IP Library Granted Patent US 8,572,721
Granted Patent B2
US 8,572,721 · App. 11/462,174 · Granted Oct 29, 2013

Methods and systems for routing packets in a VPN-client-to-VPN-client connection via an SSL/VPN network appliance

Inventors: Arkesh Kumar (Santa Clara, CA); James Harris (San Jose, CA); Ajay Soni (San Jose, CA)
Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,572,721
App. No.
11/462,174
Granted
Oct 29, 2013
Kind
B2
Abstract

In a method and system for routing packets between clients, a packet is received from a first client connected to a secure sockets layer virtual private network (an SSL/VPN) network appliance. An identification is made, responsive to an inspection of the received packet, of i) a type of connection required for transmission of the received packet to a destination address identified by the received packet and ii) a second client connected via an SSL/VPN connection to the SSL/VPN network appliance and associated with the identified destination address. A request is made for establishment by the second client of a connection of the identified type within the SSL/VPN connection. The received packet is transmitted to the second client via the established connection of the identified type.

Claims (36)

1. A method for routing packets between clients, the method comprising:

(a) receiving, by a device intermediary to a plurality of clients each connected to the device via a secure sockets layer virtual private network (SSL VPN) connection, a packet from a first client agent of a first client via a first SSL VPN connection with the device;

(b) identifying, by the device responsive to an inspection of the received packet, i) a type of transport layer connection required for transmission of the received packet to a destination address identified by the received packet and ii) a second client connected via a second SSL VPN connection to the device and associated with the identified destination address; and

(c) requesting establishment, by a second client agent executing on the second client, of the transport layer connection of the identified type within the second SSL VPN connection, the second client agent establishing a transport layer connection with a second application executing on the second client; and

(d) transmitting, by the device, the received packet to the second client via the established transport layer connection of the identified type, the received packet forwarded to the second application executing on the second client via the transport layer connection established between the second application and the second client agent.

2. The method of claim 1 , wherein step (a) further comprises receiving, by the device, the packet via a first transport layer connection within the first SSL VPN connection.

3. The method of claim 1 , wherein step (b) further comprises inspecting, by the device, the received packet.

4. The method of claim 1 , wherein step (b) further comprises identifying, responsive to the inspection of the received packet, a type of transport layer connection comprising a TCP connection.

5. The method of claim 1 , wherein step (b) further comprises identifying, responsive to the inspection of the received packet, a type of transport layer connection comprising a UDP connection.

6. The method of claim 1 , wherein step (c) further comprises requesting, by the device, establishment by the second client of a transport layer connection of the identified type.

7. The method of claim 1 , wherein step (c) comprises requesting establishment by the second client of a transport layer connection of the identified type between the second client and the device.

8. The method of claim 1 , wherein step (c) further comprises establishing, by the second client, a transport layer connection of the identified type.

9. A device for routing packets between clients each connected to the device via a secure sockets layer virtual private network (SSL VPN) connection, comprising

i. a receiver receiving a packet from a first client agent of a first client over a first SSL VPN connection with the device,

ii. a packet inspector identifying, responsive to an inspection of the received packet, 1)a type of transport layer connection required for transmission of the received packet to a destination address identified by the received packet and 2) a second client connected via a second SSL VPN connection to the device and associated with the identified destination address, and

iii. a transceiver receiving a request from a second client agent executing on the second client for establishment of a transport layer connection of the identified type and transmitting the received packet to the second client over the requested transport layer connection, the second client agent establishing a transport layer connection with an application executing on the second client and forwarding the received packet to the application.

10. A system for routing packets between clients, the system comprising:

a first client of a plurality of clients, transmitting a packet;

a second client of the plurality of clients; and

a device intermediary to the plurality of clients and connected to each client via a secure sockets layer virtual private network (SSL VPN) connection, the device comprising

i. a receiver receiving the packet from a first client agent of the first client over a first SSL VPN connection,

ii. a packet inspector identifying, responsive to an inspection of the received packet, 1) a type of transport layer connection required for transmission of the received packet to a destination address identified by the received packet and 2) the second client, the second client connected via a second SSL VPN connection to the device and associated with the identified destination address, and

iii. a transceiver receiving a request from a second client agent executing on the second client for establishment by the second client of a transport layer connection of the identified type and transmitting the received packet to the second client over the requested transport layer connection, the second client agent establishing a transport layer connection with an application executing on the second client and forwarding the received packet to the application.

11. The system of claim 10 , wherein the first client establishes the first SSL VPN connection to the device.

12. The system of claim 10 , wherein the first client transmits the packet to the device over the first SSL VPN connection.

13. The system of claim 10 , wherein the second client agent establishes a transport layer connection via an SSL VPN connection to the device.

14. The system of claim 10 , wherein the second client further comprises an association with the destination address identified by the received packet.

15. The system of claim 10 , wherein the second client agent establishes a transport layer connection of the identified type between the second client and the device.

16. The system of claim 10 , wherein the second client agent establishes a transport layer connection of the identified type within an SSL VPN connection to the device.

17. A method for routing packets between clients, the method comprising:

(a) establishing, by a first client from a first network, a first secure sockets layer virtual private network (SSL VPN) connection to a second network via a device, the device intermediary to a plurality of clients each connected to the device via a SSL VPN connection;

(b) establishing, by a second client agent of a second client from a third network, a second SSL VPN connection to the second network via the device;

(c) receiving, by the device, a request from the first client via the first SSL VPN connection to connect to the second client on the second network;

(d) identifying, by the device responsive to an inspection of the received packet, i) a type of transport layer connection required for transmission of the received packet to a destination address identified by the received packet and ii) the second client on the second network associated with the identified destination address;

(e) requesting establishment, by a second client agent executing on the second client, of the transport layer connection of the identified type via the second SSL VPN connection, the second client agent establishing a transport layer connection with a second application executing on the second client; and

(f) transmitting, by the device, the received packet to the second client via the established transport layer connection of the identified type, the received packet forwarded to the second application executing on the second client via the transport layer connection established between the second application and the second client agent.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2006
From: KUMAR, ARKESH; HARRIS, JAMES; SONI, AJAY
To: CITRIX SYSTEMS, INC.
Reel/Frame 018543/0994 →
Continuity (1)
Related Publication 20080034416A1 · Feb 7, 2008