System, method and program for managing firewalls
Abstract
Computer system, method and program for managing a firewall. First program instructions identify a first rule of the firewall. The first rule specifies a permitted message flow through the firewall to or from an IP address of a computer. The computer resides on a network. Second program instructions identify a second rule of the firewall. The second rule specifies a permitted message flow through the firewall to or from an IP address corresponding to the network. Message flows through the firewall to all computers on the network are permitted pursuant to the second rule. Third program instructions delete the first rule from the firewall based on the identification of the second rule and the computer residing on the network. Other program instructions identify and delete stale rules which are not needed. Other program instructions automatically identify rules for a new server added to a cluster.
Claims
exact text as granted — not AI-modified1 . A computer program product for managing a firewall, said computer program product comprising:
a computer readable media; first program instructions to identify a first rule of said firewall, said first rule specifying a permitted message flow through the firewall to or from an IP address of a computer, said computer residing on a network; second program instructions to identify a second rule of said firewall, said second rule specifying a permitted message flow through the firewall to or from an IP address corresponding to said network, such that message flows through the firewall to all computers on said network are permitted pursuant to said second rule; third program instructions to delete said first rule from said firewall based on the identification of said second rule and said computer residing on said network; and wherein said first, second and third program instructions are stored on said media in functional form.
2 . A computer program product as set forth in claim 1 wherein said network is a subnet.
3 . A computer program product as set forth in claim 1 wherein:
said first rule specifies a permitted message flow through the firewall from said IP address of said computer; and said second rule specifies a permitted message flow through the firewall from said network.
4 . A computer program product as set forth in claim 1 wherein:
said first rule specifies a permitted message flow through the firewall to said IP address of said computer; and said second rule specifies a permitted message flow through the firewall to said network.
5 . A computer program product for managing a firewall, said computer program product comprising:
a computer readable media; first program instructions to identify a first rule of said firewall, said first rule specifying a permitted message flow through the firewall to or from an IP address of a first computer, said first computer being a member of a group of computers identified by said firewall; second program instructions to identify a second rule of said firewall, said second rule specifying a permitted message flow through the firewall to or from said group of computers, such that message flows through the firewall to all computers of said group are permitted pursuant to said second rule; third program instructions to delete said first rule from said firewall based on the identification of said second rule and said computer being a member of said group; and wherein said first, second and third program instructions are stored on said media in functional form.
6 . A computer program product as set forth in claim 5 wherein said network is a subnet.
7 . A computer program product as set forth in claim 5 wherein:
said first rule specifies a permitted message flow through the firewall from said IP address of said first computer; and said second rule specifies a permitted message flow through the firewall from said group.
8 . A computer program product as set forth in claim 5 wherein:
said first rule specifies a permitted message flow through the firewall to said IP address of said first computer; and said second rule specifies a permitted message flow through the firewall to said group.
9 . A computer program product for managing a firewall for a first server added to a cluster of a plurality of other servers, said firewall comprising a multiplicity of rules of permitted message flows through said firewall, said computer program product comprising:
a computer readable media; first program instructions to identify a first plurality of said rules of permitted message flows through said firewall to or from said plurality of servers, respectively, said first plurality of rules being substantially the same as each other except for specification of different respective ones of said plurality of servers as a source or destination of said messages; and second program instructions, responsive to the identification of said first plurality of rules by said first program instructions, to automatically generate a new rule for said firewall, said new rule being substantially the same as said first plurality of rules except said new rule specifies said first server instead of said other servers in said cluster; and wherein said multiplicity of rules in said firewall include a rule for a permitted message flow to or from an application in one of said other servers, and the other servers in said cluster do not include a copy of said application, and there is no corresponding rule in said firewall for said application for said other servers in said cluster; and said first and second program instructions are stored on said media in functional form.
10 . A computer program product as set forth in claim 9 further comprising the step of automatically installing said new rule in said firewall.
11 . A computer program product as set forth in claim 9 wherein:
said plurality of rules specify a permitted message flow through the firewall from said IP addresses of said plurality of computers, respectively.
12 . A computer program product as set forth in claim 9 wherein:
said plurality of rules specify a permitted message flow through the firewall to said IP addresses of said plurality of computers, respectively.
13 . A computer program product for managing a firewall, said firewall comprising a multiplicity of rules of permitted message flows through said firewall, said computer program product comprising:
a computer readable media; first program instructions to identify one or more of said rules that have not been used in a predetermined time to authorize an actual, respective message flow through said firewall; second program instructions to determine if said one or more rules are listed as needed even though they have not been used in said predetermined time to authorize an actual, respective message flow through said firewall; and third program instructions to notify an administrator of any of said one or more rules that have not been used in said predetermined time to authorize an actual, respective message flow through said firewall and are not listed as needed; and wherein said first, second and third program instructions are stored on said media in functional form.
14 . A computer program product as set forth in claim 13 wherein the list of needed rules comprises a rule to permit a message flow through said firewall to or from a port of a disaster recovery computer.
15 . A computer program product as set forth in claim 13 further comprising:
fourth program instructions to receive a command from an administrator to delete from said firewall said any of said one or more rules that have not been used in said predetermined time to authorize an actual, respective message flow through said firewall and are not listed as needed; and fifth program instructions, responsive to said command, to send another command to said firewall to delete from said firewall said any of said one or more rules that have not been used in said predetermined time to authorize an actual, respective message flow through said firewall and are not listed as needed; and wherein said fourth and fifth program instructions are stored on said media in functional form.Join the waitlist — get patent alerts
Track US2008148382A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.