Title:
NETWORK ACCESS CONTROL
Document Type and Number:
WIPO Patent Application WO/2017/186181
Kind Code:
A1
Abstract:
Provided in the present disclosure are a method and device for network access control. The method for network access control: an aggregation switch is allowed to configure an ACL policy on a present device, the ACL policy comprising a first network segment and a second network segment, the first network segment and the second network segment corresponding either to a same user group or to different user groups, or the first network segment corresponding to a user group and the second network segment corresponding to a resource group. When a user packet transmitted by an access switch from a user terminal is received by the aggregation switch, same matches a source IP address of the user packet to the first network segment in the ACL policy, and matches a destination IP address of the user packet to the second network segment in the ACL policy. If the source IP address of the user packet matches the first network segment and the destination IP address of the user packet matches the second network segment, then the user packet is discarded.
Inventors:
SONG YUBING (CN)
YANG XIAOPENG (CN)
YANG XIAOPENG (CN)
Application Number:
PCT/CN2017/082690
Publication Date:
November 02, 2017
Filing Date:
May 02, 2017
Export Citation:
Assignee:
NEW H3C TECH CO LTD (CN)
International Classes:
H04L45/74; H04L12/46
Foreign References:
CN101022394A | 2007-08-22 | |||
CN1878112A | 2006-12-13 | |||
US8675664B1 | 2014-03-18 |
Other References:
See also references of EP 3451612A4
Attorney, Agent or Firm:
BEIJING BESTIPR INTELLECTUAL PROPERTY LAW CORPORATION (CN)
Download PDF:
Previous Patent: BACKGROUND DATA TRANSFER POLICY CONFIGURATION METHOD AND APPARATUS
Next Patent: HUMANIZED ANTI-BASIGIN ANTIBODIES AND THE USE THEREOF
Next Patent: HUMANIZED ANTI-BASIGIN ANTIBODIES AND THE USE THEREOF