Firewall Policy Migration in Hybrid Cloud via Object Inventory Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Migrating firewall policies between virtual data centers in a hybrid cloud environment is complex and time-consuming, as existing technologies lack visibility into the inventory of objects in the destination data center, making it difficult to enforce consistent firewall rules across locations during VM migration.

Innovation Solution

Establishing a communication link between firewall servers in source and destination virtual data centers to map policies to objects in the destination data center, generating firewall rule tuples, and sending them to enforcement points, allowing for seamless policy migration while maintaining network integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firewall policies are migrated manually between virtual data centers, then network security can be maintained, but the migration process becomes complex and time-consuming

Engineering Contradiction:
Improvenetwork securityVSAvoidmigration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by establishing communication links and obtaining inventories of objects in the destination data center before actual policy migration. This allows the source firewall server to map policies to destination objects in advance, preparing the migration pathway and reducing the time required during actual policy transfer.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mapping mechanism that connects source firewall policies with destination data center objects. The communication link between firewall servers acts as an intermediary channel, enabling automated policy translation and transfer without manual intervention, thus maintaining security while reducing migration time.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If existing firewall migration technologies are used, then some policy transfer is possible, but visibility into destination data center inventory is lacking, making consistent rule enforcement difficult

Engineering Contradiction:
Improvepolicy transfer capabilityVSAvoidmigration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements a universal communication link between firewall servers that can obtain and map any type of object inventory from the destination data center. This multi-functional approach allows the same mechanism to handle different object types (VMs, networks, storage) and policy formats, enhancing adaptability while providing comprehensive visibility to reduce complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If firewall policies are enforced without inventory visibility, then migration can proceed, but network integrity and consistency cannot be ensured

Engineering Contradiction:
Improvemigration speedVSAvoidnetwork integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements feedback by having the source firewall server obtain real-time inventory information from the destination data center through the communication link. This feedback loop allows the system to verify object existence and mapping accuracy before enforcing policies, ensuring network integrity while maintaining migration productivity through automated validation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11310277B2Network policy migration in a federated hybrid cloud
Publication Date: 2022.04.19 VMWARE INC
  • US11310277B2 patent drawing
  • US11310277B2 patent drawing
  • US11310277B2 patent drawing

AI summary

One or more embodiments provide a firewall policy between a first virtual data center and a second virtual data center. A method includes: establishing a communication link between a first firewall server in the first virtual data center and a second firewall server in the second virtual data center over a network, the first firewall server having a first firewall defined by polices applied to groups of objects in the first virtual data center; obtaining, at the first firewall server, an inventory of objects in the second virtual data center from the second firewall server; determining firewall rule tuples by mapping the policies of the first firewall to groups of objects in the inventory of the second virtual data center; and sending the firewall rule tuples to enforcement points in the second virtual data center.