VPN Gateway Captive Portal Authentication via Dynamic Firewall Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in securely accessing captive Wi-Fi networks for devices protected by virtual private network (VPN) gateways, as bypassing these gateways to interact with captive portals compromises security, and existing solutions do not effectively manage network traffic to allow secure Internet access while maintaining protection.

Innovation Solution

The proposed solution configures firewall rules of the VPN gateway to probe the captive network, discover the captive portal, redirect network traffic for authentication, and establish a VPN tunnel, minimizing exposure to public networks while ensuring secure access, using HTTP requests and AI-driven templates to manage access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the VPN gateway is bypassed to allow interaction with the captive portal, then network access to the captive network is achieved, but the security of the devices protected by the VPN gateway is lowered

Engineering Contradiction:
Improvenetwork accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a captive portal detection mechanism as an intermediary layer between the VPN gateway and the captive network. This mechanism detects captive portals and manages authentication requests without requiring complete bypass of the VPN gateway, thereby maintaining security while enabling network access. The intermediary handles the interaction with captive portals through controlled firewall rule modifications rather than full gateway bypass.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements dynamic firewall rule configuration that automatically adjusts network traffic handling based on detected captive portal conditions. The firewall rules are modified temporarily to allow captive portal authentication, then restored to maintain security. This dynamic adjustment enables the system to adapt between security and accessibility needs without permanent compromise.

Inventive Principle:
Principle #15Dynamics

2Reliability

If the VPN gateway strictly enforces security rules, then devices are protected from public network threats, but automatic authentication with captive portals cannot be performed

Engineering Contradiction:
Improvesecurity protectionVSAvoidautomatic authentication
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent enables the system to perform self-service authentication by automatically detecting captive portals and handling authentication requests without requiring manual user intervention. The VPN gateway itself performs the authentication sequence by dynamically modifying firewall rules to allow captive portal communication, then restoring security rules after authentication completes. This self-service approach maintains automation while preserving security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary detection of captive portals before attempting VPN tunnel establishment. The system proactively identifies captive network conditions and prepares authentication sequences in advance, modifying firewall rules beforehand to enable automatic authentication. This preliminary action prevents authentication failures that would occur if strict security rules blocked captive portal communication.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If firewall rules are modified to allow captive portal access, then authentication is enabled, but the attackable surface area of the protected network increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidattackable surface area
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by making firewall rule modifications highly specific and targeted. Instead of broad rule changes that would open the entire network to attacks, the system modifies only the specific firewall rules necessary for captive portal authentication. The changes are localized to authentication traffic only, preserving security for all other network communications while enabling authentication capability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by making minimal necessary modifications to firewall rules - only enough to allow captive portal authentication traffic. The system avoids excessive rule changes that would unnecessarily expand the attackable surface area. After authentication completes, the partial modifications are reverted, ensuring that only the minimum required change is applied temporarily.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10439990B2System and method to configure a firewall for access to a captive network
Publication Date: 2019.10.08 BARRACUDA NETWORKS INC
  • US10439990B2 patent drawing
  • US10439990B2 patent drawing
  • US10439990B2 patent drawing

AI summary

An approach is proposed that contemplates system and method to configure firewall rules of a VPN gateway of a protected network so that users of devices in the protected network can access Internet securely via a captive network. First, the proposed approach enables the VPN gateway to probe the captive network with an HTTP request to discover a captive portal of the captive network. After the captive portal is discovered, one or more firewall rules of the VPN gateway are added so that network traffic from the devices in the protected network are redirected to the captive portal for authentication. Once the users are authenticated and a VPN tunnel is established between the VPN gateway and a remote VPN tunnel terminal, the firewall rules previously added are removed from the VPN gateway and all network traffic from the devices in the protected network are routed over the VPN tunnel.