Juniper Networks, Inc.
Apparatus, system, and method for applying firewall rules on packets in kernel space on network devices

Last updated:

Abstract:

A disclosed method for applying firewall rules on packets in kernel space on network devices may include (1) intercepting, via a socket-intercept layer in kernel space on a routing engine of a network device, a packet that is destined for a remote device and then, in response to intercepting the packet in kernel space on the routing engine, (2) identifying an egress interface index that specifies an egress interface that (A) is external to kernel space and (B) is capable of forwarding the packet from the network device to the remote device, and (3) applying, on the packet in kernel space, at least one firewall rule based at least in part on the egress interface index before the packet egresses from the routing engine. Various other apparatuses, systems, and methods are also disclosed.

Status:
Grant
Type:

Utility

Filling date:

16 Oct 2019

Issue date:

6 Oct 2020