Data Network Microsegmentation
First Claim
1. A computer-implemented method for microsegmentation of data networks comprising:
- receiving a high-level declarative policy, the high-level declarative policy based on metadata associated with a plurality of containers from an orchestration layer;
determining a low-level firewall rule set using the high-level declarative policy; and
configuring, by a plurality of enforcement points, a respective virtual switch of a plurality of virtual switches to process packets in accordance with the low-level firewall ruleset, the virtual switches being collectively communicatively coupled to the plurality of containers, such that network communications between a first group of containers and a second group of containers of the plurality of containers are restricted by a first set of characteristics, and communications between containers of the first group of containers are at least one of permitted and restricted by a second set of characteristics.
1 Assignment
0 Petitions
Accused Products
Abstract
Methods and systems for microsegmentation of data networks are provided herein. Exemplary methods include: receiving a high-level declarative policy; getting metadata associated with a plurality of containers from an orchestration layer; determining a low-level firewall rule set using the high-level declarative policy and the metadata; and configuring by a plurality of enforcement points a respective virtual switch of a plurality of virtual switches to process packets in accordance with the low-level firewall ruleset, the virtual switches being collectively communicatively coupled to the plurality of containers, such that network communications between a first group of containers and a second group of containers of the plurality of containers are not permitted, and communications between containers of the first group of containers are permitted.
28 Citations
19 Claims
-
1. A computer-implemented method for microsegmentation of data networks comprising:
-
receiving a high-level declarative policy, the high-level declarative policy based on metadata associated with a plurality of containers from an orchestration layer; determining a low-level firewall rule set using the high-level declarative policy; and configuring, by a plurality of enforcement points, a respective virtual switch of a plurality of virtual switches to process packets in accordance with the low-level firewall ruleset, the virtual switches being collectively communicatively coupled to the plurality of containers, such that network communications between a first group of containers and a second group of containers of the plurality of containers are restricted by a first set of characteristics, and communications between containers of the first group of containers are at least one of permitted and restricted by a second set of characteristics. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A system for microsegmentation of data networks comprising:
-
a processor; and a memory coupled to the processor, the memory storing instructions which are executable by the processor to perform a method comprising; receiving a high-level declarative policy, the high-level declarative policy based on metadata associated with a plurality of containers from an orchestration layer; determining a low-level firewall rule set using the high-level declarative policy; and configuring, by a plurality of enforcement points, a respective virtual switch of a plurality of virtual switches to process packets in accordance with the low-level firewall ruleset, the virtual switches being collectively communicatively coupled to the plurality of containers, such that network communications between a first group of containers and a second group of containers of the plurality of containers are restricted by a first set of characteristics, and communications between containers of the first group of containers are at least one of permitted and restricted by a second set of characteristics. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18, 19)
-
Specification