Invention Grant
- Patent Title: Apparatus, system, and method for applying firewall rules on packets in kernel space on network devices
-
Application No.: US16654915Application Date: 2019-10-16
-
Publication No.: US10798062B1Publication Date: 2020-10-06
- Inventor: Prashant Singh , Sreekanth Rupavatharam , Hariprasad Shanmugam
- Applicant: Juniper Networks, Inc.
- Applicant Address: US CA Sunnyvale
- Assignee: Juniper Networks, Inc
- Current Assignee: Juniper Networks, Inc
- Current Assignee Address: US CA Sunnyvale
- Agency: FisherBroyles, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A disclosed method for applying firewall rules on packets in kernel space on network devices may include (1) intercepting, via a socket-intercept layer in kernel space on a routing engine of a network device, a packet that is destined for a remote device and then, in response to intercepting the packet in kernel space on the routing engine, (2) identifying an egress interface index that specifies an egress interface that (A) is external to kernel space and (B) is capable of forwarding the packet from the network device to the remote device, and (3) applying, on the packet in kernel space, at least one firewall rule based at least in part on the egress interface index before the packet egresses from the routing engine. Various other apparatuses, systems, and methods are also disclosed.
Information query