IP Library › Granted Patent US 11,700,239
Granted Patent B2
US 11,700,239 · App. 17/544,756 · Granted Jul 11, 2023

Split tunneling based on content type to exclude certain network traffic from a tunnel

Inventors: Yongjie Yin (Fremont, CA); Joby Menon (Cupertino, CA); Andrey Tverdokhleb (Cupertino, CA); Kevin Yao (San Jose, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/029H04L63/0272H04L63/0428H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,700,239
App. No.
17/544,756
Filed
Dec 7, 2021
Granted
Jul 11, 2023
Kind
B2
Art Unit
2497
USPC
726/15
Abstract

Various techniques for split tunneling based on content type to exclude certain network traffic from a tunnel (e.g., VPN tunnel) are disclosed. In some embodiments, a system, process, and/or computer program product for split tunneling based on content type to exclude certain network traffic from a tunnel includes monitoring session traffic received at a data appliance; determining if the session traffic is associated with a first content type; and redirecting the session traffic if the session traffic is associated with the first content type based on a policy.

Claims (37)

1. A system, comprising:

a processor of a security platform configured to:

monitor session traffic received from a client at the security platform, wherein the session traffic is initially routed through a Virtual Private Network (VPN) tunnel, and wherein the session traffic is decrypted and decoded at the security platform;

determine, from the decrypted and decoded session traffic, that the session traffic is associated with a first content type, wherein the first content type includes video network, audio network traffic, or another content type that is configured for split tunneling based on a policy; and

send a special redirect response, the special redirect response utilizing a special port option or a TCP option, to re-route the session traffic from a virtual adapter associated with the VPN tunnel to a physical adapter outside of the VPN tunnel, if the session traffic is associated with the first content type to perform split tunneling based on the policy, wherein the split tunneling is based on different content types based on the policy to reduce bandwidth and computing resources used for performing security inspection of network traffic associated with video network traffic or audio network traffic, and wherein the session traffic is redirected outside of the VPN tunnel using an HTTP/HTTPS redirect request with the same destination as the client after determining that the session traffic is associated with the first content type; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system recited in claim 1 , wherein the security platform comprises a security appliance that includes a VPN client, and wherein the policy further comprises a security policy.

3. The system recited in claim 1 , wherein the security platform comprises a gateway that includes a VPN client, and wherein the policy further comprises a security policy.

4. The system recited in claim 1 , wherein the session traffic is initially routed through a tunnel.

5. The system recited in claim 1 , wherein the session traffic is initially routed through a tunnel, and the session traffic is redirected outside of the tunnel.

6. The system recited in claim 1 , wherein the session traffic is initially routed through a Virtual Private Network (VPN) tunnel.

7. The system recited in claim 1 , wherein the session traffic is initially routed through a Virtual Private Network (VPN) tunnel, and the session traffic is redirected outside of the VPN tunnel.

8. The system recited in claim 1 , wherein the session traffic is encrypted, and wherein the processor is further configured to:

decrypt the session traffic.

9. The system recited in claim 1 , wherein the session traffic is encrypted, and wherein the processor is further configured to:

decrypt the session traffic; and

decode the session traffic.

10. A method, comprising:

monitoring session traffic received from a client at a security platform, wherein the session traffic is initially routed through a Virtual Private Network (VPN) tunnel, and wherein the session traffic is decrypted and decoded at the security platform;

determining, from the decrypted and decoded session traffic, that the session traffic is associated with a first content type, wherein the first content type includes video network, audio network traffic, or another content type that is configured for split tunneling based on a policy; and

sending a special redirect response, the special redirect response utilizing a special port option or a TCP option, to re-route the session traffic from a virtual adapter associated with the VPN tunnel to a physical adapter outside of the VPN tunnel, if the session traffic is associated with the first content type to perform split tunneling based on the policy, wherein the split tunneling is based on different content types based on the policy to reduce bandwidth and computing resources used for performing security inspection of network traffic associated with video network traffic or audio network traffic, and wherein the session traffic is redirected outside of the VPN tunnel using an HTTP/HTTPS redirect request with the same destination as the client after determining that the session traffic is associated with the first content type.

11. The method of claim 10 , wherein the security platform comprises a security appliance that includes a VPN client, and wherein the policy further comprises a security policy.

12. The method of claim 10 , wherein the security platform comprises a gateway that includes a VPN client, and wherein the policy further comprises a security policy.

13. The method of claim 10 , wherein the session traffic is initially routed through a tunnel.

14. The method of claim 10 , wherein the session traffic is initially routed through a tunnel, and the session traffic is redirected outside of the tunnel.

15. The method of claim 10 , wherein the session traffic is initially routed through a Virtual Private Network (VPN) tunnel.

16. The method of claim 10 , wherein the session traffic is initially routed through a Virtual Private Network (VPN) tunnel, and the session traffic is redirected outside of the VPN tunnel.

17. The method of claim 10 , wherein the session traffic is encrypted, and further comprising:

decrypting the session traffic.

18. The method of claim 10 , wherein the session traffic is encrypted, and further comprising:

decrypting the session traffic; and

decoding the session traffic.

19. A computer program product, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for:

monitoring session traffic received from a client at a security platform, wherein the session traffic is initially routed through a Virtual Private Network (VPN) tunnel, and wherein the session traffic is decrypted and decoded at the security platform;

determining, from the decrypted and decoded session traffic, whether the session traffic is associated with a first content type, wherein the first content type includes video network, audio network traffic, or another content type that is configured for split tunneling based on a policy; and

sending a special redirect response, the special redirect response utilizing a special port option or a TCP option, to re-route the session traffic from a virtual adapter associated with the VPN tunnel to a physical adapter outside of the VPN tunnel, if the session traffic is associated with the first content type to perform split tunneling based on the policy, wherein the split tunneling is based on different content types based on the policy to reduce bandwidth and computing resources used for performing security inspection of network traffic associated with video network traffic or audio network traffic, and wherein the session traffic is redirected outside of the VPN tunnel using an HTTP/HTTPS redirect request with the same destination as the client after determining that the session traffic is associated with the first content type.

20. The computer program product recited in claim 19 , wherein the security platform comprises a security appliance that includes a VPN client, and wherein the policy further comprises a security policy.

Continuity (2)
Continuation 15967351 · Apr 30, 2018
Related Publication 20220103515A1 · Mar 31, 2022
Cited By (1)
US 12,438,847