Apparatus, system, and method for applying firewall rules on packets in kernel space on network devices
US10505899B1 · kind B1 · utility
Assignee
Inventors
Key dates
| Filing date | Aug 14, 2017 |
| Grant date | Dec 10, 2019 |
| Priority date | — |
| Expiry date | Mar 16, 2038 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L63/205
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
A disclosed method for applying firewall rules on packets in kernel space on network devices may include (1) intercepting, via a socket-intercept layer in kernel space on a routing engine of a network device, a packet that is destined for a remote device and then, in response to intercepting the packet in kernel space on the routing engine, (2) identifying an egress interface index that specifies an egress interface that (A) is external to kernel space and (B) is capable of forwarding the packet from the network device to the remote device and (3) applying, on the packet in kernel space, at least one firewall rule based at least in part on the egress interface index before the packet egresses from the routing engine. Various other apparatuses, systems, and methods are also disclosed.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.