Patent · US Active

Enforcing a segmentation policy in co-existence with a system firewall

US12010098B2 · kind B2 · utility

0Cited by
5References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJul 6, 2023
Grant dateJun 11, 2024
Priority date
Expiry dateJul 6, 2043

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L41/40
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A segmentation firewall executing on a host enforces a segmentation policy. In a co-existence mode, the segmentation firewall operates in co-existence with a system firewall that enforces a security policy. The segmentation firewall is configured to either drop packets that do not match any permissive rule or pass packets that match a permissive rule to the system firewall to enable the system firewall to determine whether to drop or accept the passed packets. To enable efficient operation of the segmentation firewall when operating in co-existence with the system firewall, the segmentation firewall may include a plurality of rule chains and may be configured to exit a chain and bypass remaining rule chains upon an input packet matching a permissive rule of the segmentation policy.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.