Invention Grant
- Patent Title: Domain name based visibility and policy enforcement in a segmented network environment
-
Application No.: US16248707Application Date: 2019-01-15
-
Publication No.: US11303605B2Publication Date: 2022-04-12
- Inventor: Jaehong Park , Mukesh Gupta , Paul James Kirner , Anish Vinodkumar Desai , Daniel Richard Cook
- Applicant: Illumio, Inc.
- Applicant Address: US CA Sunnyvale
- Assignee: Illumio, Inc.
- Current Assignee: Illumio, Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: Fenwick & West LLP
- Main IPC: H04L29/12
- IPC: H04L29/12 ; H04L61/4511 ; H04L29/06

Abstract:
An enforcement module receives a DNS-based rule of a segmentation policy that controls access of a managed workload to workloads in a DNS domain in which the IP addresses of the workloads associated with a domain name are resolved by a DNS server. When the managed workload makes a connection request to the workload associated with the domain name, the enforcement module snoops on a DNS response from the DNS server to learn the IP address of the workload associated with the domain name. If a domain name of the DNS domain is in a whitelist of domain names permitted by the DNS-based rule, the enforcement module adds the learned IP address to a whitelist of IP addresses and configures a firewall associated with the managed workload to permit connections to the IP addresses in the whitelist.
Public/Granted literature
- US20200228486A1 DOMAIN NAME BASED VISIBILITY AND POLICY ENFORCEMENT IN A SEGMENTED NETWORK ENVIRONMENT Public/Granted day:2020-07-16
Information query