Preserving Packet Flow Across Bump-in-the-Wire Firewalls

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Bump-in-the-wire (BITW) firewalls in cloud data centers face challenges in preserving packet flow information across network devices, leading to loss of flow information and restricted utility due to modifications in IP addresses and ports, and proprietary headers limiting integration with third-party firewalls.

Innovation Solution

A network device embeds a flow identifier in the Media Access Control (MAC) address field of layer 2 packet headers to redirect packets to BITW firewalls, allowing the original flow to be recovered upon return, thus enabling continued stateful processing without modifying layer 2 headers and avoiding proprietary header restrictions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If packets are redirected to BITW firewalls for security processing, then network security is improved, but packet flow information is lost

Engineering Contradiction:
Improvenetwork securityVSAvoidpacket flow information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a flow identifier as an intermediary element that carries packet flow information through the BITW firewall. The flow identifier is embedded in the packet header and preserved across the firewall, enabling the network device to recover and maintain flow state information without requiring the firewall to modify layer 2 headers, thus resolving the information loss problem while maintaining security processing

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network device performs preliminary action by embedding the flow identifier into the packet header before redirecting the packet to the BITW firewall. This preliminary modification ensures that flow information is already in place and will be preserved when the packet returns from the firewall, preventing information loss before it can occur

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If BITW firewalls do not modify layer 2 headers, then integration with existing network devices is improved, but flow information preservation becomes difficult

Engineering Contradiction:
Improveintegration with existing network devicesVSAvoidflow information
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent applies local quality by making a targeted modification only to the flow identifier field within the packet header, rather than modifying the entire layer 2 header structure. This localized approach preserves the BITW firewall's non-modifying characteristic for general compatibility while introducing specific flow information preservation capability where needed

Inventive Principle:
Principle #3Local quality

3Loss of information

If proprietary headers are used for flow identification, then flow information preservation is improved, but integration with third-party firewalls is restricted

Engineering Contradiction:
Improveflow information preservationVSAvoidintegration with third-party firewalls
Core Design Contradiction:
Loss of informationVSAdaptability or versatility

Solution Approach 1:

The patent implements universality by defining the flow identifier using standard Ethernet header fields (destination MAC address) that are universally supported across different network devices and firewall types. This universal approach allows third-party firewalls to understand and process the flow information without requiring proprietary header formats, thus enabling broad integration while maintaining flow information preservation

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11929987B1Preserving packet flow information across bump-in-the-wire firewalls
Publication Date: 2024.03.12 JUNIPER NETWORKS INC
  • US11929987B1 patent drawing
  • US11929987B1 patent drawing
  • US11929987B1 patent drawing

AI summary

Techniques are disclosed for a network device to preserve packet flow information across bump-in-the-wire (BITW) firewalls. For example, a method comprises receiving, by a network device, a packet. The method also comprises determining, by the network device, that the packet matches a packet flow that is associated with an action to redirect the packet to a firewall configured as a bump-in-the-wire. The method further comprises, in response to the determination: modifying, by the network device, a Media Access Control (MAC) address field of a layer 2 (L2) packet header with a flow identifier of the packet flow; sending, by the network device, the packet to the firewall; receiving, by the network device, the packet from the firewall; and recovering, by the network device, the packet flow by modifying the packet according to the flow identifier in the packet to restore the L2 packet header of the packet.