Preserving Packet Flow Across Bump-in-the-Wire Firewalls
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Bump-in-the-wire (BITW) firewalls in cloud data centers face challenges in preserving packet flow information across network devices, leading to loss of flow information and restricted utility due to modifications in IP addresses and ports, and proprietary headers limiting integration with third-party firewalls.
Innovation Solution
A network device embeds a flow identifier in the Media Access Control (MAC) address field of layer 2 packet headers to redirect packets to BITW firewalls, allowing the original flow to be recovered upon return, thus enabling continued stateful processing without modifying layer 2 headers and avoiding proprietary header restrictions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If packets are redirected to BITW firewalls for security processing, then network security is improved, but packet flow information is lost
Solution Approach 1:
The patent introduces a flow identifier as an intermediary element that carries packet flow information through the BITW firewall. The flow identifier is embedded in the packet header and preserved across the firewall, enabling the network device to recover and maintain flow state information without requiring the firewall to modify layer 2 headers, thus resolving the information loss problem while maintaining security processing
Solution Approach 2:
The network device performs preliminary action by embedding the flow identifier into the packet header before redirecting the packet to the BITW firewall. This preliminary modification ensures that flow information is already in place and will be preserved when the packet returns from the firewall, preventing information loss before it can occur
2Adaptability or versatility
If BITW firewalls do not modify layer 2 headers, then integration with existing network devices is improved, but flow information preservation becomes difficult
Solution Approach 1:
The patent applies local quality by making a targeted modification only to the flow identifier field within the packet header, rather than modifying the entire layer 2 header structure. This localized approach preserves the BITW firewall's non-modifying characteristic for general compatibility while introducing specific flow information preservation capability where needed
3Loss of information
If proprietary headers are used for flow identification, then flow information preservation is improved, but integration with third-party firewalls is restricted
Solution Approach 1:
The patent implements universality by defining the flow identifier using standard Ethernet header fields (destination MAC address) that are universally supported across different network devices and firewall types. This universal approach allows third-party firewalls to understand and process the flow information without requiring proprietary header formats, thus enabling broad integration while maintaining flow information preservation
Data Source
AI summary
Techniques are disclosed for a network device to preserve packet flow information across bump-in-the-wire (BITW) firewalls. For example, a method comprises receiving, by a network device, a packet. The method also comprises determining, by the network device, that the packet matches a packet flow that is associated with an action to redirect the packet to a firewall configured as a bump-in-the-wire. The method further comprises, in response to the determination: modifying, by the network device, a Media Access Control (MAC) address field of a layer 2 (L2) packet header with a flow identifier of the packet flow; sending, by the network device, the packet to the firewall; receiving, by the network device, the packet from the firewall; and recovering, by the network device, the packet flow by modifying the packet according to the flow identifier in the packet to restore the L2 packet header of the packet.


