Outbound Request Manager Firewall Rule Aggregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems managing requests from multiple cluster nodes to external services are inefficient, requiring multiple firewall rules and manual updates, leading to complex traffic management and potential security vulnerabilities.

Innovation Solution

Implementing an outbound request manager that routes requests from multiple cluster nodes through a single network address, allowing the external service to identify all requests as originating from a particular network address, thereby simplifying firewall rules and caching information for subsequent requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple firewall rules are created to manage traffic from each cluster node, then security coverage is improved, but device complexity and management overhead increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidfirewall rule complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple individual firewall rules into a single aggregated firewall rule that covers all cluster nodes. Instead of maintaining separate rules for each node's IP address, the system creates one consolidated rule that handles traffic from the entire cluster, dramatically reducing rule complexity while maintaining comprehensive security coverage

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The outbound request manager serves multiple functions: it acts as a NAT device for address translation, functions as a caching server for request information, and operates as a centralized firewall management point. This multi-functionality eliminates the need for separate management systems and reduces overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Manufacturing precision

If manual updates are performed for each cluster node's firewall rules, then security accuracy is improved, but productivity and time efficiency deteriorate

Engineering Contradiction:
Improvesecurity rule accuracyVSAvoidfirewall management efficiency
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The outbound request manager automatically manages firewall rule aggregation and updates without requiring manual intervention for each cluster node. The system self-adjusts when new nodes are added or existing nodes change, maintaining security accuracy while eliminating repetitive manual configuration tasks

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements automatic detection and update mechanisms that monitor cluster node changes and相应地 adjust firewall rules. When new nodes are added to the cluster, the outbound request manager automatically incorporates them into the aggregated firewall rule set, ensuring continuous security coverage without manual intervention

Inventive Principle:
Principle #23Feedback

3Measurement precision

If individual cluster node addresses are exposed to external services, then service identification accuracy is improved, but security vulnerability increases

Engineering Contradiction:
Improveservice identification accuracyVSAvoidsecurity vulnerability
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The outbound request manager serves as an intermediary between cluster nodes and external services. It performs NAT address translation that conceals individual node addresses while maintaining accurate service identification through the translation process. External services communicate with the manager's address rather than individual node addresses, reducing exposure and vulnerability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the identification function from the address exposure function. While individual node addresses remain hidden through NAT translation, the outbound request manager maintains internal tracking and identification of requests from specific nodes, enabling accurate service identification without exposing individual addresses to external services

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11102141B2Outbound request management
Publication Date: 2021.08.24 VMWARE INC
  • US11102141B2 patent drawing
  • US11102141B2 patent drawing
  • US11102141B2 patent drawing

AI summary

The present disclosure is related to devices, systems, and methods for routing requests for an external service, originating from a plurality of cluster nodes, through an outbound request manager. An example method can include receiving a first request for an external service originating from a first cluster node having a first network address, receiving a second request for the external service originating from a second cluster node having a second network address, transmitting the first request with a particular network address to an address associated with the external service, and transmitting the second request with the particular network address to the address associated with the external service.