IP Library Granted Patent US 11,943,094
Granted Patent B2
US 11,943,094 · App. 17/343,893 · Granted Mar 26, 2024

Methods and systems for application and policy based network traffic isolation and data transfer

Inventors: Kumar Ramachandran (Fremont, CA); Venkataraman Anand (San Ramon, CA); Navneet Yadav (Cupertino, CA); Arivu Ramasamy (San Jose, CA); Aaron Edwards (Sunnyvale, CA)
Assignee: Palo Alto Networks, Inc.
H04L41/0668G06F16/285G06F16/955G06F17/18H04L12/4633H04L12/4641H04L41/12H04L41/14H04L43/04H04L43/062H04L43/065H04L43/0817H04L43/0864H04L43/0876H04L45/02H04L45/125H04L45/28H04L45/302H04L45/306H04L45/38H04L47/125H04L47/22H04L47/24H04L47/32H04L47/781H04L47/825H04L63/061H04L67/141H04L67/52H04L67/63H04L69/40H04L43/0811H04L43/10H04L45/22H04L61/2503H04L61/4511H04L61/4523H04W84/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,943,094
App. No.
17/343,893
Granted
Mar 26, 2024
Kind
B2
Abstract

A method includes allocating an identifier to each of a plurality of policies each comprising a network-isolation identifier associated with a VXWAN directive and transmitting each of the plurality of policies to one or more devices in a network.

Claims (47)

1. A centrally controllable multi-tenant controller for controlling a plurality of assets across a plurality of distributed computing environments wherein the controller is configured to:

receive from a first network tenant on a network:

an indication of a partner network tenant with which to establish a IPSEC VPN TUNNEL, and

at least one of:

a site associated with the partner network tenant to which a IPSEC VPN TUNNEL is to be established,

source prefixes or specific IP addresses at a tenant site from to which application traffic is allowed to travel over the IPSEC VPN TUNNEL, or

destination prefixes or specific IP addresses for application traffic that can travel over the IPSEC VPN TUNNEL;

receive an indication from the partner network tenant of agreement to establish the IPSEC VPN TUNNEL;

instruct one or more devices of the first network and the partner network to establish an IPSEC data tunnel between themselves, wherein only traffic between the source and destination prefixes or specific IP addresses that were specified by the first network tenant and the partner network tenant is allowed to pass through the IPSEC VPN TUNNEL, wherein a most restrictive subset of the source and destination prefixes or specific IP addresses are applied for determining the traffic allowed to pass through the IPSEC VPN TUNNEL, and wherein a policy string defines a business policy based on a first virtual extensible wide area network (VXWAN) network-isolation identifier or a second VXWAN network-isolation identifier; and

determine whether to allow the traffic to pass through the IPSEC VPN TUNNEL based on the policy string.

2. The multi-tenant controller of claim 1 , wherein the network comprises connectivity that is at least one of: hybrid, physical, or logical.

3. The multi-tenant controller of claim 1 further configured to:

perform application analysis on the application traffic on a per session basis.

4. The multi-tenant controller of claim 1 , wherein the policy string comprises a policy string format.

5. The multi-tenant controller of claim 4 , wherein the policy string format is standardized.

6. The multi-tenant controller of claim 1 , wherein the application traffic is encrypted.

7. A method for controlling a plurality of assets across a plurality of distributed computing environments, the method comprising:

receiving, from a first network tenant on a network:

an indication of a partner network tenant with which to establish a IPSEC VPN TUNNEL, and

at least one of:

a site associated with the partner network tenant to which a IPSEC VPN TUNNEL is to be established,

source prefixes or specific IP addresses at a tenant site from which application traffic is allowed to travel over the IPSEC VPN TUNNEL, or

destination prefixes or specific IP addresses for application traffic that can travel over the IPSEC VPN TUNNEL;

receive an indication from the partner network tenant of agreement to establish the IPSEC VPN TUNNEL;

instruct one or more devices of the first network and the partner network to establish an IPSEC data tunnel between themselves, wherein only traffic between the source and destination prefixes or specific IP addresses that were specified by the first network tenant and the partner network tenant is allowed to pass through the IPSEC VPN TUNNEL, wherein a most restrictive subset of the source and destination prefixes or specific IP addresses are applied for determining the traffic allowed to pass through the IPSEC VPN TUNNEL, and wherein a policy string defines a business policy based on a first virtual extensible wide area network (VXWAN) network-isolation identifier or a second VXWAN network-isolation identifier; and

determine whether to allow the traffic to pass through the IPSEC VPN TUNNEL based on the policy string.

8. The method of claim 7 , wherein the network comprises connectivity that is at least one of: hybrid, physical, or logical.

9. The method of claim 7 further comprising:

performing application analysis on the application traffic on a per session basis.

10. The method of claim 7 , wherein the policy string comprises a policy string format.

11. The method of claim 10 , wherein the policy string format is standardized.

12. The method of claim 7 , wherein the application traffic is encrypted.

13. A non-transitory computer-readable medium storing instructions that adapt at least one processor to:

receive from a first network tenant on a network:

an indication of a partner network tenant with which to establish a IPSEC VPN TUNNEL, and

at least one of:

a site associated with the partner network tenant to which a IPSEC VPN TUNNEL is to be established,

source prefixes or specific IP addresses at a tenant site from to which application traffic is allowed to travel over the IPSEC VPN TUNNEL, or

destination prefixes or specific IP addresses for application traffic that can travel over the IPSEC VPN TUNNEL;

receive an indication from the partner network tenant of agreement to establish the IPSEC VPN TUNNEL;

instruct one or more devices of the first network and the partner network to establish an IPSEC data tunnel between themselves, wherein only traffic between the source and destination prefixes or specific IP addresses that were specified by the first network tenant and the partner network tenant is allowed to pass through the IPSEC VPN TUNNEL, wherein a most restrictive subset of the source and destination prefixes or specific IP addresses are applied for determining the traffic allowed to pass through the IPSEC VPN TUNNEL, and wherein a policy string defines a business policy based on a first virtual extensible wide area network (VXWAN) network-isolation identifier or a second VXWAN network-isolation identifier; and

determine whether to allow the traffic to pass through the IPSEC VPN TUNNEL based on the policy string.

14. The non-transitory computer-readable medium of claim 13 , wherein the network comprises connectivity that is at least one of: hybrid, physical, or logical.

15. The non-transitory computer-readable medium of claim 13 , wherein the stored instructions further adapt the at least one processor to:

perform application analysis on the application traffic on a per session basis.

16. The non-transitory computer-readable medium of claim 13 , wherein the policy string comprises a policy string format.

17. The non-transitory computer-readable medium of claim 16 , wherein the policy string format is standardized.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2021
From: CLOUDGENIX INC.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 058449/0010 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2021
From: RAMACHANDRAN, KUMAR; ANAND, VENKATARAMAN; YADAV, NAVNEET; RAMASAMY, ARIVU; EDWARDS, AARON
To: CLOUDGENIX, INC.
Reel/Frame 057164/0157 →
Continuity (3)
Continuation 14856314 · Sep 16, 2015
Provisional Application 62051293 · Sep 16, 2014
Related Publication 20210367832A1 · Nov 25, 2021