The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Sep. 12, 2023

Filed:

Nov. 24, 2020
Applicant:

Vmware, Inc., Palo Alto, CA (US);

Inventors:

Sachin Mohan Vaidya, Pune, IN;

Kausum Kumar, Los Gatos, CA (US);

Jayant Jain, Cupertino, CA (US);

Shadab Shah, Sunnyvale, CA (US);

Anirban Sengupta, Saratoga, CA (US);

Assignee:

VMWARE, INC., Palo Alto, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/40 (2022.01); G06F 9/455 (2018.01); H04L 12/46 (2006.01); H04L 41/0803 (2022.01); H04L 41/0893 (2022.01); H04L 45/586 (2022.01); H04L 49/00 (2022.01); H04L 67/10 (2022.01); H04L 12/66 (2006.01); H04L 45/42 (2022.01); H04L 45/64 (2022.01);
U.S. Cl.
CPC ...
H04L 63/20 (2013.01); G06F 9/455 (2013.01); G06F 9/45558 (2013.01); H04L 12/4641 (2013.01); H04L 12/66 (2013.01); H04L 41/0803 (2013.01); H04L 41/0893 (2013.01); H04L 45/42 (2013.01); H04L 45/586 (2013.01); H04L 45/64 (2013.01); H04L 49/70 (2013.01); H04L 63/0209 (2013.01); H04L 63/0218 (2013.01); H04L 63/0236 (2013.01); H04L 63/0263 (2013.01); H04L 63/10 (2013.01); H04L 67/10 (2013.01); G06F 2009/45595 (2013.01);
Abstract

Some embodiments provide a method for a network management and control system that manages a virtual infrastructure deployed across a set of datacenters. The method receives a definition of an application to be deployed in the virtual infrastructure. The application definition specifies a requirement that the application receive data traffic from sources external to the virtual infrastructure. Based on the application definition, the method defines a first set of firewall rules for the application that indicate conditions for allowing data traffic from sources external to the virtual infrastructure. For an existing second set of higher-level firewall rules for data traffic entering and exiting the virtual infrastructure, the method specifies a new firewall rule that directs a network element implementing the sets of firewall rules to apply the first set of firewall rules to any data traffic that is from sources external to the virtual infrastructure and directed to the application.


Find Patent Forward Citations

Loading…