IP Library Granted Patent US 12,224,980
Granted Patent B2
US 12,224,980 · App. 18/756,295 · Granted Feb 11, 2025

Systems and methods for dynamic firewall policy configuration

Inventors: Jin-Gen Wang (Lafayette, CO); Travis D. Ewert (Highlands Ranch, CO)
Assignee: Level 3 Communications, LLC
H04L63/0227H04L41/0869H04L41/0886H04L41/0893H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,224,980
App. No.
18/756,295
Granted
Feb 11, 2025
Kind
B2
Abstract

Systems and methods for receiving information on network firewall policy configurations are disclosed. Based on the received firewall configuration information, a configuration of a firewall and/or subnet of network devices is automatically provisioned and/or configured to control network traffic to and from the subnet.

Claims (35)

1. A method for firewall configuration comprising:

receiving, at a processing device, input defining a firewall policy for a firewall managing access to a subnet of network components deployed within a communications network, the firewall policy including a firewall configuration for the firewall and a network component configuration for a network component of the subnet of network components;

executing, using the processing device and a virtual network component, first instructions associated with the firewall configuration;

executing, using the processing device and the virtual network component, second instructions associated with the network component configuration;

determining, based on the execution of the first instructions, that the firewall configuration is valid;

determining, based on the execution of the second instructions, that the network component configuration is valid;

automatically configuring, using the processing device, the firewall configuration at the firewall and the network component configuration at the network component in response to determining that the firewall configuration and the network component configuration are valid; and

activating, using the processing device, the firewall within the communications network to manage traffic to and from the subnet.

2. The method of claim 1 , wherein the virtual network component is a replica of the network component.

3. The method of claim 1 , wherein the firewall policy is implemented at the firewall and the network component for a finite period of time associated with a user request.

4. The method of claim 1 , wherein the firewall policy is implemented at the firewall and the network component at a time associated with a user request.

5. A system for firewall configuration comprising:

a subnet of network components deployed within a communications network, the subnet accessible through a firewall;

at least one processor; and

non-transient computer-readable media communicably coupled to the at least one processor having instructions stored thereon that, when executed by the at least one processor, cause the at least one processor to:

receive input defining a firewall policy for a firewall managing access to a subnet of network components deployed within a communications network, the firewall policy including a firewall configuration for the firewall and a network component configuration for a network component of the subnet of network components;

execute, using a virtual network component, first instructions associated with the firewall configuration;

execute, using the virtual network component, second instructions associated with the network component configuration;

determine, based on the execution of the first instructions, that the firewall configuration is valid;

determine, based on the execution of the second instructions, that the network component configuration is valid;

automatically configure the firewall configuration at the firewall and the network component configuration at the network component in response to determining that the firewall configuration and the network component configuration are logically valid; and

activate the firewall within the communications network to manage traffic to and from the subnet.

6. The system of claim 5 , wherein the virtual network component is a replica of the network component.

7. The system of claim 5 , wherein the firewall policy is implemented at the firewall and the network component for a finite period of time associated with a user request.

8. The system of claim 5 , wherein the firewall policy is implemented at the firewall and the network component at a time associated with a user request.

9. A non-transitory computer-readable medium for firewall configuration including instructions, executable by a processor, the instructions comprising:

receiving input defining a firewall policy for a firewall managing access to a subnet of network components deployed within a communications network, the firewall policy including a firewall configuration for the firewall and a network component configuration for a network component of the subnet of network components;

executing, using a virtual network component, first instructions associated with the firewall configuration;

executing, using the virtual network component, second instructions associated with the network component configuration;

determining, based on the execution of the first instructions, that the firewall configuration is valid;

determining, based on the execution of the second instructions, that the network component configuration is valid;

automatically configuring the firewall configuration at the firewall and the network component configuration at the network component in response to determining that the firewall configuration and the network component configuration are logically valid; and

activating the firewall within the communications network to manage traffic to and from the subnet.

10. The non-transitory computer-readable medium of claim 9 , wherein the virtual network component is a replica of the network component.

11. The non-transitory computer-readable medium of claim 9 , wherein the firewall policy is implemented at the firewall and the network component for a finite period of time associated with a user request.

Assignments (3)
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (SECOND LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0749 →
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (FIRST LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0858 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 5, 2024
From: WANG, JIN-GEN; EWERT, TRAVIS D.
To: LEVEL 3 COMMUNICATIONS, LLC
Reel/Frame 067917/0131 →