Distributed Firewalling in Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication networks with distributed architecture, migrating stateful firewall flows between access points (APs) and controllers during client roaming is complex and prone to connection drops, especially when traffic is load-balanced across multiple controllers, leading to increased chances of communication session failures.

Innovation Solution

Implementing a system where each controller maintains a wireless client table with MAC/AP bindings and applies stateless firewalling for packets from unassociated clients, bypassing APs and avoiding flow migration, while ensuring stateful firewalling for wired devices and trusted clients, thereby eliminating the need for firewall flow migration among multiple APs and controllers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If stateful firewalling is implemented at both APs and controllers in distributed architecture, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidfirewall configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the firewall functionality by implementing stateful firewalling at APs for local traffic and stateless firewalling at controllers for tunneled traffic. This segmentation allows each device to handle firewalling appropriately for its role, reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where the AP performs initial stateful firewalling on traffic before it reaches the controller. This intermediary firewall at the AP acts as a first line of defense, reducing the firewalling burden on the controller and simplifying the overall architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If firewall flow migration is implemented across multiple controllers, then connection continuity during roaming is improved, but device complexity and migration complexity increase

Engineering Contradiction:
Improveconnection continuityVSAvoidflow migration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent inverts the traditional approach by having the AP maintain stateful firewall flows locally rather than migrating them to the controller. When clients roam, the AP keeps the firewall state and continues to handle traffic, eliminating the need for complex flow migration across controllers while maintaining connection continuity.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The AP performs self-service by maintaining its own stateful firewall flows locally without requiring controller intervention for flow migration. This self-service capability at the AP simplifies the overall system by eliminating complex inter-controller coordination for firewall flow management.

Inventive Principle:
Principle #25Self-service

3Productivity

If traffic is load-balanced across multiple controllers, then network capacity is improved, but firewall flow migration complexity increases

Engineering Contradiction:
Improvenetwork capacityVSAvoidfirewall flow management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments firewall responsibilities by having APs handle stateful firewalling for their associated clients while controllers handle stateless firewalling for tunneled traffic. This segmentation allows load-balancing across controllers for traffic forwarding without requiring complex firewall flow migration, as each AP maintains its own firewall state independently.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8516567B2Distributed firewalling in a wireless communication network
Publication Date: 2013.08.20 EXTREME NETWORKS INC
  • US8516567B2 patent drawing
  • US8516567B2 patent drawing
  • US8516567B2 patent drawing

AI summary

A method and system for distributed collaborative firewalling in a wireless wide area communication network including a plurality of controllers, comprises a binding table that is built by the controller in response to receiving identifiers of wireless clients being served by the controller, where the binding table lists the wireless clients associated with each access port under control of the controller. A processor of the controller is operable to apply stateless firewalling on wireless communication traffic from a wireless client using the binding table, and applying, by each access port, stateful firewalling on the wireless communication traffic from the wireless client.