Integrated MPLS-Aware Firewall for Stateful Security Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional firewalls face difficulties in applying security services to MPLS traffic due to the lack of state information in the data plane, making it challenging to provide deep packet inspection and other stateful analysis, leading to the need for separate firewall devices that increase management and infrastructure burdens for service providers.
Innovation Solution
An MPLS-aware firewall is integrated within a routing device, allowing it to apply security policies to MPLS traffic and provide both routing and firewall services, enabling stateful analysis and services like intrusion detection and virus scanning, while also supporting zone-based security policies and virtual security systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional firewalls are deployed separately from routing devices, then firewall security policies can be applied to traffic, but device complexity and management burden increase
Solution Approach 1:
The patent merges the firewall function with the routing device by integrating a firewall module into the routing device architecture. This allows the routing device to perform both routing and security functions, reducing the total number of devices while maintaining security policy application capabilities. The firewall module processes packets according to security policies while the routing device handles packet forwarding and routing decisions.
2Reliability
If separate firewall devices are deployed, then security functions are isolated, but infrastructure management burden increases
Solution Approach 1:
By integrating the firewall module into the routing device, the patent reduces management burden while maintaining security function isolation through software-based packet processing. The unified device can be managed as a single entity, reducing operational complexity while the internal firewall module maintains security policy enforcement capabilities.
3Reliability
If MPLS traffic is processed by conventional firewalls, then security inspection can be applied, but stateful analysis capability is lost
Solution Approach 1:
The patent introduces a control plane as an intermediary between the routing/forwarding plane and the firewall module. The control plane receives packets from the forwarding plane, extracts MPLS label information, and provides this state information to the firewall module. This enables the firewall to perform stateful analysis of MPLS traffic by maintaining context about packet flows and their associated MPLS labels.
4Measurement precision
If deep packet inspection is performed on MPLS traffic, then security analysis improves, but processing time increases
Solution Approach 1:
The patent segments the packet processing into distinct phases: forwarding plane processing (fast path for routing decisions) and firewall module processing (security inspection). The control plane acts as an intermediary that prepares state information about MPLS traffic, allowing the firewall module to perform deep packet inspection more efficiently by having pre-extracted routing and label information available.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An MPLS-aware firewall allows firewall security policies to be applied to MPLS traffic. The firewall, which may be integrated within a routing device, can be configured into multiple virtual security systems. The routing device provides a user interface by which a user specifies one or more zones to be recognized by the integrated firewall when applying stateful firewall services to the packets. The user interface allows the user to define different zones and policies for different ones of the virtual security systems. In addition, the user interface supports a syntax that allows the user to define the zones for the firewall by specifying the customer VPNs as interfaces associated with the zones. The routing device generates mapping information for the integrated firewall to map the customer VPNs to specific MPLS labels for the MPLS tunnels carrying the customer's traffic.