The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Feb. 09, 2021

Filed:

Jun. 21, 2018
Applicant:

Cisco Technology, Inc., San Jose, CA (US);

Inventors:

Murukanandam Panchalingam, San Jose, CA (US);

Umamaheswararao Karyampudi, Fremont, CA (US);

Gianluca Mardente, San Francisco, CA (US);

Aram Aghababyan, Oakland, CA (US);

Assignee:

CISCO TECHNOLOGY, INC., San Jose, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); H04L 12/24 (2006.01);
U.S. Cl.
CPC ...
H04L 63/20 (2013.01); H04L 41/0806 (2013.01); H04L 41/0893 (2013.01); H04L 41/12 (2013.01); H04L 63/00 (2013.01); H04L 63/0227 (2013.01); H04L 63/101 (2013.01);
Abstract

Systems, methods, and computer-readable media for on-demand security provisioning using whitelist and blacklist rules. In some examples, a system in a network including a plurality of pods can configure security policies for a first endpoint group (EPG) in a first pod, the security policies including blacklist and whitelist rules defining traffic security enforcement rules for communications between the first EPG and a second EPG in a second pods in the network. The system can assign respective implicit priorities to the one or more security policies based on a respective specificity of each policy, wherein more specific policies are assigned higher priorities than less specific policies. The system can respond to a detected move of a virtual machine associated with the first EPG to a second pod in the network by dynamically provisioning security policies for the first EPG in the second pod and removing security policies from the first pod.


Find Patent Forward Citations

Loading…