Active-Active L2 Firewall Cluster VLAN Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security devices, such as L2 firewalls, can fail, leading to disruptions in network traffic, and existing high availability configurations often require complex setups like Spanning Tree Protocol to prevent data loops, which can reduce the active-active configuration to active-backup, resulting in less throughput and increased hardware requirements.

Innovation Solution

Configuring two or more L2 firewalls in an active-active high availability cluster, where each device operates as both active and backup for the other, processing different VLANs without the need for per-VLAN Spanning Tree Protocol, allowing simultaneous operation and increased throughput while maintaining redundancy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Spanning Tree Protocol is used to prevent data loops in L2 firewall high availability configuration, then data loop prevention is improved, but device complexity and hardware requirements increase

Engineering Contradiction:
Improvedata loop preventionVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts and eliminates the Spanning Tree Protocol from the L2 firewall HA configuration by introducing VLAN-based segmentation. Each VLAN has its own STP instance, allowing independent operation without requiring global STP coordination between multiple firewalls, thus simplifying the overall configuration while maintaining loop prevention

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the network into separate VLANs, where each VLAN operates as an independent broadcast domain with its own STP instance. This segmentation allows multiple L2 firewalls to operate simultaneously in active mode for different VLANs without creating data loops, reducing the need for complex per-VLAN STP configurations

Inventive Principle:
Principle #1Segmentation

2Productivity

If active-active high availability cluster is configured for L2 firewalls, then throughput and processing capability are improved, but device complexity increases

Engineering Contradiction:
Improveprocessing throughputVSAvoidconfiguration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the firewall cluster into multiple active firewalls handling different VLANs simultaneously. Each firewall operates independently for its assigned VLANs with simple active-passive pairing, avoiding the need for complex per-VLAN STP configurations while achieving high throughput through parallel processing

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent makes each L2 firewall multi-functional by enabling them to handle multiple VLANs through the VLAN STP mechanism. A single firewall can serve as active for some VLANs and backup for others, or serve different VLANs at different times, increasing productivity without requiring specialized hardware or complex configurations

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7941837B1Layer two firewall with active-active high availability support
Publication Date: 2011.05.10 JUNIPER NETWORKS INC
  • US7941837B1 patent drawing
  • US7941837B1 patent drawing
  • US7941837B1 patent drawing

AI summary

Techniques are described to enable two or more layer two (L2) firewall devices to be configured as a high availability (HA) cluster in an active-active configuration. A first layer two (L2) firewall and a second L2 firewall are positioned within the same L2 network. The first L2 firewall and the second L2 firewall are concurrently configured with active virtual security devices (VSDs) within the L2 network, and concurrently apply L2 firewall services to packets within the L2 network. A VSD of one of the L2 firewalls automatically switches to an active VSD status for a VSD group in place of a VSD of another L2 firewall when the other L2 firewall fails.