Shared Firewall Policy Configuration Across Hierarchical Groups

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large-scale deployments face challenges in efficiently managing and maintaining configuration policies across numerous systems or endpoints due to the hierarchical structure, leading to inefficiencies and increased error likelihood from manual configuration processes.

Innovation Solution

A system and method for managing policy configurations that enables sharing and deployment of pre-defined configurations across multiple entities within an entity hierarchy, utilizing a management platform to create, associate, and deploy snippets of configurations, with features like version control, conflict resolution, and role-based permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If administrators individually configure each leaf node manually, then configuration flexibility and control are maintained, but time consumption and error likelihood increase significantly

Engineering Contradiction:
ImproveConfiguration management easeVSAvoidTime for configuration updates
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent combines multiple individual configuration operations into a single bulk operation. Administrators can select multiple leaf nodes and apply configuration changes to all selected nodes simultaneously through a unified interface, eliminating the need to configure each node separately and significantly reducing time consumption.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements a universal configuration management system that can handle multiple types of configuration changes across different leaf nodes through a single interface. The system provides multi-functional capabilities including bulk selection, various configuration options, and unified deployment, allowing administrators to manage diverse configuration tasks using one standardized tool.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If administrators individually configure each leaf node, then specific policy configurations can be applied, but consistency and uniformity across the hierarchy become difficult to maintain

Engineering Contradiction:
ImproveConfiguration consistencyVSAvoidConfiguration management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges configuration operations across multiple leaf nodes into a single unified action. By selecting multiple nodes and applying configuration changes simultaneously, the system ensures that all selected nodes receive identical configuration updates, thereby maintaining consistency and uniformity across the hierarchical structure.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements feedback mechanisms that provide administrators with visibility into the configuration status across all leaf nodes. The system displays which nodes have been configured, which are pending, and which have errors, allowing administrators to monitor and maintain configuration consistency across the entire hierarchy.

Inventive Principle:
Principle #23Feedback

3Productivity

If manual configuration processes are used across large numbers of systems, then individual system requirements can be addressed, but productivity and efficiency decrease

Engineering Contradiction:
ImproveConfiguration deployment speedVSAvoidNumber of configuration operations
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent combines numerous individual configuration operations into a single bulk operation. Administrators can select multiple leaf nodes and apply configuration changes to all selected nodes simultaneously, reducing the number of separate operations from potentially hundreds or thousands of individual configurations to a single unified deployment action.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent allows administrators to pre-select multiple leaf nodes and prepare configuration changes before deployment. The system enables pre-configuration review, selection of target nodes, and validation of configuration parameters before actual deployment, streamlining the overall process and improving productivity by reducing preparatory time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12483534B2Alternate means to sharing configuration across multiple firewalls or groups of firewalls
Publication Date: 2025.11.25 PALO ALTO NETWORKS INC
  • US12483534B2 patent drawing
  • US12483534B2 patent drawing
  • US12483534B2 patent drawing

AI summary

The present application discloses a method, system, and computer system for providing policy configurations. The method includes (i) receiving a set of shared policy configurations, (ii) sharing the set of shared policy configurations across a plurality of entities, and (iii) deploying the set of shared policy configurations across the plurality of entities.