Distributed Firewalling in Wireless Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless communication networks with distributed architecture, migrating stateful firewall flows between access points (APs) and controllers during client roaming is complex and prone to connection drops, especially when traffic is load-balanced across multiple controllers, leading to increased chances of communication session failures.
Innovation Solution
Implementing a system where each controller maintains a wireless client table with MAC/AP bindings and applies stateless firewalling for packets from unassociated clients, bypassing APs and avoiding flow migration, while ensuring stateful firewalling for wired devices and trusted clients, thereby eliminating the need for firewall flow migration among multiple APs and controllers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If stateful firewalling is implemented at both APs and controllers in distributed architecture, then security is improved, but device complexity increases
Solution Approach 1:
The patent segments the firewall functionality by implementing stateful firewalling at APs for local traffic and stateless firewalling at controllers for tunneled traffic. This segmentation allows each device to handle firewalling appropriately for its role, reducing overall system complexity while maintaining security.
Solution Approach 2:
The patent introduces an intermediary mechanism where the AP performs initial stateful firewalling on traffic before it reaches the controller. This intermediary firewall at the AP acts as a first line of defense, reducing the firewalling burden on the controller and simplifying the overall architecture.
2Reliability
If firewall flow migration is implemented across multiple controllers, then connection continuity during roaming is improved, but device complexity and migration complexity increase
Solution Approach 1:
The patent inverts the traditional approach by having the AP maintain stateful firewall flows locally rather than migrating them to the controller. When clients roam, the AP keeps the firewall state and continues to handle traffic, eliminating the need for complex flow migration across controllers while maintaining connection continuity.
Solution Approach 2:
The AP performs self-service by maintaining its own stateful firewall flows locally without requiring controller intervention for flow migration. This self-service capability at the AP simplifies the overall system by eliminating complex inter-controller coordination for firewall flow management.
3Productivity
If traffic is load-balanced across multiple controllers, then network capacity is improved, but firewall flow migration complexity increases
Solution Approach 1:
The patent segments firewall responsibilities by having APs handle stateful firewalling for their associated clients while controllers handle stateless firewalling for tunneled traffic. This segmentation allows load-balancing across controllers for traffic forwarding without requiring complex firewall flow migration, as each AP maintains its own firewall state independently.
Data Source
AI summary
A method and system for distributed collaborative firewalling in a wireless wide area communication network including a plurality of controllers, comprises a binding table that is built by the controller in response to receiving identifiers of wireless clients being served by the controller, where the binding table lists the wireless clients associated with each access port under control of the controller. A processor of the controller is operable to apply stateless firewalling on wireless communication traffic from a wireless client using the binding table, and applying, by each access port, stateful firewalling on the wireless communication traffic from the wireless client.


