Layer 7 Firewall Inspection Markers for Cloud Interconnects

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing software defined cloud interconnect (SDCI) SDWAN networks incur redundant and inefficient Layer 7 firewall inspections at both ends of the network, consuming significant CPU and processing resources.

Innovation Solution

A control plane system is implemented to identify firewall policies and add markers to data packets, allowing network devices to determine if further Layer 7 inspections are necessary based on pre-configured policies, thereby optimizing firewall enforcement and reducing redundant inspections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Layer 7 firewall inspections are performed at both edge device and core device, then security coverage is improved, but CPU and processing resources are excessively consumed

Engineering Contradiction:
Improvesecurity coverageVSAvoidCPU and processing resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies preliminary action by performing Layer 7 firewall inspection at the edge device before traffic reaches the core device. A marker is added to inspected packets to indicate they have already undergone Layer 7 inspection, allowing the core device to skip redundant inspections while maintaining security coverage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the Layer 7 inspection function from the core device and relocates it to the edge device. This separation allows the core device to focus on routing while the edge device handles security inspection, reducing redundant processing at the core device.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If identical URL filtering policy is deployed at branch site and headend device, then security consistency is improved, but redundant inspections occur

Engineering Contradiction:
Improvesecurity consistencyVSAvoidnetwork processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs URL filtering inspection at the branch site (edge device) before traffic reaches the headend device. A marker is added to indicate the packet has been inspected, allowing the headend device to enforce the same policy without redundant inspection while maintaining security consistency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a marker as an intermediary mechanism to communicate inspection status between branch site and headend device. This marker allows the headend device to recognize that inspection has already occurred and enforce the policy without repeating the inspection process.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If firewall inspections are performed at multiple network devices, then security enforcement is improved, but processing time is increased

Engineering Contradiction:
Improvesecurity enforcementVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs firewall inspection at the first network device (edge device) in the path and adds a marker to indicate completion. Subsequent network devices recognize the marker and skip inspection, maintaining security enforcement while significantly reducing total processing time by avoiding redundant inspections.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250286861A1Service optimization in networks and cloud interconnects
Publication Date: 2025.09.11 CISCO TECHNOLOGY INC
  • US20250286861A1 patent drawing
  • US20250286861A1 patent drawing
  • US20250286861A1 patent drawing

AI summary

This disclosure describes techniques and mechanisms for disclosure describes techniques and mechanisms for optimizing firewall enforcement. The techniques may implement a dynamic detection of Layer 7 processing at one end of the network, alleviating the need to enforce another layer 7 firewall inspection at the other end, thereby saving processing and network resources. The techniques enable firewalls and policies to be statically defined and located in one place.