US 11,706,133 B2
Inband group-based network policy using SRV6
Clarence Filsfils, Brussels (BE); Ahmed Mohamed Ahmed Abdelsalam, L'Aquila (IT); Francois Clad, Strasbourg (FR); Pablo Camarillo Garvia, Madrid (ES); and Kiran Sasidharan Pillai, Fremont, CA (US)
Assigned to Cisco Technology, Inc., San Jose, CA (US)
Filed by Cisco Technology, Inc., San Jose, CA (US)
Filed on Jul. 14, 2022, as Appl. No. 17/865,125.
Application 17/865,125 is a continuation of application No. 16/860,896, filed on Apr. 28, 2020, granted, now 11,418,435.
Claims priority of provisional application 62/968,418, filed on Jan. 31, 2020.
Prior Publication US 2022/0385573 A1, Dec. 1, 2022
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 45/50 (2022.01); H04L 12/46 (2006.01); H04L 45/74 (2022.01); H04L 45/28 (2022.01); H04L 69/22 (2022.01); H04L 45/42 (2022.01); H04L 45/00 (2022.01); H04L 45/741 (2022.01)
CPC H04L 45/50 (2013.01) [H04L 12/4633 (2013.01); H04L 45/28 (2013.01); H04L 45/42 (2013.01); H04L 45/566 (2013.01); H04L 45/74 (2013.01); H04L 45/741 (2013.01); H04L 69/22 (2013.01)] 20 Claims
OG exemplary drawing
 
15. A system, comprising:
a processor;
a non-transitory computer readable media storing instructions which are programmed to cause the processor to perform operations comprising:
receive, at an egress node located downstream from an ingress node, a first data packet with Segment Routing over an IPv6 dataplane (SRv6) encapsulation, the first data packet being associated with from a source application to a destination application;
remove the SRv6 encapsulation from the first data packet;
forward the unencapsulated first data packet to the destination application in response to content in the SRv6 encapsulation indicating that a first policy was applied at the ingress node;
in response to the content in the SRv6 encapsulation indicating that the first policy was not applied at the ingress node:
apply a second policy to the unencapsulated first data packet;
forward the unencapsulated first data packet to the destination application in response to the second policy allowing forwarding of the unencapsulated first data packet; and
drop the unencapsulated first data packet in response to the second policy prohibiting forwarding of the unencapsulated first data packet.