IP Library › Granted Patent US 12,531,837
Granted Patent B2
US 12,531,837 · App. 18/401,612 · Granted Jan 20, 2026

Validation engine for firewall migration

Inventors: Anish Palan (Mumbai, IN); Anurag Verma (Karnataka, IN); Vinayak Manjunath (Karnataka, IN)
Assignee: Fortinet, Inc.
H04L63/029H04L41/145H04L43/026H04L63/02H04L63/0218H04L63/0263H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,531,837
App. No.
18/401,612
Granted
Jan 20, 2026
Kind
B2
Abstract

Log data is gathered from the first firewall. The log data includes first firewall activity and actions responsive to past traffic. Production traffic can then be simulated by running the gathered log data of first firewall activity through the second firewall. The simulation results are analyzed to rate configuration settings including whether policy lookups are successful and retrieving a policy ID for successful policy lookups. Invalid lookups are identified. The configuration settings of the second firewall are automatically adjusted (e.g., with a ne rule) with respect to the invalid lookups. The second firewall configuration settings are validated based on the automatic adjustments.

Claims (29)

1 . A computer-implemented method in a firewall migration device for validating configuration data transferred during migration from a first firewall currently in service to a second firewall launching into service, the method comprising:

gathering log data from the first firewall, wherein the log data includes first firewall activity and actions responsive to past traffic;

producing a simulation of traffic by running the gathered log data of first firewall activity through the second firewall, wherein the second firewall is distinct from the first firewall;

analyzing the simulation results to rate configuration settings including whether policy lookups are successful and retrieving a policy ID for successful policy lookups;

identifying unsuccessful policy lookups from the simulation;

automatically adjusting configuration settings of the second firewall with respect to the unsuccessful policy lookups;

validating the second firewall configuration settings based on the automatic adjustments; and

running live traffic through the second firewall as validated.

2 . The method of claim 1 , wherein the step of running live traffic runs live traffic through the second firewall as validated using first firewall policies.

3 . The method of claim 1 , wherein the step of running live traffic runs live traffic through the second firewall as validated using separately converted first firewall policies.

4 . A non-transitory computer-readable medium in a firewall migration device on a data communication network, for validating configuration data transferred during migration from a first firewall currently in service to a second firewall launching into service, the method comprising:

gathering log data from the first firewall, wherein the log data includes first firewall activity and actions responsive to past traffic;

producing a simulation of traffic by running the gathered log data of first firewall activity through the second firewall, wherein the second firewall is distinct from the first firewall;

analyzing the simulation results to rate configuration settings including whether policy lookups are successful and retrieving a policy ID for successful policy lookups;

identifying unsuccessful policy lookups from the simulation;

automatically adjusting configuration settings of the second firewall with respect to the unsuccessful policy lookups;

validating the second firewall configuration settings based on the automatic adjustments; and

running live traffic through the second firewall as validated.

5 . A firewall migration device on a data communication network, for validating configuration data transferred during migration from a first firewall currently in service to a second firewall launching into service, the firewall migration device comprising:

a processor;

a network interface communicatively coupled to the processor and to a data communication network; and

a memory, communicatively coupled to the processor and storing code, that when executed by the processor, performs the steps of:

gathering log data from the first firewall, wherein the log data includes first firewall activity and actions responsive to past traffic;

producing a simulation of traffic by running the gathered log data of first firewall activity through the second firewall, wherein the second firewall is distinct from the first firewall;

analyzing the simulation results to rate configuration settings including whether policy lookups are successful and retrieving a policy ID for successful policy lookups;

identifying unsuccessful policy lookups from the simulation;

automatically adjusting configuration settings of the second firewall with respect to the unsuccessful policy lookups;

validating the second firewall configuration settings based on the automatic adjustments; and

running live traffic through the second firewall as validated.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2024
From: PALAN, ANISH; VERMA, ANURAG; MANJUNATH, VINAYAK
To: FORTINET, INC.
Reel/Frame 066079/0189 →
Continuity (1)
Related Publication 20250219999A1 · Jul 3, 2025
References Cited (6)
US 11570148B2 · Liu · 2023 [cited by examiner]
US 20170012940A1 · Chang · 2017 [cited by examiner]
US 20190394170A1 · Shameli-Sendi · 2019 [cited by examiner]
US 20200329011A1 · Cai · 2020 [cited by examiner]
“Two Firewalls on the Same Subnet”—Spiceworks, Verizon Business, Sep. 2019 https://community.spiceworks.com/t/two-firewall-on-the-same-subnet-firewall-migration/731713 (Year: 2019). [cited by examiner]
“Your Comprehensive Firewall Migration Checklist”—Avidgor Book, Tufin, Sep. 4, 2023 https://www.tufin.com/blog/comprehensive-firewall-migration-checklist (Year: 2023). [cited by examiner]