IP Library Granted Patent US 9,100,449
Granted Patent B2
US 9,100,449 · App. 13/186,350 · Granted Aug 4, 2015

Virtual inline configuration for a network device

Inventors: Haseeb Budhani (Fremont, CA); Paul G. Sutter (San Francisco, CA)
Assignee: CITRIX SYSTEMS, INC.
H04L67/2814H04L12/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,100,449
App. No.
13/186,350
Granted
Aug 4, 2015
Kind
B2
Abstract

A performance enhancing proxy network device is configured to operate in a virtual inline mode, in which selected network traffic is redirected to and through the network device by a router using simple routing policies. In this way, the network device can be coupled to the router in series but can still operate as if it were physically connected inline.

Claims (31)

1. A method for processing a packet, destined to a computing device, via a network device coupled in parallel to a router, the method comprising:

receiving, by a network device having a first internet protocol (IP) address and coupled to a plurality of routers, a packet from a first router of the plurality of routers, the packet having a second destination IP address of an intended destination computing device;

identifying, by the network device, the first router of the plurality of routers as the router that diverted the packet to the network device;

preserving, by the network device, the identification of the first router of the plurality of routers as the router that diverted the packet to the network device;

processing, by the network device, the packet while preserving the second destination IP address of the packet to specify the intended destination computing device; and

transmitting, by the network device, the processed packet to the first router for transmission to the intended destination computing device, based on the preserved identification of the first router of the plurality of routers as the router that diverted the packet to the network device, the processed packet transmitted with the second destination internet protocol (IP) address of the intended destination computing device.

2. The method of claim 1 , further comprising receiving, by the network device, the packet having the second destination IP address diverted by the first router via Internet Protocol (IP) layer routing without the first router replacing the second destination IP address of the packet with the first IP address of the network device.

3. The method of claim 2 , further comprising diverting, by the first router, the packet according to the second destination IP address of the packet matching a policy based IP routing rule of a set of IP routing rules instead of changing the second destination IP address of the packet to the first IP address of the network device.

4. The method of claim 1 , further comprising sending, by the first router, the processed packet to the computing device identified by the second destination IP address.

5. The method of claim 1 , wherein preserving the identification of the first router further comprises preserving, by the network device, the selection of the first router from load balancing applied to the plurality of routers.

6. The method of claim 1 , further comprising processing, by the network device, the packet by transforming the packet.

7. The method of claim 1 , further comprising processing, by the network device, the packet by compressing the packet.

8. The method of claim 1 , further comprising receiving, by the network device, the packet diverted by the first router based on one or more of the following: direction, subnet or service.

9. The method of claim 1 , wherein the packet is diverted to the network device without the first router changing the destination address of the packet from the second IP address of the intended destination computing device.

10. The method of claim 1 , wherein the network device does not change the second destination IP address of the received packet before transmitting the processed packet to the first router.

11. The method of claim 1 , wherein receiving the packet from the first router further comprises receiving the packet from the first router as a next hop from the router to the computing device.

12. The method of claim 1 , wherein the network device is deployed in a virtual inline configuration.

13. A system for processing a packet, destined to a computing device, via a network device coupled in parallel to a router, the system comprising:

a network device having a first internet protocol (IP) address, coupled to a plurality of routers, the network device receiving a packet from a first router of the plurality of routers, the packet having a second destination internet protocol (IP) address of an intended destination computing device; and

wherein the network device

identifies the first router of the plurality of routers as the router that diverted the packet to the network device,

preserves the identification of the first router of the plurality of routers as the router that diverted the packet to the network device,

processes the packet while preserving the second destination IP address of the packet to specify the intended destination computing device, and

transmits the processed packet to the first router for transmission to the intended destination computing device based on the preserved identification of the first router of the plurality of routers as the router that diverted the packet to the network device, the processed packet transmitted with the second destination internet protocol (IP) address of the intended destination computing device.

14. The system of claim 13 , wherein the network device receives the packet having the second destination IP address diverted by the first router via Internet Protocol (IP) layer routing without the first router replacing the second destination IP address of the packet with the first IP address of the network device.

15. The system of claim 14 , wherein the first router diverts the packet according to the second destination IP address of the packet matching a policy based IP routing rule of a set of IP routing rules instead of changing the second destination IP address of the packet to the first IP address of the network device.

16. The system of claim 13 , wherein the first router transmits the processed packet to the computing device identified by the second destination IP address.

17. The system of claim 13 , wherein the network device preserves the identification of selection of the first router from load balancing applied to the plurality of routers.

18. The system of claim 13 , wherein the network device processes the packet by transforming the packet.

19. The system of claim 13 , wherein the network device processes the packet by compressing the packet.

20. The system of claim 13 , wherein the network device receives the packet diverted by the first router based on one or more of the following: direction, subnet or service.

Assignments (10)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Dec 15, 2011
From: ORBITAL DATA CORPORATION
To: CITRIX SYSTEMS, INC.
Reel/Frame 027392/0357 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2011
From: BUDHANI, HASEEB; SUTTER, PAUL
To: ORBITAL DATA CORPORATION
Reel/Frame 027101/0064 →
Continuity (2)
Continuation 11380004 · Apr 25, 2006
Related Publication 20120093156A1 · Apr 19, 2012