IP Library › Granted Patent US 11,558,350
Granted Patent B2
US 11,558,350 · App. 17/120,047 · Granted Jan 17, 2023

Localization at scale for a cloud-based security service

Inventors: Thomas Arthur Warburton (San Jose, CA); Shu Lin (Saratoga, CA); Devendra Raut (Saratoga, CA); Jialiang Li (Sunnyvale, CA); Hao Long (Campbell, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/0236H04L63/029H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,558,350
App. No.
17/120,047
Granted
Jan 17, 2023
Kind
B2
Abstract

Techniques for providing localization at scale for a cloud-based security service are disclosed. In some embodiments, a system/method/computer program product for providing localization at scale for a cloud-based security service includes receiving a connection request at a network gateway of a cloud-based security service; performing a source Network Address Translation (NAT) from a registered set of public IP addresses associated with a tenant; and providing secure access to a Software as a Service (SaaS) using the cloud-based security service.

Claims (34)

1. A system comprising:

a processor configured to:

receive a connection request at a network gateway of a cloud-based security service;

perform a source Network Address Translation (NAT) from a registered set of public Internet Protocol (IP) addresses associated with a tenant, wherein an egress IP from the network gateway is associated with a region that corresponds to the region of a user that sent the connection request to facilitate an enhanced user experience of locality for a user of a Software as a Service (SaaS); and

provide secure access to a Software as a Service (SaaS) using the cloud-based security service, wherein the cloud-based security service maintains a set of IP address ranges for each of their supported regions to provide distinct public IP address pools for each customer of the cloud-based security service; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system recited in claim 1 , wherein a first customer configures a distinct security policy associated with the distinct public IP address pool associated with the first customer.

3. The system recited in claim 1 , wherein the cloud-based security service is provided using a public cloud service provider.

4. The system recited in claim 1 , wherein the cloud-based security service is provided using a plurality of public cloud service providers.

5. The system recited in claim 1 , wherein the cloud-based security service is provided using a public cloud service provider that provides high-speed network connectivity from each of the public cloud service provider's various regional cloud-based computing service data centers to one or more SaaS providers.

6. The system recited in claim 1 , wherein the network gateway enforces a security policy.

7. The system recited in claim 1 , wherein the network gateway comprises a virtual firewall.

8. The system recited in claim 1 , wherein the connection request is associated with a new session, and wherein the processor is further configured to:

determine a zone associated with the new session.

9. The system recited in claim 1 , wherein the connection request is associated with a new session, and wherein the processor is further configured to:

determine a zone associated with the new session based on a secure tunnel configuration associated with the connection request.

10. The system recited in claim 1 , wherein the connection request is associated with a new session, and wherein the processor is further configured to:

determine a zone associated with the new session based on a domain associated with the connection request.

11. A method of synchronizing a honey network configuration to reflect a target network environment, comprising:

receiving a connection request at a network gateway of a cloud-based security service;

performing a source Network Address Translation (NAT) from a registered set of public Internet Protocol (IP) addresses associated with a tenant, wherein an egress IP from the network gateway is associated with a region that corresponds to the region of a user that sent the connection request to facilitate an enhanced user experience of locality for a user of a Software as a Service (SaaS); and

providing secure access to a Software as a Service (SaaS) using the cloud-based security service, wherein the cloud-based security service maintains a set of IP address ranges for each of their supported regions to provide distinct public IP address pools for each customer of the cloud-based security service.

12. The method of claim 11 , wherein a first customer configures a distinct security policy associated with the distinct public IP address pool associated with the first customer.

13. The method of claim 11 , wherein the cloud-based security service is provided using a public cloud service provider.

14. The method of claim 11 , wherein the cloud-based security service is provided using a plurality of public cloud service providers.

15. The method of claim 11 , wherein the cloud-based security service is provided using a public cloud service provider that provides high-speed network connectivity from each of the public cloud service provider's various regional cloud-based computing service data centers to one or more SaaS providers.

16. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving a connection request at a network gateway of a cloud-based security service;

performing a source Network Address Translation (NAT) from a registered set of public Internet Protocol (IP) addresses associated with a tenant, wherein an egress IP from the network gateway is associated with a region that corresponds to the region of a user that sent the connection request to facilitate an enhanced user experience of locality for a user of a Software as a Service (SaaS); and

providing secure access to a Software as a Service (SaaS) using the cloud-based security service, wherein the cloud-based security service maintains a set of IP address ranges for each of their supported regions to provide distinct public IP address pools for each customer of the cloud-based security service.

17. The computer program product recited in claim 16 , wherein a first customer configures a distinct security policy associated with the distinct public IP address pool associated with the first customer.

18. The computer program product recited in claim 16 , wherein the cloud-based security service is provided using a public cloud service provider.

19. The computer program product recited in claim 16 , wherein the cloud-based security service is provided using a plurality of public cloud service providers.

20. The computer program product recited in claim 16 , wherein the cloud-based security service is provided using a public cloud service provider that provides high-speed network connectivity from each of the public cloud service provider's various regional cloud-based computing service data centers to one or more SaaS providers.

Continuity (2)
Continuation 16985050 · Aug 4, 2020
Related Publication 20220045987A1 · Feb 10, 2022