US 12,231,404 B1
Systems and methods for firewall deployment in a cloud computing environment
Xiaobo Sherry Wei, Palo Alto, CA (US); and Shanshan Xu, Fremont, CA (US)
Assigned to Aviatrix Systems, Inc., Santa Clara, CA (US)
Filed by AVIATRIX SYSTEMS, INC., Santa Clara, CA (US)
Filed on Mar. 29, 2021, as Appl. No. 17/216,596.
Claims priority of provisional application 63/069,653, filed on Aug. 24, 2020.
Int. Cl. H04L 29/00 (2006.01); H04L 9/40 (2022.01); H04L 45/00 (2022.01)
CPC H04L 63/0263 (2013.01) [H04L 45/22 (2013.01); H04L 63/0236 (2013.01); H04L 63/0272 (2013.01); H04L 63/20 (2013.01)] 19 Claims
OG exemplary drawing
 
1. A distributed cloud computing system comprising:
a controller configured to deploy a transit gateway, a first gateway in a first virtual private cloud network (VPC), a second gateway in a first security VPC, and a third gateway in a second security VPC, wherein:
the second gateway is connected to a first firewall instance deployed within the first security VPC,
the third gateway is deployed between the transit gateway and an on-premises component and connected to a second firewall instance deployed within the second security VPC,
and the transit gateway and the first gateway are in direct communication with each other; and
logic, stored on non-transitory, computer-medium, that, upon execution by one or more processors, causes performance of operations including:
inspecting, via the first security VPC, egress traffic; and
inspecting, via the second security VPC, network traffic exchanged between spoke VPCs and between spoke VPCs and the on-premises component.