Offloading Dropped Flows to Access Switches
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In modern network architectures, enforcing network security policies at firewall clusters can lead to bottlenecks and inefficient use of bandwidth, as dropped traffic flows continue to consume resources.
Innovation Solution
The technology offloads dropped traffic flows from firewall clusters to access switches based on host location, allowing network policies to be enforced closer to the traffic source, thereby reducing resource consumption and mitigating bottlenecks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network security policies are enforced at firewall clusters, then network security is improved, but bandwidth efficiency deteriorates due to dropped traffic flows consuming resources
Solution Approach 1:
The patent segments the network security function by moving policy enforcement from centralized firewall clusters to distributed access switches. Each access switch independently enforces security policies for its connected hosts, dividing the enforcement burden across multiple locations rather than concentrating it at single points.
Solution Approach 2:
The controller acts as an intermediary that detects dropped flows at firewall clusters, determines host locations, and programs corresponding flow entries at access switches. This intermediary coordinates the redistribution of enforcement responsibilities without requiring direct intervention at each enforcement point.
2Device complexity
If dropped traffic flows are handled at firewall clusters, then security policy enforcement is centralized, but network bottlenecks increase due to resource consumption
Solution Approach 1:
The patent extracts dropped flow handling from the centralized firewall cluster and redistributes it to access switches. By removing the burden of processing dropped flows from the firewall cluster, the system eliminates the bottleneck while maintaining security policy enforcement capabilities.
Solution Approach 2:
The patent implements local quality by having each access switch enforce security policies specifically for its connected hosts. This localized enforcement approach ensures that security decisions are made close to the traffic source, reducing the need for centralized processing and improving overall network throughput.
3Loss of energy
If network policies are enforced at access switches closer to hosts, then bandwidth waste is reduced, but policy management complexity increases
Solution Approach 1:
The controller continuously monitors network conditions and firewall cluster behavior to detect dropped flows. This feedback mechanism enables the controller to dynamically identify which flows should be offloaded to access switches, automating the policy management process while reducing bandwidth waste from dropped flows.
Solution Approach 2:
The system implements self-service by having access switches autonomously enforce security policies for their connected hosts without requiring constant centralized control. The controller initially programs the flow entries, but once configured, the access switches independently handle policy enforcement, reducing management overhead.
Data Source
AI summary
Technique or mechanism in which network security policies are applied close to the source or origin associated with policy decisions. For example. the disclosed technology moves dropped flows from a firewall cluster to a leaf switch based on host location.


