IP Library Granted Patent US 11,206,243
Granted Patent B2
US 11,206,243 · App. 16/805,360 · Granted Dec 21, 2021

Multiple gateway controllers to establish network access

Inventors: Kurt Glazemakers (Grembergen, BE); Gokhan Berberoglu (Gothenburg, SE); Kosmas Valianos (Ojersjo, SE); Per Johan Allansson (Kungsbacka, SE); Hoang Long Nguyen (Gothenburg, SE); Thomas Bruno Emmanuel Cellerier (Kungalv, SE); Aitor Perez Iturri (Gothenburg, SE); Harish Dinne (Gothenburg, SE); Salvatore Tomaselli (Gothenburg, SE)
Assignee: Cyxtera Cybersecurity, Inc.
H04L63/029H04L12/4633H04L12/4641H04L12/66H04L45/54H04L45/74H04L63/0272H04L63/08H04L63/10H04W48/16H04W48/18H04W76/12H04W88/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,206,243
App. No.
16/805,360
Granted
Dec 21, 2021
Kind
B2
Abstract

Network access is provided to a networking device. In one approach, a method includes: obtaining, by a gateway, access rules for a networking device; providing, by the gateway, one or more dedicated networking tunnels between the gateway and respective remote gateways to one or more respective network segments, wherein the networking device is authorized to access the one or more network segments by the access rules; and routing, by the gateway, networking packets from the networking device based on source address information in the networking packets to the one or more dedicated networking tunnels, and based on destination address information in the networking packets, routing the networking packets to a selection of the one or more dedicated networking tunnels.

Claims (66)

1. A method comprising:

sending, to a first access controller, an instruction to terminate access control for a networking device, wherein the first access controller serves as a default gateway for the networking device, and in response to receiving the instruction, the first access controller terminates a networking tunnel to a remote gateway; and

sending, to a second access controller, access rules for the networking device, wherein the second access controller, in response to receiving the access rules:

re-establishes the networking tunnel to the remote gateway; and

sends a packet to the networking device announcing that the second access controller will serve as the default gateway for the networking device.

2. The method of claim 1 , further comprising, prior to sending the instruction, sending the access rules to the first access controller.

3. The method of claim 2 , wherein the access rules authorize access by the networking device to a network segment via the remote gateway.

4. The method of claim 1 , further comprising:

detecting that the networking device has connected to a local network;

in response to detecting that the networking device has connected to the local network, determining at least one property of the networking device;

prior to sending the instruction, determining, based on the at least one property, the access rules; and

sending the access rules to the first access controller.

5. The method of claim 4 , further comprising selecting, based on the access rules, the first access controller as the default gateway for the networking device.

6. The method of claim 5 , wherein, prior to sending the instruction, the first access controller uses the access rules for establishing the networking tunnel.

7. The method of claim 1 , wherein the first access controller and the second access controller each use a same network address.

8. The method of claim 7 , wherein the second access controller:

receives a broadcast message sent by the networking device to the first access controller and the second access controller;

compares an address of the broadcast message with networking devices for which the second access controller has received access rules; and

in response to determining that the address does not match the networking devices for which the second access controller has received access rules, refrains from responding to the broadcast message.

9. The method of claim 8 , wherein the first access controller:

matches the address of the broadcast message with access rules received by the first access controller; and

in response to matching the address of the broadcast message with the access rules received by the first access controller, sending a response to the networking device that includes a hardware address of the first access controller.

10. The method of claim 1 , further comprising sending a default gateway address to the networking device, wherein the default gateway address corresponds to the first access controller.

11. A system comprising:

at least one processor; and

at least one memory containing instructions configured to instruct the at least one processor to:

receive, by a first access controller, an instruction to terminate access by a networking device via a networking tunnel to a remote gateway;

in response to receiving the instruction, terminate, by the first access controller, the networking tunnel;

receive, by a second access controller, access rules for the networking device; and

in response to the receiving the access rules:

re-establish, by the second access controller, the networking tunnel to the remote gateway; and

announce, by the second access controller, to the networking device that the second access controller will serve as a default gateway for the networking device.

12. The system of claim 11 , wherein the instructions are further configured to instruct the at least one processor to:

determine at least one property of the networking device; and

prior to receiving the instruction, determine, based on the at least one property, the access rules.

13. The system of claim 11 , wherein the instructions are further configured to instruct the at least one processor to:

match the address of a broadcast message with access rules associated with the first access controller; and

in response to matching the address of the broadcast message with the access rules associated with the first access controller, send a response to the networking device that includes a hardware address of the first access controller.

14. The system of claim 11 , wherein the instructions are further configured to instruct the at least one processor to:

receive, by each of the first access controller and the second access controller, a broadcast message sent by the networking device;

compare an address of the broadcast message with networking devices for which the second access controller has received access rules; and

in response to determining that the address does not match the networking devices for which the second access controller has received access rules, refrain, by the second access controller, from responding to the broadcast message.

15. The system of claim 11 , wherein the instructions are further configured to instruct the at least one processor to:

receive, by the first access controller, the access rules;

in response to the first access controller receiving the access rules, create, by the first access controller, a routing table; and

add, by the first access controller, to the routing table, a source-based routing rule for the networking device, and a destination-based routing rule for the networking device, wherein the destination-based routing rule routes packets to the networking tunnel.

16. A system comprising:

a first access controller configured to:

receive an instruction to terminate access control for a networking device, wherein the first access controller serves as a default gateway for the networking device; and

in response to receiving the instruction, terminate a first networking tunnel to a remote gateway; and

a second access controller configured to:

receive access rules for the networking device; and

in response to receiving the access rules:

establish a second networking tunnel to the remote gateway; and

announce to the networking device that the second access controller will serve as the default gateway for the networking device.

17. The system of claim 16 , wherein the second networking tunnel is the first networking tunnel.

18. The system of claim 16 , wherein the first access controller is further configured to:

receive the access rules;

in response to receiving the access rules, create a routing table; and

add, to the routing table, a destination-based routing rule for the networking device, wherein the destination-based routing rule routes packets to the first networking tunnel.

19. The system of claim 18 , wherein the second access controller is further configured to:

receive a broadcast message sent by the networking device;

compare an address of the broadcast message with networking devices for which the second access controller has received access rules; and

in response to determining that the address does not match the networking devices for which the second access controller has received access rules, refrain from responding to the broadcast message.

20. The system of claim 16 , wherein the second access controller is further configured to:

prior to establishing the second networking tunnel to the remote gateway, create a virtual network device with a dedicated networking interface for the networking device.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: APPGATE FUNDING, LLC
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068311/0570 →
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068311/0970 →
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: SIS HOLDINGS, L.P.
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068312/0011 →
SECURITY INTEREST Recorded Aug 22, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: APPGATE FUNDING, LLC
Reel/Frame 064672/0383 →
SECURITY INTEREST Recorded Jul 6, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: SIS HOLDINGS, L.P.
Reel/Frame 064461/0539 →
SECURITY INTEREST Recorded Jun 10, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 063956/0470 →
CHANGE OF NAME Recorded Jul 28, 2022
From: CYXTERA CYBERSECURITY, INC.
To: APPGATE CYBERSECURITY, INC.
Reel/Frame 060663/0045 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2020
From: GLAZEMAKERS, KURT; BERBEROGLU, GOKHAN; VALIANOS, KOSMAS; ALLANSSON, PER JOHAN; NGUYEN, HOANG LONG; CELLERIER, THOMAS BRUNO EMMANUEL; ITURRI, AITOR PEREZ; DINNE, HARISH; TOMASELLI, SALVATORE
To: CYXTERA CYBERSECURITY, INC.
Reel/Frame 052012/0324 →
Continuity (2)
Provisional Application 62813610 · Mar 4, 2019
Related Publication 20200287749A1 · Sep 10, 2020