Techniques for providing a secure web gateway through a zero trust network environment
A system and method for configuring a client device to communicate utilizing a secure web gateway. The method includes generating a virtual network interface having a namespace with a plurality of names, wherein a first name of the namespace is assigned to a client device; assigning a second name of the namespace to a resource accessible to the client device through a zero trust network environment, wherein the resource is deployed in a secure network environment; and configuring the client device to communicate only through the virtual network interface.
1 . A method comprising:
generating a virtual network interface having a namespace with a plurality of names, wherein a first name of the namespace is assigned to a client device;
assigning a second name of the namespace to a resource accessible to the client device through a zero trust network environment, wherein the resource is deployed in a secure network environment;
configuring the client device to communicate only through the virtual network interface;
inspecting network traffic received from the client device;
determining a destination of the network traffic;
sending the network traffic to the destination in response to determining that the network traffic is allowable based on a policy of the zero trust network environment; and
altering a packet of the network traffic so that a response from the resource is directed to the zero trust network environment instead of the client device.
2 . The method of claim 1 , further comprising:
receiving credentials of a user account associated with the user device;
providing access to the resource through the zero trust network in response to authenticating the received credentials.
3 . The method of claim 1 , wherein the virtual network interface further includes a routing table.
4 . The method of claim 1 , further comprising:
performing a deep packet inspection on the network traffic.
5 . The method of claim 1 wherein the resource is deployed in any one of: a private network, a public network, and any combination thereof.
6 . The method of claim 1 , wherein the resource is any one of: a web application, a remote desktop protocol (RDP) server, a secure shell (SSH) server, a file server, an object database, a transactional database, a SQL database, a NoSQL database, a web server, a data repository, and any combination thereof.
7 . The method of claim 1 , further comprising:
assigning a third name of the namespace to another resource accessible to the client device through a zero trust network environment, wherein the resource is deployed in a private network and the another resource is deployed in a public network; and
blocking network traffic to the another resource in response to determining that the client device requested content from the resource within a time period which is less than a predefined time period.
8 . The method of claim 1 , wherein the zero trust network environment includes any one of: a frontend SSH server, a frontend RDP server, an access portal server, a backend server, and any combination thereof.
9 . A non-transitory computer-readable medium comprising instructions executable by processing circuitry to:
assign a first name of a namespace of a virtual network interface having to a client device, the namespace having a plurality of names, and wherein the client device is configured to communicate only through the virtual network interface;
assign a second name of the namespace to a resource accessible to the client device through a zero trust network environment, wherein the resource is deployed in a secure network environment;
inspect network traffic received from the client device;
determine a destination of the network traffic;
send the network traffic to the destination in response to determining that the network traffic is allowable based on a policy of the zero trust network environment; and
alter a packet of the network traffic so that a response from the resource is directed to the zero trust network environment instead of the client device.
10 . The non-transitory computer-readable medium of claim 9 , wherein the instructions are executable to:
assign a third name of the namespace to another resource accessible to the client device through a zero trust network environment, wherein the resource is deployed in a private network and the another resource is deployed in a public network; and
block network traffic to the another resource in response to determining that the client device requested content from the resource within a time period which is less than a predefined time period.
11 . The non-transitory computer-readable medium of claim 9 , wherein the instructions are executable to:
receive credentials of a user account associated with the user device; and
provide access to the resource through the zero trust network in response to authenticating the received credentials.
12 . The non-transitory computer-readable medium of claim 9 , wherein the virtual network interface further includes a routing table.
13 . The non-transitory computer-readable medium of claim 9 , wherein the instructions are executable to:
perform a deep packet inspection on the network traffic.
14 . A system comprising:
processing circuitry; and
a non-transitory machine readable storage medium comprising instructions executable by the processing circuitry to:
assign a first name of a namespace of a virtual network interface to a client device, the namespace having a plurality of names, and wherein the client device is configured to communicate only through the virtual network interface;
assign a second name of the namespace to a resource accessible to the client device through a zero trust network environment, wherein the resource is deployed in a secure network environment;
inspect network traffic received from the client device;
determine a destination of the network traffic;
send the network traffic to the destination in response to determining that the network traffic is allowable based on a policy of the zero trust network environment; and
alter a packet of the network traffic so that a response from the resource is directed to the zero trust network environment instead of the client device.
15 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
receive credentials of a user account associated with the user device; and
provide access to the resource through the zero trust network in response to authenticating the received credentials.
16 . The system of claim 14 , wherein the virtual network interface further includes a routing table.
17 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
perform a deep packet inspection on the network traffic.
18 . The system of claim 14 , wherein the resource is deployed in any one of: a private network, a public network, and any combination thereof.
19 . The system of claim 14 , wherein the resource is any one of: a web application, a remote desktop protocol (RDP) server, a secure shell (SSH) server, a file server, an object database, a transactional database, a SQL database, a NoSQL database, a web server, a data repository, and any combination thereof.
20 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
assign a third name of the namespace to another resource accessible to the client device through a zero trust network environment, wherein the resource is deployed in a private network and the another resource is deployed in a public network; and
block network traffic to the another resource in response to determining that the client device requested content from the resource within a time period which is less than a predefined time period.
21 . The system of claim 14 , wherein the zero trust network environment includes any one of: a frontend SSH server, a frontend RDP server, an access portal server, a backend server, and any combination thereof.