Controlling wi-fi traffic from network applications with centralized firewall rules implemented at the edge of a data communication network
Application data collected by an IDS (intrusion detection system) on the data communication network and concerning applications executing on stations coupled to the plurality of access points, is received. Additionally, firewall rules for applications from a firewall device coupled to the data communication network and providing firewall services to the plurality of access points, including outbound traffic from the plurality of access points, are received. The firewall rules can be parsed to expose configured actions for applications. A customized application control policy is prepared for each particular application for implementation on the network edge by at least one of the plurality of access points.
1. A computer-implemented method, in a Wi-Fi controller on a data communication network, for improving computer network security by implementing security policies of a firewall device locally at a plurality of access points, the method comprising the steps of:
receiving application data collected by an IDS (intrusion detection system) on the data communication network and concerning a plurality of applications executing on each station coupled to the plurality of access points;
receiving firewall rules for the plurality of applications from a firewall device coupled to the data communication network and providing firewall services to the plurality of access points, including outbound traffic from the plurality of access points;
parsing the firewall rules to expose configured actions for the plurality of applications;
preparing a customized application control policy for each particular application for implementation by at least one of the plurality of access points, wherein the customized application policy concerns how the at least one access point prioritizes network traffic for DPI (deep packet inspection) for data packets for a specific application of the plurality of applications of a station based on the firewall rules and application data for the specific application; and
distributing customized application control policies to the plurality access points based on application traffic handled by each access point.
2. The method of claim 1 , further wherein the configured actions comprise one or more of monitor, block, and quarantine.
3. The method of claim 1 , further comprising:
receiving application information from an IPS (intrusion prevention system), the application information comprising at least one of application risk and application popularity.
4. The method of claim 1 , wherein the access point applies the firewall rules against a data packet, and responsive to the firewall rules, drops the data packet before reaching the firewall device.
5. The method of claim 1 , wherein the network applications is categorized as either high risk or low risk, wherein data packets from high risk applications are prioritized for processing over data packets from low risk applications.
6. The method of claim 1 , further comprising:
updating the firewall rules for applications and updating customized application control polices that are affected.
7. The method of claim 1 , further comprising:
providing less AirTime in a packet prioritization scheme for high risk applications relative to low risk applications.
8. The method of claim 1 , further comprising:
dropping one or more packets at the access point based on firewall rules.
9. The method of claim 1 , further comprising:
dropping one or more packets at the Wi-Fi controller based on firewall rules.
10. The method of claim 1 , further comprising:
dropping one or more packets based on an application generating the traffic.
11. A non-transitory computer-readable medium storing source code that, when executed by a processor, performs a computer-implemented method, in a Wi-Fi controller on a data communication network and implemented at least partially in hardware, for improving computer network security by implementing security policies of a firewall device locally at a plurality of access points, the method comprising the steps of:
receiving application data collected by an IDS (intrusion detection system) on the data communication network and concerning a plurality of applications executing on each station coupled to the plurality of access points;
receiving firewall rules for the plurality of applications from a firewall device coupled to the data communication network and providing firewall services to the plurality of access points, including outbound traffic from the plurality of access points;
parsing the firewall rules to expose configured actions for the plurality of applications;
preparing a customized application control policy for each particular application for implementation by at least one of the plurality of access points, wherein the customized application policy concerns how the at least one access point prioritizes network traffic for DPI (deep packet inspection) for data packets for a specific application of the plurality of applications of a station based on the firewall rules and application data for the specific application; and
distributing customized application control policies to the plurality access points based on application traffic handled by each access point.
12. A Wi-Fi controller on a data communication network and implemented at least partially in hardware, for improving computer network security by implementing security policies of a firewall device locally at a plurality of access points, the Wi-Fi controller comprising:
a processor;
a network interface, communicatively coupled to the processor; and
a memory, communicatively coupled to the processor and storing source code, comprising:
a first module to receive application data collected by an IDS (intrusion detection system) on the data communication network and concerning plurality of applications executing on each station coupled to the plurality of access points;
a second module to receive firewall rules for the plurality of applications from a firewall device coupled to the data communication network and providing firewall services to the plurality of access points, including outbound traffic from the plurality of access points;
a third module to parse the firewall rules to expose configured actions for the plurality of applications;
a fourth module to prepare a customized application control policy for each particular application for implementation by at least one of the plurality of access points, wherein the customized application policy concerns how the at least one access point prioritizes network traffic for DPI (deep packet inspection) for data packets for a specific application of the plurality of applications of a station based on the firewall rules and application data for the specific application; and
a fifth module to distribute customized application control policies to the plurality access points based on application traffic handled by each access point.