Nova Patents
EP1523138B1

Access control mechanism for routers

Abstract

This record has no abstract on file.

EP1523138B1, drawing sheet 1
Sheet 1 of 3

Term

Term ended

Expired 4 October 2024, 2 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

10 claims: 5 independent, 5 dependent

  1. 1
    A method of controlling access of packets arrived at a router (10) over a plurality of interfaces (14-20) of a line card with improved use of memory space storing access control rules, the method comprising the steps of:a. storing at said line card at least two access control rule lists, ACL, a shared access control line card rule list, ACL, (28) with rules that are applicable to the plurality of interfaces (14-20) and a specific access control rule list, ACL, (26) with rules specific to a single interface (14) of the plurality of interfaces;b. associating said shared access control list to the plurality of interfaces and said specific ACL (26) to said single interface (14);c. calculating (52) a key for an incoming data packet arriving at said the single of interface (14) d. identifying (56) in said specific ACL (26) a rule that applies to said packet, based on said key, and processing (58) said packet according to said rule;e. identifying (56) in said shared ACL (28) a rule that applies to said packet based on said key, and processing (58) said packet according to said rule, said rule not being in said specific ACL (26).
  2. 4
    The method of anyone of claims I to 3 wherein each rule has an associated action, each associated action being one of packet denial, packet allowance, packet counting, and packet copying.
  3. 5
    The method of anyone of claims 2 to 4 wherein the key is determined from information contained within a header of the IP packet.
  4. 7
    The method of anyone of claims 1 to 6 further comprising determining a priority order for said shared an specific ACL (28, 26);and performing steps d. and e. in an order established according to said priority order.
  5. 8
    A line card (12) for a router (10), comprising:a plurality of interfaces (14-20), each for receiving a plurality of incoming data packets;a plurality of specific access control rule lists, ACL's, (26) for storing rules specific to each interface (14-20) each specific ACL (26) being associated individually to a respective one of said interfaces (14);means for determining a key for a data packet arriving at a certain of the plurality of interfaces (14);a shared access control rule list, ACL, (28) for storing rules that are applicable to the plurality of interfaces (14-20), said shared ACL (28) being associated to the plurality of interfaces (14-20) at said router (10);means for accessing said shared (28) and specific (26) ACL associated to the interface over which a packet arrived, based on said key for identifying rules pertinent to said packet in the specific and shared ACLs;and means for processing said packet according to said rules identified in said shared and specific ACLs.