EP0909073A2

Methods and apparatus for a computer network firewall with proxy reflection

Abstract

The invention provides improved computer network firewalls which include one or more features for increased processing efficiency. A firewall in accordance with the invention can support multiple security policies, multiple users or both, by applying any one of several distinct sets of access rules. The firewall can also be configured to utilize "stateful" packet filtering which involves caching rule processing results for one or more packets, and then utilizing the cached results to bypass rule processing for subsequent similar packets. To facilitate passage to a user, by a firewall, of a separate later transmission which is properly in response to an original transmission, a dependency mask can be set based on session data items such as source host address, destination host address, and type of service. The mask can be used to query a cache of active sessions being processed by the firewall, such that a rule can be selected based on the number of sessions that satisfy the query. Dynamic rules may be used in addition to pre-loaded access rules in order to simplify rule processing. To unburden the firewall of application proxies, the firewall can be enabled to redirect a network session to a separate server for processing.

EP0909073A2, drawing sheet 1
Sheet 1 of 13

Term

Term ended

Projected expiry passed 1 September 2018, 8.1 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

11 claims: 10 independent, 1 dependent

  1. 1
    A method for providing a firewall service in a computer network, comprising the steps of:receiving a request, at a firewall, for a session from a source to a destination;ascertaining whether granting the request by the firewall requires a service which can be fulfilled by a remote server and, if so, fulfilling said request via said remote server.
  2. 2
    A method for providing a firewall service in a computer network, comprising the steps of:receiving a request, at a firewall, for a session from a source to a destination;ascertaining whether granting the request by the firewall requires a service which can be provided by a remote server and, if so, forwarding said request to said remote server.
  3. 4
    A method for providing a firewall service in a computer network, comprising the steps of:receiving a request, at a firewall, for a session from a source to a destination;ascertaining whether granting the request by the firewall requires a service which can be fulfilled by a remote proxy and, if so, fulfilling said request via said remote proxy.
  4. 5
    A method for providing a firewall service in a computer network, comprising the steps of:receiving a request, at a firewall, for a session from a source to a destination;ascertaining whether granting the request by the firewall requires a service which can be provided by a remote proxy and, if so, forwarding said request to said remote proxy.
  5. 6
    A method for providing a firewall service in a computer network, comprising the steps of:receiving a request, at a firewall, for a session from a source to a destination;ascertaining whether granting the request by the firewall requires a service which can be met by a remote proxy and, if so, setting up a dynamic rule to enable a direct connection from the source to the destination.
  6. 7
    A method as claimed in any of the preceding claims wherein the ascertaining step comprises the step of using session key data.
  7. 8
    A method as claimed in any of claims 1 to 6 wherein the ascertaining step comprises the step of using session key data in a table look-up.
  8. 9
    A method as claimed in any of the preceding claims further including the step of having the service, when performed, appear to the destination as coming from the source.
  9. 10
    A computer system for providing a firewall service in a computer network, comprising means arranged to carry out each step of a method as claimed in any of the preceding claims.
  10. 11
    A computer system for providing a firewall service in a computer network, comprising a processor which is instructed for carrying out a method as claimed in any of the preceding claims.