IP Library Granted Patent US 11,240,208
Granted Patent B2
US 11,240,208 · App. 15/967,351 · Granted Feb 1, 2022

Split tunneling based on content type to exclude certain network traffic from a tunnel

Inventors: Yongjie Yin (Fremont, CA); Joby Menon (Cupertino, CA); Andrey Tverdokhleb (Cupertino, CA); Kevin Yao (San Jose, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/029H04L63/0272H04L63/0428H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,240,208
App. No.
15/967,351
Granted
Feb 1, 2022
Kind
B2
Abstract

Various techniques for split tunneling based on content type are disclosed. In some embodiments, a system, process, and/or computer program product for split tunneling based on content type includes monitoring session traffic received at a data appliance; determining if the session traffic is associated with a first content type; and redirecting the session traffic if the session traffic is associated with the first content type based on a policy.

Claims (39)

1. A system for performing split tunneling based on content type, comprising:

a physical adapter;

a Virtual Private Network (VPN) with a virtual adapter;

a processor of a security platform configured to:

monitor session traffic received from a client at the security platform, wherein the session traffic is initially routed through a Virtual Private Network (VPN) tunnel, and wherein the session traffic is decrypted and decoded at the security platform;

determine, from the decrypted and decoded session traffic, if the session traffic is associated with a first content type, wherein the first content type includes video network or audio network traffic; and

send a special redirect response, the special redirect response utilizing a special port option or a TCP option, to re-route the session traffic from the virtual adapter of the VPN tunnel to the physical adapter outside of the VPN tunnel, if the session traffic is associated with the first content type based on a security policy, wherein the session traffic redirect is based on the security policy to perform split tunneling, wherein the split tunneling is based on different content types based on the security policy to reduce bandwidth and computing resources used for performing security inspection of network traffic associated with video network traffic or audio network traffic, and wherein the session traffic is redirected outside of the VPN tunnel using an HTTP/HTTPS redirect request with the same destination as the client after determining that the session traffic is associated with the first content type; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system recited in claim 1 , wherein the security platform comprises a security appliance that includes a VPN client.

3. The system recited in claim 1 , wherein the security platform comprises a gateway that includes a VPN client.

4. The system recited in claim 1 , wherein the session traffic is initially routed through a tunnel.

5. The system recited in claim 1 , wherein the session traffic is initially routed through a tunnel, and the session traffic is redirected outside of the tunnel.

6. The system recited in claim 1 , wherein the first content type comprises an approved audio traffic content type that is configured in the security policy.

7. The system recited in claim 1 , wherein the first content type comprises an approved video content type that is configured in the security policy.

8. The system recited in claim 1 , wherein the session traffic is encrypted, and wherein the processor is further configured to:

decrypt the session traffic.

9. The system recited in claim 1 , wherein the session traffic is encrypted, and wherein the processor is further configured to:

decrypt the session traffic; and

decode the session traffic.

10. A method for performing split tunneling based on content type, comprising:

monitoring session traffic received from a client at a security platform, wherein the session traffic is initially routed through a Virtual Private Network (VPN) tunnel, and wherein the session traffic is decrypted and decoded at the security platform;

determining, from the decrypted and decoded session traffic, if the session traffic is associated with a first content type, wherein the first content type includes video network or audio network traffic; and

send a special redirect response, the special redirect response utilizing a special port option or a TCP option, to re-route the session traffic from a virtual adapter of the VPN tunnel to a physical adapter outside of the VPN tunnel, if the session traffic is associated with the first content type based on a security policy, wherein the session traffic redirect is based on the security policy to perform split tunneling, wherein the split tunneling is based on different content types based on the security policy to reduce bandwidth and computing resources used for performing security inspection of network traffic associated with video network traffic or audio network traffic, and wherein the session traffic is redirected outside of the VPN tunnel using an HTTP/HTTPS redirect request with the same destination as the client after determining that the session traffic is associated with the first content type.

11. The method of claim 10 , wherein the security platform comprises a security appliance that includes a VPN client.

12. The method of claim 10 , wherein the security platform comprises a gateway that includes a VPN client.

13. The method of claim 10 , wherein the session traffic is initially routed through a tunnel.

14. The method of claim 10 , wherein the session traffic is initially routed through a tunnel, and the session traffic is redirected outside of the tunnel.

15. The method of claim 10 , wherein the first content type comprises an approved audio traffic content type that is configured in the security policy.

16. The method of claim 10 , wherein the first content type comprises an approved video content type that is configured in the security policy.

17. The method of claim 10 , wherein the session traffic is encrypted, and further comprising:

decrypting the session traffic.

18. The method of claim 10 , wherein the session traffic is encrypted, and further comprising:

decrypting the session traffic; and

decoding the session traffic.

19. A computer program product for performing split tunneling based on content type, the computer program product being embodied in a non-transitory, tangible computer readable storage medium and comprising computer instructions for:

monitoring session traffic received from a client at a security platform, wherein the session traffic is initially routed through a Virtual Private Network (VPN) tunnel, and wherein the session traffic is decrypted and decoded at the security platform;

determining, from the decrypted and decoded session traffic, if the session traffic is associated with a first content type, wherein the first content type includes video network or audio network traffic; and

send a special redirect response, the special redirect response utilizing a special port option or a TCP option, to re-route the session traffic from a virtual adapter of the VPN tunnel to a physical adapter outside of the VPN tunnel, if the session traffic is associated with the first content type based on a security policy, wherein the session traffic redirect is based on the security policy to perform split tunneling, wherein the split tunneling is based on different content types based on the security policy to reduce bandwidth and computing resources used for performing security inspection of network traffic associated with video network traffic or audio network traffic, and wherein the session traffic is redirected outside of the VPN tunnel using an HTTP/HTTPS redirect request with the same destination as the client after determining that the session traffic is associated with the first content type.

20. The computer program product recited in claim 19 , wherein the security platform comprises a security appliance that includes a VPN client.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2018
From: YIN, YONGJIE; MENON, JOBY; TVERDOKHLEB, ANDREY; YAO, KEVIN
To: PALO ALTO NETWORKS, INC.
Reel/Frame 046503/0529 →
Continuity (1)
Related Publication 20190334864A1 · Oct 31, 2019
Cited By (1)
US 12,255,873