Adaptive Load Balancing for Firewall Security Device Clusters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current load balancing systems for firewall clusters face limitations in handling asymmetric traffic flows, achieving high session-based performance, and managing geographically distributed firewall systems, particularly due to insufficient processing capabilities and difficulty in adapting to varying traffic demands.

Innovation Solution

A method and system for adaptive load balancing among firewall security devices, utilizing a network switching device that configures a load balancing function based on administrator inputs and maintains a load balancing table to distribute traffic among cluster units, dynamically adjusting to maintain ideal traffic distribution and handle asymmetric flows.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single network switch is used for load balancing among firewall systems, then device complexity is reduced, but the number of firewall systems that can be handled is limited

Engineering Contradiction:
Improveload balancing arrangementVSAvoidnumber of firewall systems
Core Design Contradiction:
Device complexityVSQuantity of substance

Solution Approach 1:

The system segments the load balancing function into multiple components: a central controller that manages the load balancing table and multiple network switches that execute the load balancing based on distributed table segments. This allows the system to handle more firewall systems than a single switch could manage alone.

Inventive Principle:
Principle #1Segmentation

2Productivity

If traditional load balancing systems are used, then processing capability is limited, but adapting to varying traffic demands becomes difficult

Engineering Contradiction:
Improveprocessing capabilityVSAvoidadaptation to varying traffic demands
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The load balancing system dynamically adapts to varying traffic demands through the controller that monitors traffic conditions and updates the load balancing table in real-time. The system can adjust hash function parameters, modify table entries, and rebalance traffic distribution dynamically based on current network conditions and traffic patterns.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where the controller monitors traffic flow patterns and performance metrics, then uses this information to optimize the load balancing table and hash function configuration. This feedback loop enables the system to adapt to changing traffic demands and improve processing capability over time.

Inventive Principle:
Principle #23Feedback

3Reliability

If load balancing is implemented among multiple firewall systems, then high availability is improved, but handling asymmetric traffic flows becomes difficult

Engineering Contradiction:
Improvehigh availabilityVSAvoidhandling asymmetric traffic flows
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system applies different load balancing strategies to different traffic flows based on their characteristics. The controller can identify asymmetric traffic patterns and apply appropriate hash function variations or table configurations for specific flow types, while maintaining standard load balancing for symmetric flows. This localized adaptation enables effective handling of asymmetric traffic while preserving high availability.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10084751B2Load balancing among a cluster of firewall security devices
Publication Date: 2018.09.25 FORTINET INC
  • US10084751B2 patent drawing
  • US10084751B2 patent drawing
  • US10084751B2 patent drawing

AI summary

A method for balancing load among firewall security devices (FSDs) is provided. According to one embodiment, a switching device performs adaptive load balancing among cluster units of an HA cluster of firewall security devices. A load balancing (LB) function implemented by the switching device is configured based on information received from a network administrator. A LB table is maintained that forms associations between hash values output by the LB function and corresponding ports of the switching device to which the cluster units are coupled. Network traffic received by the switching device is directed to appropriate cluster units based on the LB function and the LB table. A traffic load on each of the cluster units is monitored. Responsive to a deviation from a predefined ideal traffic distribution, an attempt is made to improve performance of the HA cluster by dynamically adjusting the LB balancing table to address the deviation.