IP Library Granted Patent US 12712848
Granted Patent B2
US 12712848 · App. 18/122,756 · Granted Aug 18, 2026

Flow based breakout of firewall usage based on trust

Inventors: Saravanan Kandasamy (Bangalore, IN); Santosh Pallagatti Kotrabasappa (Bangalore, IN); Moses Devadason (Chennai, IN); Hari Narayan Gopalan (Chennai, IN); Praveen Kumar Rajendran (Chennai, IN); Sivakumar Seenivasan (Chennai, IN); Jayaprakash Harikrishnan (Chennai, IN)
Assignee: Velocloud Networks, LLC
H04L63/0263H04L63/0236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12712848
App. No.
18/122,756
Granted
Aug 18, 2026
Kind
B2
Abstract

A method for flow based breakout of firewall usage based on trust is provided. Some embodiments include receiving flow data for one or more flows associated with an endpoint external to a data center, the flow data indicating the one or more flows meet one or more good flow criteria, the one or more flows corresponding to flows of data communicated via a firewall and determining, based on the flow data meeting one or more trusted endpoint criteria, the endpoint is trusted. Some embodiments of the method include generating one or more policies that flows associated with the endpoint can bypass the firewall and configuring an edge services gateway with the one or more policies to cause the edge services gateway to apply the one or more policies without applying the firewall.

Claims (51)

1 . A method for flow based breakout of firewall usage based on trust, the method comprising:

receiving, at an edge services gateway, flow data for one or more flows communicated via a firewall external to a data center between one or more internal endpoints internal to the data center and an external endpoint that is external to the data center, wherein each of the one or more flows comprises respective sequences of packets that share a certain set of attributes;

detecting that the flow data indicates that the one or more flows meet one or more good flow criteria, wherein the one or more good flow criteria comprise one or more of:

no resets or retransmits occurring for the one or more flows; or

a termination packet being sent to terminate the one or more flows;

determining, based on the flow data meeting one or more trusted endpoint criteria, the external endpoint is trusted, wherein the one or more trusted endpoint criteria comprises one or more of:

a threshold number of the one or more flows to the external endpoint meeting the one or more good flow criteria within a moving time window; or

the one or more flows to the external endpoint lacking any flow that fails to meet the one or more good flow criteria for a threshold duration;

generating one or more policies that flows associated with the external endpoint can bypass the firewall; and

configuring the edge services gateway with the one or more policies to cause the edge services gateway to facilitate subsequent flows with the external endpoint while bypassing the firewall.

2 . The method of claim 1 , wherein receiving the flow data comprises receiving one or more portions of the flow data from a plurality of edge services gateways, and further comprising configuring the plurality of edge services gateways with one or more rules.

3 . The method of claim 1 , wherein the data center is a software-defined data center (SDDC) comprising a plurality of hosts, each of the plurality of hosts comprising a virtualization layer that abstracts physical resources for one or more virtual computing instances (VCI) supported by the virtualization layer.

4 . The method of claim 1 , wherein the one or more trusted endpoint criteria further comprises: the one or more flows meeting the one or more good flow criteria having lasted for a threshold duration.

5 . The method of claim 1 , further comprising identifying each of the one or more flows is associated with the external endpoint based on packets of the one or more flows including in a header a destination IP address, destination port, and application associated with the endpoint.

6 . The method of claim 1 , further comprising communicating with the external endpoint without the firewall.

7 . The method of claim 1 , further comprising expiring the one or more policies at the edge services gateway after a time period to cause the edge services gateway to communicate with the external endpoint via the firewall.

8 . A system for flow based breakout of firewall usage based on trust, comprising:

at least one processor; and

at least one memory, the at least one processor and the at least one memory configured to cause the system to:

receive, at an edge services gateway, flow data for one or more flows communicated via a firewall to a data center between one or more internal endpoints internal to the data center and an external endpoint that is external to a data center, wherein each of the one or more flows comprises respective sequences of packets that share a certain set of attributes;

detect that the flow data indicates that the one or more flows meet one or more good flow criteria, wherein the one or more good flow criteria comprise one or more of:

no resets or retransmits occurring for the one or more flows; or

a termination packet being sent to terminate the one or more flows;

determine, based on the flow data meeting one or more trusted endpoint criteria, the external endpoint is trusted, wherein the one or more trusted endpoint criteria comprises one or more of:

a threshold number of the one or more flows to the external endpoint meeting the one or more good flow criteria within a moving time window; or

the one or more flows to the external endpoint lacking any flow that fails to meet the one or more good flow criteria for a threshold duration;

generate one or more policies that flows associated with the external endpoint can bypass the firewall; and

configure the edge services gateway with the one or more policies to cause the edge services gateway to facilitate subsequent flows with the external endpoint while bypassing the firewall.

9 . The system of claim 8 , wherein receiving the flow data comprises receiving one or more portions of the flow data from a plurality of edge services gateways, and further comprising configuring the plurality of edge services gateways with one or more rules.

10 . The system of claim 8 , wherein the data center is a software-defined data center (SDDC) comprising a plurality of hosts, each of the plurality of hosts comprising a virtualization layer that abstracts physical resources for one or more virtual computing instances (VCI) supported by the virtualization layer.

11 . The system of claim 8 , wherein the one or more trusted endpoint criteria further comprises:

the one or more flows meeting the one or more good flow criteria having lasted for a threshold duration.

12 . The system of claim 8 , wherein the at least one memory and at the least one processor are further configured to cause the system to identify that each of the one or more flows is associated with the external endpoint based on packets of the one or more flows including in a header a destination IP address, destination port, and application associated with the endpoint.

13 . The system of claim 8 , wherein the at least one memory and at the least one processor are further configured to cause the system to communicate with the external endpoint without the firewall.

14 . The system of claim 8 , wherein the at least one memory and at the least one processor are further configured to cause the system to expire the one or more policies at the edge services gateway after a time period to cause the edge services gateway to communicate with the external endpoint via the firewall.

15 . A non-transitory computer-readable medium for flow based breakout of firewall usage based on trust comprising instructions that, when executed by at least one processor of a computing system, cause the computing system to perform operations comprising:

receiving, at an edge services gateway, flow data for one or more flows communicated via a firewall external to a data center between one or more internal endpoints internal to the data center and an external endpoint that is external to the data center, wherein each of the one or more flows comprises respective sequences of packets that share a certain set of attributes;

detecting that the flow data indicates that the one or more flows meet one or more good flow criteria, wherein the one or more good flow criteria comprise one or more of:

no resets or retransmits occurring for the one or more flows; or

a termination packet being sent to terminate the one or more flows;

determining, based on the flow data meeting one or more trusted endpoint criteria, the external endpoint is trusted, wherein the one or more trusted endpoint criteria comprises one or more of:

a threshold number of the one or more flows to the external endpoint meeting the one or more good flow criteria within a moving time window; or

the one or more flows to the external endpoint lacking any flow that fails to meet the one or more good flow criteria for a threshold duration;

generating one or more policies that flows associated with the external endpoint can bypass the firewall; and

configuring the edge services gateway with the one or more policies to cause the edge services gateway to facilitate subsequent flows with the external endpoint while bypassing the firewall.

16 . The non-transitory computer-readable medium of claim 15 , wherein receiving the flow data comprises receiving one or more portions of the flow data from a plurality of edge services gateways, and further comprising configuring the plurality of edge services gateways with one or more rules.

17 . The non-transitory computer-readable medium of claim 15 , wherein the data center is a software-defined data center (SDDC) comprising a plurality of hosts, each of the plurality of hosts comprising a virtualization layer that abstracts physical resources for one or more virtual computing instances (VCI) supported by the virtualization layer.

18 . The non-transitory computer-readable medium of claim 15 , wherein the one or more trusted endpoint criteria further comprises:

the one or more flows meeting the one or more good flow criteria having lasted for a threshold duration.

19 . The non-transitory computer-readable medium of claim 15 , the operations further comprising identifying that each of the one or more flows is associated with the external endpoint based on packets of the one or more flows including in a header a destination IP address, destination port, and application associated with the endpoint.

20 . The non-transitory computer-readable medium of claim 15 , the operations further comprising expiring the one or more policies at the edge services gateway after a time period to cause the edge services gateway to communicate with the external endpoint via the firewall.