Enforcing a segmentation policy in co-existence with a system firewall
US11736443B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Apr 26, 2022 |
| Grant date | Aug 22, 2023 |
| Priority date | — |
| Expiry date | Apr 26, 2042 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L41/40
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
A segmentation firewall executing on a host enforces a segmentation policy. In a co-existence mode, the segmentation firewall operates in co-existence with a system firewall that enforces a security policy. The segmentation firewall is configured to either drop packets that do not match any permissive rule or pass packets that match a permissive rule to the system firewall to enable the system firewall to determine whether to drop or accept the passed packets. To enable efficient operation of the segmentation firewall when operating in co-existence with the system firewall, the segmentation firewall may include a plurality of rule chains and may be configured to exit a chain and bypass remaining rule chains upon an input packet matching a permissive rule of the segmentation policy.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.