Disaster recovery for cloud-based monitoring of internet access
Systems and methods include receiving one or more disaster recovery configurations; identifying activation of a disaster recovery mode; and controlling traffic flow such that the traffic is any of blocked to all destinations, allowed to all destinations, and allowed to preselected destinations based on the one or more received disaster recovery configurations.
1 . A non-transitory computer-readable medium including instructions that, when executed, cause one or more processors to perform steps of:
receiving one or more disaster recovery configurations;
identifying activation of a disaster recovery mode, wherein the disaster recovery mode is triggered based on detection that a cloud-based system is unavailable to perform security processing for network traffic associated with a user device, the detection comprising receipt of or query of a Domain Name System (DNS) record signaling the unavailability; and
controlling traffic flow such that the traffic is any of blocked to all destinations, allowed to all destinations, and allowed to preselected destinations based on the one or more received disaster recovery configurations, wherein the disaster recovery configurations include preconfigured actions for the user device to perform local security processing based on cached policies when the cloud-based system is unavailable, the cached policies being dynamically updated based on prior cloud-enforced actions and tenant-specific configurations, and wherein conflicts between customer-defined and global default destination lists are deterministically resolved in favor of the customer-defined lists.
2 . The non-transitory computer-readable medium of claim 1 , wherein the steps further include:
updating a cache based on the actions taken during activation of the disaster recovery mode, wherein the actions include locally allowing or blocking traffic based on a previously cached policy when the cloud-based system is unavailable.
3 . The non-transitory computer-readable medium of claim 1 , wherein the one or more disaster recovery configurations are each associated with one or more specific tenants of a cloud-based system.
4 . The non-transitory computer-readable medium of claim 1 , wherein the one or more disaster recovery configurations include a list of global default destinations preselected by a cloud provider.
5 . The non-transitory computer-readable medium of claim 4 , wherein the one or more disaster recovery configurations additionally include one or more customer defined destination lists.
6 . The non-transitory computer-readable medium of claim 5 , wherein the one or more customer defined destination lists take priority over the list of global default destinations, and wherein conflicting entries between the lists are resolved in favor of the customer defined destination lists.
7 . The non-transitory computer-readable medium of claim 5 , wherein the list of global default destinations and the customer defined destination lists include domains which are instructed to be one of blocked or allowed.
8 . A cloud-based system comprising:
one or more processors; and
memory storing computer-executable instructions, wherein the computer-executable instructions cause the one or more processors to:
receive one or more disaster recovery configurations;
identify activation of a disaster recovery mode, wherein the disaster recovery mode is triggered based on detection that the cloud-based system is unavailable to perform security processing for network traffic associated with a user device, the detection comprising receipt of or query of a Domain Name System (DNS) record signaling the unavailability; and
control traffic flow such that the traffic is any of blocked to all destinations, allowed to all destinations, and allowed to preselected destinations based on the one or more received disaster recovery configurations, wherein the disaster recovery configurations include preconfigured actions for the user device to perform local security processing based on cached policies when the cloud-based system is unavailable, the cached policies being dynamically updated based on prior cloud-enforced actions and tenant-specific configurations, and wherein conflicts between customer-defined and global default destination lists are deterministically resolved in favor of the customer-defined lists.
9 . The cloud-based system of claim 8 , wherein the steps further include:
updating a cache based on the actions taken during activation of the disaster recovery mode, wherein the actions include locally allowing or blocking traffic based on a previously cached policy when the cloud-based system is unavailable.
10 . The cloud-based system of claim 8 , wherein the one or more disaster recovery configurations are each associated with one or more specific tenants of a cloud-based system.
11 . The cloud-based system of claim 8 , wherein the one or more disaster recovery configurations include a list of global default destinations preselected by a cloud provider.
12 . The cloud-based system of claim 11 , wherein the one or more disaster recovery configurations additionally include one or more customer defined destination lists.
13 . The cloud-based system of claim 12 , wherein the one or more customer defined destination lists take priority over the list of global default destinations, and wherein conflicting entries between the lists are resolved in favor of the customer defined destination lists.
14 . The cloud-based system of claim 12 , wherein the list of global default destinations and the customer defined destination lists include domains which are instructed to be one of blocked or allowed.
15 . A method comprising steps of:
receiving one or more disaster recovery configurations;
identifying activation of a disaster recovery mode, wherein the disaster recovery mode is triggered based on detection that a cloud-based system is unavailable to perform security processing for network traffic associated with a user device, the detection comprising receipt of or query of a Domain Name System (DNS) record signaling the unavailability; and
controlling traffic flow such that the traffic is any of blocked to all destinations, allowed to all destinations, and allowed to preselected destinations based on the one or more received disaster recovery configurations, wherein the disaster recovery configurations include preconfigured actions for the user device to perform local security processing based on cached policies when the cloud-based system is unavailable, the cached policies being dynamically updated based on prior cloud-enforced actions and tenant-specific configurations, and wherein conflicts between customer-defined and global default destination lists are deterministically resolved in favor of the customer-defined lists.
16 . The method of claim 15 , wherein the steps further include:
updating a cache based on the actions taken during activation of the disaster recovery mode, wherein the actions include locally allowing or blocking traffic based on a previously cached policy when the cloud-based system is unavailable.
17 . The method of claim 15 , wherein the one or more disaster recovery configurations are each associated with one or more specific tenants of a cloud-based system.
18 . The method of claim 15 , wherein the one or more disaster recovery configurations include a list of global default destinations preselected by a cloud provider.
19 . The method of claim 18 , wherein the one or more disaster recovery configurations additionally include one or more customer defined destination lists.
20 . The method of claim 19 , wherein the one or more customer defined destination lists take priority over the list of global default destinations, and wherein conflicting entries between the lists are resolved in favor of the customer defined destination lists.