The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Sep. 02, 2025

Filed:

May. 01, 2024
Applicant:

Illumio, Inc., Sunnyvale, CA (US);

Inventors:

Daniel Richard Cook, San Jose, CA (US);

Anish Vinodkumar Desai, Palo Alto, CA (US);

Thomas Michael Mccormick, San Jose, CA (US);

Assignee:

Illumio, Inc., Sunnyvale, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/40 (2022.01); G06F 9/38 (2018.01); G06F 9/448 (2018.01); H04L 41/0803 (2022.01); H04L 41/0894 (2022.01); H04L 43/04 (2022.01); H04L 41/069 (2022.01); H04L 41/0895 (2022.01); H04L 41/40 (2022.01);
U.S. Cl.
CPC ...
H04L 63/0227 (2013.01); G06F 9/3826 (2013.01); G06F 9/4486 (2018.02); H04L 41/0803 (2013.01); H04L 41/0894 (2022.05); H04L 43/04 (2013.01); H04L 63/0236 (2013.01); H04L 63/0254 (2013.01); H04L 63/0263 (2013.01); H04L 63/20 (2013.01); H04L 41/069 (2013.01); H04L 41/0895 (2022.05); H04L 41/40 (2022.05);
Abstract

A segmentation firewall executing on a host enforces a segmentation policy. In a co-existence mode, the segmentation firewall operates in co-existence with a system firewall that enforces a security policy. The segmentation firewall is configured to either drop packets that do not match any permissive rule or pass packets that match a permissive rule to the system firewall to enable the system firewall to determine whether to drop or accept the passed packets. To enable efficient operation of the segmentation firewall when operating in co-existence with the system firewall, the segmentation firewall may include a plurality of rule chains and may be configured to exit a chain and bypass remaining rule chains upon an input packet matching a permissive rule of the segmentation policy.


Find Patent Forward Citations

Loading…