Distributed Firewall Control Plane for Switching Stacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In centralized communication networks, the non-uniform configuration and increased administration overhead due to varying firewall capabilities across multiple switching units lead to inefficiencies and higher costs, especially when not all units have hardware or software firewall capabilities.
Innovation Solution
A distributed control plane mechanism optimally routes packets to available firewall modules within a switching stack, enabling stateful capabilities and centralized configuration and administration, allowing for flexible deployment and reduced packet routing overhead.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized communication scheme with controller is used, then network control and security are improved, but device complexity and administration overhead increase due to non-uniform configuration requirements
Solution Approach 1:
The patent extracts the firewall capability from individual switching units and consolidates it into a centralized controller. The controller receives packets from multiple switching units, performs deep packet inspection and firewall functions centrally, then forwards packets to appropriate destinations. This eliminates the need for each switching unit to have built-in firewall capabilities, achieving uniform configuration while maintaining strong network control and security.
Solution Approach 2:
The controller acts as an intermediary between multiple switching units. Instead of each switching unit independently performing firewall functions, packets are routed through the controller which mediates the firewall processing. The controller receives packets from switching units without firewalls, processes them centrally, and forwards them to destinations or back to switching units for forwarding.
2Reliability
If enhanced firewall capabilities are added to all switching units, then network security is improved, but cost and administration overhead increase
Solution Approach 1:
The patent extracts the expensive and complex firewall functionality from individual switching units and consolidates it into a centralized controller. This allows standard, cost-effective switching units to be deployed without requiring expensive firewall hardware or software licenses on each unit, while the centralized controller provides comprehensive firewall capabilities for the entire network.
Solution Approach 2:
The controller provides universal firewall functionality to multiple switching units that individually lack this capability. Instead of each switching unit having dedicated firewall hardware, the controller serves all switching units by receiving their packets, performing firewall inspection, and forwarding them appropriately. This multi-functional approach provides security to the entire network through a single centralized system.
3Productivity
If each switching unit has firewall capabilities, then distributed security processing is improved, but administration overhead increases due to non-uniform configuration
Solution Approach 1:
The patent extracts firewall processing from distributed switching units and consolidates it in a centralized controller. This eliminates the need for administrators to configure and manage firewall settings on multiple individual devices, significantly reducing administration overhead. The controller centrally manages all firewall policies and packet processing for the entire network.
Solution Approach 2:
The patent merges the firewall processing functions that were previously distributed across multiple switching units into a single centralized controller. By combining these functions, the system achieves simplified administration while maintaining efficient packet processing. The controller aggregates packets from multiple switching units and performs firewall inspection centrally, then distributes the results back to the network.
Data Source
AI summary
According to one embodiment, a method comprises an operation of identifying a plurality of network devices, and detecting a presence of firewall processing functionality in a subset of the network devices. At least one of the network devices not in the firewall subset is configured to forward packets to a network device of the subset for firewall processing.


