发明名称 Provisioning network access through a firewall
摘要 A method may include determining one or more rules and communicating the one or more rules to a firewall, where the firewall receives a data unit and determines, based on the one or more rules, whether to forward the data unit to a destination address; receiving a redirection of a device from the firewall when the firewall determines not to forward the data unit to the destination address; receiving an indication that the firewall did not forward the data unit to the destination address; and determining a new rule to allow the firewall to forward the data unit to the destination address and communicating the new rule to the firewall; and redirecting the device to the destination address.
申请公布号 US9350704(B2) 申请公布日期 2016.05.24
申请号 US201414454912 申请日期 2014.08.08
申请人 Juniper Networks, Inc. 发明人 Chickering Roger A.
分类号 H04L29/06 主分类号 H04L29/06
代理机构 Harrity & Harrity, LLP 代理人 Harrity & Harrity, LLP
主权项 1. A method comprising: receiving, by a firewall device, one or more rules for provisioning access to a resource; receiving, by the firewall device, a data unit from a device; determining, by the firewall device and based on the one or more rules, not to forward the data unit to a destination address associated with the resource; redirecting, by the firewall device, the device to a server associated with provisioning access to the resource, the firewall device redirecting the device to the server based on determining not to forward the data unit to the destination address; receiving, by the firewall device and from the server, a rule for allowing the firewall device to provision access to the resource for the device, the rule being received by the firewall device after the server determines that the firewall device should provision access to the resource for the device; provisioning, by the firewall device, access to the resource for the device based on the rule; providing, by the firewall device and to the server, information indicating that the access to the resource for the device has been provisioned, the information being used to permit the server to redirect the device to the destination address via the firewall device; and allowing, by the firewall device, the device to access the resource, based on provisioning the access to the resource, after the device is redirected to the destination address.
地址 Sunnyvale CA US