Method and framework for integrating a plurality of network policies
First Claim
1. A framework for integrating a plurality of filter based policies to be applied to packets of data including at least a firewall policy and a security policy, comprising:
- a set of layer processes for identifying at least one parameter associated with a packet;
a policy engine in communication with the set of layer processes; and
a set of filters stored in the policy engine, each filter in the set of filters having filter conditions, an action identifying the firewall policy, and a policy context identifying the security policy.
1 Assignment
0 Petitions
Accused Products
Abstract
A method and system is disclosed for managing and implementing a plurality of network policies in a network device. Each of the plurality of policies are defined by one or more filters. The filters are installed in a policy engine. A layer identifies the network policy to be applied to a packet by sending a request to the policy engine. The policy engine then returns the policy to the requesting layer. The method and system may be used to implement a programmable, host-based, distributed, authenticating firewall that enables security and other policies to be applied at several protocol layers.
-
Citations
11 Claims
-
1. A framework for integrating a plurality of filter based policies to be applied to packets of data including at least a firewall policy and a security policy, comprising:
- a set of layer processes for identifying at least one parameter associated with a packet;
a policy engine in communication with the set of layer processes; and
a set of filters stored in the policy engine, each filter in the set of filters having filter conditions, an action identifying the firewall policy, and a policy context identifying the security policy. - View Dependent Claims (2, 3, 4, 5, 6, 7)
- a set of layer processes for identifying at least one parameter associated with a packet;
-
8. A computer-readable medium for executing computer-executable instructions for facilitating a framework for integrating a plurality of filter based policies to be applied to packets of data including at least a firewall policy and a security policy, comprising:
- a set of layer processes for identifying at least one parameter associated with a packet;
a policy engine in communication with the set of layer processes; and
a set of filters stored in the policy engine, each filter in the set of filters having filter conditions, an action identifying the firewall policy, and a policy context identifying the security policy. - View Dependent Claims (9, 10, 11)
- a set of layer processes for identifying at least one parameter associated with a packet;
Specification