发明名称 Configuring and managing remote security devices
摘要 Techniques for configuring and managing remote security devices are disclosed. In some embodiments, configuring and managing remote security devices includes receiving a registration request for a remote security device at a device for configuring and managing a plurality of remote security devices; verifying the registration request to determine that the remote security device is an authorized remote security device for an external network; and sending a response identifying one or more security gateways to the remote security device, in which the remote security device is automatically configured to connect to each of the one or more security gateways using a distinct Layer 3 protocol tunnel (e.g., a virtual private network (VPN)).
申请公布号 US9413723(B2) 申请公布日期 2016.08.09
申请号 US201414495804 申请日期 2014.09.24
申请人 Palo Alto Networks, Inc. 发明人 Chen Yueh-Zen;Xu Wilson;Gill Monty Sher
分类号 H04L29/06;G06F21/62 主分类号 H04L29/06
代理机构 Van Pelt, Yi & James LLP 代理人 Van Pelt, Yi & James LLP
主权项 1. A system, comprising: a processor of a device for configuring and managing a plurality of remote security devices configured to: receive a registration request for a remote security device, wherein the registration request includes a serial number of the remote security device, a media access control (MAC) address of the remote security device, or a user entered unique identifier, or any combination thereof;verify the registration request to determine that the remote security device is an authorized remote security device for an external network;send a response identifying one or more security gateways to the remote security device, wherein the sending of the response includes sending a certificate to the remote security device to establish an associated tunnel;identify an updated prioritized list of two or more security gateways to the remote security device, wherein the remote security device is automatically configured to connect to a second security gateway over the remote security device's associated tunnel, wherein the second security gateway is included in the updated prioritized list of two or more security gateways, wherein each of the two or more security gateways performs security processing on received outbound network traffic based on a security policy, and wherein the remote security device routes traffic based on an availability of security gateways identified in the updated prioritized list of two or more security gateways; andrevoke the certificate issued to the remote security device, wherein the remote security device can no longer connect to a first security gateway after revocation of its certificate; and a memory of the device for configuring and managing a plurality of remote security devices coupled to the processor of the device for configuring and managing a plurality of remote security devices and configured to provide the processor of the device for configuring and managing a plurality of remote security devices with instructions.
地址 Santa Clara CA US