DETAILED ACTION
Notice of Pre-AIA or AIA Status
1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendment
2. The Amendment filed June 30, 2026 has been entered and made of record. Claims 1, 19 and 20 have been amended. Claims 1-20 were presented for examination. Applicant’s amendments to claims 1 have overcome the claim objections previously set forth in the Office action mailed March 31, 2026. The objection of claim 1 has been withdrawn.
Response to Arguments
3. Applicant's arguments, filed on June 30, 2026, with respect to the rejection(s) of independent claims 1, 19 and 20 have been fully considered but are moot in view of the new grounds of rejection. The amended claims do not overcome the new ground of rejection made in view of newly found prior art references.
4. Applicant's arguments, filed on June 30, 2026, with respect to the rejection(s) of claims 2-18 have been fully considered but are moot in view of the new grounds of rejection. The claims do not overcome the new ground of rejection made in view of newly found prior art references.
Claim Objections
5. Claim 1, 19 and 20 are objected to because of the following informalities:
In claims 1 and 19, the recited operations use base-form verbs (“generate,” “determine,” “encapsulate,” “send”), while the second conditional uses the gerund “sending.” A consistent grammatical form is suggested (e.g., “send the data packet without encapsulating the data packet within the header”).
In claims 1,19 and 20, for the limitation “sending the data packet without encapsulating the data packet within a header,” the indefinite article “a header” is used where the header comprising the fully qualified security group (FQSG field) (recited earlier in the claim ) is intended. Suggested: “without encapsulating the data packet within the header,” or “within the fully qualified security group (FQSG) header.”
Claim Rejections - 35 USC § 112
6. The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
7. Claims 1, 19 and 20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 1 recites a single determination step, “determine whether the data is destined for a second functional domain”, but then recites two conditional branches: one “in response to determining that the data packet is destined for the second functional domain,” and another “in response to determining that the data packet is destined for the first functional domain.” The claim is indefinite because it does not recite any step of determining whether the data packet is destined for the first functional domain, such that there is in sufficient antecedent for “determining that the data is destined for the first functional domain.” The metes and bounds of the claim are therefore unclear. Applicant may overcome this rejection by amending “determine whether the data packet is destined for a second functional domain” to recite “determine whether the data packet is destined for a second functional domain or the first functional domain;” consistent with the specification (see, e.g., FIG. 3A and [0033]). Claims 19 and 20 are rejected for the reasons stated for claim 1.
Claim Rejections - 35 USC § 103
8. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
9. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
10. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
11. Claims 1-5, 7, 8, 10, 11, 13, 14, 16, 19 and 20 are rejected under 35 U.S.C. § 103 as being unpatentable over Hooda et al. (US 2020/0177503 A1), hereafter Hooda, in view of Eyada (US 11,729,146 B1), hereafter Eyada, and further in view of Zacks et al. (US 2023/0198946 A1), hereafter Zacks, and further in view of Mahalingam et al., (RFC 7438: “Virtual eXtensible Local Area Network (VXLAN): A Framework for Overlaying Virtualized Layer 2 Networks over Layer 3 Networks”), hereafter Mahalingam, available at http://www.rfc-editor.org/info/rfc7348.
Regarding claim 1, Hooda teaches a computer system comprising: a processor; and memory coupled to the processor and storing instructions that, when executed by the processor, are configurable to cause the computer system to: {Hooda [0024] “[A] system is provided comprising one or more processors; and memory including instructions that, when executed by the one or more processors, cause the system to receive, from an egress edge device of a first overlay network under administrative control of a first network controller, a first encapsulated packet including an original packet,…”}
“generate a data packet within a first functional domain;” In Hooda, a source host initiates a packet within a first administrative (logical) domain (e.g., the campus administrative domain 502A), which corresponds to the first functional domain (Hooda: [0077]). “The source host can generate an original packet 702 fir transmission to the destination host” ([0077]).
“determine whether the data packet is destined for a second functional domain;” The packet is routed toward another (second) administrative domain (WAN 502B; ultimately data-center 502C) and the overlay edge device determines the inter-domain next hop and applicable inter-domain policies (Hooda: [0077], [0080]).
“and in response to determining that the data packet is destined for the second functional domain: encapsulate the data packet within a header comprising a fully qualified security group (FQSG) field,” The first overlay edge device performs an inter-domain encapsulation using VXLAN-GOP, wherein the carried user or group identifier is a security group tag (SGT) (Hooda: [0080], [0081]).
“and send the encapsulated data packet to the second functional domain;” The egress edge device forwards the encapsulated packet to the ingress edge device of the second overlay network under the second administrative domain (Hooda: [0082]).
“and in response to determining that the data packet is destined for the first functional domain, sending the data packet without encapsulating the data packet within a header,” The overlay edge device performs the inter-domain encapsulation only for traffic routed toward another administrative domain, such that traffic destined within the first (same) domain is handled by intra-domain policies and is not inter-domain encapsulated, which is inherent in the edge encapsulation architecture. (Hooda, [0078]-[0080]).
Hooda further teaches that the grouper identifier field is carried within the header and used to “enable security enforcement at the second functional domain,” as the edge egress device extracts the SGT from the VXLAN header and applies the corresponding policy at the destination based on that identifier (Hooda: [0083], [0084]).
Hooda further teaches “wherein the first functional domain is a group of functions and/or processes that are separate and distinct,” as the campus, WAN and data-center administrative domains 502A/502B/503C are separate and distinct, each under its own network controller (Hooda: [0070]).
However, Hooda does not expressly teach that the group-identifier field is a fully qualified security group (FQSG) field associated with one or more cloud native security groups, or (ii) that the first functional domain is a group of functions and/or processes that are separate and distinct from functions and/or processes of the second functional domain.
Eyada teaches “a fully qualified security group (FQSG) field associated with one or more cloud native security groups.” Eyada recites a “fully-qualified security group identifier maybe represented by a combination of the account identifier, VPC identifier, and a local identifier of the security group” (Eyada: col. 6, ll. 22-31), where the cloud security groups are a web security group (WSG) and a database security group (DSG) for resources instances (Eyada: col. 5, ll. 51-62).
Eyada further teaches “wherein the first functional domain is a group of functions and/or processes that are separate and distinct from functions and/or processes of the second functional domain. The WSG comprises web-server instances (labeled “function=web server”) and the DSG comprises database-server instances (labeled “function=db_server), which are separate, distinct functional groups (Eyada: col. 5, ll. 34-42, 51-62; col. 7, ll. 3-12).
Eyada is analogous art because it is in the same field of endeavors as the claimed invention and Hooda, namely network-security segmentation of cloud resources using security groups. It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to configure the user or group identifier carried in Hooda’s encapsulation header as the fully-qualified security group of Eyada, associate with one or more cloud native security groups. One of ordinary skill would have had a reasonable expectation of success, as both references operates on security-group identifiers used for cloud-network segmentation and the modification leaves Hooda’s encapsulation and egress-enforcement mechanism unchanged. The motivation to do so is provided by Eyada, which teaches that automatically creating security groups keyed to a resource’s function “improve the security and scalability of virtual private clouds” (Eyada, col. 2, ll. 54-60).
Hooda in view of Eyada does not expressly teaches that the fully qualified security group identifier is carried as a field included within the header that wraps the data packet. Eyada’s FQSG identifier is used to reference security groups in the firewall control plane rather than being carried in a packet header.
Zacks teaches “the FOSG field included within the header that wraps the data packet and carrying identity and security policy context.” In Zacks, a GPO (group policy object) header includes a VXLAN portion, a virtual network identifier (VNI), and a scalable group tag (SGT) that “designates a policy group associated with the traffic flow” (Zacks: [0021]). The GPO header further includes a tenant identifier that serves as a “master classifier or a superset classifier for some of the tenant specific policy applications… subsuming other identifiers (such as the VNI 132, the SGI 134…)” carried in the header (Zacks: [0037]), namely a hierarchical, multi-component group identifier (tenant/VNI/SGT) carried as a field within the encapsulation header. Zacks further teaches that this enables enforcement, as downstream nodes “extract the enriched metadata…from the fields of the overlay header, determine one or more … network policies to apply based on the enriched metadata, and apply the determined network policy” (Zacks: [0023]).
Zacks is analogous art because it is in the same field of endeavor, namely carrying security group identity within an overlay/VXLAN encapsulation header for network policy enforcement. It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to configure the system of Hooda as modified by Eyada so that the FQSG identifier is carried as a field within the VXLAN/GPO encapsulation header, as taught by Zacks. This combination uses a known technique to improve a similar device in the same way to yield predictable results, with a reasonable expectation of success because Hooda already encapsulates using VXLAN-GPO. The motivation is provided by Zacks, which teaches that carrying the identity metadata in the header lets transit nodes gain knowledge of the traffic flow “without performing the DPI themselves, which is often impossible on these higher-throughput network devices” (Zacks: [0013]).
Hooda discloses sending a same-domain packet without encapsulation inherently, as set forth above. Mahalingam additionally discloses this limitation expressly: a VTEP prepends the outer/VXLAN header only when “there is a mapping of the destination MAC address to the remote VTEP,” such that a packet whose destination is on the same segment is forward without the VXLAN encapsulation (Mahalingam: Sect. 4.1, [Page 7]).
Mahalingam is analogous art because it is a VXLAN specification on which Hooda’s own encapsulation is based. It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to forward a same-domain packet without encapsulation while VXLAN-encapsulating an inter-domain packet, in accordance with Mahalingam’s standard behavior of encapsulating only remote VTEP-destined traffic as specified in RFC 7438. This combination combines prior art elements according to known methods to yield predictable results, with a reasonable expectation of success because Hooda’s encapsulation is itself VXLAN-based, and it avoids unnecessary encapsulation of intra-domain traffic.
Claim 2:
Regarding claim 2, Hooda, Eyada, Zacks and Mahalingam teach the limitation of claim 1 as outlined above. However, Hooda do not expressly disclose the limitations of claim 2.
However, Eyada teaches wherein the first functional domain and the second functional domain are within a common functional instance. In Eyada, the web security group and the database security group reside within the same VPC (Eyada: col. 7, ll. 3-12). The rationale and motivation to combine set forth above with respect to claim 1 apply equally.
Claim 3:
Regarding claim 3, Hooda, Eyada, Zacks and Mahalingam teach the elements of claim 1 as outlined above. However, Hoods does not expressly disclose that the FQSG field comprises unique identifier
Eyada teaches wherein the FQSG field comprises a unique identifier. Each security group is assigned a unique identifier (Eyada: col. 6, ll. 22-31). The rationale and motivation to combine set forth above with respect to claim 1 apply equally.
Claim 4:
Regarding claim 4, Hooda, Eyada, Zacks and Mahalingam teach the elements of claim 1 as outlined above.
Hooda further teaches wherein the encapsulated data packet is sent to the second functional domain via an overlay tunnel. In Hooda, the packet is VXLAN-GPO encapsulated and forwarded through the overlay to the ingress edge device of the second overlay network (Hooda: [0080], [0082]).
Claim 5:
Regarding claim 5, Hooda teaches the limitations of claim 4 as outlined above.
Hooda further teaches wherein the overlay tunnel comprises user datagram protocol (UDP) or transmission control protocol (TCP). The VXLAN-GPO encapsulation includes an outer UDP header (Hooda: [0030], [0080], [0083]).
Claim 7:
Regarding claim 7, Hooda, Eyada, Zacks and Mahalingam teach the elements of claim 1 as outlined above. However, Hooda does not expressly disclose the limitations of claim 7.
However, Eyada teaches wherein the first functional domain is a source domain having a first Internet protocol (IP) subnet, and wherein the second functional domain is a destination domain having a second IP subnet. {In the embodiment of Fig. 2, the web-server instances (the source functional domain ) reside in a first IP subnet (the public subnet 235) and the database-server instances (the destination functional domain) reside in a second IP subnet (the private subnet 250) (Eyada: col. 5, ll. 14-25). The rationale and motivation to combine set forth above with respect to claim 1 apply equally.
Claim 8:
Regarding claim 8, Eyada teaches the elements of claim 7 as outlined above.
However, Hooda does not expressly disclose the limitations of claim 8.
However, Eyada teaches wherein the first IP subnet and second IP subnet do not overlap, as the public subnet 235 and the private subnet 250 of Fig. 2 are two distinct, non-overlapping IP subnets. (Eyada: col. 5, ll. 14-25). The rationale and motivation to combine set forth above with respect to claim 1 apply equally.
Claim 10:
Regarding claim 10, Hooda, Eyada, Zacks and Mahalingam teach the elements of claim 1 as outlined above. However, Hooda does not expressly disclose the limitations of claim 10.
However, Eyada teaches wherein the FQSG field is associated with an FQSG policy comprising a plurality of parameters. In Eyada, the fully qualified security group identifier comprises a plurality of parameters (the account identifier, VPC identifier and local identifier) (Eyada: col. 6, ll. 22-31), and the security policy identifies cloud resources by their respective tags indicating the function, resource type, or application type (Eyada: col. 8, ll. 52-58, Fig. 5). The rationale and motivation to combine set forth above with respect to claim 1 apply equally.
Claim 11:
Regarding claim 11, Eyada teaches the elements of claim 10 as outlined above.
However, Hooda does not expressly disclose the limitations of claim 11.
However, Eyada further teaches wherein a parameter from the plurality of parameters in the FQSG policy is a destination parameter associated with the second functional domain. The outbound firewall rule specifies a destination communication endpoint identifier (Eyada: col. 10, ll. 32-56). The rationale and motivation to combine set forth above with respect to claim 1 apply equally.
Claim 13:
Regarding claim 13, Eyada teaches the elements of claim 11 as outlined above.
However, Hooda does not expressly disclose the limitations of claim 13.
However, Eyada teaches wherein the destination parameter identifies a functional instance associated with the second functional domain. The destination communication endpoint identifier is substituted with the identifier of a security group that is associated with one or more cloud resource instances (Eyada: col. 10, ll. 43-67). The rationale and motivation to combine set forth above with respect to claim 1 apply equally.
Claim 14:
Regarding claim 14, Eyada teaches the elements of claim 10 as outlined above.
However, However, Hooda does not expressly disclose the limitations of claim 14.
However, Eyada teaches wherein a parameter from the plurality of parameters in the FQSG policy is a source parameter associated with the first functional domain. The inbound firewall rule specifies a source of communication endpoint identifier (Eyada col. 10, ll. 43-56). The rationale and motivation to combine set forth above with respect to claim 1 apply equally.
Claim 16:
Regarding claim 16, Eyada teaches the elements of claim 14 as outlined above.
However, Hooda does not expressly disclose the limitations of claim 16.
However, Eyada teaches wherein the source parameter identifies a functional instance associated with the first functional domain. The source communication endpoint identifier is substituted with the identifier of a security group that is associated with one or more cloud resource instances (Eyada: col. 10, ll. 43-60; col. 11, ll. 6-14).The rationale and motivation to combine set forth above with respect to claim 1 apply equally.
Claim 19:
Regarding claim 19, the claim is directed to a computer-readable medium storing instructions that, when executed by a computer system, cause the computer system to implement the operations recited by claim 1. Therefore, the rejection applied to claim 1 also applies to claim 19. Claim 1 is rejected under the same rationale as claim 19.
Claim 19 further recites a tangible, non-transitory computer-readable medium storing instructions that, when executed by a computer system, are configurable to cause the computer system to implement the operations recited by claim 1. {Hooda: [0025] “[A] non-transitory computer-readable storage medium including instructions that, when executed by one or more processors of a system, cause the system to receive, from an egress edge device of a first overlay network under administrative control of a first network controller, a first encapsulated packet including an original packet,…”}
Claim 20:
Regarding claim 20, the claim is directed to a method comprising the operations recited by claim 1. Therefore, the rejection applied to claim 1 also applies to claim 20. Claim 1 is rejected under the same rationale as claim 20.
Claim 20 further recites a method comprising: the operations recited by claim 1. {Hooda [0018] “[A] computer-implemented method is provided for receiving, from an egress edge device of a first overlay network under administrative control of a first network controller by an ingress edge device of a second overlay network under administrative control of a second network controller, a first encapsulated packet including an original packet,…”}
12. Claims 9, 12 and 15 are rejected under 35 U.S.C. § 103 as being unpatentable over Hooda in view of Eyada, Zacks and Mahalingam as applied to claims 1, 7, 10, 11 and 14, and further in view of Nguyen (US 20210136118 A1), hereafter Nguyen.
Regarding claim 9, Eyada teaches the elements of claim 7 as outlined above.
However, the combination set forth above for claim 7 does not expressly disclose wherein the first IP subnet and the second IP subnet at least partially overlap.
However, Nguyen teaches wherein the first IP subnet and the second IP subnet at least partially overlap. Nguyen represents each subnetwork as an IP range. When comparing two network security specifications, Nguyen identifies two subnetworks whose root nodes have overlapping subnetworks, and distinguishes the overlapping and non-overlapping parts of the two subnetworks (Nguyen: [0044], [0049]-[0050]).
Nguyen is analogous art because it is directed to network security policy governing permitted connections between subnetworks of a network. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Nguyen with the combination of Hooda, Eyada, Zacks and Mahalingam, because Nguyen stores the permitted connections between subnetworks used by different services “using a data structure that allows efficient comparison of the underlying network security policies” and identification of discrepancies between them (Nguyen: [0014]). One of ordinary skill in the art would have had a reasonable expectation of success in doing so.
Claim 12:
Regarding claim 12, Eyada teaches the elements of claim 11 as outlined above.
Nguyen teaches wherein the destination parameter identifies a service associated with the second functional domain. Nguyen’s network security rule (e.g., Rule2) specifies a destination service group that specifies a list of services (Nguyen: [0022]-[0023]). The rationale and motivation to combine Nguyen set forth above with respect to claim 9 apply equally.
Claim 15:
Regarding claim 15, Eyada teaches the elements of claim 14 as outlined above.
Nguyen teaches wherein the source parameter identifies a service associated with the first functional domain. Nguyen’s network security rule (e.g., Rule2) specifies a source service group that specifies a list of services (Nguyen [0022]-[0023]). The rationale and motivation to combine Nguyen set forth above with respect to claim 9 apply equally.
13. Claim 6 is rejected under 35 U.S.C. § 103 as being unpatentable over Hooda in view of Eyada, Zacks and Mahalingam as applied to claim 1, and further in view of Meyers (US 2017/0104790 A1), hereafter Meyer.
Regarding claim 6, Hooda, Eyada, Zacks and Mahalingam teach the elements of claim 1 as outlined above. However, the combination do not expressly discloses that one or more cloud native security groups is defined based on a risk profile.
However, Meyers teaches wherein the one or more cloud native security groups is defined based on a risk profile. Meyers maintains a plurality of groups, and each group is defined by an associated risk level. Each group is assigned the security policy corresponding to that risk level. (e.g., a group containing a high risk traffic is assigned a strict security policy) (Meyers, [0013]; see also [0008], [0012], [0036]).
Meyer is analogous art because it is directed to defining security policy and asset grouping based on the risk of network assets. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Meyers with Hooda, Eyada, Zacks and Mahalingam because a user can define the risk levels “to improve flexibility where the risk assessment achieves a flexible security policy when the risk assessment is below a vulnerability score set by the user” (Meyers, [0042]). One of ordinary skill in the art would have had a reasonable expectation of success in doing so.
14. Claim 17 is rejected under 35 U.S.C. § 103 as being unpatentable over Hooda in view of Eyada, Zacks and Mahalingam as applied to claims 1, 10 and 14, and further in view of Jeong et al., (WO 2019/098678 A1, machine translation of patent application from European Patent Office website), hereafter Jeong.
Regarding claim 17, Eyada teaches the limitations of claim 14 as outlined above.
However, Hooda does not expressly disclose “wherein the source parameter identifies foundation and control telemetry features associated with the first functional domain.” However, Eyada teaches the recited foundation features: the source parameter is a source communication endpoint identifier associated with the source functional domain (Eyada: col. 10, ll. 32-56), as applied to claim 14 above). Under the broadest reasonable interpretation of the recited ‘foundation’, a functional domain designation, is met by Eyada’s identification of the source functional domain.
The combination of Hooda in view of Eyada, Zacks and Mahalingam does not expressly disclose wherein the source parameter identifies control telemetry features associated with the first functional domain.
However, Jeong teaches this limitation. Specifically, Jeong’s security policy data structure includes a telemetry data filed representing information related to telemetry collection (Jeong: [0015]), and the telemetry data field includes a telemetry source field identified by a telemetry source ID, - i.e., a source side parameter that identifies control-telemetry features (Jeong: [0020], [0169], [0171]).
Jeong is analogous art because it is directed to encoding network security policy governing security services. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Jeong with Hooda, Eyada, Zacks and Mahalingam, because Jeong’s architecture supports “flexible and efficient security policies of NSF” (Jeong: [0022]). The base combination’s source parameter identifies the functional domain; Jeong’s telemetry-source field still identifies the telemetry source, and the combination predictably yields a source parameters that identifies both.
15. Claim 18 is rejected under 35 U.S.C. § 103 as being unpatentable over Hooda in view of Eyada, Zacks and Mahalingam as applied to claims 1 and 10, and further in view of Xing et al. (US 2016/0036860 A1), hereafter Xing.
Regarding claim 18, Eyada teaches the limitations of claim 10 as outlined above.
Eyada teaches an FQSG policy that comprises a plurality of parameters (Eyada, col. 6, ll. 22-31; col. 8, ll. 52-58, as applied to claim 10 above). However, the combination set forth above for claims 1 and 10 does not expressly disclose wherein the FQSG field is associated with a second FQSG policy comprising a plurality of parameters and wherein the second FQSG policy is to override a pre-existing first FQSG policy.
However, Xing teaches this limitation. Xing discloses a first policy and a second policy. The second policy is a policy, other than the first policy, defined for a subclass, wherein “such a policy overrides said first policy when executing a request” (Xing: [0019]), thereby teaching a second policy that overrides a pre-existing first policy.
Xing is analogous art because it is directed to policy-based access control employing hierarchical policy precedence. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Xing with Hooda, Eyada, Zacks and Mahalingam, because Xing “enables a user to flexibly define policies,… as well as to amend and/or delete defined policies in an efficient way” (Xing: [0007]). In the proposed combination, Eyada’s multi-parameter FQSG policy (as applied to claim 10 above) is the pre-existing first FQSG policy, and Xing’s more specific overriding policy is implemented as a further such FQSG policy, yielding a second FQSG policy comprising a plurality of parameters that overrides the pre-existing first FQSG policy (Xing: [0019]).
Conclusion
16. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Smith et al., (“VXLAN Group Policy Option draft-smith-vxlan-group-05”, available at https://data draft-smith-vxlan-group-policy-05), discloses a Group Policy Option filed carrying a policy/group identifier within the VXLAN header.
17. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
18. Any inquiry concerning this communication or earlier communications from the examiner should be directed to BIN QING ZHENG whose telephone number is (703)756-1535. The examiner can normally be reached on M-F 9:30 am - 5:30 pm.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip J. Chea can be reached on 571-272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BIN QING ZHENG/
Examiner, Art Unit 2499
/PHILIP J CHEA/Supervisory Patent Examiner, Art Unit 2499