IP Library Granted Patent US 8,849,988
Granted Patent B2
US 8,849,988 · App. 12/625,010 · Granted Sep 30, 2014

Systems and methods to monitor an access gateway

Inventors: Rishi Mutnuru (Santa Clara, CA); Josephine Suganthi (Sunnyvale, CA); Praveen Grover (Santa Clara, CA)
Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,849,988
App. No.
12/625,010
Granted
Sep 30, 2014
Kind
B2
Abstract

The present invention is directed towards systems and methods for monitoring an access gateway. The systems and methods include monitors on appliances that generate and send requests to logon agents or login page services on access gateways. Based on the responses from the logon agents or login page services, the monitors determine whether the logon agents or login page services are available.

Claims (34)

1. A method for monitoring by an intermediary device a status of a login page service of an access gateway to a plurality of remote access servers, the method comprising:

(a) generating, by a monitor of an intermediary device between a plurality of a clients and an access gateway to a plurality of remote access servers, a first request to access a login page service of the access gateway, the login page service providing a login page hosted by the access gateway;

(b) transmitting, by the intermediary device, the generated first request to the login page service of the access gateway;

(c) determining, by the monitor, that both a first response from the login page service to the first request identifies a successful response and that a body of the first response comprises at least one predetermined field name of a plurality of predetermined hidden fields within non-header application layer content of a web-based form, identified by a predetermined form name, of the login page provided by the login page service, the first response comprising Hypertext Transfer Protocol (HTTP) content;

(d) identifying, by the monitor, a status of the login page service as available responsive to the determination of step (c);

(e) transmitting, by the intermediary device, a generated second request to the login page service of the access gateway;

(f) determining, by the monitor, that a second response from the login page service to the second request is successful and a body of the second response does not identify at least one predetermined field name of the plurality of predetermined hidden fields within non-header application layer content of the web-based form identified by the predetermined form name, the first second comprising Hypertext Transfer Protocol (HTTP) content; and

(g) identifying, by the monitor, the status of the login page service as unavailable responsive to the determination of step (f).

2. The method of claim 1 , wherein step (a) further comprises generating, by the monitor, for the first request a HyperText Transfer Protocol GET request of a logon point provided by the login page service.

3. The method of claim 2 , wherein step (a) further comprises specifying, by the monitor, the logon point in the generated first request based on a configuration setting of the intermediary service.

4. The method of claim 1 , wherein step (a) further comprises generating, by the monitor, the first request to include user agent information.

5. The method of claim 1 , wherein step (a) further comprises generating, by the monitor, the first request to include an IP address hosted by the intermediary device.

6. The method of claim 1 , wherein step (b) further comprises transmitting by the intermediary device the first generated request at a predetermined frequency.

7. The method of claim 1 , wherein step (d) further comprises transmitting by the intermediary device the second generated request at a predetermined frequency.

8. The method of claim 1 , wherein step (c) further comprises determining that the body of the first response comprises the predetermined field name for the predetermined hidden field of application layer content of the web-based form of the predetermined form name, the predetermined field identifying a name of a server farm.

9. The method of claim 1 , wherein step (f) further comprises determining that the second response does not include any of the plurality of predetermined hidden fields.

10. The method of claim 1 , wherein step (f) further comprises determining that the second response does not include a selected predetermined hidden field of the plurality of predetermined hidden fields, the selected predetermined hidden field selected via configuration of the monitor of the intermediary device.

11. A method for monitoring by an intermediary device a status of a login agent of an access gateway to a plurality of remote access servers, the method comprising:

(a) generating, by a monitor of an intermediary device between a plurality of a clients and an access gateway to a plurality of remote access servers, a first post request to a logon agent of the access gateway, the first post request identifying a logon point and a version of the logon agent, the logon agent providing the logon point, the logon point defines a logon page hosted by the access gateway and specifies settings for user sessions via the logon page;

(b) transmitting, by the intermediary device, the generated first post request to the login agent of the access gateway, the generated first post request requesting to begin a logon sequence;

(c) determining, by the monitor, that both a first response from the logon agent to the first request is successful and that a non-header application layer body of the first response includes a predetermined string with a predetermined prefix and identifying to begin the logon sequence, the first response comprising Hypertext Transfer Protocol (HTTP) content;

(d) identifying, by the monitor, a status of the logon agent as available responsive to the determination of step (c);

(e) transmitting, by the intermediary device, a generated second post request to the logon agent of the access gateway;

(f) determining, by the monitor, that a second response from the logon agent to the second request is successful and a non-header application layer body of the second response does not include the predetermined string with the predetermined prefix that identifies to begin the logon sequence, the second response comprising Hypertext Transfer Protocol (HTTP) content; and

(g) identifying, by the monitor, the status of the logon agent as unavailable responsive to the determination of step (f).

12. The method of claim 11 , wherein step (a) further comprises generating, by the monitor, for the first request a HyperText Transfer Protocol PUSH request to the identified logon point.

13. The method of claim 12 , wherein step (a) further comprises specifying, by the monitor, the logon point in the generated first push request based on a configuration setting of the intermediary service.

14. The method of claim 11 , wherein step (a) further comprises generating, by the monitor, the first request to identify a MAC address of the intermediary device.

15. The method of claim 11 , wherein step (a) further comprises generating, by the monitor, the first request to identify a source IP address routable to the intermediary device.

16. The method of claim 11 , wherein step (b) further comprises transmitting by the intermediary device the first push request at a predetermined frequency.

17. The method of claim 11 , wherein step (d) further comprises transmitting by the intermediary device the second push request at a predetermined frequency.

18. The method of claim 11 , wherein step (c) further comprises determining that the first response includes a string within XML formatted values indicating the response was successful.

19. The method of claim 11 , wherein step (c) further comprising determining that the predetermined string has a predetermined prefix of “_CTX”, the predetermined string carried in the non-header application layer body of the first response comprising Hypertext Transfer Protocol (HTTP) content that does not include an HTTP header.

20. The method of claim 11 , wherein step (f) further comprises determining that the second response does not include a string within XML formatted values indicating the response was successful.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2018
From: MUTNURU, RISHI; SUGANTHI, JOSEPHINE; GROVER, PRAVEEN
To: CITRIX SYSTEMS, INC.
Reel/Frame 045458/0439 →
Continuity (2)
Provisional Application 61117885 · Nov 25, 2008
Related Publication 20100138534A1 · Jun 3, 2010