Integration and implementation of global edge functionalities
This disclosure is related to methods and apparatus for securely routing and controlling access of various types of traffic for one or more end-user devices. Securely routing and controlling access of the various types of traffic includes securely routing private application traffic from a first end-user device to a private network, securely routing private network traffic from a second end-user device to a private network, and filtering and monitoring Internet traffic for a third end-user device from the Internet or a Software-as-a-Service (SaaS) application. Securely routing and controlling access of the various types of traffic includes using a Zero Trust Network Access (ZTNA) proxy to authenticate the end-user devices and a firewall connector coupled with a network firewall to establish a connector tunnel.
1 . A method for securely routing and controlling access of various types of traffic for one or more end-user devices, the method comprising:
securely routing private application traffic from a first end-user device to a private network, comprising:
receiving a first request by the first end-user device for verification by a Zero Trust Network Access (ZTNA) proxy;
authenticating the first end-user device by the ZTNA proxy;
based on a successful authentication, providing a unique session token to a firewall connector coupled with a network firewall;
receiving, by a license manager, a request from the firewall connector to initiate connector provisioning; and
establishing, by the firewall connector and a centralized management platform, a first connector tunnel for the private application traffic;
securely routing private network traffic from a second end-user device to the private network, comprising:
receiving the private network traffic at the firewall connector coupled with the network firewall;
inspecting the private network traffic based on rules related to network traffic; and
establishing a second connector tunnel for the private network traffic.
2 . The method of claim 1 , wherein an access control service is a cloud-based service of the centralized management platform wherein the method further comprising:
managing, by the centralized management platform, the access control service to provide administrators to manage and monitor end-user devices from a single interface, configure firewall policies, and view real-time reporting and analytics on network activity.
3 . The method of claim 2 , further comprising:
verifying, by the access control service, authorization of the first end-user device to access the private network;
evaluating, by the access control service, device characteristics of the first end-user device;
applying, by the access control service, configured application control policies based on the device characteristics; and
evaluating, by the access control service, Zero Trust Network Access (ZTNA) policies based on the device characteristics and application configured application control policies.
4 . The method of claim 3 , further comprising:
generating, by the access control service, the unique session token when the request is approved;
providing, by the access control service, the unique session token to the firewall connector; and
forming, by the access control service, a connector tunnel that establishes a secure connection between the first end-user device and the private network.
5 . The method of claim 1 , further comprising:
assigning, by the centralized management platform, a unique source IP address to the second end-user device;
receiving a data packet from an access tier at the firewall connector, wherein the access tier receives the data packet from the second end-user device for the private network;
changing, by the firewall connector, the unique source IP address or a destination IP address of the data packet;
forwarding, by the firewall connector, the data packet to a correct location on the private network;
receiving, from the firewall connector, periodic requests to get updates on connector configuration; and
sending, to the firewall connector, updates about connector tunnel performance and availability.
6 . The method of claim 1 , wherein the second connector tunnel uses WireGuard peering.
7 . The method of claim 2 , further comprising:
provisioning a child tenant associated with the first end-user device for a managed service provider;
assigning customer access rights to the child tenant; and
managing product licenses for the child tenant.
8 . The method of claim 7 , further comprising:
requesting to register, through a browser, the managed service provider and the child tenant through the access control service;
requesting to provision the managed service provider with the centralized management platform;
after the managed service provider is successfully provisioned, provisioning the child tenant with the centralized management platform;
creating administrators for the managed service provider;
assigning one or more of the administrators to the child tenant; and
sending provisioning status to the browser.
9 . The method of claim 2 , further comprising:
requesting, by the firewall connector, a license through the license manager;
sending to the license manager a list of local network routes and private DNS domains; and
provision JavaScript Object Notation (JSON) specifications in the centralized management platform for the firewall connector.
10 . The method of claim 9 , further comprising:
calling, by the license manager, the access control service;
requesting, by the access control service, the centralized management platform to issue an org admin-scoped Application Programming Interface (API) key to the license manager;
providing, by the centralized management platform, an org admin-scoped API key to the access control service;
providing, by the access control service, the org admin-scoped API key to the license manager;
using, by the license manager, the org admin-scoped API key to provision a connector-scoped API key in the centralized management platform;
creating, in the centralized management platform, the connector-scoped API key based on connector specifications that ties the firewall connector to the connector-scoped API key; and
providing the connector-scoped API key to the license manager.
11 . The method of claim 10 , further comprising:
sending, by the license manager, the connector-scoped API key to the firewall connector; and
calling, by the firewall connector, the centralized management platform by using the connector-scoped API key to fetch connector configurations and reporting connector tunnel status.
12 . The method of claim 11 , further comprising:
fetching, by the firewall connector, a tunnel config of the first connector tunnel with the connector-scoped API key from the centralized management platform;
receiving, by the access control service, the tunnel config;
applying, by the access control service, any config changes to the first connector tunnel; and
publish, by the access control service, tunnel health status to the centralized management platform.
13 . The method of claim 1 , wherein inspecting the private network traffic is based on rules related to network traffic at a transport level, and wherein the second connector tunnel is established upon successful inspection of the private network traffic.
14 . The method of claim 1 , further comprising:
filtering and monitoring Internet traffic for a third end-user device from the Internet or a Software-as-a-Service (Saas) application, comprising:
receiving a second request for the Internet traffic from the third end-user device;
filtering the Internet traffic using one or more security policies; and
after filtering, establishing a secure connection for the Internet traffic.
15 . A system for securely routing and controlling access of various types of traffic for one or more end-user devices, the system comprising:
a centralized management platform; and
a firewall connector coupled with a network firewall, the firewall connector configured to:
securely route private application traffic from a first end-user device to a private network, comprising:
receiving a request by the first end-user device for verification by a Zero Trust Network Access (ZTNA) proxy;
authenticating the first end-user device by the ZTNA proxy;
based on a successful authentication, providing a unique session token to the firewall connector coupled with a network firewall; and
establishing, with the centralized management platform, a first connector tunnel for the private application traffic; and
securely route private network traffic from a second end-user device to the private network, comprising:
receiving the private network traffic at the firewall connector;
inspecting the private network traffic based on rules related to network traffic; and
establishing a second connector tunnel between the second end-user device and an access tier in a lowest-latency location closest to a location of the second end-user device for the private network traffic.
16 . The system for securely routing of claim 15 , wherein the firewall connector is further configured to:
receive a data packet from an access tier, wherein the access tier receives the data packet from the second end-user device for the private network;
change a unique source IP address or a destination IP address of the data packet; and
forward the data packet to a correct location on the private network.
17 . The system of claim 15 , wherein the centralized management platform is configured to assign a unique source IP address to a respective end-user device.
18 . The system of claim 15 , wherein inspecting the private network traffic is based on rules related to network traffic at a transport level, and wherein the second connector tunnel is established upon successful inspection of the private network traffic.
19 . The system of claim 15 , wherein the firewall connector is further configured to:
filter and monitor Internet traffic for a third end-user device from the Internet or a Software-as-a-Service (SaaS) application, comprising:
receiving a request for the Internet traffic from the third end-user device; and
after the Internet traffic is filtered using one or more security policies, establishing a secure connection for the Internet traffic.
20 . A non-transitory computer readable storage medium having embodied thereon a program executable by a processor for implementing a method for securely routing and controlling access of various types of traffic for one or more end-user devices, the method comprising:
securely routing private application traffic from a first end-user device to a private network, comprising:
receiving a request by the first end-user device for verification by a Zero Trust Network Access (ZTNA) proxy;
authenticating the first end-user device by the ZTNA proxy;
based on a successful authentication, providing a unique session token to a firewall connector coupled with a network firewall; and
receiving, by a license manager, a request from the firewall connector to initiate connector provisioning;
establishing, by the firewall connector and a centralized management platform, a first connector tunnel for the private application traffic;
securely routing private network traffic from a second end-user device to the private network, comprising:
receiving the private network traffic at the firewall connector coupled with the network firewall;
inspecting the private network traffic based on rules related to network traffic; and
establishing a second connector tunnel for the private network traffic.