Dynamic Firewall Policy Enforcement in Virtualized Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtualized computing environments pose challenges for firewall rules that rely on static information, such as static IP addresses, as virtual machines can be dynamically migrated, leading to changes in IP addresses and requiring dynamic policy enforcement.

Innovation Solution

A data appliance is configured to enforce policies using dynamic group definitions and virtual machine information, allowing for the creation of abstracted dynamic address objects that can be updated in real-time, ensuring policies are applied regardless of IP address changes, with the help of an agent and log server that collect and provide VM information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If firewall rules rely on static IP addresses, then rule simplicity is maintained, but adaptability to virtual machine migration deteriorates

Engineering Contradiction:
Improveadaptability to VM migrationVSAvoidfirewall rule complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies dynamics by transitioning from static IP address-based firewall rules to dynamic group-based rules. The system continuously updates firewall rules based on real-time VM information from the virtualization manager, allowing rules to automatically adapt when VMs are migrated between hosts. This enables the firewall to maintain security policies without manual intervention despite the dynamic nature of virtualized environments.

Inventive Principle:
Principle #15Dynamics

2Productivity

If manual updates of IP addresses are performed, then policy accuracy is maintained, but time consumption and operational overhead increase

Engineering Contradiction:
Improvepolicy update efficiencyVSAvoidtime for manual updates
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system implements self-service by automatically collecting VM information from the virtualization manager and dynamically updating firewall rules without requiring manual intervention. The firewall appliance receives VM data (including IP addresses, host information, and virtualization metadata) and autonomously generates and updates the appropriate firewall rules, eliminating the need for administrators to manually track and update IP addresses during VM migration.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent employs feedback mechanisms where the virtualization manager continuously provides updated VM information to the firewall appliance. This real-time feedback loop ensures that the firewall always has current information about VM locations and can automatically adjust rules accordingly, creating a closed-loop system that maintains policy accuracy without manual input.

Inventive Principle:
Principle #23Feedback

3Reliability

If static firewall rules are used, then rule stability is maintained, but reliability in dynamic environments deteriorates

Engineering Contradiction:
Improvepolicy enforcement reliabilityVSAvoidfirewall rule stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The system ensures continuous policy enforcement by maintaining constant communication with the virtualization manager to receive real-time VM information. The firewall appliance continuously updates its ruleset based on current VM states, ensuring that security policies remain effective and reliable even as VMs are dynamically migrated throughout the infrastructure.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS9619260B2Policy enforcement in a virtualized environment
Publication Date: 2017.04.11 PALO ALTO NETWORKS INC
  • US9619260B2 patent drawing
  • US9619260B2 patent drawing
  • US9619260B2 patent drawing

AI summary

Policy enforcement in an environment that includes virtualized systems is disclosed. Virtual machine information associated with a first virtual machine instance executing on a host machine is received. The information can be received from a variety of sources, including an agent, a log server, and a management infrastructure associated with the host machine. A policy is applied based at least in part on the received virtual machine information.