L2/L3 MULTI-MODE SWITCH INCLUDING POLICY PROCESSING
First Claim
1. A method for forwarding data packets in a computer network comprising the steps of:
- receiving a data packet;
examining the data packet to classify the data packet including classifying the data packet as a L2 or L3 packet and including determining at least one zone associated with the packet;
processing the packet in accordance with one or more policies associated with the zone;
determining forwarding information associated with the data packet; and
if one or more policies permit, forwarding the data packet toward an intended destination using the forwarding information.
1 Assignment
0 Petitions
Accused Products
Abstract
Methods and apparatus for processing data packets in a computer network are described. One general method includes receiving a data packet; examining the data packet to classify the data packet including classifying the data packet as a L2 or L3 packet and including determining at least one zone associated with the packet; processing the packet in accordance with one or more policies associated with the zone; determining forwarding information associated with the data packet; and if one or more policies permit, forwarding the data packet toward an intended destination using the forwarding information.
224 Citations
18 Claims
-
1. A method for forwarding data packets in a computer network comprising the steps of:
-
receiving a data packet; examining the data packet to classify the data packet including classifying the data packet as a L2 or L3 packet and including determining at least one zone associated with the packet; processing the packet in accordance with one or more policies associated with the zone; determining forwarding information associated with the data packet; and if one or more policies permit, forwarding the data packet toward an intended destination using the forwarding information. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A device comprising:
-
A multi-mode switch for classifying received data packets as L2 or L3 packets and determining a zone associated with received packets; An L2 routing table for use in determining a L2 forwarding definition; An L3 routing table for use in determining a L3 routing definition; A policy engine for determining one or more policies associated with received packets based on a zone; A policy set; and A processing engine for processing the received packets in accordance with any associated policies and forwarding received packets in accordance with L2/L3 forwarding/routing definitions. - View Dependent Claims (12, 13, 14, 15)
-
-
16. A method comprising:
-
receiving a data packet; examining the data packet to determine if the packet is a layer 2 or layer 3 packet for forwarding purposes; determining a zone associated with the packet and a security policy; starting a session based on the policy determination; and forwarding the packet in accordance with the look-up information. - View Dependent Claims (17, 18)
-
Specification