Method and framework for integrating a plurality of network policies
First Claim
1. A framework for integrating a plurality of filter based policies to be applied to packets of data including at least a firewall policy and a security policy, comprising:
- a set of layer processes for identifying at least one parameter associated with a packet;
a policy engine in communication with the set of layer processes; and
a set of filters stored in the policy engine, each filter in the set of filters having filter conditions, an action identifying the firewall policy, and a policy context identifying the security policy.
2 Assignments
0 Petitions
Accused Products
Abstract
A method and system is disclosed for managing and implementing a plurality of network policies in a network device. Each of the plurality of policies are defined by one or more filters. The filters are installed in a policy engine. A layer identifies the network policy to be applied to a packet by sending a request to the policy engine. The policy engine then returns the policy to the requesting layer. The method and system may be used to implement a programmable, host-based, distributed, authenticating firewall that enables security and other policies to be applied at several protocol layers.
-
Citations
37 Claims
-
1. A framework for integrating a plurality of filter based policies to be applied to packets of data including at least a firewall policy and a security policy, comprising:
-
a set of layer processes for identifying at least one parameter associated with a packet;
a policy engine in communication with the set of layer processes; and
a set of filters stored in the policy engine, each filter in the set of filters having filter conditions, an action identifying the firewall policy, and a policy context identifying the security policy. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A method for determining a plurality of network policies to be applied to a packet at a layer process, comprising:
-
identifying, by the layer process, a set of parameters associated with the packet;
sending, by the layer process, a request to identify the network policies to be applied to the packet;
the request including the parameters associated with the packet; and
receiving, at the layer process, a response that includes a first policy value identifying a first network policy and a second policy value identifying a second network policy. - View Dependent Claims (9, 10, 11, 12, 13)
-
-
14. A method for maintaining a plurality of network policies in a network device, comprising:
installing a set of filters into a policy engine, each of the filters comprising;
a set of filter conditions;
a first policy value identifying a first network policy and a second policy value identifying a second network policy. - View Dependent Claims (15, 16, 17, 18, 19, 20, 21, 22)
-
23. A computer-readable medium having stored thereon a data structure defining a filter, comprising:
-
a first set of data comprising a set of filter conditions defining matching packets;
a second set of data comprising a first network policy; and
a third set of data comprising a second network policy, wherein the first network policy is distinct from the second network policy. - View Dependent Claims (24, 25, 26, 27, 28, 29)
-
-
30. A computer-readable medium for executing computer-executable instructions for facilitating a framework for integrating a plurality of filter based policies to be applied to packets of data including at least a firewall policy and a security policy, comprising:
-
a set of layer processes for identifying at least one parameter associated with a packet;
a policy engine in communication with the set of layer processes; and
a set of filters stored in the policy engine, each filter in the set of filters having filter conditions, an action identifying the firewall policy, and a policy context identifying the security policy. - View Dependent Claims (31, 32, 33)
-
-
34. A computer-readable medium for executing computer-executable instructions for determining a plurality of network policies to be applied to a packet at a layer process, comprising:
-
identifying, by the layer process, a set of parameters associated with the packet;
sending, by the layer process, a request to identify the network policies to be applied to the packet;
the request including the parameters associated with the packet; and
receiving, at the layer process, a response that includes a first policy value identifying a first network policy and a second policy value identifying a second network policy.
-
-
35. A computer-readable medium for executing computer-executable instructions for maintaining a plurality of network policies in a network device, comprising:
installing a set of filters into a policy engine, each of the filters comprising;
a set of filter conditions;
a first policy value identifying a first network policy and a second policy value identifying a second network policy. - View Dependent Claims (36, 37)
Specification