Patent · US Active

Enforcing a segmentation policy in co-existence with a system firewall

US11736443B2 · kind B2 · utility

0Cited by
5References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateApr 26, 2022
Grant dateAug 22, 2023
Priority date
Expiry dateApr 26, 2042

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L41/40
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A segmentation firewall executing on a host enforces a segmentation policy. In a co-existence mode, the segmentation firewall operates in co-existence with a system firewall that enforces a security policy. The segmentation firewall is configured to either drop packets that do not match any permissive rule or pass packets that match a permissive rule to the system firewall to enable the system firewall to determine whether to drop or accept the passed packets. To enable efficient operation of the segmentation firewall when operating in co-existence with the system firewall, the segmentation firewall may include a plurality of rule chains and may be configured to exit a chain and bypass remaining rule chains upon an input packet matching a permissive rule of the segmentation policy.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.