US 11,888,815 B2
Scalable and on-demand multi-tenant and multi region secure network
Amit Bareket, Tel-Aviv (IL); and Sagi Gidali, Rishon-LeZion (IL)
Assigned to CHECK POINT SSE SOLUTIONS LTD, Tel-Aviv (IL)
Filed by CHECK POINT SSE SOLUTIONS LTD., Tel-Aviv (IL)
Filed on Nov. 8, 2022, as Appl. No. 17/982,561.
Application 17/982,561 is a continuation of application No. 16/988,777, filed on Aug. 10, 2020, granted, now 11,502,993.
Prior Publication US 2023/0064092 A1, Mar. 2, 2023
Int. Cl. H04L 9/40 (2022.01); H04L 45/02 (2022.01); H04L 12/66 (2006.01); H04L 61/5007 (2022.01)
CPC H04L 63/0236 (2013.01) [H04L 12/66 (2013.01); H04L 45/04 (2013.01); H04L 61/5007 (2022.05); H04L 63/029 (2013.01); H04L 63/0272 (2013.01)] 15 Claims
OG exemplary drawing
 
1. A system for applying security policies in a cloud based network segmented to a plurality of virtual private networks based on Internet Protocol (IP) segmentation, comprising:
at least one processor configured to:
receive at least one security policy defined for at least one of a plurality of private virtual networks of at least one multi-tenant multi-regional cloud based network constructed segmented to a plurality of segments each serving as a respective one of the plurality of private virtual networks, each of the plurality of segments is mapped by a respective IP address range which is a low layer IP address range and is non-conflicting with the low layer IP address range of any other of the plurality of segments;
deploy automatically at least one security engine configured to apply the at least one security policy for at least one of a plurality of client devices accessing the at least one private virtual network by:
intercepting at least one packet transmitted by the at least one client device which is assigned an IP address in the IP address range mapping the respective segment serving as the at least one virtual private network,
identifying the IP address of the at least one client device in the at least one intercepted packet, and
applying the at least one security policy according to the identified IP address.