Internet protocol (IP) work group routing
First Claim
1. A method of routing datagrams from a source to a destination in an IP communications network including routers having multiple router interfaces connecting multiple physical networks, wherein the routers forward IP datagrams based upon IP addresses, the method comprising the steps of:
- defining an IP work group by assigning multiple router interfaces connecting a given router to multiple host networks, a single IP work group address,forwarding IP datagrams through the routers based on the IP work group address; and
assigning a security level to the IP work group by identifying hosts as "free" in order to permit forwarding to/from any interface in the group or "secured" in order to permit forwarding to/from a designated interface in the groupwherein four levels of security are provided;
in a "low" security work group, a host with any physical address is free to reside on any interface in the group as long as its IP address does not lie within a specified host address range, but if it does fall in the rangers then it must reside on a designated interface for that range;
in a "medium" security work group, a host'"'"'s IP address must fall within a specified host address range for a designated interface, but unless a physical address is also specified, the physical address is not constrained;
in a "high" security work group, a host must have a specified host IP address for a designated interface and have a designated physical address; and
in a "none" security work group, a host are is free.
11 Assignments
0 Petitions
Accused Products
Abstract
Apparatus and method wherein multiple router interfaces are assigned the same IP network address, creating an IP work group. This enhances host mobility by allowing, in one embodiment, a host to be relocated anywhere in the work group without requiring reconfiguration of the host. As a further option, host address ranges may be specified (i.e., locked) to designated interfaces of the work group, to enhance security by restricting the allowed host mobility within the work group. An additional advantage is a reduced consumption of network and subnet addresses, because now a single address is used for several physical networks.
360 Citations
31 Claims
-
1. A method of routing datagrams from a source to a destination in an IP communications network including routers having multiple router interfaces connecting multiple physical networks, wherein the routers forward IP datagrams based upon IP addresses, the method comprising the steps of:
-
defining an IP work group by assigning multiple router interfaces connecting a given router to multiple host networks, a single IP work group address, forwarding IP datagrams through the routers based on the IP work group address; and assigning a security level to the IP work group by identifying hosts as "free" in order to permit forwarding to/from any interface in the group or "secured" in order to permit forwarding to/from a designated interface in the group wherein four levels of security are provided; in a "low" security work group, a host with any physical address is free to reside on any interface in the group as long as its IP address does not lie within a specified host address range, but if it does fall in the rangers then it must reside on a designated interface for that range; in a "medium" security work group, a host'"'"'s IP address must fall within a specified host address range for a designated interface, but unless a physical address is also specified, the physical address is not constrained; in a "high" security work group, a host must have a specified host IP address for a designated interface and have a designated physical address; and in a "none" security work group, a host are is free. - View Dependent Claims (2)
-
-
3. In a method of forwarding IP datagrams in a router based on IP address, wherein the router has multiple host network interface comprising;
- multiple physical interfaces connecting multiple host networks to the router, the improvement comprising;
assigning a plurality of the multiple host network interfaces to an IP work group, the IP work group having a single IP work group address; and the router forwarding IP datagrams to the multiple host network interfaces based on the IP work group address, such that a host is attachable to any interface in the IP work group without requiring reconfiguration of the host IP address. - View Dependent Claims (4, 5, 6, 7, 8, 9, 10, 11, 12, 14, 15, 16, 17, 22, 23, 24, 25)
- multiple physical interfaces connecting multiple host networks to the router, the improvement comprising;
-
13. The method of claim, wherein the designated range is for a single physical address.
-
26. In a router for forwarding IP datagrams based on IP address, wherein the router has multiple host network interface comprising multiple physical interfaces connecting multiple host networks to the router, the improvement comprising:
means for assigning a plurality of the multiple host network interfaces to an IP work group, the IP work group having a single IP work group address; and
means for forwarding IP datagrams to the multiple host network interfaces based on the IP work group address, such that a host is attachable to any interface in the IP work group without requiring reconfiguration of the host IP address.- View Dependent Claims (18, 19, 20, 21, 27, 28, 29, 30, 31)
Specification