×

Hierarchical firewalls

  • US 8,336,094 B2
  • Filed: 01/05/2009
  • Issued: 12/18/2012
  • Est. Priority Date: 03/27/2008
  • Status: Active Grant
First Claim
Patent Images

1. A method of implementing a virtual machine firewall on a host node to protect at least one virtual machine on the host node, the method comprising:

  • receiving, with the firewall, a layer of firewall policies from each of a plurality of entities with different levels of authority over the at least one virtual machine on the host node;

    maintaining, with the firewall, a first layer of policies received from a first entity with a first level of authority and a second layer of policies received from a second entity with a second level of authority for the virtual machine, wherein the first level of authority is higher than the second level of authority;

    evaluating, with the firewall, a packet received by the host node for the virtual machine based on the first layer of policies with the first level of authority prior to evaluating the packet based on the second level of authority associated with the second layer of policies; and

    in response to the evaluation of the packet based on the first layer of policies for the virtual machine, determining to one of allow the received packet through the firewall to the virtual machine, block the received packet from the virtual machine, or delegate a decision of whether to allow or block the received packet to the second layer of policies for the virtual machine.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×