The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 25, 2019

Filed:

Apr. 10, 2013
Applicants:

Meng Xu, Los Altos, CA (US);

Yi Sun, San Jose, CA (US);

Hsisheng Wang, Fremont, CA (US);

Choung-yaw Shieh, Palo Alto, CA (US);

Inventors:

Meng Xu, Los Altos, CA (US);

Yi Sun, San Jose, CA (US);

Hsisheng Wang, Fremont, CA (US);

Choung-Yaw Shieh, Palo Alto, CA (US);

Assignee:

VARMOUR NETWORKS, INC., Santa Clara, CA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 15/173 (2006.01); H04L 12/721 (2013.01); H04L 29/06 (2006.01); G06F 9/455 (2018.01); H04L 12/751 (2013.01);
U.S. Cl.
CPC ...
H04L 45/14 (2013.01); G06F 9/45558 (2013.01); H04L 63/0209 (2013.01); H04L 63/20 (2013.01); G06F 2009/4557 (2013.01); G06F 2009/45595 (2013.01); H04L 45/02 (2013.01);
Abstract

A network system includes a first network access device having an input/output (IO) module of a firewall to capture a packet of a network session originated from a first node associated with the first network access device, a first security device having a firewall processing module to determine based on the captured packet whether the first node is a destination node that is receiving VM migration from a second node that is associated with a second network access device. The first security device is to update a first flow table within the first network access device. The network system further includes a second security device to receive a message from the first security device concerning the VM migration to update a second flow table of the second network access device, such that further network traffic of the network session is routed to the first node without interrupting the network session.


Find Patent Forward Citations

Loading…