The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Dec. 17, 2024

Filed:

Dec. 22, 2022
Applicant:

Palo Alto Networks, Inc., Santa Clara, CA (US);

Inventors:

Bala Gautama, San Jose, CA (US);

Arivu Mani Ramasamy, San Jose, CA (US);

Venkata Sarat Kumar Vajrapu, Bengaluru, IN;

Arun Kumar Palani, Bangalore, IN;

Anil Kumar Reddy Sirigiri, Bangalore, IN;

Nagaraj A. Bagepalli, Fremont, CA (US);

Assignee:

Palo Alto Networks, Inc., Santa Clara, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 69/22 (2022.01); H04L 12/46 (2006.01);
U.S. Cl.
CPC ...
H04L 12/4633 (2013.01); H04L 69/22 (2013.01); H04L 2212/00 (2013.01);
Abstract

A network controller in an overlay network maintains collective sets of identity-based policies and identity mappings for onboarded users of the network for informed distribution to network elements across the network. As new users are onboarded, the controller identifies a site of the network at which the user was onboarded and determines identity mappings of the user and applicable policies for distribution to a network element at the identified site. The controller assigns index values to each identity and communicates the indices to network elements with the corresponding identity mappings and policies. The network elements encapsulate cross-site traffic with the index values corresponding to senders so recipient network elements can obtain the index value from encapsulation header formats, query the controller for the corresponding identity mappings, and apply policies to the traffic that are determined to be pertinent based on the sender's identity mappings obtained from the controller.


Find Patent Forward Citations

Loading…