Firewall State Synchronization for Asymmetric Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Multi-homed networks face asymmetric routing problems when using different security devices for each link, leading to failed connections due to a single security device becoming a point of failure and inability to manage asymmetric connections effectively.

Innovation Solution

Implementing software in security devices to monitor for re-transmission messages and update internal state tables across different links, allowing responses to be forwarded even if received by a different security device, thereby enabling asymmetric connections and minimizing re-transmission delays through intelligent processing and state table synchronization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If different security devices are used for different links in a multi-homed network, then reliability is improved by eliminating single points of failure, but asymmetric routing problems occur that prevent connections from being established

Engineering Contradiction:
Improvenetwork reliabilityVSAvoidconnection establishment
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges state information from multiple security devices into a shared state table accessible by all security devices. This allows different security devices to cooperate and recognize each other's state, enabling asymmetric connections to be established successfully while maintaining the reliability benefits of distributed security devices.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared state table acts as an intermediary between different security devices, allowing them to exchange and synchronize connection state information without direct peer-to-peer communication. This mediator enables the security devices to coordinate their actions and resolve asymmetric routing issues.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a single security device manages all links, then operational simplicity is maintained, but the security device becomes a single point of failure reducing network reliability

Engineering Contradiction:
Improvetraffic management simplicityVSAvoidnetwork reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The shared state table provides a universal mechanism that works across all security devices and all network links. Each security device can independently manage its links while contributing to and accessing the common state information, achieving both operational simplicity and improved reliability through this multi-functional shared resource.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If security devices operate independently on different links, then device autonomy is maintained, but state synchronization issues cause connection failures in asymmetric routing scenarios

Engineering Contradiction:
Improvedevice autonomyVSAvoidconnection reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the state management function by allowing each security device to independently maintain its local state while simultaneously participating in a shared state table. This segmentation enables device autonomy to be preserved while achieving state synchronization through the distributed shared table architecture.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8782286B2Optimizing state sharing between firewalls on multi-homed networks
Publication Date: 2014.07.15 CISCO TECHNOLOGY INC
  • US8782286B2 patent drawing
  • US8782286B2 patent drawing
  • US8782286B2 patent drawing

AI summary

In one embodiment, a security device monitors for outgoing re-transmission messages indicating that an endpoint located in a multi-homed network transmitted an unanswered initial connection request. Responsive to identifying one of the outgoing re-transmission messages, the security device identifies destination address information included in the identified re-transmission message. The security device then causes another security device associated with a different link of the same multi-homed network to update its internal state table according to the identified destination address information. As a result, a response to the outgoing re-transmission can be forwarded to the multi-homed network regardless of which security device receives the response.