×

Port isolation for restricting traffic flow on layer 2 switches

  • US 7,881,296 B2
  • Filed: 07/26/2006
  • Issued: 02/01/2011
  • Est. Priority Date: 12/20/2000
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • configuring a plurality of ports sharing a single virtual local area network (VLAN) on a layer 2 switch as protected or non-protected;

    generating a forwarding map for a data packet allowing said data packet to be forwarded from a protected port to a non-protected port while preventing said data packet from being forwarded to another of said protected ports; and

    matching a destination address on said data packet with a physical address on said layer 2 switch, said data packet received by an ingress port;

    wherein generating the forwarding map for the data packet allowing said data packet to be forwarded from the protected port to the non-protected port while preventing said data packet from being forwarded to another of said protected ports comprises editing, by a global mask on the layer 2 switch, a forwarding feature of the data packet by modifying port numbers on the forwarding map such that when the ingress port is configured as protected port, the global mask modifies the forwarding map so that the data packet will not be forwarded to ports configured as protected on the layer 2 switch.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×