Firewall Service Insertion with Security Group Tag Preservation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewalls in enterprise network fabrics typically strip source host contexts from data packets, making it difficult to enforce policies, especially in multi-site networks with dual homed borders and redundancy/load balancing, which complicates policy enforcement across virtual routing and forwarding instances.

Innovation Solution

The technology involves selectively encapsulating data packets with source host context information at border nodes within the enterprise network fabric after firewall policies are applied, using security group tags and LISP mappings to preserve and apply source host context for policy control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firewalls apply security policies to data packets in enterprise network fabric, then security enforcement is improved, but source host context information is stripped from packets making policy enforcement difficult

Engineering Contradiction:
Improvefirewall security policy enforcementVSAvoidsource host context
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The ingress border node performs preliminary encapsulation of data packets with source host context information (such as Security Group Tags) before the packets are forwarded to the firewall. This ensures that the context is preserved through the firewall processing, allowing both security enforcement and context-aware policy application.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces border nodes as intermediary devices between the firewall and the network fabric. These border nodes perform encapsulation and decapsulation operations, acting as mediators that protect source host context information while allowing firewall security policies to be applied. The border nodes rewrite packet headers to preserve context through the firewall.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dual homed borders with redundancy/load balancing are used in multi-site enterprise network fabric, then network reliability is improved, but preserving source host context across borders becomes more complex

Engineering Contradiction:
Improvenetwork redundancyVSAvoidcontext preservation across borders
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The border nodes are designed with multi-functionality to handle both single-homed and dual-homed scenarios. They can operate as primary or secondary borders, perform encapsulation/decapsulation, and maintain source host context information across multiple sites. The same border node infrastructure supports redundancy, load balancing, and context preservation through standardized operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the state of packet headers through encapsulation and decapsulation operations at border nodes. By modifying packet parameters (adding outer headers with context information, removing inner headers), the system preserves source host context across dual-homed borders while maintaining network redundancy and load balancing capabilities.

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If firewalls strip source host contexts from data packets, then firewall processing is simplified, but end-to-end policy enforcement across virtual networks becomes difficult

Engineering Contradiction:
Improvefirewall processing simplicityVSAvoidend-to-end policy enforcement
Core Design Contradiction:
Ease of manufactureVSEase of operation

Solution Approach 1:

The patent segments the network infrastructure into distinct functional components: ingress border nodes that perform encapsulation, firewalls that apply security policies, and egress border nodes that perform decapsulation. This segmentation allows each component to perform its function independently - firewalls process packets with simplified header structures while border nodes handle context preservation, achieving both processing simplicity and end-to-end policy enforcement.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11516184B2Firewall service insertion across secure fabric preserving security group tags end to end with dual homed firewall
Publication Date: 2022.11.29 CISCO TECHNOLOGY INC
  • US11516184B2 patent drawing
  • US11516184B2 patent drawing
  • US11516184B2 patent drawing

AI summary

Systems, methods, and computer-readable media for preserving source host context when firewall policies are applied to traffic in an enterprise network fabric. A data packet to a destination host from a source host can be received at a first border node instance in an enterprise network fabric as part of network traffic. The data packet can include a context associated with the source host. Further, the data packet can be sent to a firewall of the enterprise network fabric and can be received at a second border node instance after the firewall applies a firewall policy to the data packet. The data packet can then be selectively encapsulated with the context associated with the source host at the second border node instance for applying one or more policies to control transmission of the network traffic through the enterprise network fabric.