Anti-spoofing techniques for overlay networks
US10764249B1 · kind B1 · utility
Assignee
Inventors
Key dates
| Filing date | Nov 30, 2017 |
| Grant date | Sep 1, 2020 |
| Priority date | — |
| Expiry date | Feb 2, 2039 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L12/4641
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
A network device is configured to receive an inbound packet from a first server device via a network tunnel, the first inbound packet including an outer header, a virtual private network (VPN) label, an inner header, and a data payload, the inner header including an inner source IP address of a source virtual machine. The processors are also configured to determine a first tunnel identifier, determine, based on the inner source IP address, a second tunnel identifier associated with a second server device hosting the source virtual machine, compare the second tunnel identifier with the first tunnel identifier to determine whether the tunnel on which the first inbound packet was received is the same as a tunnel used for forwarding traffic to the source virtual machine, and drop the inbound packet when the second tunnel identifier does not match the first tunnel identifier.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.