Adaptive Load Balancing for Firewall Security Device Clusters
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current load balancing systems for firewall clusters face limitations in handling asymmetric traffic flows, achieving high session-based performance, and managing geographically distributed firewall systems, particularly due to insufficient processing capabilities and difficulty in adapting to varying traffic demands.
Innovation Solution
A method and system for adaptive load balancing among firewall security devices, utilizing a network switching device that configures a load balancing function based on administrator inputs and maintains a load balancing table to distribute traffic among cluster units, dynamically adjusting to maintain ideal traffic distribution and handle asymmetric flows.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single network switch is used for load balancing among firewall systems, then device complexity is reduced, but the number of firewall systems that can be handled is limited
Solution Approach 1:
The system segments the load balancing function into multiple components: a central controller that manages the load balancing table and multiple network switches that execute the load balancing based on distributed table segments. This allows the system to handle more firewall systems than a single switch could manage alone.
2Productivity
If traditional load balancing systems are used, then processing capability is limited, but adapting to varying traffic demands becomes difficult
Solution Approach 1:
The load balancing system dynamically adapts to varying traffic demands through the controller that monitors traffic conditions and updates the load balancing table in real-time. The system can adjust hash function parameters, modify table entries, and rebalance traffic distribution dynamically based on current network conditions and traffic patterns.
Solution Approach 2:
The system implements feedback mechanisms where the controller monitors traffic flow patterns and performance metrics, then uses this information to optimize the load balancing table and hash function configuration. This feedback loop enables the system to adapt to changing traffic demands and improve processing capability over time.
3Reliability
If load balancing is implemented among multiple firewall systems, then high availability is improved, but handling asymmetric traffic flows becomes difficult
Solution Approach 1:
The system applies different load balancing strategies to different traffic flows based on their characteristics. The controller can identify asymmetric traffic patterns and apply appropriate hash function variations or table configurations for specific flow types, while maintaining standard load balancing for symmetric flows. This localized adaptation enables effective handling of asymmetric traffic while preserving high availability.
Data Source
AI summary
A method for balancing load among firewall security devices (FSDs) is provided. According to one embodiment, a switching device performs adaptive load balancing among cluster units of an HA cluster of firewall security devices. A load balancing (LB) function implemented by the switching device is configured based on information received from a network administrator. A LB table is maintained that forms associations between hash values output by the LB function and corresponding ports of the switching device to which the cluster units are coupled. Network traffic received by the switching device is directed to appropriate cluster units based on the LB function and the LB table. A traffic load on each of the cluster units is monitored. Responsive to a deviation from a predefined ideal traffic distribution, an attempt is made to improve performance of the HA cluster by dynamically adjusting the LB balancing table to address the deviation.


