IP Library › Granted Patent US 8,654,659
Granted Patent B2
US 8,654,659 · App. 12/645,889 · Granted Feb 18, 2014

Systems and methods for listening policies for virtual servers of appliance

Inventors: Dinesh Gandhewar (Bangalore, IN); Josephine Suganthi (Santa Clara, CA)
Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,654,659
App. No.
12/645,889
Filed
Dec 23, 2009
Granted
Feb 18, 2014
Kind
B2
Art Unit
2474
USPC
370/252
Abstract

The present invention is directed towards a method for using a listening policy for a virtual server on an intermediary device. An intermediary device establishes for a first virtual server a first listening policy with an expression for evaluating packets received by the intermediary device to determine whether the packet may access the first virtual server. The intermediary device listens for packets at a first internet protocol (IP) address and a first port specified for the first virtual server. Then, the intermediary device evaluates the expression of the first listening policy to a first packet received at the first IP address and first port and determines whether to provide the first packet to the first virtual server based on a result of the evaluation.

Claims (26)

1. A method of using a listening policy for a virtual server on an intermediary device, the method comprising:

(a) establishing for a first virtual server executing on an intermediary device deployed between a plurality of clients and one or more servers, a first listen policy, the first listen policy comprising an expression for evaluating packets received by the intermediary device to determine whether the packets may access the first virtual server;

(b) listening, by a packet engine of the intermediary device for a plurality of packets to be received at a network interface card of the intermediary device at a first internet protocol (IP) address and a first port specified for the first virtual server;

(c) evaluating, by a policy engine of the intermediary device, the expression of the first listen policy of the first virtual server and a second listen policy of a second virtual server to a first packet of the plurality of packets received by the packet engine at the first IP address and the first port; and

(d) determining, by the intermediary device responsive to the first packet matching both the first listen policy and the second listen policy, whether to provide the first packet received by the packet engine to the first virtual server or the second virtual server based on a result of the evaluation.

2. The method of claim 1 , wherein step (a) further comprises establishing for the first virtual server the listen policy comprising the expression to compare a virtual local area network (VLAN) identifier of the first packet to a predetermined value.

3. The method of claim 1 , wherein step (c) further comprises evaluating a VLAN identifier of the first packet and wherein step (d) further comprises determining to provide the first packet to the first virtual server if the VLAN identifier of the first packet matches a predetermined value.

4. The method of claim 1 , wherein step (a) further comprises establishing the listen policy comprising the expression to compare an interface identifier of the first packet to a predetermined value.

5. The method of claim 1 , wherein step (c) further comprises evaluating a interface identifier of the first packet and wherein step (d) further comprises determining to provide the first packet to the first virtual server if the interface identifier of the first packet matches a predetermined value.

6. The method of claim 1 , wherein step (b) further comprises listening, by the intermediary device for packets for a service type specified for the first virtual server.

7. The method of claim 1 , wherein step (a) further comprises establishing the first listening priority for the first virtual server and establishing the second listening policy and a second listening priority for a second virtual server executing on the intermediary device.

8. The method of claim 7 , wherein step (b) further comprises listening by the intermediary device on the first IP address and the first port specified for both the first virtual server and the second virtual server.

9. The method of claim 7 , wherein step (d) further comprises determining to forward the first packet to the second virtual server instead of the first virtual server based on a comparison of the second listening priority to the first listening priority.

10. A system of using a listening policy for a virtual server on an intermediary device, the system comprising:

a first virtual server executing on an intermediary device deployed between a plurality of clients and one or more servers, the first virtual server configured to have a first listen policy, the first listen policy comprising an expression for evaluating packets received by the intermediary device to determine whether the packets may access the first virtual server;

a packet engine of the intermediary device listening for a plurality of packets to be received at a network interface card of the intermediary device at a first internet protocol (IP) address and a first port specified for the first virtual server;

a policy engine of the intermediary device evaluating the expression of the first listen policy of the first virtual server and a second listen policy of a second virtual server to a first packet of the plurality of packets received by the packet engine at the first IP address and the first port; and

wherein the intermediary device determines responsive to the first packet matching both the first listen policy and the second listen policy, whether to provide the first packet received by the packet engine to the first virtual server or the second virtual server based on a result of the evaluation.

11. The system of claim 10 , wherein the listen policy comprises the expression to compare a virtual local area network (VLAN) identifier of the first packet to a predetermined value.

12. The system of claim 11 , wherein the packet engine evaluates the VLAN identifier of the first packet and determines to provide the first packet to the first virtual server if the VLAN identifier of the first packet matches the predetermined value.

13. The system of claim 10 , wherein the listen policy comprises the expression to compare an interface identifier of the first packet to a predetermined value.

14. The system of claim 13 , wherein the packet engine evaluates the interface identifier of the first packet and determines to provide the first packet to the first virtual server if an interface identifier of the first packet matches the predetermined value.

15. The system of claim 10 , wherein the packet engine listens for packets for a service type specified for the first virtual server.

16. The system of claim 10 , wherein the intermediary device establishes the first listening priority for the first virtual server and establishes a second listening policy and the second listening priority for a second virtual server.

17. The system of claim 16 , wherein the packet engine listens on the first IP address and the first port specified for both the first virtual server and the second virtual server.

18. The system of claim 16 , wherein the intermediary device determines to forward the first packet to the second virtual server instead of the first virtual server based on a comparison of the second listening priority to the first listening priority.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2010
From: GANDHEWAR, DINESH; SUGANTHI, JOSEPHINE
To: CITRIX SYSTEMS, INC.
Reel/Frame 024050/0523 →
Continuity (1)
Related Publication 20110149755A1 · Jun 23, 2011