Methods and apparatus to generate and update fibre channel firewall filter rules using address prefixes
US8364852B1 · kind B1 · utility
Assignee
Inventors
Key dates
| Filing date | Dec 22, 2010 |
| Grant date | Jan 29, 2013 |
| Priority date | — |
| Expiry date | Dec 22, 2030 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L12/433
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
In one embodiment, a network management module converts zone policies for a network into access sets and access set lists. The network management module can define access sets for a collection of peripheral processing devices that share the same communication restrictions imposed by the zone policies. The network management module can allocate address blocks for each access set such that at least some of the peripheral processing devices in the same access can share a common address prefix. The network management module can define access sets lists such that each access set references an access set list that includes all the peripheral processing devices in the network that can communicate with the peripheral processing devices in the referencing access set. The network management module can apply access sets and access set lists in generating or updating firewall filter rules, and in some embodiments, the access sets can be expressed in terms of the one or more common address prefixes. The conversion of zone policies into access sets and access set lists can, for example, improve the efficiency of zone policy conversion and the optimal state of the firewall filter rules, which can…
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.