Firewall Cluster Virtual Adapters for State Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for sharing state between firewall processors in a cluster are inadequate, particularly for higher level protocols, as they typically duplicate the IP stack and attached state, failing to handle states effectively.

Innovation Solution

Implementing a master-slave configuration with virtual adapters that allow each firewall processor to manage and share state across the cluster, enabling transparent addition of processors and dynamic creation of logical connections, while maintaining load balancing and supporting high-level protocols through firewall extension modules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the IP stack and state are duplicated across firewall processors in a cluster, then state sharing between processors is achieved, but higher level protocol states cannot be handled effectively

Engineering Contradiction:
Improvestate sharing capabilityVSAvoidhigher level protocol support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the firewall cluster into master and slave processors with distinct roles. The master processor handles higher-level protocol states while slave processors handle IP-level state, dividing the state management function to resolve the contradiction between state sharing capability and higher-level protocol support.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtual adapters as an intermediary layer between processors. These virtual adapters enable state sharing and communication between master and slave processors while maintaining protocol-specific state management, allowing both IP-level and higher-level protocol states to coexist effectively.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If firewall processors are added to the cluster, then processing capability and reliability are improved, but system complexity and configuration difficulty increase

Engineering Contradiction:
Improveprocessing capabilityVSAvoidcluster configuration
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements automatic master processor selection and virtual adapter configuration. When new processors are added to the cluster, they automatically integrate with the existing system, with the system self-configuring the master-slave relationships and state distribution without requiring manual administrative intervention.

Inventive Principle:
Principle #25Self-service

3Speed

If each processor manages its own state independently, then processing speed is improved, but state sharing and load balancing become problematic

Engineering Contradiction:
Improveprocessing speedVSAvoidstate sharing
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent merges state management capabilities at the virtual adapter level while maintaining independent processor operation. Virtual adapters combine state information from multiple processors, enabling both fast local processing and coordinated state sharing through the unified virtual adapter interface.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8353020B2Transparently extensible firewall cluster
Publication Date: 2013.01.08 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8353020B2 patent drawing
  • US8353020B2 patent drawing
  • US8353020B2 patent drawing

AI summary

A generic master-slave mechanism enables a single processor of a cluster of firewall processors to define the behavior of the other processors in the cluster for a specific logical connection. The cluster of firewall processors utilizes virtual adapters representing physical adapters on other processors in the firewall cluster. This virtualization allows each cluster member to act as though it is a standalone machine that owns all local IP addresses of the entire cluster. When traffic is received by a firewall processor, the firewall processor determines if there is a master associated with the logical connection for the traffic. If so, the traffic is routed to the master. If no master is associated, in an example configuration, the receiving firewall processor becomes the master. A message traffic logical connection has a single master. A master remains the master of a logical connection until the connection is terminated.