IP Library Granted Patent US 8,516,567
Granted Patent B2
US 8,516,567 · App. 13/306,352 · Granted Aug 20, 2013

Distributed firewalling in a wireless communication network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,516,567
App. No.
13/306,352
Granted
Aug 20, 2013
Kind
B2
Abstract

A method and system for distributed collaborative firewalling in a wireless wide area communication network including a plurality of controllers, comprises a binding table that is built by the controller in response to receiving identifiers of wireless clients being served by the controller, where the binding table lists the wireless clients associated with each access port under control of the controller. A processor of the controller is operable to apply stateless firewalling on wireless communication traffic from a wireless client using the binding table, and applying, by each access port, stateful firewalling on the wireless communication traffic from the wireless client.

Claims (17)

1. A controller for distributed collaborative firewalling in a wireless wide area communication network including a plurality of controllers, the controller comprising:

a binding table that is built by the controller in response to receiving identifiers of wireless clients being served by the controller by sending a confirmation request asking for a confirmation that a wireless client is properly associated in order to verify that wireless communication traffic really corresponds to the wireless client, wherein the sending of the confirmation request is rate-limited so that every roam of a wireless client does not generate a confirmation request, the binding table lists the wireless clients properly associated with each access port under control of the controller; and

a processor coupled to the binding table, the processor operable to apply stateless firewalling on wireless communication traffic from the wireless client using the binding table, and applying, by each access port, stateful firewalling on the wireless communication traffic from the wireless client.

2. The controller of claim 1 , wherein the communication traffic is tunneled wide area network traffic that is bridged between wireless and wired devices.

3. The controller of claim 1 , wherein the identifier in the binding table is a Media Access Control (MAC) address of the wireless client.

4. The controller of claim 1 , wherein the identifier in the binding table is a Mesh Interconnection Network Technology (MINT) header that identifies that a packet is coming from a particular wireless client.

5. The controller of claim 1 , wherein stateless firewalling is only applied if the wireless client is not directly associated with an on-board radio of the controller itself.

6. The controller of claim 1 , wherein if the wireless client is associated with an AP, and is wirelessly communicating with another device on the same AP, the firewall flow on the AP is stateful.

7. The controller of claim 1 , wherein stateful firewalling is applied for wired devices connected to the controller through a wired communication network.

8. The controller of claim 1 , wherein if the wireless client is associated with first AP of a first controller A, and is wirelessly communicating with another device associated with a second AP of a second controller B, the firewall flow on both APs is stateful, and the firewall flows on both controllers will be stateless.

9. The controller of claim 1 , wherein whenever the wireless client, for which the controller was doing stateless firewalling, roams directly onto an on-board radio or port of the controller, the controller will make all its firewall flows stateful by dropping all stateless firewall flows and installing the migrating stateful firewall flows.

10. The controller of claim 1 , wherein the binding table includes a trust value for each wireless client, the trust value is entered in the binding table in response to the confirmation.

11. A machine-implemented method for distributed collaborative firewalling in a wireless wide area communication network including a plurality of controllers, the method comprising the steps of:

receiving a wireless client identifier for binding to a known access port;

building, by each controller, a binding table listing wireless clients properly associated with each access port under control of the controller by sending a confirmation request asking for a confirmation that a wireless client is properly associated in order to verify that wireless communication traffic really corresponds to the wireless client, wherein the sending of the confirmation request is rate-limited so that every roam of a wireless client does not generate a confirmation request; and

applying, by each controller, stateless firewalling on wireless communication traffic from the wireless client using the binding table, and applying, by each access port, stateful firewalling on the wireless communication traffic from the wireless client.

12. The method of claim 11 , wherein the binding table includes a trust value for each wireless client, the trust value is entered in the binding table in response to the confirmation.

Assignments (8)
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2016
From: SYMBOL TECHNOLOGIES, LLC
To: EXTREME NETWORKS, INC.
Reel/Frame 040579/0410 →
AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2016
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 040521/0762 →
SECURITY AGREEMENT Recorded Oct 31, 2014
From: ZIH CORP.; LASER BAND, LLC; ZEBRA ENTERPRISE SOLUTIONS CORP.; SYMBOL TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC. AS THE COLLATERAL AGENT
Reel/Frame 034114/0270 →