US 12,294,532 B2
Stretched EPG and micro-segmentation in multisite fabrics
Javed Asghar, Dublin, CA (US); Sridhar Vallepalli, Fremont, CA (US); Umamaheswararao Karyampudi, Fremont, CA (US); and Srinivas Kotamraju, Saratoga, CA (US)
Assigned to Cisco Technology, Inc., San Jose, CA (US)
Filed by Cisco Technology, Inc., San Jose, CA (US)
Filed on Apr. 1, 2024, as Appl. No. 18/623,693.
Application 17/448,320 is a division of application No. 16/162,199, filed on Oct. 16, 2018, granted, now 11,159,451, issued on Oct. 26, 2021.
Application 18/623,693 is a continuation of application No. 17/448,320, filed on Sep. 21, 2021, granted, now 11,949,602.
Claims priority of provisional application 62/694,349, filed on Jul. 5, 2018.
Prior Publication US 2024/0244012 A1, Jul. 18, 2024
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 12/00 (2006.01); H04L 9/40 (2022.01); H04L 12/46 (2006.01); H04L 41/0893 (2022.01); H04L 45/02 (2022.01); H04L 45/16 (2022.01); H04L 45/24 (2022.01); H04L 45/74 (2022.01); H04L 49/104 (2022.01); H04L 49/15 (2022.01); H04L 49/201 (2022.01); H04L 61/106 (2022.01); H04L 69/22 (2022.01)
CPC H04L 49/104 (2013.01) [H04L 12/462 (2013.01); H04L 12/4633 (2013.01); H04L 41/0893 (2013.01); H04L 45/04 (2013.01); H04L 45/16 (2013.01); H04L 45/24 (2013.01); H04L 45/74 (2013.01); H04L 49/1553 (2013.01); H04L 49/203 (2013.01); H04L 61/106 (2013.01); H04L 63/20 (2013.01); H04L 69/22 (2013.01)] 14 Claims
OG exemplary drawing
 
1. A system comprising:
a first switching fabric at a first site including a first plurality of endpoints, communicatively coupled via a network to a second switching fabric at a second site including a second plurality of endpoints, wherein the first site is at a different geographic location than the second site, a multi-site controller communicably connected with the first site and the second site;
wherein the multi-site controller is configured to:
define a Virtual Routing and Forwarding (VRF) domain extending between the first and second sites enabling communication between a group of endpoints including multiple endpoints at the first site and multiple endpoints at the second site;
identify at least a subset of endpoints within the group of endpoints using one or more filtering criteria, wherein the subset of endpoints includes at least one endpoint at the first site and at least one endpoint at the second site;
apply a shared security policy to the subset of endpoints; and
define a second VRF domain extending between the first and second sites enabling communication between a second group of endpoints including at least one endpoint at the first site and at least one endpoint at the second site, wherein the system selectively allows communication between endpoints connected via the VRF domain and endpoints connected via the second VRF domain.