The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Feb. 18, 2025

Filed:

May. 13, 2022
Applicant:

Palo Alto Networks, Inc., Santa Clara, CA (US);

Inventors:

Tapraj Singh, Danville, CA (US);

Harshavardhan Parandekar, San Jose, CA (US);

Nazanin Magharei, San Jose, CA (US);

Rimu Bhardwaj, Sunnyvale, CA (US);

Vikram Guleria, Fremont, CA (US);

Assignee:

Palo Alto Networks, Inc., Santa Clara, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/40 (2022.01); H04L 61/2514 (2022.01); H04L 61/256 (2022.01);
U.S. Cl.
CPC ...
H04L 63/0236 (2013.01); H04L 61/2514 (2013.01); H04L 61/256 (2013.01); H04L 63/0263 (2013.01);
Abstract

A pseudo-active/active firewall configuration handles firewall switchover events with minimized session disconnection. A passive firewall is set to an active state, and an active firewall is switched to a pseudo-active state wherein it continues to process ingress and egress traffic according to traffic handling protocols for its active state. During updating of a corresponding Network Address Translation (NAT) table to route traffic to the now-active firewall, the pseudo-active firewall enters a forwarding state wherein it forwards ingress network sessions to the now-active firewall and processes the ingress network sessions according to its active state. The now-active firewall receives the ingress network sessions and records session states prior to discarding them. After updating the NAT table, when traffic is routed to the now-active firewall, the recorded session states are used to maintain active sessions.


Find Patent Forward Citations

Loading…