REVERSIBLE FIREWALL POLICIES
A method of determining whether to allow multiple data packets to pass a firewall, each data packet having a source address and a destination address. The method evaluates a data packet by using a first set of policies when no previous packet with an opposite address has been allowed under the first set of policies. Two packets have opposite addresses when a source address of the first of the two packets is the same as the destination address of the second of the two packets and the destination address of the first packet is the same as the source address of the second packet. The method evaluates the data packet using a second set of policies when a previous packet with an opposite address has been allowed under the first set of policies.
1 . A method of determining whether to allow a plurality of data packets to pass a firewall, each data packet having a source address and a destination address, the method comprising:
a) evaluating a data packet using a first set of policies when no previous packet with an opposite address has been allowed under the first set of policies, wherein two packets have opposite addresses when a source address of the first of the two packets is the same as the destination address of the second of the two packets and the destination address of the first packet is the same as the source address of the second packet; and
b) evaluating the data packet using a second set of policies when a previous packet with an opposite address has been allowed under the first set of policies.
2 . The method of claim 1 , wherein each source address comprises a source IP address and a source port address, wherein each destination address comprises a destination IP address and a destination port address.
3 . The method of claim 1 further comprising storing records of data packets allowed to pass the firewall under the first set of firewall policies.
4 . The method of claim 3 , wherein said evaluating the data packet further comprises using the stored records to determine whether to evaluate a received data packet using the first set of firewall policies or the second set of firewall policies.
5 . The method of claim 3 further comprising not storing records of data packets evaluated under the second set of policies.
6 . The method of claim 1 further comprising storing the first set of policies in a first policy table and the second set of policies in a second policy table.
7 . The method of claim 1 further comprising storing the first set of policies and the second set of policies in a common policy table.
8 . The method of claim 1 , wherein the firewall protects a plurality of virtual machines on a host node of a hosting system that moves virtual machines among the host nodes.
9 . The method of claim 8 , wherein the host node is a first host node, the firewall is a first firewall, the first firewall is for retrieving the first set of policies and the second set of policies from a second firewall on a second host node.
10 . A computer readable storage medium storing a computer program which when executed by at least one processor implements a firewall, the computer program comprising:
a) a set of instructions for determining whether a received first data packet has an opposite set of addresses compared to any data packet referenced in a set of records;
b) a set of instructions for, when the first data packet has an opposite set of addresses compared to any data packet referenced in the set of records, evaluating the first data packet according to a first set of firewall policies and, when the first data packet is allowed, storing a records of the data in the set of records; and
c) a set of instructions for, when the first data packet has an opposite set of addresses compared to a data packet referenced in the records, evaluating the first data packet according to a second set of firewall policies.
11 . The computer readable storage medium of claim 10 , wherein data packets have source addresses, destination addresses and associated protocols, wherein the first data packet has an opposite set of addresses compared to a second data packet when it has the same source address as the destination address of the second data packet and the same destination address as the source address of the first data packet.
12 . The computer readable storage medium of claim 10 , wherein the computer program further comprises a set of instructions for storing the first set of policies in a first policy table and storing the second set of policies in a second policy table.
13 . The computer readable storage medium of claim 10 , wherein the computer program further comprises a set of instructions for storing the first and second sets of policies in a policy table.
14 . The computer readable storage medium of claim 10 , wherein the computer program further comprises a set of instructions for storing records of data packets received by the firewall and allowed to pass according to the second set of firewall policies
15 . The computer readable storage medium of claim 14 , wherein the computer program further comprises:
a) a set of instructions for storing said records of data packets received by the firewall and allowed to pass according to a first set of firewall policies in a first table of connections; and
b) a set of instructions for storing records of data packets received by the firewall and allowed to pass according to the second set of firewall policies in a second table of connections.
16 . The computer readable storage medium of claim 14 , wherein the computer program further comprises:
a) a set of instructions for storing said records of data packets received by the firewall and allowed to pass according to a first set of firewall policies in a table of connections; and
b) a set of instructions for storing records of data packets received by the firewall and allowed to pass according to the second set of firewall policies in the table of connections.
17 . The computer readable storage medium of claim 10 , wherein the data packets each comprise a source IP address, a destination IP address, a source port address, a destination port address and an associated protocol and wherein the first data packet is a reversed address data packet to a second data packet when the first data packet comprises:
a) a same source IP address as a destination IP address of the second data packet;
b) a same destination IP address as a source IP address of the second data packet;
c) a same source port address as a destination port address of the second data packet;
d) a same destination port address as a source port address of the second data packet; and
e) a same associated protocol as an associated protocol of the second data packet.
18 . The computer readable storage method of claim 10 , wherein the firewall protects a plurality of virtual machines on a host node of a hosting system that moves virtual machines among the host nodes.
19 . The computer readable storage medium of claim 10 , wherein the computer program further comprises a set of instructions for using the stored records to determine whether to evaluate a received data packet using the first set of firewall policies or the second set of firewall policies.
20 . The computer readable storage medium of claim 10 , wherein the computer program further comprises a set of instructions for storing records of data packets allowed to pass by the first set of firewall policies.