Invention Grant
- Patent Title: Selective enforcement of a segmentation policy
-
Application No.: US16776505Application Date: 2020-01-30
-
Publication No.: US11444920B2Publication Date: 2022-09-13
- Inventor: Juraj George Fandli , Yair Harel , Ronald Isaacson , Russell Stuart Goodwin , Roy Nobuo Nakashima , Nathanael John Iversen
- Applicant: Illumio, Inc.
- Applicant Address: US CA Sunnyvale
- Assignee: Illumio, Inc.
- Current Assignee: Illumio, Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: Fenwick & West LLP
- Main IPC: H04L9/40
- IPC: H04L9/40

Abstract:
A policy management server enables selective enforcement of a segmentation policy. The policy management server manages a segmentation policy that specifies a set of segmentation rules specifying permitted communications between workloads. The policy management server separately manages an enforcement policy that controls whether or not the segmentation policy is enforced for different services provided by the workloads. For services that are enforced, the policy management server distributes instructions to distributed enforcement modules that configure traffic filters to block traffic pertaining to enforced services that does not meet the segmentation rules. For non-enforced services, the policy management server obtains traffic data from the distributed enforcement modules without enforcing the segmentation policy to enable an administrator to build and/or test the segmentation policy.
Public/Granted literature
- US20210243158A1 SELECTIVE ENFORCEMENT OF A SEGMENTATION POLICY Public/Granted day:2021-08-05
Information query