IP Library › Granted Patent US 12,732,482
Granted Patent B2
US 12,732,482 · App. 18/621,596 · Granted Sep 8, 2026

Selective offloading of packet flows with flow state management

Inventors: Pradeep Patel (Fremont, CA); Jonathan A. Kunder (San Jose, CA); Ashish K. Dey (Sunnyvale, CA); Andrew E. Ossipov (Lewisville, TX); Jianxin Wang (Saratoga, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L63/0245G06F16/9017H04L47/2441H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,482
App. No.
18/621,596
Granted
Sep 8, 2026
Kind
B2
Abstract

A first packet of a packet flow is received at a classifying network device. The first packet is forwarded from the classifying network device to a firewall network device. An indication that the packet flow is to be offloaded is received at the classifying network device. Data is stored at the classifying network device indicating that the packet flow is to be offloaded. A non-control packet of the packet flow is received at the classifying network device. A determination is made that the non-control packet belongs to the packet flow by comparing data contained in the non-control packet to the stored data. The non-control packet of the packet flow is directed to a processing entity in response to the determining. A control packet of the packet flow is received at the classifying network device. The control packet of the packet flow is directed to the firewall network device.

Claims (51)

1 . A method comprising:

obtaining a received packet of a packet flow at a network security device;

evaluating, by a classifying device associated with the network security device, whether the received packet is part of a first group of packets eligible for fast path offloading or part of a second group of packets not eligible for fast path offloading;

in response to an evaluation that the received packet is part of the first group of packets eligible for fast path offloading, determining whether the received packet matches a stored indicator identifying the received packet as part of a flow to be offloaded;

in response to a determination that the received packet matches the stored indicator identifying the received packet as part of a flow to be offloaded, sending the received packet to an offload network processor; and

if the received packet is not part of the first group of packets eligible for fast path offloading, processing the received packet by a firewall device associated with the network security device;

wherein evaluating, by a classifying device associated with the network security device, whether the received packet is part of a first group of packets eligible for fast path offloading or part of a second group of packets not eligible for fast path offloading includes:

identifying whether the received packet is a control packet or a non-control packet, and assigning non-control packets to the first group of packets eligible for fast path offloading and assigning control packets to the second group of packets not eligible for fast path offloading; and

identifying whether the received packet is fragmented, and assigning non-fragmented packets to the first group of packets eligible for fast path offloading and assigning fragmented packets to the second group of packets not eligible for fast path offloading.

2 . The method of claim 1 , wherein in response to a determination that the received packet does not match a stored indicator, further comprising:

classifying the packet flow and, if the received packet is part of a flow to be offloaded, storing an indicator identifying the packet flow.

3 . The method of claim 1 , wherein the method further comprises using the received packet to maintain a flow state of the packet flow at the network security device.

4 . The method of claim 3 , further comprising storing data maintaining the flow state of the packet flow at the network security device.

5 . The method of claim 1 , further comprising:

obtaining an indication that non-control packets of the packet flow are no longer to be offloaded; and

processing a second received packet from the packet flow by the firewall device associated with the network security device instead of the offload network processor.

6 . An apparatus comprising:

one or more memories;

one or more network interfaces configured to enable network communications; and

one or more processors, wherein the one or more processors are configured to perform operations, the operations comprising:

obtaining a received packet of a packet flow at a network security device;

evaluating, by a classifying device associated with the network security device, whether the received packet is part of a first group of packets eligible for fast path offloading or part of a second group of packets not eligible for fast path offloading;

in response to an evaluation that the received packet is part of the first group of packets eligible for fast path offloading, determining whether the received packet matches a stored indicator identifying the received packet as part of a flow to be offloaded;

in response to a determination that the received packet matches the stored indicator identifying the received packet as part of a flow to be offloaded, sending the received packet to an offload network processor; and

if the received packet is not part of the first group of packets eligible for fast path offloading, processing the received packet by a firewall device associated with the network security device,

wherein evaluating, by a classifying device associated with the network security device, whether the received packet is part of a first group of packets eligible for fast path offloading or part of a second group of packets not eligible for fast path offloading includes:

identifying whether the received packet is a control packet or a non-control packet, and assigning non-control packets to the first group of packets eligible for fast path offloading and assigning control packets to the second group of packets not eligible for fast path offloading; and

identifying whether the received packet is fragmented, and assigning non-fragmented packets to the first group of packets eligible for fast path offloading and assigning fragmented packets to the second group of packets not eligible for fast path offloading.

7 . The apparatus of claim 6 , wherein in response to a determination that the received packet does not match a stored indicator, the operations further include:

classifying the packet flow and, if the received packet is part of a flow to be offloaded, storing an indicator identifying the packet flow.

8 . The apparatus of claim 6 , wherein the operations further comprise using the received packet to maintain a flow state of the packet flow at the network security device.

9 . The apparatus of claim 8 , wherein the operations further comprise storing data maintaining the flow state of the packet flow at the network security device.

10 . The apparatus of claim 6 , wherein the operations further comprise:

obtaining an indication that non-control packets of the packet flow are no longer to be offloaded; and

processing a second received packet from the packet flow by the firewall device associated with the network security device instead of the offload network processor.

11 . One or more tangible non-transitory computer readable media containing instructions, wherein the instructions, when executed, cause one or more processors associated with a network security device to perform operations comprising:

obtaining a received packet of a packet flow at a network security device;

evaluating, by a classifying device associated with the network security device, whether the received packet is part of a first group of packets eligible for fast path offloading or part of a second group of packets not eligible for fast path offloading;

in response to an evaluation that the received packet is part of the first group of packets eligible for fast path offloading, determining whether the received packet matches a stored indicator identifying the received packet as part of a flow to be offloaded;

in response to a determination that the received packet matches the stored indicator identifying the received packet as part of a flow to be offloaded, sending the received packet to an offload network processor; and

if the received packet is not part of the first group of packets eligible for fast path offloading, processing the received packet by a firewall device associated with the network security device,

wherein evaluating, by a classifying device associated with the network security device, whether the received packet is part of a first group of packets eligible for fast path offloading or part of a second group of packets not eligible for fast path offloading includes;

identifying whether the received packet is a control packet or a non-control packet, and assigning non-control packets to the first group of packets eligible for fast path offloading and assigning control packets to the second group of packets not eligible for fast path offloading; and

identifying whether the received packet is fragmented, and assigning non-fragmented packets to the first group of packets eligible for fast path offloading and assigning fragmented packets to the second group of packets not eligible for fast path offloading.

12 . The one or more tangible non-transitory computer readable media containing instructions of claim 11 , wherein in response to a determination that the received packet does not match a stored indicator, the operations further comprise:

classifying the packet flow and, if the received packet is part of a flow to be offloaded, storing an indicator identifying the packet flow.

13 . The one or more tangible non-transitory computer readable media containing instructions of claim 11 , wherein the operations further comprise using the received packet to maintain a flow state of the packet flow at the network security device.

14 . The one or more tangible non-transitory computer readable media containing instructions of claim 13 , wherein the operations further comprise storing data maintaining the flow state of the packet flow at the network security device.

15 . The one or more tangible non-transitory computer readable media containing instructions of claim 11 , wherein the operations further comprise:

obtaining an indication that non-control packets of the packet flow are no longer to be offloaded; and

processing a second received packet from the packet flow by the firewall device associated with the network security device instead of the offload network processor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2024
From: PATEL, PRADEEP; KUNDER, JONATHAN A.; DEY, ASHISH K.; OSSIPOV, ANDREW E.; WANG, JIANXIN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 066952/0795 →
Continuity (3)
Continuation 17374468 · Jul 13, 2021
Continuation 15220697 · Jul 27, 2016
Related Publication 20250016136A1 · Jan 9, 2025
References Cited (43)
US 6496935B1 · Fink et al. · 2002 [cited by applicant]
US 7107609B2 · Cheng et al. · 2006 [cited by applicant]
US 7397762B1 · Firoiu · 2008 [cited by examiner]
US 7536715B2 · Markham · 2009 [cited by applicant]
US 7546635B1 · Krohn et al. · 2009 [cited by applicant]
US 8462780B2 · Vincent et al. · 2013 [cited by applicant]
US 8776207B2 · Mihelich et al. · 2014 [cited by applicant]
US 8789135B1 · Pani · 2014 [cited by applicant]
US 8955107B2 · Eyada · 2015 [cited by applicant]
US 9240975B2 · Roberson · 2016 [cited by applicant]
US 9264402B2 · Anderson · 2016 [cited by applicant]
US 9286472B2 · Dalal et al. · 2016 [cited by applicant]
US 9769115B2 · Nantel · 2017 [cited by applicant]
US 9917928B2 · Pan · 2018 [cited by applicant]
US 10250466B2 · Pasupathy et al. · 2019 [cited by applicant]
US 10277506B2 · Timmons et al. · 2019 [cited by applicant]
US 10516568B2 · Jain et al. · 2019 [cited by applicant]
US 10841206B2 · Menon et al. · 2020 [cited by applicant]
US 20020016826A1 · Johansson et al. · 2002 [cited by applicant]
US 20050182968A1 · Izatt et al. · 2005 [cited by applicant]
US 20080271134A1 · Johnson et al. · 2008 [cited by applicant]
US 20090327514A1 · Foschiano · 2009 [cited by examiner]
US 20100180342A1 · An · 2010 [cited by applicant]
US 20100242093A1 · Zuk et al. · 2010 [cited by applicant]
US 20110075557A1 · Chowdhury · 2011 [cited by examiner]
US 20120250686A1 · Vincent · 2012 [cited by examiner]
US 20140086211A1 · Liu · 2014 [cited by examiner]
US 20140215560A1 · Roberson · 2014 [cited by examiner]
US 20140226474A1 · Janarthanan et al. · 2014 [cited by applicant]
US 20140325636A1 · Mihelich et al. · 2014 [cited by applicant]
US 20150019702A1 · Kancherla · 2015 [cited by applicant]
US 20150312142A1 · Barabash et al. · 2015 [cited by applicant]
US 20150341314A1 · Roberson et al. · 2015 [cited by applicant]
US 20160277293A1 · Lopez · 2016 [cited by applicant]
US 20170195255A1 · Pham et al. · 2017 [cited by applicant]
US 20180034734A1 · Yin · 2018 [cited by applicant]
EP 3342127B1 · 2021 [cited by applicant]
Fortinet Community: “Technical Tip: Factors for Hardware Acceleration (Offload to NPx) to Take Place”, FortiGate, https://community.fortinet.com/t5/FortiGate/Technical-Tip-Factors-for-Hardware-Acceleration-offload-to-NP… [cited by applicant]
Fortinet: “Fortinet Details Updates to Their Cybersecurity Operating System”, Fortinet, Press Releases, Jan. 28, 2016, https://www.fortinet.com/tw/corporate/about-us/newsroom/press-releases/2016/fortinet-details-updates… [cited by applicant]
Fortinet: “Offloading Flow-Based Content Inspection with NTurbo and IPSA”, RSSing, https://fortinet77.rssing.com/chan-56127603/article118.html, Apr. 12, 2016, 2 Pages. [cited by applicant]
Fortinetguru: “Chapter 12—Hardware Acceleration”, Tag Archives: Fortios 5.4.1 Release Notes, https://www.fortinetguru.com/tag/fortios-5-4-1-release-notes/page/2/, Jun. 9, 2016, 4 Pages. [cited by applicant]
Fortinetguru: “Configuring NP4 Traffic Offloading”, https://shorturl.at/FWjgu, Sep. 3, 2016, 3 Pages. [cited by applicant]
Fortinetguru: “Hardware Acceleration”, NP6 Diagnose Commands and Get Command Changes (288738), https://www.fortinetguru.com/2016/06/hardware-acceleration/, Jun. 12, 2016, 3 Pages. [cited by applicant]