US2023370429A1PendingUtilityA1

Upgrading firewall module on port-by-port basis

Assignee: VMWARE INCPriority: Apr 6, 2021Filed: Jul 28, 2023Published: Nov 16, 2023
Est. expiryApr 6, 2041(~14.7 yrs left)· nominal 20-yr term from priority
H04L 63/0263H04L 12/4633H04L 63/0236H04L 63/20H04L 41/082
61
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Some embodiments of the invention provide a method of upgrading a firewall module executing on a host computer to process traffic sent to and from machines executing on the host computer. While a first version of the firewall module executes on the host computer to process the traffic to and from the machines, the method loads a second version of the firewall module alongside the first version of the firewall module. For each of multiple ports associated with machines executing on the host computer for which the firewall module processes traffic sent to and from the port, the method saves a runtime state of the first version that relates to the port, transfers association of a firewall filter associated with the port from the first version to the second version, and restores the saved runtime state for the port to the second version.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A method of upgrading a firewall module executing on a host computer to process traffic sent to and from a plurality of machines executing on the host computer, the method comprising:
 while a first version of a firewall module is executing on the host computer to process the traffic to and from the plurality of machines, loading a second version of the firewall module alongside the first version of the firewall module; and   for each port of a plurality of ports associated with machines executing on the host computer for which the firewall module processes traffic sent to and from the port:
 saving a runtime state of the first version of the firewall module that relates to the port; 
 transferring association of a firewall filter associated with the port from the first version of the firewall module to the second version of the firewall module; and 
 restoring the saved runtime state for the port to the second version of the firewall module, 
   wherein the saving, transferring, and restoring is performed iteratively such that for each port after an initial port, the saving, transferring, and restoring is only performed for the port after the saved runtime state for a directly previous port has been restored to the second version of the firewall module.   
     
     
         22 . The method of  claim 21 , wherein the first version of the firewall module is an existing version of the firewall module and the second version of the firewall module is an upgraded version of the firewall module. 
     
     
         23 . The method of  claim 21  further comprising unloading the first version of the firewall module from the host computer after the saved runtime state has been restored to the second version of the firewall module for each port of the plurality of ports. 
     
     
         24 . The method of  claim 21 , wherein a plurality of non-firewall SDN (software defined network) modules executing on the host computer are upgraded before the firewall module is upgraded. 
     
     
         25 . The method of  claim 24 , wherein a runtime migrator module is responsible for upgrading the plurality of SDN modules and the firewall module, wherein the runtime migrator module is loaded onto the host computer before upgrading the plurality of SDN modules and the firewall module, and unloaded after the plurality of SDN modules and the firewall module are upgraded. 
     
     
         26 . The method of  claim 21 , wherein the first version of the firewall module is identified by a first number and the second version of the firewall module is identified by a different second number. 
     
     
         27 . The method of  claim 26 , wherein the first number is associated with a first namespace defined for the firewall module and the different second number is associated with a second namespace defined for the firewall module. 
     
     
         28 . The method of  claim 21 , wherein after the initial port of the plurality of ports is upgraded, and before a last port of the plurality of ports is upgraded, at least one port of the plurality of ports is being serviced by the first version of the firewall module while at least another port of the plurality of ports is being serviced by the second version of the firewall module. 
     
     
         29 . The method of  claim 21 , wherein each particular firewall filter is a distributed virtual (DV) firewall filter that performs filtering, encapsulation, and decapsulation of packets sent to and from the port associated with the particular DV firewall filter. 
     
     
         30 . The method of  claim 21 , wherein the runtime state for a particular port comprises (i) a plurality of active firewall rules that relate to the particular port and (ii) connection state for active connections associated with the particular port. 
     
     
         31 . A non-transitory machine-readable medium storing a program which when executed by at least one processing unit upgrades a firewall module executing on a host computer to process traffic sent to and from a plurality of machines executing on the host computer, the program comprising sets of instructions for:
 while a first version of a firewall module is executing on the host computer to process the traffic to and from the plurality of machines, loading a second version of the firewall module alongside the first version of the firewall module; and   for each port of a plurality of ports associated with machines executing on the host computer for which the firewall module processes traffic sent to and from the port:
 saving a runtime state of the first version of the firewall module that relates to the port; 
 transferring association of a firewall filter associated with the port from the first version of the firewall module to the second version of the firewall module; and 
 restoring the saved runtime state for the port to the second version of the firewall module, 
   wherein the sets of instructions for saving, transferring, and restoring are executed iteratively such that for each port after an initial port, the saving, transferring, and restoring is only performed for the port after the saved runtime state for a directly previous port has been restored to the second version of the firewall module.   
     
     
         32 . The non-transitory machine-readable medium of  claim 31 , wherein the first version of the firewall module is an existing version of the firewall module and the second version of the firewall module is an upgraded version of the firewall module. 
     
     
         33 . The non-transitory machine-readable medium of  claim 31 , wherein the program further comprises a set of instructions for unloading the first version of the firewall module from the host computer after the saved runtime state has been restored to the second version of the firewall module for each port of the plurality of ports. 
     
     
         34 . The non-transitory machine-readable medium of  claim 31 , wherein a plurality of non-firewall SDN (software defined network) modules executing on the host computer are upgraded before the firewall module is upgraded. 
     
     
         35 . The non-transitory machine-readable medium of  claim 34 , wherein the program is a runtime migrator module that is (i) loaded onto the host computer before upgrading the plurality of SDN modules and the firewall module and (ii) unloaded after the plurality of SDN modules and the firewall module are upgraded. 
     
     
         36 . The non-transitory machine-readable medium of  claim 31 , wherein the first version of the firewall module is identified by a first number and the second version of the firewall module is identified by a different second number. 
     
     
         37 . The non-transitory machine-readable medium of  claim 36 , wherein the first number is associated with a first namespace defined for the firewall module and the different second number is associated with a second namespace defined for the firewall module. 
     
     
         38 . The non-transitory machine-readable medium of  claim 31 , wherein after the initial port of the plurality of ports is upgraded, and before a last port of the plurality of ports is upgraded, at least one port of the plurality of ports is being serviced by the first version of the firewall module while at least another port of the plurality of ports is being serviced by the second version of the firewall module. 
     
     
         39 . The non-transitory machine-readable medium of  claim 31 , wherein each particular firewall filter is a distributed virtual (DV) firewall filter that performs filtering, encapsulation, and decapsulation of packets sent to and from the port associated with the particular DV firewall filter. 
     
     
         40 . The non-transitory machine-readable medium of  claim 31 , wherein the runtime state for a particular port comprises (i) a plurality of active firewall rules that relate to the particular port and (ii) connection state for active connections associated with the particular port.

Join the waitlist — get patent alerts

Track US2023370429A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.