IP Library Granted Patent US 12,603,867
Granted Patent B2
US 12,603,867 · App. 18/777,147 · Granted Apr 14, 2026

Enhanced sase network processing node high availability

Inventors: Prasad Chigurupati (Fremont, CA); Srinivasan Komandoor Santhanam (Sunnyvale, CA); Naveen Bombarsnahalli Neelakanta (Mountain House, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/029H04L47/125H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,603,867
App. No.
18/777,147
Granted
Apr 14, 2026
Kind
B2
Abstract

Various techniques for enhanced SASE network processing node (NPN) IPSec high availability are disclosed. In some embodiments, a system, a process, and/or a computer program product for enhanced SASE NPN IPSec high availability includes monitoring a plurality of secure tunnels at an active network processing node (NPN); synchronizing periodically from the active NPN to a standby NPN; and processing each of the plurality of secure tunnels at the standby NPN using a predicted sequence number for an anti-replay sequence window for each of the plurality of secure tunnels after a failover event from the active NPN to the standby NPN.

Claims (35)

1 . A system, comprising:

a processor configured to:

monitor a plurality of secure tunnels at an active network processing node (NPN);

synchronize periodically from the active NPN to a standby NPN; and

process each of the plurality of secure tunnels at the standby NPN using a predicted sequence number for an anti-replay sequence window for each of the plurality of secure tunnels after a failover event from the active NPN to the standby NPN, wherein the active NPN and the standby NPN are associated with a Secure Access Service Edge (SASE) network, wherein the SASE network includes a plurality of security processing nodes (SPNs), and wherein branch flows are assigned by a load balancer for security processing at one of the plurality of the SPNs; and

a non-transitory memory coupled to the processor and configured to provide the processor with instructions.

2 . The system of claim 1 , wherein the predicted sequence number for the anti-replay sequence window for each of the plurality of secure tunnels is weighted for a recency bias.

3 . The system of claim 1 , wherein the SASE network includes the load balancer.

4 . The system of claim 1 , wherein the processor is further configured to:

periodically synchronize an IPSec sequence number for each of a plurality of branch flows from the active NPN to the standby NPN.

5 . The system of claim 1 , wherein the processor is further configured to:

periodically synchronize an IPSec sequence number for each of a plurality of branch flows from the active NPN to the standby NPN; and

periodically synchronize a security association (SA) for each of the plurality of branch flows from the active NPN to the standby NPN.

6 . A method, comprising:

monitoring a plurality of secure tunnels at an active network processing node (NPN);

synchronizing periodically from the active NPN to a standby NPN; and

processing each of the plurality of secure tunnels at the standby NPN using a predicted sequence number for an anti-replay sequence window for each of the plurality of secure tunnels after a failover event from the active NPN to the standby NPN, wherein the active NPN and the standby NPN are associated with a Secure Access Service Edge (SASE) network, wherein the SASE network includes a plurality of security processing nodes (SPNs), and wherein branch flows are assigned by a load balancer for security processing at one of the plurality of the SPNs.

7 . The method of claim 6 , wherein the predicted sequence number for the anti-replay sequence window for each of the plurality of secure tunnels is weighted for a recency bias.

8 . The method of claim 6 , wherein the SASE network includes the load balancer.

9 . The method of claim 6 , further comprising:

periodically synchronizing an IPSec sequence number for each of a plurality of branch flows from the active NPN to the standby NPN.

10 . The method of claim 6 , further comprising:

periodically synchronizing an IPSec sequence number for each of a plurality of branch flows from the active NPN to the standby NPN; and

periodically synchronizing a security association (SA) for each of the plurality of branch flows from the active NPN to the standby NPN.

11 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

monitoring a plurality of secure tunnels at an active network processing node (NPN);

synchronizing periodically from the active NPN to a standby NPN; and

processing each of the plurality of secure tunnels at the standby NPN using a predicted sequence number for an anti-replay sequence window for each of the plurality of secure tunnels after a failover event from the active NPN to the standby NPN, wherein the active NPN and the standby NPN are associated with a Secure Access Service Edge (SASE) network, wherein the SASE network includes a plurality of security processing nodes (SPNs), and wherein branch flows are assigned by a load balancer for security processing at one of the plurality of the SPNs.

12 . The computer program product of claim 11 , wherein the predicted sequence number for the anti-replay sequence window for each of the plurality of secure tunnels is weighted for a recency bias.

13 . The computer program product recited in claim 11 , wherein the SASE network includes the load balancer.

14 . The computer program product recited in claim 11 , further comprising:

periodically synchronizing an IPSec sequence number for each of a plurality of branch flows from the active NPN to the standby NPN.

15 . The computer program product recited in claim 11 , further comprising:

periodically synchronizing an IPSec sequence number for each of a plurality of branch flows from the active NPN to the standby NPN; and

periodically synchronizing a security association (SA) for each of the plurality of branch flows from the active NPN to the standby NPN.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2024
From: CHIGURUPATI, PRASAD; KOMANDOOR SANTHANAM, SRINIVASAN; BOMBARSNAHALLI NEELAKANTA, NAVEEN
To: PALO ALTO NETWORKS, INC.
Reel/Frame 068770/0220 →
Continuity (1)
Related Publication 20260025365A1 · Jan 22, 2026
References Cited (18)
US 7571343B1 · Xiang · 2009 [cited by examiner]
US 10257167B1 · Matthews · 2019 [cited by examiner]
US 10498529B1 · Hashmi · 2019 [cited by examiner]
US 10601779B1 · Matthews · 2020 [cited by examiner]
US 10771476B2 · Thubert · 2020 [cited by examiner]
US 20120281522A1 · Kumar · 2012 [cited by examiner]
US 20150237069A1 · Rochon · 2015 [cited by examiner]
US 20150304282A1 · Xu · 2015 [cited by examiner]
US 20190173920A1 · Gopal · 2019 [cited by examiner]
US 20190297533A1 · Liedes · 2019 [cited by examiner]
US 20220215101A1 · Rioux · 2022 [cited by examiner]
US 20230269191A1 · Mestery · 2023 [cited by examiner]
US 20250119471A1 · Parla · 2025 [cited by examiner]
6WIND, 6WIND: Virtualized Networking Software | Cloud-Native Solutions, downloaded Jul. 11, 2024, pp. 1-6. [cited by applicant]
Amazon Web Services, Load Balancer—Elastic Load Balancing (ELB)—AWS, downloaded Jul. 10, 2024, pp. 1-7. [cited by applicant]
Red Hat, 6WIND Virtual Service Router (VSR), Red Hat Ecosystem Catalog, downloaded Jul. 11, 2024, pp. 1-6. [cited by applicant]
StrongSwan, strongSwan Documentation, ha Plugin, downloaded Jul. 10, 2024, pp. 1-2. [cited by applicant]
Zhang et al., IPsec Anti-Replay Algorithm without Bit Shifting, RFC 6479, Jan. 2012, pp. 1-9. [cited by applicant]