Processing internet protocol security traffic
First Claim
Patent Images
1. A method comprising:
- determining at a first classifying forwarding element if a classification parameter is available for Internet Protocol security (IPsec) traffic that indicates a route for the IPsec traffic and classifying said traffic if available;
if said classification parameter is not available, and the IPsec traffic is encrypted then decrypting traffic in a decrypting forwarding element separate from the first classifying forwarding element after said traffic has passed through said classifying forwarding element, and determining the classification parameter for the IPsec traffic;
forwarding the IPsec traffic based on the classification parameter; and
providing the classification parameter to the first classifying forwarding element.
1 Assignment
0 Petitions
Accused Products
Abstract
Processing Internet Protocol security (IPsec) traffic includes determining at a first location if a classification parameter is available for the IPsec traffic that indicates a route for the IPsec traffic and forwarding the IPsec traffic based on the classification parameter. If a classification parameter is not available, processing IPsec traffic includes decrypting the IPsec traffic at a second location if the IPsec traffic is encrypted and determining the classification parameter for the IPsec traffic at the second location.
85 Citations
25 Claims
-
1. A method comprising:
-
determining at a first classifying forwarding element if a classification parameter is available for Internet Protocol security (IPsec) traffic that indicates a route for the IPsec traffic and classifying said traffic if available; if said classification parameter is not available, and the IPsec traffic is encrypted then decrypting traffic in a decrypting forwarding element separate from the first classifying forwarding element after said traffic has passed through said classifying forwarding element, and determining the classification parameter for the IPsec traffic; forwarding the IPsec traffic based on the classification parameter; and providing the classification parameter to the first classifying forwarding element. - View Dependent Claims (2, 3, 4, 5)
-
-
6. An article comprising:
-
a machine-readable medium which stores machine-executable instructions, the instructions causing a machine to; determine at a first mechanism if a classification parameter is available for Internet Protocol security (IPsec) traffic that indicates a route for the IPsec traffic; if a classification parameter is not available, sending said traffic to a second mechanism separate from the first mechanism after said traffic has passed said first mechanism, and which second mechanism decrypts the IPsec traffic if the IPsec traffic is encrypted and determine the classification parameter for the IPsec traffic forward the IPsec traffic based on the classification parameter; and provide the classification parameter to the first mechanism. - View Dependent Claims (7, 8, 9, 10)
-
-
11. A system comprising:
-
a classifying forwarding element configured to communicate with a network, to determine if a classification parameter that indicates a route for a traffic stream is available for a packet included in the traffic stream; a control element in communication with the classifying forwarding element, the control element configured to receive information including classification information for the traffic stream and cryptographic information for the traffic stream, the control element further configured to transmit at least some classification information to the classifying forwarding element and to transmit at least one key based on the cryptographic information to a decrypting forwarding element separate from the classifying forwarding element; and wherein the decrypting forwarding element is configured to receive the packet from the classifying forwarding element, and to perform an encryption-related procedure on the packet if the packet is encrypted and associated with the at least one key. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25)
-
Specification