Invention Grant
- Patent Title: Dynamically scalable application firewall deployment for cloud native applications
-
Application No.: US17139103Application Date: 2020-12-31
-
Publication No.: US11575651B2Publication Date: 2023-02-07
- Inventor: Liron Levin , Isaac Schnitzer , Elad Shuster , Ory Segal
- Applicant: Palo Alto Networks, Inc.
- Applicant Address: US CA Santa Clara
- Assignee: Palo Alto Networks, Inc.
- Current Assignee: Palo Alto Networks, Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Gilliam IP PLLC
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/40 ; G06F9/50

Abstract:
A configuration of a cloud application exposed via a public IP address is duplicated with modifications to include a private IP address to expose the application internally. The original configuration is updated so that external network traffic sent to the application is redirected to and distributed across agents running on nodes of a cloud cluster by which web application firewalls (WAFs) are implemented. A set of agents for which the respective WAFs should inspect the redirected network traffic are selected based on cluster metrics, such as network and resource utilization metrics. The redirected network traffic targets a port allocated to the agents that is unique to the application, where ports are allocated on a per-application basis so each of the agents can support WAF protection for multiple applications. Network traffic which a WAF allows to pass is directed from the agent to the application via its private IP address.
Public/Granted literature
- US20220210122A1 DYNAMICALLY SCALABLE APPLICATION FIREWALL DEPLOYMENT FOR CLOUD NATIVE APPLICATIONS Public/Granted day:2022-06-30
Information query