Distributed Firewall Manager for Network Backbone Latency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network communication systems face inefficiencies and latency due to centralized firewall management, particularly in long haul network communications, which hinder optimal utilization of network backbone performance and introduce 'trombone' effects.
Innovation Solution
A distributed firewall management system with a centralized network controller that integrates multiple client site network components, enabling template-based policy management, asset aliasing, and intelligent packet distribution across diverse network connections for improved throughput and reduced latency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If centralized firewall management is used, then ease of operation is improved, but latency increases due to trombone network effects
Solution Approach 1:
The system segments the centralized firewall management function into distributed firewall instances deployed at multiple network locations. Each location has its own firewall that can independently manage local traffic, eliminating the need for all traffic to traverse back to a central management site and thus reducing latency while maintaining centralized policy control through the controller.
Solution Approach 2:
The system introduces a distributed controller as an intermediary that manages firewall policies across multiple locations without requiring traffic to pass through a central site. The controller communicates with firewalls at various locations via the network backbone, enabling centralized management while avoiding the trombone effect of traffic routing.
2Productivity
If bonded/aggregated links are used to increase throughput, then network performance is improved, but network impedance increases causing long haul effects
Solution Approach 1:
The system implements local firewall management at each network location, allowing traffic to be processed locally without traversing long distances through the network backbone. This local processing quality reduces the impact of network impedance and long haul effects while bonded/aggregated links maintain high throughput for traffic that does require backbone traversal.
3Ease of operation
If traffic is forwarded to remote central monitoring site, then centralized control is achieved, but inefficiencies and latency increase
Solution Approach 1:
The system segments the centralized control function into a distributed controller that can manage firewalls at multiple locations simultaneously without requiring traffic to be forwarded to a single remote central monitoring site. This segmentation allows efficient local traffic processing while maintaining centralized policy control.
Solution Approach 2:
The system transitions from a single-point centralized control model to a multi-point distributed control model. The controller operates across multiple dimensions by simultaneously managing firewalls at various locations through the network backbone, eliminating the need to forward all traffic to a single remote site and improving overall processing efficiency.
Data Source
AI summary
A network system is provided between at least a first client site and a second client site, the first and the second client site are at a distance from one another. A client site network component is implemented at least at the first client site, the client site network component bonding or aggregating one or more diverse network connections so as to configure a bonded/aggregated connection that has increased throughput. At least one network server component may be configured to connect to the client site network component using the bonded/aggregated connection. A cloud network controller may be configured to manage the data traffic and a virtual edge providing transparent lower-link encryption for the bonded/aggregated connection between the client site network component and the network server component.


