×

Data network microsegmentation

  • US 10,009,383 B2
  • Filed: 12/16/2016
  • Issued: 06/26/2018
  • Est. Priority Date: 06/24/2016
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method for microsegmentation of data networks comprising:

  • receiving a high-level declarative policy, the high-level declarative policy based on metadata associated with a plurality of containers from an orchestration layer;

    determining a low-level firewall rule set using the high-level declarative policy; and

    configuring, by a plurality of enforcement points, a respective virtual switch of a plurality of virtual switches to process packets in accordance with the low-level firewall ruleset, the virtual switches being collectively communicatively coupled to the plurality of containers, such that network communications between a first group of containers and a second group of containers of the plurality of containers are restricted by a first set of characteristics, and communications between containers of the first group of containers are at least one of permitted and restricted by a second set of characteristics; and

    wherein the metadata includes at least one of an image name, an image type, service name, ports, tags and labels associated with the plurality of containers.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×