- 专利标题: Methods for revalidating FQDN rulesets in a firewall
-
申请号: US16841962申请日: 2020-04-07
-
公开(公告)号: US12034700B2公开(公告)日: 2024-07-09
- 发明人: Sushruth Gopal , Jayant Jain , Davide Celotto , Josh Swerdlow
- 申请人: VMware, Inc.
- 申请人地址: US CA Palo Alto
- 专利权人: VMware, Inc.
- 当前专利权人: VMware, Inc.
- 当前专利权人地址: US CA Palo Alto
- 代理机构: King Intellectual Asset Management
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; G06F9/455 ; H04L9/40
摘要:
A method comprises: in response to detecting a new expression in a policy rule, updating a global version number to a new value; identifying a particular IP address that corresponds to an FQDN matching on the new expression; storing an entry comprising the particular IP address, the new expression, and an entry version number in a first data structure, the entry version number being assigned the new value; in response to detecting a new connection to a destination IP address: finding a matching entry in the first data structure corresponding to the destination IP address; determining whether the global version number matches the entry version number for the matching entry; and in response to determining that the global version number does not match the entry version number for the matching entry, sending update information to a slowpath process that associates an updated configuration information for the matching entry.
公开/授权文献
- US20210314299A1 METHODS FOR REVALIDATING FQDN RULESETS IN A FIREWALL 公开/授权日:2021-10-07
信息查询