Firewall Policy Migration Between Virtual Data Centers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Migrating network policies across different virtual data centers in a hybrid cloud environment is complex and time-consuming, as existing technologies lack visibility into the inventory of objects in the destination data center, making it difficult to enforce consistent firewall policies during VM migration.

Innovation Solution

A method involving generating a static firewall from a firewall document at the source virtual data center, sending it to the destination, migrating VMs, and importing the firewall document by mapping policies to groups of objects in the destination data center, ensuring seamless policy enforcement across platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network policies are migrated manually between virtual data centers, then policy consistency can be maintained, but the migration process becomes complex and time-consuming

Engineering Contradiction:
Improvepolicy consistencyVSAvoidmigration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by generating a static firewall from the firewall document at the source data center before VM migration begins. This static firewall is then transferred to the destination data center in advance, ensuring policy consistency is established before the actual migration occurs, thereby reducing overall migration time while maintaining reliability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention creates a copy of the firewall document and generates a static firewall representation that can be transferred independently. This copying mechanism allows the firewall policies to be replicated across data centers without requiring complex real-time synchronization, significantly reducing migration time while preserving policy consistency

Inventive Principle:
Principle #26Copying

2Reliability

If firewall policies are transferred before VM migration, then policy enforcement can be maintained, but visibility into destination inventory is required

Engineering Contradiction:
Improvefirewall policy enforcementVSAvoidinventory mapping complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary inventory mapping mechanism that bridges the source and destination data centers. This intermediary layer translates and maps firewall policies to the destination inventory structure, enabling policy transfer before VM migration while managing the complexity of inventory visibility through a standardized mapping interface

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The firewall document format is designed to be universal and adaptable to different data center inventories. The static firewall generation process creates a policy representation that can be enforced across different inventory structures, allowing the same mechanism to handle multiple destination inventory types without increasing complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If dynamic firewall rules are used in the source data center, then flexible policy management is achieved, but consistent enforcement in the destination data center becomes difficult

Engineering Contradiction:
Improvepolicy management flexibilityVSAvoidpolicy enforcement consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system converts dynamic firewall rules into a static firewall representation before transfer. This preliminary conversion captures the essence of the flexible policies while creating a enforceable format for the destination data center, ensuring that the adaptability gained at the source is preserved as consistent enforcement at the destination

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention transforms the parameter representation of firewall rules from a dynamic, inventory-dependent format to a static, enforceable format. This parameter change maintains the functional equivalence of the policies while enabling consistent enforcement across different data center environments with different inventory structures

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11184397B2Network policy migration to a public cloud
Publication Date: 2021.11.23 VMWARE INC
  • US11184397B2 patent drawing
  • US11184397B2 patent drawing
  • US11184397B2 patent drawing

AI summary

An example method of migrating a firewall policy between a first virtual data center and a second virtual data center includes: generating a static firewall from a firewall document at a first firewall server in the first virtual data center, the firewall document defining polices applied to groups of objects in the first virtual data center, the static firewall including firewall rule tuples; sending the static firewall from the first firewall server to a second firewall server in the second virtual data center; migrating a plurality of virtual machines (VMs) from the first virtual data center to the second virtual data center; and importing the firewall document from the first firewall server to the second firewall server by mapping the policies of the first firewall to groups of objects in an inventory of the second virtual data center.