Invention Grant
US08479275B1 Secure high-throughput data-center network employing routed firewalls
有权
使用路由防火墙的安全高吞吐量数据中心网络
- Patent Title: Secure high-throughput data-center network employing routed firewalls
- Patent Title (中): 使用路由防火墙的安全高吞吐量数据中心网络
-
Application No.: US11345186Application Date: 2006-02-01
-
Publication No.: US08479275B1Publication Date: 2013-07-02
- Inventor: Zeeshan Naseh
- Applicant: Zeeshan Naseh
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Fish & Richardson P.C.
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A reliable and secure data-center. The data center includes a first data-center tier that is adapted to connect to an external network and an internal portion of the data center. A first firewall instance interfaces the first tier and the external network. A second firewall instance interfaces the first tier and the internal portion of the data center. In a more specific embodiment, the first firewall instance and the second firewall instance accommodate Internet Protocol SECurity (IPSEC) terminations using one or more VPNSMs. In this embodiment, the first data-center tier implements a core tier that includes one or more core switches that facilitate implementing the first firewall instance and the second firewall instance. The interior portion of the network represents a DeMilitarized Zone (DMZ) that includes a second tier that is connected between the first data-center tier and a third tier. The second tier implements an aggregation tier that includes one or more aggregation switches that facilitate implementing reverse-proxy caching. Overall Layer-3 design methodology is used within each tier and across tiers for optimized packet switching. The aggregation tier includes one or more aggregation-tier service modules for implementing load balancing, Secure Socket Layer (SSL) offloading, and/or the reverse-proxy caching.
Information query