System and method for restricting network access using forwarding databases
First Claim
1. A method, comprising:
- receiving a data unit including layer 2 client-identification data;
if the data unit does include layer 3 address data, forwarding the data unit, and if the included layer 3 address data confirms a layer 3 address assignment and if a layer 3 address assignment status restriction attribute associated with the received data unit is enabled, disabling the layer 3 address assignment status restriction attribute associated with the received data unit; and
if the data unit does not include layer 3 address data and if the layer 3 address assignment status restriction attribute associated with the received data unit is enabled, discarding the data unit.
3 Assignments
0 Petitions
Accused Products
Abstract
This specification describes a system that can offer, among other advantages, dynamically allowing or rejecting non-DHCP packets entering a switch. In addition, a FDB is commonly used by a bridge or switch to store an incoming packet'"'"'s source MAC address and its port number, then later on if the destination MAC address of another incoming packet matching any entry in FDB will be forwarded to its associated port. Using the techniques described herein, not only this will be completely transparent to user, the techniques can also result in an increase in switch performance by blocking unwanted traffic at an earlier stage of forwarding process and freeing up other processing units at a later stage, like switch fabric or packet processing stages.
605 Citations
19 Claims
-
1. A method, comprising:
-
receiving a data unit including layer 2 client-identification data; if the data unit does include layer 3 address data, forwarding the data unit, and if the included layer 3 address data confirms a layer 3 address assignment and if a layer 3 address assignment status restriction attribute associated with the received data unit is enabled, disabling the layer 3 address assignment status restriction attribute associated with the received data unit; and if the data unit does not include layer 3 address data and if the layer 3 address assignment status restriction attribute associated with the received data unit is enabled, discarding the data unit. - View Dependent Claims (2, 3, 4, 5)
-
-
6. A system comprising:
-
a switching device configured to perform layer 2 functions and receive a data unit; a memory coupled to the switching device, the memory having a forwarding database storing an entry associated with the received data unit, the entry having an associated layer 2 address and a layer 3 address assignment status restriction attribute; and a processor coupled to the memory and the switching device, the processor configured to execute packet forwarding functions, if the received data unit includes layer 3 address data, the switching device forwards the data unit, and if the included layer 3 address data confirms a layer 3 address assignment and if the layer 3 address assignment status restriction attribute associated with the received data unit is enabled, disable the layer 3 address assignment status restriction attribute associated with the received data unit. - View Dependent Claims (7, 8, 9, 10, 11, 12, 13, 14, 15)
-
-
16. A system comprising:
-
a switching device configured to perform layer 2 functions; a memory coupled to the switching device, the memory configured to have a forwarding database storing an entry associated with a received data, said entry having an associated layer 2 address and a layer 3 address assignment status restriction attribute associated with the received data; and an address restriction engine coupled to the memory and the switching device, the address restriction engine configured to execute packet forwarding and data traffic filtering functions, said address restriction engine having; an address status restriction module having control logic configured to manipulate a layer 3 address assignment status restriction attribute associated with the received data, and a packet forwarding module having logic configured to monitor data traffic and notify the address status restriction module that a first data with layer 3 address assignment data has been received; the address status restriction module configured to disable the layer 3 address assignment status restriction attribute associated with the first data if the layer 3 address assignment data confirms a layer 3 address assignment, based on a second data the address status restriction module receives from the packet forwarding module. - View Dependent Claims (17, 18, 19)
-
Specification