×

Network policy implementation in a tag-based policy architecture

  • US 10,652,281 B1
  • Filed: 08/31/2017
  • Issued: 05/12/2020
  • Est. Priority Date: 08/31/2017
  • Status: Active Grant
First Claim
Patent Images

1. A system comprising:

  • one or more processors coupled to a network of a virtualized computing environment;

    a control plane executable by at least one of the one or more processors, the control plane configured to implement a network policy of the virtualized computing environment by associating the network policy to a global firewall and apportioning the global firewall into one or more individual firewalls, the control plane further configured to translate the network policy associated with the global firewall into rules of an individual firewall; and

    a packet filter module executable by at least one processor of a first computer node, the packet filter module configured to receive the rules from the control plane and implement the individual firewall to enforce the network policy on packets of network traffic as a respective portion of the global firewall, wherein the first computer node is configured to execute a hypervisor and a virtual machine instance (VMI), wherein the VMI is managed by the hypervisor, wherein a guest operating system and an intermediary manager run in the VMI, wherein the packet filter module is a component of the intermediary manager, wherein the packet filter module is configured to enforce the network policy on the packets when passed between the hypervisor and the guest operating system.

View all claims
  • 5 Assignments
Timeline View
Assignment View
    ×
    ×