EMACVLAN FDB Synchronization in HA Clusters
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing VLAN architectures face limitations in supporting high availability (HA) active-active mode and suffer from reduced concurrent sessions and degraded throughput when using intermediate front-end transparent (TP) VDOMs to connect virtual firewalls with external network devices.
Innovation Solution
The implementation of an enhanced media access control (MAC) VLAN (EMACVLAN) architecture that synchronizes the forwarding database (FDB) between primary and secondary units within a high-availability cluster, allowing real-time updates and synchronization of MAC address associations via interprocess communication (IPC) and host-to-host communication services, enabling seamless failover and efficient network traffic processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If an intermediate front-end transparent (TP) VDOM is used to connect virtual firewalls with external network devices, then network communication is enabled, but concurrent session capacity is reduced to half and throughput is degraded
Solution Approach 1:
The patent removes the intermediate TP VDOM from the network architecture, allowing virtual firewalls to communicate directly with external network devices. This extraction eliminates the redundant routing step where packets had to traverse through the TP VDOM, thereby restoring full concurrent session capacity and improving throughput without the complexity of managing additional virtual domain interfaces.
Solution Approach 2:
Instead of using an intermediate TP VDOM to enable communication (the conventional approach), the patent inverts the architecture by allowing virtual firewalls to directly interface with external network devices. This inversion eliminates the need for the intermediate routing layer that was causing the session capacity reduction and throughput degradation.
2Adaptability or versatility
If an intermediate TP VDOM is used to enable communication between VDOMs and external network devices, then network connectivity is achieved, but the number of concurrent sessions is reduced to half
Solution Approach 1:
The patent extracts and removes the intermediate TP VDOM component from the network architecture, enabling virtual firewalls to establish direct connections with external network devices. This removal restores the full concurrent session capacity by eliminating the routing constraint that limited sessions to half of the normal capacity.
3Reliability
If FDB synchronization is implemented between primary and secondary units in an HA cluster, then network reliability is enhanced, but system complexity increases due to interprocess communication requirements
Solution Approach 1:
The patent merges the FDB synchronization functionality into the existing HA cluster architecture by implementing interprocess communication (IPC) mechanisms between primary and secondary units. This integration approach maintains network reliability through real-time FDB synchronization while avoiding the need for separate, complex synchronization systems, as the IPC infrastructure is already part of the HA cluster design.
Data Source
AI summary
Systems and methods for synchronizing an EMACVLAN FDB among cluster units of an HA cluster are provided. According to one embodiment, real-time synchronization of a first FDB maintained within a kernel space of a first network security operating system running on a primary unit and a second FDB maintained within a kernel space of a second network security operating system running on a secondary unit is performed by: transferring information regarding an entry from the kernel space of the first network security operating system to a first synchronization unit running within a user space of the first network security operating system, and causing the second forwarding database to be updated by the first synchronization unit in response to receipt of the information regarding the entry, by transmitting the information regarding the entry to a second synchronization unit running within the user space of the second network security operating system.


