Firewall Coordination for Wireless Access Point Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The imposition of multiple firewalls in a chain of interconnected wireless access points leads to unnecessary signal delays and performance reduction in network operations, as devices connected to one access point are subjected to firewall protection by both the connected access point and the gateway access point, resulting in redundant firewalling.
Innovation Solution
Implementing a firewall coordination system that discovers network topology and host devices, allowing each attached device to be firewalled only by the access point it is connected to, bypassing uplink access points to optimize firewall operations and eliminate redundant firewalling.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple firewalls are imposed on devices connected to a chain of access points, then network security is enhanced, but signal delays increase and overall network performance decreases
Solution Approach 1:
The patent extracts the firewall function from multiple access points and concentrates it at the gateway access point only. Child access points are configured to forward packets without applying firewall rules, removing the redundant firewall processing from the packet path while maintaining security at the gateway where a single firewall instance handles all traffic.
Solution Approach 2:
The patent merges the firewall protection function into a single centralized location (the gateway access point) rather than distributing it across multiple access points. This consolidation eliminates redundant firewall processing in the chain while maintaining comprehensive security coverage for all connected devices.
2Reliability
If multiple firewalls process packets from connected devices, then security coverage is increased, but processing time increases causing signal delays
Solution Approach 1:
The firewall processing function is extracted from child access points and centralized at the gateway. Packets traverse only the gateway's firewall once, eliminating multiple sequential firewall processing steps and the associated time delays, while the gateway's single firewall instance maintains comprehensive security coverage.
3Productivity
If firewall coordination is implemented to bypass uplink access points, then redundant firewalling is eliminated, but network topology discovery complexity increases
Solution Approach 1:
The gateway access point automatically discovers the network topology and identifies child access points through self-service mechanisms. The system performs autonomous topology discovery and configures firewall bypass rules without manual intervention, eliminating redundant firewalling while the added complexity is confined to the gateway's automated discovery process.
Data Source
AI summary
Embodiments are directed to host discovery for firewall coordination. An embodiment of a storage medium includes instructions for discovering a network topology for a network branch, the network branch including multiple access points including a first access point, the first access point having an interface to a network, the discovery of the network topology including identifying any access point that is linked to the first access point directly or via one or more intermediary access points; discovering one or more host devices that are connected by wireless or wired connections to one or more access points in the network branch; and generating a firewall coordination plan for the network branch based on the discovered network topology and the discovered one or more hosts, the firewall coordination plan including applying a firewall process for an access point to which a first host device is attached and bypassing one or more other firewall processes.


