IP Library Granted Patent US 10,044,677
Granted Patent B2
US 10,044,677 · App. 15/222,794 · Granted Aug 7, 2018

System and method to configure a firewall for access to a captive network

Inventors: William J. Black (San Jose, CA); Marco Miska (Imst, AT); Gean Han (San Jose, CA)
Assignee: Barracuda Networks, Inc.
H04L63/0263G06Q20/14H04L63/029H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,044,677
App. No.
15/222,794
Granted
Aug 7, 2018
Kind
B2
Abstract

An approach is proposed that contemplates system and method to configure firewall rules of a VPN gateway of a protected network so that users of devices in the protected network can access Internet securely via a captive network. First, the proposed approach enables the VPN gateway to probe the captive network with an HTTP request to discover a captive portal of the captive network. After the captive portal is discovered, one or more firewall rules of the VPN gateway are added so that network traffic from the devices in the protected network are redirected to the captive portal for authentication. Once the users are authenticated and a VPN tunnel is established between the VPN gateway and a remote VPN tunnel terminal, the firewall rules previously added are removed from the VPN gateway and all network traffic from the devices in the protected network are routed over the VPN tunnel.

Claims (56)

1. A system to support dynamic firewall configuration for Internet access through a captive network, comprising:

a network appliance serving as an VPN gateway of a protected network and configured to

initiate automatically an HTTP request to a known-good Internet host to discover a captive portal of the captive network when a VPN tunnel cannot be established through the captive network;

add one or more firewall rules to allow network traffic from one or more devices in the protected network to be automatically routed to a captive portal and only the captive portal for authentication once the captive portal is discovered;

redirect users of the devices in the protected network attempting to access Internet via the devices to the captive portal for authorization;

establish the VPN tunnel between the VPN gateway and a remote VPN tunnel terminal point through the captive network over the Internet if the users from the protected network are authenticated, wherein every device behind the VPN tunnel terminal point routes its traffic over the VPN tunnel;

remove the firewall rules previously added so that all network traffic from the devices in the protected network is routed thereafter over the VPN tunnel once the VPN tunnel is established;

said captive network configured to

receive and redirect the HTTP request to its captive portal so that the captive portal is discovered by the VPN gateway.

2. The system of claim 1 , wherein:

the captive network is a public Wi-Fi network that the users subscribe to or pay to access at a public location.

3. The system of claim 1 , wherein:

the network appliance is an x86 or ARM based device that is programmable, wherein the firewall rules are adjustable at runtime.

4. The system of claim 1 , wherein:

the captive portal is identified by one or more of IP address, DNS name, and a combination of attributes of an authorization server that runs the captive portal.

5. The system of claim 1 , wherein:

the VPN gateway is configured to conduct virus or malware scanning of all network traffic that comes to the captive portal.

6. The system of claim 1 , wherein:

the VPN gateway is configured to pre-scan the captive portal for specific URLs allowed to be accessed by the devices in the protected network for authentication.

7. The system of claim 1 , wherein:

the VPN gateway is configured to include and utilize one or more templates to identify a set of commonly-used captive portals to allow only specific URL requests from the devices.

8. The system of claim 1 , wherein:

the VPN gateway is configured to capture and replay communication of the devices with the captive portal in case the same captive portal is visited again.

9. The system of claim 1 , wherein:

the VPN gateway is configured to allow only one designated device in the protected network to access the captive portal before the VPN tunnel is established in order to leave rest of the devices in the protected network secure.

10. The system of claim 9 , wherein:

the designated device is a specific laptop in the protected network.

11. The system of claim 9 , wherein:

the VPN gateway is configured to allow the users to designate and confirm the insecure device before adding the firewall rules.

12. The system of claim 1 , wherein:

the VPN gateway is configured to allow the captive portal to continue communication to only the device that has been authenticated after the VPN tunnel has been established.

13. A method to support dynamic firewall configuration for Internet access through a captive network, comprising:

initiating automatically by an VPN gateway an HTTP request to a known-good Internet host to discover a captive portal of the captive network when a VPN tunnel cannot be established through the captive network;

receiving and redirecting the HTTP request to its captive portal so that the captive portal is discovered by the VPN gateway;

adding one or more firewall rules to allow network traffic from devices in the protected network to be automatically routed to a captive portal and only the captive portal for authentication once the captive portal is discovered;

redirecting users of the devices in the protected network attempting to access Internet via the devices to the captive portal for authorization;

establishing the VPN tunnel between the VPN gateway and a remote VPN tunnel terminal point through the captive network over the Internet if the users from the protected network are authenticated, wherein every device behind the VPN tunnel terminal point routes its traffic over the VPN tunnel;

removing the firewall rules previously added so that all network traffic from the devices in the protected network is routed thereafter over the VPN tunnel once the VPN tunnel is established.

14. The method of claim 13 , wherein:

the VPN gateway runs on a programmable network appliance, wherein the firewall rules are adjustable at runtime.

15. The method of claim 13 , further comprising:

identifying the captive portal by one or more of IP address, DNS name, and a combination of attributes of an authorization server that runs the captive portal.

16. The method of claim 13 , further comprising:

conducting virus or malware scanning of all network traffic that comes to the captive portal.

17. The method of claim 13 , further comprising:

pre-scanning the captive portal for specific URLs allowed to be accessed by the devices in the protected network for authentication.

18. The method of claim 13 , further comprising:

including and utilizing one or more templates to identify a set of commonly-used captive portals to allow only specific URL requests from the devices.

19. The method of claim 13 , further comprising:

capturing and replaying communication of the devices with the captive portal in case the same captive portal is visited again.

20. The method of claim 13 , further comprising:

allowing only one designated device in the protected network to access the captive portal before the VPN tunnel is established in order to leave rest of the devices in the protected network secure.

21. The method of claim 20 , further comprising:

allowing the users to designate and confirm the insecure device before adding the firewall rules.

22. The method of claim 13 , further comprising:

allowing the captive portal to continue communication to only the device that has been authenticated after the VPN tunnel has been established.

Assignments (10)
SECURITY INTEREST Recorded Mar 17, 2025
From: BARRACUDA NETWORKS, INC.
To: OAKTREE FUND ADMINISTRATION, LLC, AS COLLATERAL AGENT
Reel/Frame 070529/0123 →
SECURITY INTEREST Recorded Sep 3, 2022
From: BARRACUDA NETWORKS, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 061377/0208 →
SECURITY INTEREST Recorded Sep 3, 2022
From: BARRACUDA NETWORKS, INC.
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 061377/0231 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN IP RECORDED AT R/F 045327/0877 Recorded Aug 16, 2022
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 061179/0602 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN IP RECORDED AT R/F 054260/0746 Recorded Aug 16, 2022
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 061521/0086 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 30, 2020
From: BARRAUDA NETWORKS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 054260/0746 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT R/F 045327/0934 Recorded Apr 15, 2019
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 048895/0841 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 14, 2018
From: BARRACUDA NETWORKS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045327/0877 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 14, 2018
From: BARRACUDA NETWORKS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045327/0934 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2016
From: BLACK, WILLIAM J.; MISKA, MARCO; HAN, GEAN
To: BARRACUDA NETWORKS, INC.
Reel/Frame 039286/0201 →
Continuity (2)
Provisional Application 62260111 · Nov 25, 2015
Related Publication 20170149736A1 · May 25, 2017