Active-Active L2 Firewall Cluster VLAN Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network security devices, such as L2 firewalls, can fail, leading to disruptions in network traffic, and existing high availability configurations often require complex setups like Spanning Tree Protocol to prevent data loops, which can reduce the active-active configuration to active-backup, resulting in less throughput and increased hardware requirements.
Innovation Solution
Configuring two or more L2 firewalls in an active-active high availability cluster, where each device operates as both active and backup for the other, processing different VLANs without the need for per-VLAN Spanning Tree Protocol, allowing simultaneous operation and increased throughput while maintaining redundancy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Spanning Tree Protocol is used to prevent data loops in L2 firewall high availability configuration, then data loop prevention is improved, but device complexity and hardware requirements increase
Solution Approach 1:
The patent extracts and eliminates the Spanning Tree Protocol from the L2 firewall HA configuration by introducing VLAN-based segmentation. Each VLAN has its own STP instance, allowing independent operation without requiring global STP coordination between multiple firewalls, thus simplifying the overall configuration while maintaining loop prevention
Solution Approach 2:
The patent segments the network into separate VLANs, where each VLAN operates as an independent broadcast domain with its own STP instance. This segmentation allows multiple L2 firewalls to operate simultaneously in active mode for different VLANs without creating data loops, reducing the need for complex per-VLAN STP configurations
2Productivity
If active-active high availability cluster is configured for L2 firewalls, then throughput and processing capability are improved, but device complexity increases
Solution Approach 1:
The patent segments the firewall cluster into multiple active firewalls handling different VLANs simultaneously. Each firewall operates independently for its assigned VLANs with simple active-passive pairing, avoiding the need for complex per-VLAN STP configurations while achieving high throughput through parallel processing
Solution Approach 2:
The patent makes each L2 firewall multi-functional by enabling them to handle multiple VLANs through the VLAN STP mechanism. A single firewall can serve as active for some VLANs and backup for others, or serve different VLANs at different times, increasing productivity without requiring specialized hardware or complex configurations
Data Source
AI summary
Techniques are described to enable two or more layer two (L2) firewall devices to be configured as a high availability (HA) cluster in an active-active configuration. A first layer two (L2) firewall and a second L2 firewall are positioned within the same L2 network. The first L2 firewall and the second L2 firewall are concurrently configured with active virtual security devices (VSDs) within the L2 network, and concurrently apply L2 firewall services to packets within the L2 network. A VSD of one of the L2 firewalls automatically switches to an active VSD status for a VSD group in place of a VSD of another L2 firewall when the other L2 firewall fails.


