US 12,231,400 B2
Firewall switchover with minimized session disconnection
Tapraj Singh, Danville, CA (US); Harshavardhan Parandekar, San Jose, CA (US); Nazanin Magharei, San Jose, CA (US); Rimu Bhardwaj, Sunnyvale, CA (US); and Vikram Guleria, Fremont, CA (US)
Assigned to Palo Alto Networks, Inc., Santa Clara, CA (US)
Filed by Palo Alto Networks, Inc., Santa Clara, CA (US)
Filed on May 13, 2022, as Appl. No. 17/663,257.
Prior Publication US 2023/0370422 A1, Nov. 16, 2023
Int. Cl. H04L 9/40 (2022.01); H04L 61/2514 (2022.01); H04L 61/256 (2022.01)
CPC H04L 63/0236 (2013.01) [H04L 61/2514 (2013.01); H04L 61/256 (2013.01); H04L 63/0263 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A method comprising,
based on switchover from a first firewall to a second firewall in a first network, instructing an Internet gateway communicatively coupled to the first firewall and the second firewall over the first network to update an Internet Protocol (IP) address binding for a public IP address associated with the first and second firewalls to indicate a first private IP address of the second firewall;
initiating a first transition from an active state to a pseudo-active state for the first firewall, wherein, in the pseudo-active state, based on ingress of a first packet corresponding to a first session, the first firewall forwards the first packet along a data plane link to the second firewall;
initiating a second transition from a passive state to an active state for the second firewall, wherein, in the active state, the second firewall discards the first packet based, at least in part, on a determination of a first state of the first session indicated in the first packet; and
based on determining that an expected duration for updating the IP address binding has expired, initiating a third transition from the pseudo-active state to a passive state for the first firewall.