Dynamic Firewall Configuration for Virtual Network IP Changes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewalls in virtual networks face challenges in maintaining access to services when IP addresses change frequently, requiring labor-intensive manual reconfiguration, which is unsuitable for dynamic environments.

Innovation Solution

A system and method for dynamic firewall configuration that monitors IP address changes in virtual networks, using a hosted service metadata collector to notify a firewall policy management interface, which automatically configures the firewall to allow access to the service, reducing the need for manual reconfiguration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual firewall configuration is used to control access to hosted services, then firewall security control is maintained, but labor intensity increases and the system cannot adapt to frequent IP address changes

Engineering Contradiction:
Improveadaptability to IP address changesVSAvoidautomation of firewall configuration
Core Design Contradiction:
Adaptability or versatilityVSExtent of automation

Solution Approach 1:

The system implements a feedback mechanism where the metadata collector continuously monitors hosted service IP addresses and automatically notifies the firewall policy management interface of any changes. This closed-loop feedback system enables the firewall configuration to adapt dynamically to IP address changes without manual intervention, resolving the contradiction between adaptability and automation.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The firewall configuration system performs self-service by automatically detecting IP address changes through metadata collection and reconfiguring itself without requiring manual IT department intervention. This self-service capability enables the system to maintain both high adaptability to IP changes and operational automation simultaneously.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual firewall reconfiguration is performed when IP addresses change, then access control security is maintained, but downtime increases and productivity decreases

Engineering Contradiction:
Improvefirewall access controlVSAvoidservice accessibility
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary action by proactively monitoring and detecting IP address changes before they impact service accessibility. The metadata collector continuously tracks IP addresses and triggers automatic firewall reconfiguration in advance, ensuring that access control security is maintained while minimizing service downtime and maintaining productivity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system ensures continuity of useful action by implementing continuous monitoring of IP addresses and maintaining uninterrupted firewall access control. The automatic detection and reconfiguration process runs continuously without service interruption, preserving both security reliability and service productivity simultaneously.

Inventive Principle:
Principle #20Continuity of useful action

3Adaptability or versatility

If frequent firewall reconfiguration is performed to accommodate IP address changes, then access to hosted services is maintained, but labor intensity and operational complexity increase

Engineering Contradiction:
Improveresponse to IP address changesVSAvoidfirewall management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary metadata collector that automatically gathers IP address information and mediates between the dynamic hosted services and the firewall configuration system. This intermediary layer handles the complexity of frequent IP changes and firewall reconfiguration automatically, enabling the system to maintain high adaptability while reducing the perceived operational complexity for users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11212260B2Dynamic firewall configuration and control for accessing services hosted in virtual networks
Publication Date: 2021.12.28 KEYSIGHT TECHNOLOGIES INC
  • US11212260B2 patent drawing
  • US11212260B2 patent drawing
  • US11212260B2 patent drawing

AI summary

A method for dynamic firewall configuration for accessing service hosted in virtual networks includes monitoring, in a virtual network, changes in an Internet protocol (IP) address of a service hosted in a virtual network. The method further includes detecting a change the IP address of the service hosted in the virtual network. The method further includes communicating notification of the change in IP address to a firewall policy management interface. The method further includes, automatically configuring a firewall to allow access to the service hosted in the virtual network.