Fault tolerant firewall sandwiches
First Claim
Patent Images
1. A computer-readable medium comprising computer-executable instructions for performing a method in application-space, said method comprising:
- receiving a packet from a computer network;
selecting one of a plurality of firewalls for processing the packet; and
forwarding the packet to the selected one of the firewalls.
1 Assignment
0 Petitions
Accused Products
Abstract
Firewall sandwich configurations having improved levels of system availability as well as an application-space implementation of a firewall load balancer (FLB) which provides greater operational flexibility while reducing the need for custom hardware and/or operating system software. Also disclosed is a firewall capable of functionally replacing an FLB upon detecting a failure therein.
71 Citations
23 Claims
-
1. A computer-readable medium comprising computer-executable instructions for performing a method in application-space, said method comprising:
-
receiving a packet from a computer network;
selecting one of a plurality of firewalls for processing the packet; and
forwarding the packet to the selected one of the firewalls. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8)
-
-
9. A system comprising:
-
a plurality of firewalls;
a first FLB for exchanging packets between a first network and the plurality of firewalls;
a second FLB for exchanging packets between a second network and the plurality of firewalls; and
a first standby FLB configured to detect a failure in either one of the first FLB and the second FLB, and to functionally replace a corresponding one of the first FLB and the second FLB after detecting the failure. - View Dependent Claims (10, 11, 12)
-
-
13. A system comprising:
-
a plurality of firewalls;
a first FLB for exchanging packets between a first network and the plurality of firewalls; and
a second FLB for exchanging packets between a second network and the plurality of firewalls;
wherein at least the first FLB is configured to both exchange packets between the first network and the plurality of firewalls, and exchange packets between the second network and the plurality of firewalls, after determining that a failure has occurred in the second FLB. - View Dependent Claims (14, 15, 16, 17, 18, 19)
-
-
20. A system comprising:
-
a plurality of firewalls;
a first FLB for exchanging packets between a first network and the plurality of firewalls; and
a second FLB for exchanging packets between a second network and the plurality of firewalls;
wherein at least one of the firewalls is configured to functionally replace the first FLB after detecting a failure in the first FLB. - View Dependent Claims (21, 22, 23)
-
Specification