Multi-Tenant Firewall Virtualization for Data Center Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Internet data centers face challenges in managing and configuring separate firewalls for each customer, leading to complex networks, high costs, and increased downtime due to the need for redundant equipment.
Innovation Solution
A centralized Internet security system utilizing a firewall engine, authentication engine, and virtual private networks (VPNs) that apply policies to data packets, allowing for dynamic resource allocation and management of multiple customers' security needs through a single device, reducing the complexity and cost of network infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a separate firewall device is deployed for each customer, then security management for each customer is ensured, but device complexity and network complexity increase
Solution Approach 1:
The patent combines multiple customer firewalls into a single shared firewall device. The firewall is divided into multiple virtual domains, each handling security for a specific customer. This merging approach reduces the total number of physical firewall devices while maintaining separate security management for each customer through virtualization.
Solution Approach 2:
The single firewall device is designed to serve multiple customers simultaneously by implementing virtual domain technology. Each virtual domain within the firewall can independently manage security policies for different customers, making the firewall universal in its ability to handle multiple customer security requirements with one device.
2Reliability
If redundant firewall boxes are provided to reduce downtime, then reliability improves, but cost and space requirements increase
Solution Approach 1:
The patent implements virtual domain technology that allows a single firewall device to function as multiple firewalls simultaneously. This eliminates the need for redundant physical firewall boxes while maintaining high availability through software-based virtualization and failover mechanisms within the single device.
3Reliability
If separate firewall devices are used for each customer, then security isolation is maintained, but rack space and physical infrastructure requirements increase
Solution Approach 1:
The patent merges multiple customer firewalls into one physical device using virtual domain technology. This consolidation dramatically reduces rack space requirements while maintaining security isolation through virtual boundaries that separate each customer's traffic and policies within the shared hardware infrastructure.
4Reliability
If multiple separate firewall devices are deployed, then customer security needs are met, but wiring and switching infrastructure complexity increases
Solution Approach 1:
The patent consolidates multiple firewall functions into a single device, which simplifies the network wiring and switching infrastructure. Instead of requiring separate network paths and switching configurations for each firewall, the single multi-tenant firewall reduces the overall wiring complexity while still providing dedicated security processing for each customer through virtualization.
Data Source
AI summary
Methods and apparatus, including computer program products, implementing and using techniques for processing a data packet in a packet forwarding device. A data packet is received. A virtual local area network destination is determined for the received data packet, and a set of rules associated with the virtual local area network destination is identified. The rules are applied to the data packet. If a virtual local area network destination has been determined for the received data packet, the data packet is output to the destination, using the result from the application of the rules. If no destination has been determined, the data packet is dropped. A security system for partitioning security system resources into a plurality of separate security domains that are configurable to enforce one or more policies and to allocate security system resources to the one or more security domains, is also described.


