IP Library › Granted Patent US 8,897,299
Granted Patent B2
US 8,897,299 · App. 13/739,895 · Granted Nov 25, 2014

Method and systems for routing packets from a gateway to an endpoint

Inventors: Goutham P. Rao (San Jose, CA); Robert A. Rodriguez (San Jose, CA); Eric R. Brueggemann (Cupertino, CA)
Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,897,299
App. No.
13/739,895
Filed
Jan 11, 2013
Granted
Nov 25, 2014
Kind
B2
Art Unit
2463
USPC
370/389
Abstract

A method for routing packets from a gateway to an endpoint includes the step of associating a private internet protocol (IP) address with an endpoint having a public IP address. A packet addressed to the private IP address of the endpoint is captured. A policy is applied to the packet. The packet is transmitted to the public IP address of the endpoint, responsive to the application of the policy to the packet.

Claims (26)

1. A method for routing packets by a device intermediary to a client and a server, the method comprising:

(a) establishing, by a device intermediary to a client on a public network and a server on a private network, for the client a private internet protocol (IP) address on the private network, the client having a public IP address on the public network, the device not providing the private IP address to the client;

(b) receiving, by a management process executing in user mode memory space of the device from a driver operating in kernel mode of the device, a packet originating from the server and addressed to the private IP address of the client; and

(c) applying, by a policy engine executing on the device responsive to the management process, a policy to the packet to determine whether to transmit the packet to the client based on source of the packet.

2. The method of claim 1 , wherein step (a) further comprises assigning, by an addressing element executing in user mode memory space of the device, the private network address to the client.

3. The method of claim 1 , wherein step (b) further comprises intercepting, by the driver, the packet at a Media Access Control (MAC) layer.

4. The method of claim 1 , wherein step (b) further comprises intercepting, by the driver, at a layer below a transport layer, the packet communicated via a transport layer connection between the device and the server.

5. The method of claim 1 , wherein step (b) further comprising communicating, by the driver, the packet to the management process responsive to the management process requesting the driver to forward packets addressed to the private IP address.

6. The method of claim 1 , wherein step (c) further comprises applying, by the policy engine executing in user mode memory space of the device, the policy to the packet to determine whether the packet originated from the source comprising one of a trusted source or a protected server.

7. The method of claim 1 , further comprising determining, by the policy engine, to transmit the packet to the client, and responsive to the determination, the device modifying the packet to be addressed to the public IP address of the client.

8. The method of claim 7 , further comprising transmitting, by the device, the packet to the public IP address of the client via a transport layer connection between the device and the client.

9. The method of claim 8 , further comprising transmitting, by the device, the packet to a client application on the device that terminates the transport layer connection to the device.

10. The method of claim 9 , wherein the client application terminates a second transport layer connection with an application on the client to which the packet is destined.

11. A system intermediary to a client and a server for routing packet, the system comprising:

a device intermediary to a client on a public network and a server on a private network, the device to establish for the client a private internet protocol (IP) address on the private network, the client having a public IP address on the public network, the device not providing the private IP address to the client;

a management process executable in user mode memory space of the device to receive from a driver operating in kernel mode of the device a packet originating from the server and addressed to the private IP address of the client; and

a policy engine executable on the device to apply, responsive to the management process, a policy to the packet to determine whether to transmit the packet to the client based on source of the packet.

12. The system of claim 11 , further comprising an addressing element executable in user mode memory space of the device to assign the private network address to the client.

13. The system of claim 11 , wherein the driver is configured to intercept the packet at a Media Access Control (MAC) layer.

14. The system of claim 11 , wherein the driver is configured to intercept at a layer below a transport layer, the packet communicated via a transport layer connection between the device and the server.

15. The system of claim 11 , wherein the driver is configured to communicate the packet to the management process responsive to the management process requesting the driver to forward packets addressed to the private IP address.

16. The system of claim 11 , wherein the policy engine executable in user mode memory space of the device to apply the policy to the packet to determine whether packet originated from the source comprising one of a trusted source or a protected server.

17. The system of claim 11 , wherein the policy engine is configured to determine to transmit the packet to the client, and responsive to the determination, the device is configured to modify the packet to be addressed to the public IP address of the client.

18. The system of claim 17 , wherein the device is configured to transmit the packet to the public IP address of the client via a transport layer connection between the device and the client.

19. The system of claim 18 , wherein the device is configured to transmit the packet to a client application on the device that terminates the transport layer connection to the device.

20. The system of claim 19 , wherein the client application is configured to terminate a second transport layer connection with an application on the client to which the packet is destined.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2013
From: RAO, GOUTHAM P.; RODRIGUEZ, ROBERT A.; BRUEGGEMANN, ERIC E.
To: CITRIX SYSTEMS, INC.
Reel/Frame 029863/0606 →
Continuity (6)
Continuation 11161091 · Jul 22, 2005
Provisional Application 60590837 · Jul 23, 2004
Provisional Application 60601431 · Aug 13, 2004
Provisional Application 60607420 · Sep 3, 2004
Provisional Application 60634379 · Dec 7, 2004
Related Publication 20130128892A1 · May 23, 2013