US 12,457,246 B2
Network connectivity policy management system
Daniel Boris Kovenat, New Rochelle, NY (US); Dheepak Ramanujam, Jersey City, NJ (US); and Michael Joel O'Connor, Chicago, IL (US)
Assigned to Cisco Technology, Inc., San Jose, CA (US)
Filed by Cisco Technology, Inc., San Jose, CA (US)
Filed on Oct. 26, 2023, as Appl. No. 18/495,429.
Application 18/495,429 is a continuation of application No. 17/246,413, filed on Apr. 30, 2021, granted, now 11,848,912.
Application 17/246,413 is a continuation of application No. 16/997,829, filed on Aug. 19, 2020, granted, now 11,025,590, issued on Jun. 1, 2021.
Prior Publication US 2024/0056420 A1, Feb. 15, 2024
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 9/40 (2022.01); H04L 41/0894 (2022.01); H04L 41/12 (2022.01); H04L 61/256 (2022.01)
CPC H04L 63/20 (2013.01) [H04L 41/0894 (2022.05); H04L 41/12 (2013.01); H04L 61/256 (2013.01); H04L 63/0209 (2013.01); H04L 63/0263 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A computer-implemented method for configuring a network security device, the method comprising:
receiving, by a network security system, a connectivity policy for a network environment including a plurality of network addresses, the connectivity policy corresponding to a first network address and a second network address within a network environment;
generating a universal representation of the connectivity policy using a network topology mapping of the network environment, the network topology mapping including a set of possible zone paths for the network environment that connect the first network address and the second network address, wherein the set of possible zone paths includes:
an active zone path allowing communication between the first network address and the second network address; and
an alternate zone path allowing communication between the first network address and the second network address responsive to the active zone path becoming unavailable;
identifying, using the network topology mapping, a security device in the network environment on a network zone path between the first network address and the second network address, the security device configured to implement connectivity policies using a native syntax;
generating, based on the universal representation, a native representation of the connectivity policy in the native syntax; and
configuring the security device to allow communication between the first network address and the second network address using the generated native representation.