IP Library Granted Patent US 7,451,306
Granted Patent B2
US 7,451,306 · App. 10/474,856 · Granted Nov 11, 2008

Network security device

Assignee: Firebridge Systems Pty Ltd.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,451,306
App. No.
10/474,856
Granted
Nov 11, 2008
Kind
B2
Abstract

A network security device that does not require a separate computer for implementation is disclosed. The device may be in the form of a boxed hardware component and may be configured from an HTML interface. The device contains and uses three network cards. The first two cards are used for the firewall. A third card is a management interface having a private, non publicly routed IP address. A first network card forwards packets to a packet filter. Packets which pass the packet filter are then forwarded to a second network card and subsequently to their destination. None of the three network cards have a publicly routed IP address. The device acts as a packet filter that bridges rather than routes or proxies. The device may be connected between a router and a hub or a server machine.

Claims (19)

1. A network security device for controlling the flow of a packet into and out of an internal network, said network security device comprising:

(a) a first network card;

(b) a second network card;

(c) a firewall comprising a packet filter; and

(d) a third network card that is a management interface comprising a private, not publicly routed, IP address,

(i) wherein said first and said second network cards do not have publicly routed IP addresses;

(ii) wherein said third network card is used to configure said firewall;

(iii) wherein during inflow of a packet, said first network card forwards said packet to said packet filter for inspection wherein said packet is compared with a first set of rules to determine whether said packet is acceptable to said internal network or is not acceptable to said internal network, wherein if said packet is acceptable to said internal network, it is forwarded to said second network card and to said internal network and if said packed is not acceptable, it is dropped and disappears;

(iv) wherein during outflow of said packet, said packet passes through said second network card to said packet filter wherein said packet is compared with a second set of rules to determine whether said outbound packet is acceptable to said internal network or is not acceptable to said internal network, wherein if said packet is acceptable to said internal network, it is forwarded to said first network card to exit said network security device and if said packet is not acceptable to said internal network, it is dropped and disappears; and

(v) wherein said packet filter bridges said packet after the packet is inspected.

2. The network security device of claim 1 wherein the device is connected in between a router and a hub or a server machine.

3. The network security device of claim 1 wherein the device implements independent of a separate computer.

4. The network security device of claim 1 wherein the device is configurable from an HTML interface.

5. The network security device of claim 1 wherein the device is configured with an HTML interface that is supplied with the device.

6. The network security device of claim 1 wherein the device further comprises a LOAD monitor that provides LOAD status and a graphic notification of the current load on a CPU to a user.

7. The network security device of claim 1 wherein the device further comprises a CONFIGURATION status monitor that provides a graphic notification of the commitment of changes made to the configuration of the firewall to a user.

8. The network security device of claim 1 wherein the device further comprises a monitor and log that provides a graphic indication of the allowance and denial of the packets.

9. The network security device of claim 1 wherein the device further comprises an HTML interface for configuration so that the device may be configured with any networked computer installed with an HTML browser.

10. The network security device of claim 1 wherein the first and second network cards are provided with a non-assigned IP address protocol.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 25, 2008
From: CULBERT, PATRICK
To: FIREBRIDGE SYSTEMS PTY LTD.
Reel/Frame 021588/0044 →
Priority Claims (1)
AU PR4355 · Apr 11, 2001 · national
Continuity (1)
Related Publication 20040172529A1 · Sep 2, 2004