Patent · US Active

Apparatus, system, and method for applying firewall rules on packets in kernel space on network devices

US10505899B1 · kind B1 · utility

13Cited by
2References
16Claims
0Family size

Assignee

Inventors

Key dates

Filing dateAug 14, 2017
Grant dateDec 10, 2019
Priority date
Expiry dateMar 16, 2038

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/205
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A disclosed method for applying firewall rules on packets in kernel space on network devices may include (1) intercepting, via a socket-intercept layer in kernel space on a routing engine of a network device, a packet that is destined for a remote device and then, in response to intercepting the packet in kernel space on the routing engine, (2) identifying an egress interface index that specifies an egress interface that (A) is external to kernel space and (B) is capable of forwarding the packet from the network device to the remote device and (3) applying, on the packet in kernel space, at least one firewall rule based at least in part on the egress interface index before the packet egresses from the routing engine. Various other apparatuses, systems, and methods are also disclosed.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.