Invention Grant
- Patent Title: Selectively disabling anti-replay protection by a network security device
-
Application No.: US16729853Application Date: 2019-12-30
-
Publication No.: US11477241B2Publication Date: 2022-10-18
- Inventor: Yixin Pan
- Applicant: Fortinet, Inc.
- Applicant Address: US CA Sunnyvale
- Assignee: Fortinet, Inc.
- Current Assignee: Fortinet, Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: Law Office of Dorian Cartwright
- Agent Dorian Cartwright
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/40 ; H04L41/0893

Abstract:
Systems and methods for selectively disabling anti-replay security checks based on a defined network policy that can override the globally-defined defaults for specific network sessions are provided. A network security device protecting a private network receives a packet associated with a network traffic flow between a source computing device and an internal destination computing device. The network security device identifies an anti-replay policy associated with the network traffic flow and whether the anti-replay policy is intended to override a global anti-replay policy of the network security device. When the identifying is affirmative, the network security device performs one or more anti-replay security checks in accordance with the anti-replay policy. When the identifying is negative, the network security device performs the one or more anti-replay security checks in accordance with the global anti-replay policy.
Public/Granted literature
- US20210203698A1 SELECTIVELY DISABLING ANTI-REPLAY PROTECTION BY A NETWORK SECURITY DEVICE Public/Granted day:2021-07-01
Information query