×

Method, systems, and computer program products for implementing function-parallel network firewall

  • US 8,037,517 B2
  • Filed: 12/22/2005
  • Issued: 10/11/2011
  • Est. Priority Date: 12/22/2004
  • Status: Active Grant
First Claim
Patent Images

1. A function-parallel firewall comprising:

  • (a) a first firewall node for filtering received packets using a first portion of a rule set including a plurality of rules, the first portion including less than all of the rules in the rule set; and

    (b) at least one second firewall node for filtering packets using a second portion of the rule set, the second portion including at least one rule in the rule set that is not present in the first portion, wherein the first and second portions together include all of the rules in the rule set, wherein the first and second firewall nodes are configured to implement a gateless design wherein the rules are distributed among the first and second firewall nodes such that for any given packet, only one of the first and the at least one second firewall nodes accepts the packet and the other of the first and at least one second firewall nodes always denies the packet, wherein each of the packets is replicated to each of the firewall nodes and wherein the first firewall node is adapted to forward packets that pass one of the rules in the first portion to an internal network in a manner that bypasses the at least one second firewall node.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×