US 12,267,203 B2
Network access control for devices in a software defined access (SDA) fabric
Eric Levy Abegnoli, Valbonne (FR); Pascal Thubert, La Colle sur Loup (FR); and Patrick Wetterwald, Mouans Sartoux (FR)
Assigned to Cisco Technology, Inc., San Jose, CA (US)
Filed by Cisco Technology, Inc., San Jose, CA (US)
Filed on Jan. 24, 2019, as Appl. No. 16/256,544.
Prior Publication US 2020/0244519 A1, Jul. 30, 2020
Int. Cl. H04L 41/0659 (2022.01); H04L 9/40 (2022.01); H04L 61/103 (2022.01); H04L 45/64 (2022.01); H04L 101/622 (2022.01)
CPC H04L 41/0661 (2023.05) [H04L 61/103 (2013.01); H04L 63/101 (2013.01); H04L 45/64 (2013.01); H04L 2101/622 (2022.05)] 20 Claims
OG exemplary drawing
 
1. A method comprising:
receiving, by a first access switch from a first device, a first address resolution request;
resolving, by the first access switch with a central database of a network, the address resolution request; and
sending, by the first access switch in response to resolving the first address resolution request, a second address resolution request to a sensor, wherein sending the second address resolution request comprises converting, by the first access switch, the first address resolution request into the second address resolution request and a third address resolution request, wherein each of the second address resolution request and the third resolution request is a unicast message, and wherein converting the first address resolution request into the second address resolution request and the third address resolution request comprises converting the first address resolution request serially into the second address resolution request and the third address resolution request, and wherein converting the first address resolution request serially into the second address resolution request and the third address resolution request further comprises:
sending the second address resolution request to the sensor;
sending, by the sensor to the first device in response to the sensor determining that the first device is a bad endpoint, an address resolution response;
establishing a session between the sensor and the first device in response to the sensor sending the address resolution response;
prompting, by the sensor via the established session, the first device to resolve issues that lead the sensor to determine that the first device is a bad endpoint; and
sending the third address resolution request to a second device after the first device resolving the issues that lead the sensor to determine that the first device is a bad endpoint.