method of securing a dynamic virtualized network, the method comprising:

receiving, with a network automation device, a current network policy of the dynamic virtualized network, wherein the current network policy includes a first plurality of network policy elements, each of the first plurality of network policy elements identifies an authorized endpoint in the dynamic virtualized network, and the dynamic virtualized network is overlaid on a physical network;

monitoring membership in the dynamic virtualized network;

in response to changes in the membership of the dynamic virtualized network,

determining a network security policy for the dynamic virtualized network from the current network policy, wherein the network security policy includes one or more second network policy elements that is a different network policy element than one of the plurality of first network policy elements of the current network policy, and each of the one or more second network policy network elements adds an additional policy on how network traffic in the dynamic virtualized network is processed by a port of one of a plurality of network access devices, and

applying the network security policy to each network access device of the plurality of network access devices that is affected by the network security policy.

2. The method of claim 1 , wherein the dynamic virtualized network is a Virtual eXtensible Local Area Network (VxLAN) that is overlaid on a layer 3 network that includes a plurality of network access devices.

3. The method of claim 1 , wherein the additional policy is a multicast join filter that passes a multicast join request on a port of a network access device that has an authorized endpoint associated with that port.

4. The method of claim 1 , wherein the additional policy is a multicast join filter that drops a multicast join request on a port of a network access device that does not have an authorized endpoint associated with that port.

5. The method of claim 1 , wherein the additional policy is an access control list on a port of a network access device that that has an authorized endpoint associated with that port, the access control list to pass network traffic that includes an identification associated with the authorized endpoint.

6. The method of claim 5 , wherein the identification is a Virtual eXtensible Local Area Network Network Identifier.

7. The method of claim 1 , wherein the additional policy is an access control list on a port of a network access device that has an authorized endpoint associated with that port, the access control list to drop network traffic that does not include an identification associated with the authorized endpoint.

8. The method of claim 1 , wherein the additional policy is an access control list on a port of a network access device that does not have an authorized endpoint with that port, the access control list to drop network traffic that is encapsulated for the dynamic virtualized network.

9. The method of claim 1 , wherein a network access device is selected from the group consisting of a switch and a router.

10. A non-transitory machine-readable medium having executable instructions to cause one or more processing units to perform a method of securing a dynamic virtualized network, the method comprising:

receiving, with a network automation device, a current network policy of the dynamic virtualized network, wherein the current network policy includes a first plurality of network policy elements, each of the first plurality of network policy elements identifies an authorized endpoint in the dynamic virtualized network, and the dynamic virtualized network is overlaid on a physical network;

monitoring membership in the dynamic virtualized network; and

in response to changes in the membership of the dynamic virtualized network,

determining a network security policy for the dynamic virtualized network from the current network policy, wherein the network security policy includes one or more second network policy elements that is a different network policy element than one of the plurality of first network policy elements of the current network policy, and each of the one or more second network policy network elements adds an additional policy on how network traffic in the dynamic virtualized network is processed by a port of one of a plurality of network access devices, and

applying the network security policy to each network access device of the plurality of network access devices that is affected by the network security policy.

11. The non-transitory machine-readable medium of claim 10 , wherein the dynamic virtualized network is a Virtual eXtensible Local Area Network (VxLAN) that is overlaid on a layer 3 network that includes a plurality of network access devices.

12. The non-transitory machine-readable medium of claim 10 , wherein the additional policy is a multicast join filter that passes a multicast join request on a port of a network access device that has an authorized endpoint associated with that port.

13. The non-transitory machine-readable medium of claim 10 , wherein the additional policy is a multicast join filter that drops a multicast join request on a port of a network access device that does not have an authorized endpoint associated with that port.

14. The non-transitory machine-readable medium of claim 10 , wherein the additional policy is an access control list on a port of a network access device that that has an authorized endpoint associated with that port, the access control list to pass network traffic that includes an identification associated with the authorized endpoint.

15. The non-transitory machine-readable medium of claim 14 , wherein the identification is a Virtual eXtensible Local Area Network Network Identifier.

16. A system to secure a dynamic virtualized network, the system comprising:

a plurality of physical network access devices;

a physical network interconnecting the plurality of physical network access devices;

a dynamic virtualized network overlaid on the physical network, wherein the dynamic virtualized network includes the current network policy that further includes a first plurality of network policy elements, and each of the first plurality of network policy elements identifies an authorized endpoint in the dynamic virtualized network; and

a network automation element that receives the current network policy, monitors membership in the dynamic virtualized network, and, in response to changes in the membership of the dynamic virtualized network, determines a network security policy for the dynamic virtualized network from the current network policy, wherein the network security policy includes one or more second network policy elements that are a different network policy element than one of the plurality of first network policy elements of the current network policy, and each of the one or more second network policy network elements adds an additional policy on how network traffic in the dynamic virtualized network is processed by a port of one of the plurality of physical network access devices, and applies the network security policy to each physical network access device of the plurality of physical network access devices that is affected by the network security policy.

17. The system of claim 16 , wherein the dynamic virtualized network is a Virtual eXtensible Local Area Network.

18. The system of claim 17 , wherein the additional policy is a multicast join filter that passes a multicast join request on the port of a physical network access device that has an authorized endpoint associated with that port.

19. The system of claim 17 , wherein the additional policy is a multicast join filter that drops a multicast join request on the port of a physical network access device that does not have an authorized endpoint associated with that port.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2016
From: LUMINUS NETWORKS, INC.
To: FORTINET, INC.
Reel/Frame 039774/0396 →
CHANGE OF NAME Recorded Mar 21, 2016
From: STATELESS NETWORKS INC.
To: LUMINUS NETWORKS INC.
Reel/Frame 038190/0333 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 26, 2014
From: WANSER, KELLY; ANTONOPOULOS, ANDREAS MARKOS
To: STATELESS NETWORKS, INC.
Reel/Frame 034273/0386 →
Continuity (4)
Continuation 13911925 · Jun 6, 2013
Continuation 13842695 · Mar 15, 2013
Provisional Application 61720343 · Oct 30, 2012
Related Publication 20150089583A1 · Mar 26, 2015