HA Cluster Architecture for Seamless Failover and Load Balancing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cluster architectures face inefficiencies in load balancing and failover protection due to master-slave configurations, which lead to increased load on the master unit, potential data loss, and delays in switching between cluster units, especially in active-active HA clusters where all traffic is routed through a single master unit.

Innovation Solution

A novel cluster-based network architecture that establishes active and backup connections between network devices and cluster units, allowing seamless transition and load balancing without a master-slave configuration, enabling immediate failover and synchronization of traffic flow between cluster units using dual HA links and shared virtual IP/MAC addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a master-slave configuration is used in HA clusters, then failover protection is provided, but the load on the master unit increases and switching delays occur

Engineering Contradiction:
Improvefailover protectionVSAvoidload balancing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent divides the cluster into peer units without master-slave hierarchy, where each unit independently handles traffic and maintains session information. This segmentation eliminates the bottleneck at the master unit and enables parallel processing across all cluster units, resolving the contradiction between reliability and productivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of the conventional master-slave inversion where one unit dominates, the patent inverts the model to peer-to-peer equality where all units have equal status and capability. Each unit can independently accept and process traffic, reversing the traditional load concentration model and achieving both failover protection and efficient load balancing simultaneously.

Inventive Principle:
Principle #13The other way round (Inversion)

2Ease of operation

If all traffic is routed through a single master unit in active-active HA clusters, then centralized control is maintained, but delays in switching between cluster units occur

Engineering Contradiction:
Improvecentralized controlVSAvoidswitching delay
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

Each cluster unit pre-synchronizes session information with peer units before failover is needed. This preliminary action ensures that when switching occurs, the standby unit already has the necessary session data ready, eliminating switching delays while maintaining centralized control through coordinated synchronization protocols.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a synchronization mechanism as an intermediary that coordinates information exchange between peer units without creating a central bottleneck. This mediator enables rapid failover by ensuring all units have consistent session information, reducing switching delays while preserving centralized control through standardized synchronization protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If master-slave configuration is used, then configuration simplicity is maintained, but potential data loss occurs during failover

Engineering Contradiction:
Improveconfiguration simplicityVSAvoiddata loss
Core Design Contradiction:
Ease of manufactureVSLoss of information

Solution Approach 1:

The patent merges the session information storage capability across all peer units rather than concentrating it in the master unit. Each unit maintains and synchronizes session data independently, creating redundant copies across the cluster. This combining approach eliminates data loss risks during failover while keeping configuration simple through standardized peer-to-peer synchronization.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11068362B2High-availability cluster architecture and protocol
Publication Date: 2021.07.20 FORTINET INC
  • US11068362B2 patent drawing
  • US11068362B2 patent drawing
  • US11068362B2 patent drawing

AI summary

Methods and systems are provided for an improved cluster-based network architecture. According to one embodiment, an active connection is established between a first interface of a network device and an enabled interface of a first cluster unit of an HA cluster of network security devices. The HA cluster is configured to provide connectivity between network devices of an internal and external network. A backup connection is established between a second interface of the network device and a disabled interface of a second cluster unit. While the first cluster unit is operational and has connectivity, it receives and processes all network traffic from the network device that is destined for the external network. Upon determining the first cluster unit has failed or has lost connectivity, then all subsequent network traffic originated by the network device that is destined for the external network is directed to the second cluster unit.