| CPC H04L 63/0227 (2013.01) [H04L 47/825 (2013.01); H04L 2212/00 (2013.01)] | 20 Claims |

|
1. A method comprising:
determining a stateless rule corresponding to communication between a first virtual forwarding and routing (VRF) segment of a network fabric and a second VRF segment of the network fabric, the stateless rule being usable to enforce network policy on communications between the first and second VRF segments;
receiving first network layer prefixes associated with first subscriber devices in the first VRF segment and second network layer prefixes associated with second subscriber devices in the second VRF segment;
receiving a packet sent from a first subscriber device of the first VRF, the packet having a source address that is included in the first network layer prefixes and a destination address included in the second network layer prefixes; and
determining, using the stateless rule, the source address, and the destination address, that the packet is allowed to be communicated from the first VRF and to the second VRF.
|