Firewall Service Insertion with Security Group Tag Preservation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Firewalls in enterprise network fabrics typically strip source host contexts from data packets, making it difficult to enforce policies, especially in multi-site networks with dual homed borders and redundancy/load balancing, which complicates policy enforcement across virtual routing and forwarding instances.
Innovation Solution
The technology involves selectively encapsulating data packets with source host context information at border nodes within the enterprise network fabric after firewall policies are applied, using security group tags and LISP mappings to preserve and apply source host context for policy control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firewalls apply security policies to data packets in enterprise network fabric, then security enforcement is improved, but source host context information is stripped from packets making policy enforcement difficult
Solution Approach 1:
The ingress border node performs preliminary encapsulation of data packets with source host context information (such as Security Group Tags) before the packets are forwarded to the firewall. This ensures that the context is preserved through the firewall processing, allowing both security enforcement and context-aware policy application.
Solution Approach 2:
The patent introduces border nodes as intermediary devices between the firewall and the network fabric. These border nodes perform encapsulation and decapsulation operations, acting as mediators that protect source host context information while allowing firewall security policies to be applied. The border nodes rewrite packet headers to preserve context through the firewall.
2Reliability
If dual homed borders with redundancy/load balancing are used in multi-site enterprise network fabric, then network reliability is improved, but preserving source host context across borders becomes more complex
Solution Approach 1:
The border nodes are designed with multi-functionality to handle both single-homed and dual-homed scenarios. They can operate as primary or secondary borders, perform encapsulation/decapsulation, and maintain source host context information across multiple sites. The same border node infrastructure supports redundancy, load balancing, and context preservation through standardized operations.
Solution Approach 2:
The patent changes the state of packet headers through encapsulation and decapsulation operations at border nodes. By modifying packet parameters (adding outer headers with context information, removing inner headers), the system preserves source host context across dual-homed borders while maintaining network redundancy and load balancing capabilities.
3Ease of manufacture
If firewalls strip source host contexts from data packets, then firewall processing is simplified, but end-to-end policy enforcement across virtual networks becomes difficult
Solution Approach 1:
The patent segments the network infrastructure into distinct functional components: ingress border nodes that perform encapsulation, firewalls that apply security policies, and egress border nodes that perform decapsulation. This segmentation allows each component to perform its function independently - firewalls process packets with simplified header structures while border nodes handle context preservation, achieving both processing simplicity and end-to-end policy enforcement.
Data Source
AI summary
Systems, methods, and computer-readable media for preserving source host context when firewall policies are applied to traffic in an enterprise network fabric. A data packet to a destination host from a source host can be received at a first border node instance in an enterprise network fabric as part of network traffic. The data packet can include a context associated with the source host. Further, the data packet can be sent to a firewall of the enterprise network fabric and can be received at a second border node instance after the firewall applies a firewall policy to the data packet. The data packet can then be selectively encapsulated with the context associated with the source host at the second border node instance for applying one or more policies to control transmission of the network traffic through the enterprise network fabric.


