Firewall Cluster Virtual Adapters for State Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for sharing state between firewall processors in a cluster are inadequate, particularly for higher level protocols, as they typically duplicate the IP stack and attached state, failing to handle states effectively.
Innovation Solution
Implementing a master-slave configuration with virtual adapters that allow each firewall processor to manage and share state across the cluster, enabling transparent addition of processors and dynamic creation of logical connections, while maintaining load balancing and supporting high-level protocols through firewall extension modules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the IP stack and state are duplicated across firewall processors in a cluster, then state sharing between processors is achieved, but higher level protocol states cannot be handled effectively
Solution Approach 1:
The patent segments the firewall cluster into master and slave processors with distinct roles. The master processor handles higher-level protocol states while slave processors handle IP-level state, dividing the state management function to resolve the contradiction between state sharing capability and higher-level protocol support.
Solution Approach 2:
The patent introduces virtual adapters as an intermediary layer between processors. These virtual adapters enable state sharing and communication between master and slave processors while maintaining protocol-specific state management, allowing both IP-level and higher-level protocol states to coexist effectively.
2Productivity
If firewall processors are added to the cluster, then processing capability and reliability are improved, but system complexity and configuration difficulty increase
Solution Approach 1:
The patent implements automatic master processor selection and virtual adapter configuration. When new processors are added to the cluster, they automatically integrate with the existing system, with the system self-configuring the master-slave relationships and state distribution without requiring manual administrative intervention.
3Speed
If each processor manages its own state independently, then processing speed is improved, but state sharing and load balancing become problematic
Solution Approach 1:
The patent merges state management capabilities at the virtual adapter level while maintaining independent processor operation. Virtual adapters combine state information from multiple processors, enabling both fast local processing and coordinated state sharing through the unified virtual adapter interface.
Data Source
AI summary
A generic master-slave mechanism enables a single processor of a cluster of firewall processors to define the behavior of the other processors in the cluster for a specific logical connection. The cluster of firewall processors utilizes virtual adapters representing physical adapters on other processors in the firewall cluster. This virtualization allows each cluster member to act as though it is a standalone machine that owns all local IP addresses of the entire cluster. When traffic is received by a firewall processor, the firewall processor determines if there is a master associated with the logical connection for the traffic. If so, the traffic is routed to the master. If no master is associated, in an example configuration, the receiving firewall processor becomes the master. A message traffic logical connection has a single master. A master remains the master of a logical connection until the connection is terminated.


