Firewall Policy Migration in Hybrid Cloud via Object Inventory Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Migrating firewall policies between virtual data centers in a hybrid cloud environment is complex and time-consuming, as existing technologies lack visibility into the inventory of objects in the destination data center, making it difficult to enforce consistent firewall rules across locations during VM migration.
Innovation Solution
Establishing a communication link between firewall servers in source and destination virtual data centers to map policies to objects in the destination data center, generating firewall rule tuples, and sending them to enforcement points, allowing for seamless policy migration while maintaining network integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firewall policies are migrated manually between virtual data centers, then network security can be maintained, but the migration process becomes complex and time-consuming
Solution Approach 1:
The system performs preliminary actions by establishing communication links and obtaining inventories of objects in the destination data center before actual policy migration. This allows the source firewall server to map policies to destination objects in advance, preparing the migration pathway and reducing the time required during actual policy transfer.
Solution Approach 2:
The patent introduces an intermediary mapping mechanism that connects source firewall policies with destination data center objects. The communication link between firewall servers acts as an intermediary channel, enabling automated policy translation and transfer without manual intervention, thus maintaining security while reducing migration time.
2Adaptability or versatility
If existing firewall migration technologies are used, then some policy transfer is possible, but visibility into destination data center inventory is lacking, making consistent rule enforcement difficult
Solution Approach 1:
The system implements a universal communication link between firewall servers that can obtain and map any type of object inventory from the destination data center. This multi-functional approach allows the same mechanism to handle different object types (VMs, networks, storage) and policy formats, enhancing adaptability while providing comprehensive visibility to reduce complexity.
3Productivity
If firewall policies are enforced without inventory visibility, then migration can proceed, but network integrity and consistency cannot be ensured
Solution Approach 1:
The system implements feedback by having the source firewall server obtain real-time inventory information from the destination data center through the communication link. This feedback loop allows the system to verify object existence and mapping accuracy before enforcing policies, ensuring network integrity while maintaining migration productivity through automated validation.
Data Source
AI summary
One or more embodiments provide a firewall policy between a first virtual data center and a second virtual data center. A method includes: establishing a communication link between a first firewall server in the first virtual data center and a second firewall server in the second virtual data center over a network, the first firewall server having a first firewall defined by polices applied to groups of objects in the first virtual data center; obtaining, at the first firewall server, an inventory of objects in the second virtual data center from the second firewall server; determining firewall rule tuples by mapping the policies of the first firewall to groups of objects in the inventory of the second virtual data center; and sending the firewall rule tuples to enforcement points in the second virtual data center.


