SYSTEMS AND METHODS FOR PACKET FILTERING

Systems and methods are described for converting priority based rules into isomorphic longest match rules. Rules for packet processing may be presented to a networking device in priority order, through an interface such as a Command Line Interface (CLI) or from networking applications which may resi...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
1. Verfasser: YAKOV TEPLITSKY
Format: Patent
Sprache:eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:Systems and methods are described for converting priority based rules into isomorphic longest match rules. Rules for packet processing may be presented to a networking device in priority order, through an interface such as a Command Line Interface (CLI) or from networking applications which may reside on the networking device. The networking device may include hardware and/or software layers for accelerating packet processing; a forwarding layer may include hardware and/or software designed to perform longest match searches on packets. Prioritized rules may be converted into a data structure for the forwarding layer, so that a longest match search performed by the forwarding layer on the data structure is equivalent to a priority order search on the prioritized rules.