IP Library Granted Patent US 11,153,280
Granted Patent B1
US 11,153,280 · App. 16/916,092 · Granted Oct 19, 2021

True transparent proxy to support multiple HTTP/S web applications on same IP and port on a data communication network

Inventor: Radhesh Ramakant Walwadkar (Pune, IN)
Assignee: Fortinet, Inc.
H04L63/0281H04L63/0236H04L63/166H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,153,280
App. No.
16/916,092
Granted
Oct 19, 2021
Kind
B1
Abstract

A true transparent proxy for a web application firewall is provided. Granular network security policies are applied on a per web application basis using unique SSL inspection certificates for web applications sharing a common IP address.

Claims (25)

1. A computer-implemented method in a web application firewall (WAF) of a data communication network, at least partially implemented in hardware and coupled to a data communication network, for providing true transparent proxy to multiple web sites, the method comprising:

publishing, by a processor of the WAF, each of a plurality of real servers on a fully qualified domain name (FQDN), associated with a COMMON domain name Internet protocol (IP) address and each FQDN protecting a web-based application running on the FQDN;

assigning and storing, by a memory element of the WAF, a secure socket layer (SSL) inspection certificate to each of the FQDN real servers;

receiving, at a network communication interface of an access point (AP) coupled to the data communication network, network traffic at a single IP address on the data communication network, the network traffic having multiple web site destinations for web-based applications;

responsive to the received network traffic, retrieving an SSL inspection certificate for each of the FQDN real servers associated with the multiple web site destinations; and

forwarding the network traffic securely to the web site destinations;

wherein each SSL inspection certificate has a separate network security policy corresponding to a specific web-based application;

wherein the received network traffic is sourced from a firewall between the WAF and the data communication network and destined to the plurality of web-based applications.

2. The method of claim 1 , wherein the network traffic uses the HTTPS (hypertext protocol secure) standard.

3. A non-transitory computer-readable medium storing instructions that, when executed by a processor, perform a computer-implemented method in a web application firewall (WAF) of a data communication network and coupled to a wireless network, for providing true transparent proxy to multiple web sites, the method comprising:

publishing, by a processor of the WAF, each of a plurality of real servers on a fully qualified domain name (FQDN), associated with a domain name Internet protocol (IP) address and each FQDN protecting a web-based application running on the FQDN;

assigning and storing, by a memory element of the WAF a secure socket layer (SSL) inspection certificate to each of the FQDN real servers;

receiving, at a network communication interface of an access point (AP) coupled to the data communication network, network traffic at a single IP address on the data communication network, the network traffic having multiple web site destinations for web-based applications;

responsive to the received network traffic, retrieving an SSL inspection certificate for each of the FQDN real servers associated with the multiple web site destinations; and

forwarding the network traffic securely to the web site destinations;

wherein each SSL inspection certificate has a separate network security policy corresponding to a specific web-based application;

wherein the received network traffic is sourced from a firewall between the WAF and the data communication network and destined to the plurality of web-based applications.

4. A web application firewall (WAF) system of a data communication network, at least partially implemented in hardware and coupled to a data communication network, for providing true transparent proxy to multiple web sites, the system comprising:

a secure socket layer (SSL) module to publish each of a plurality of real servers on a fully qualified domain name (FQDN), associated with a domain name Internet protocol (IP) address and each FQDN protecting a web-based application running on the FQDN;

a memory element of the WAF system to assign and store a secure socket layer (SSL) inspection certificate to each of the FQDN real servers;

a network communication interface of the WAF system, coupled to the data communication network, to receive network traffic at a single IP address on the data communication network, the network traffic having multiple web site destinations for web-based applications; and

the SSL module to retrieve an SSL inspection certificate for each of the FQDN real servers associated with the multiple web site destinations,

wherein the network communication interface forwards the network traffic securely to the web site destinations;

wherein each SSL inspection certificate has a separate network security policy corresponding to a specific web-based application;

wherein the received network traffic is sourced from a firewall between the WAF and the data communication network and destined to the plurality of web-based applications.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2020
From: WALWADKAR, RADHESH RAMAKANT
To: FORTINET, INC.
Reel/Frame 053104/0786 →
Cited By (7)
US 12,481,978 US 12,488,321 US 12,518,257 US 12,549,391 US 12,562,889 US 12,568,152 US 12,683,934