IP Library Granted Patent US 9,888,055
Granted Patent B2
US 9,888,055 · App. 14/200,948 · Granted Feb 6, 2018

Firewall for a virtual network and related techniques

Inventors: Conrad N. Wood (Berlin, DE); Achim Weiss (Berlin, DE)
Assignee: Profitbricks GmbH
H04L67/02H04L47/10H04L47/125H04L49/00H04L67/1008
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,888,055
App. No.
14/200,948
Filed
Mar 7, 2014
Granted
Feb 6, 2018
Kind
B2
Art Unit
2447
USPC
709/224
Abstract

A system for filtering traffic in virtual networks includes a first virtual machine executed by a first physical server connected to a physical network and a second virtual machine executed by a second physical server connected to the physical network. The first and second virtual machines are connected to a same virtual network. A first firewall module is executed by the first physical server and a second firewall module is executed by the second physical server. The firewall modules are configured to filter network traffic received by the physical servers and addressed to the virtual servers.

Claims (28)

1. A system comprising:

a first server device executing a first virtual machine and connected to a physical network;

a second server device executing a second virtual machine and connected to the physical network, wherein the first and second virtual machines are connected to a same virtual network;

a first firewall module that functions as a firewall for the first virtual machine and a second firewall module that functions as a firewall for the second virtual machine, the firewall modules configured to filter network traffic received by the physical servers and addressed to the respective virtual servers;

wherein the first firewall module is executed by a core processor of the first virtual machine and the second firewall module is executed by a core processor of the second virtual machine;

wherein the first and second firewall modules each include a superset of the same firewall rules.

2. The system of claim 1 wherein the firewall modules are configured to filter the network traffic prior to the network traffic being received by the virtual network.

3. The system of claim 1 wherein the firewall modules are configured to filter the network traffic based on custom traffic filters.

4. The system of claim 3 wherein the custom traffic filters include a rule to filter traffic based on a client ID of a client that owns a virtual machine.

5. The system of claim 3 wherein the custom traffic filters include a rule to filter traffic based on which virtual machine generated the traffic filter.

6. The system of claim 3 wherein the custom traffic filters include a rule to filter traffic based on a virtual network identifier.

7. The system of claim 3 wherein the custom traffic filters include a rule to filter traffic based on a virtual machine that is a recipient of the traffic.

8. A method comprising:

executing, by a first server device connected to a physical network, a first virtual machine;

executing, by a second server device connected to the physical network, a second virtual machine, wherein the first and second virtual machines are connected to a same virtual network;

executing a first firewall module to function as a firewall for the first virtual machine and a second firewall module to function as a firewall module for the second virtual machine, the firewall modules configured to filter network traffic received by the physical servers and addressed to the virtual machines;

wherein the first firewall module is executed by a core processor of the first virtual machine and the second firewall module is executed by a core processor of the second virtual machine

wherein the first and second firewall modules each include a superset of the same firewall rules.

9. The method of claim 8 wherein the firewall modules are configured to filter the network traffic prior to the network traffic being received by the virtual network.

10. The method of claim 8 wherein the firewall modules are configured to filter the network traffic based on custom traffic filters.

11. The method of claim 10 wherein the custom traffic filters include a rule to filter traffic based on a client ID of a client that owns a virtual machine.

12. The method of claim 10 wherein the custom traffic filters include a rule to filter traffic based on which virtual machine generated the traffic filter.

13. The method of claim 10 wherein the custom traffic filters include a rule to filter traffic based on a virtual network identifier.

14. The method of claim 10 wherein the custom traffic filters include a rule to filter traffic based on a virtual machine that is a recipient of the traffic.

15. A system comprising:

a physical server connected to a physical network and executing a virtual machine connected to a virtual network;

a firewall module executed by the virtual machine and configured to function as a firewall for the first virtual machine and to filter network traffic received by the physical server and addressed to the virtual server;

wherein the firewall module includes a superset of firewall rules shared by other firewalls operating on the physical and/or virtual network.

Assignments (5)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE DOC DATE WAS ENTERED AS 08/26/2019 AND SHOULD BE 10/25/2018 PREVIOUSLY RECORDED ON REEL 73084 FRAME 476. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Mar 9, 2026
From: PROFITBRICKS GMBH
To: 1&1 IONOS CLOUD GMBH
Reel/Frame 075065/0912 →
CHANGE OF NAME Recorded Feb 27, 2026
From: 1&1 IONOS SE
To: IONOS SE
Reel/Frame 073919/0244 →
MERGER Recorded Feb 23, 2026
From: 1&1 IONOS CLOUD GMBH
To: 1&1 IONOS SE
Reel/Frame 073861/0812 →
CHANGE OF NAME Recorded Oct 13, 2025
From: PROFITBRICKS GMBH
To: 1&1 IONOS CLOUD GMBH
Reel/Frame 073084/0476 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2014
From: WOOD, CONRAD N.; WEISS, ACHIM
To: PROFITBRICKS GMBH
Reel/Frame 032460/0185 →
Continuity (2)
Provisional Application 61801391 · Mar 15, 2013
Related Publication 20140280911A1 · Sep 18, 2014