×

Scalable security services for multicast in a router having integrated zone-based firewall

  • US 8,713,627 B2
  • Filed: 04/29/2009
  • Issued: 04/29/2014
  • Est. Priority Date: 08/14/2008
  • Status: Active Grant
First Claim
Patent Images

1. A network router comprising:

  • a plurality of interfaces configured to send and receive multicast packets;

    a firewall integrated within the network router, the firewall configured to apply stateful firewall services to the multicast packets;

    a routing engine comprising a control unit that executes a routing protocol to maintain routing information specifying routes through a network, wherein the control unit executes at least one multicast protocol to establish a multicast group for communicating the multicast packets from a multicast source to a plurality of multicast receivers;

    a forwarding engine configured by the routing engine to select next hops for the multicast packets in accordance with the routing information, the forwarding engine comprising a switch fabric to forward the multicast packets to the interfaces based on the selected next hops, wherein the forwarding engine includes a flow control module that, upon receiving multicast packets from the network, directs one or more of the multicast packets to the firewall for application of the stateful firewall services; and

    a user interface by which a user specifies one or more zones to be recognized by the firewall when applying the stateful firewall services to the multicast packets, wherein the user interface supports a syntax that;

    (i) allows the user to define subsets of the plurality of interfaces associated with the zones, and(ii) allows the user to define a single multicast policy to be applied to multicast sessions associated with a multicast group, wherein the multicast policy specifies actions to be applied to multicast sessions for the specified zones,wherein the syntax allows the user to define the single multicast policy to specify one or more common stateful firewall services of the stateful firewall services to be applied by the firewall to copies of the multicast packets destined for one or more of the zones, and to specify one or more exceptions specifying one or more of the zones and one or more additional services of the stateful firewall services to be applied by the firewall to copies of the multicast packets for the one or more zones; and

    a services component executing on the firewall, wherein the services component is configured to determine, based on the single multicast policy, which of the common stateful firewall services are to be applied by the firewall pre-replication to copies of the multicast packets destined for two or more particular interfaces in the one or more of the zones,wherein the services component is configured to determine, based on the single multicast policy, which of the additional services of the stateful firewall services are to be applied by the firewall post-replication to copies of the multicast packets destined for one or more particular interfaces associated with the one or more zones,wherein the firewall is configured to apply the stateful firewall services to the multicast packets as determined by the services component.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×