Integrated MPLS-Aware Firewall for Stateful Security Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional firewalls face difficulties in applying security services to MPLS traffic due to the lack of state information in the data plane, making it challenging to provide deep packet inspection and other stateful analysis, leading to the need for separate firewall devices that increase management and infrastructure burdens for service providers.

Innovation Solution

An MPLS-aware firewall is integrated within a routing device, allowing it to apply security policies to MPLS traffic and provide both routing and firewall services, enabling stateful analysis and services like intrusion detection and virus scanning, while also supporting zone-based security policies and virtual security systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional firewalls are deployed separately from routing devices, then firewall security policies can be applied to traffic, but device complexity and management burden increase

Engineering Contradiction:
Improvesecurity policy applicationVSAvoidnumber of devices
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the firewall function with the routing device by integrating a firewall module into the routing device architecture. This allows the routing device to perform both routing and security functions, reducing the total number of devices while maintaining security policy application capabilities. The firewall module processes packets according to security policies while the routing device handles packet forwarding and routing decisions.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If separate firewall devices are deployed, then security functions are isolated, but infrastructure management burden increases

Engineering Contradiction:
Improvesecurity function isolationVSAvoidmanagement burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

By integrating the firewall module into the routing device, the patent reduces management burden while maintaining security function isolation through software-based packet processing. The unified device can be managed as a single entity, reducing operational complexity while the internal firewall module maintains security policy enforcement capabilities.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If MPLS traffic is processed by conventional firewalls, then security inspection can be applied, but stateful analysis capability is lost

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidstateful analysis capability
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent introduces a control plane as an intermediary between the routing/forwarding plane and the firewall module. The control plane receives packets from the forwarding plane, extracts MPLS label information, and provides this state information to the firewall module. This enables the firewall to perform stateful analysis of MPLS traffic by maintaining context about packet flows and their associated MPLS labels.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Measurement precision

If deep packet inspection is performed on MPLS traffic, then security analysis improves, but processing time increases

Engineering Contradiction:
Improvedeep packet inspection capabilityVSAvoidpacket processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the packet processing into distinct phases: forwarding plane processing (fast path for routing decisions) and firewall module processing (security inspection). The control plane acts as an intermediary that prepares state information about MPLS traffic, allowing the firewall module to perform deep packet inspection more efficiently by having pre-extracted routing and label information available.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2154834B1Routing device having integrated MPLS-Aware firewall
Publication Date: 2017.10.04 JUNIPER NETWORKS INC
  • EP2154834B1 patent drawingFigure 1
  • EP2154834B1 patent drawingFigure 2
  • EP2154834B1 patent drawingFigure 3

AI summary

An MPLS-aware firewall allows firewall security policies to be applied to MPLS traffic. The firewall, which may be integrated within a routing device, can be configured into multiple virtual security systems. The routing device provides a user interface by which a user specifies one or more zones to be recognized by the integrated firewall when applying stateful firewall services to the packets. The user interface allows the user to define different zones and policies for different ones of the virtual security systems. In addition, the user interface supports a syntax that allows the user to define the zones for the firewall by specifying the customer VPNs as interfaces associated with the zones. The routing device generates mapping information for the integrated firewall to map the customer VPNs to specific MPLS labels for the MPLS tunnels carrying the customer's traffic.