Perimeter Firewall Configuration via SDN Security Groups

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud data centers, configuring firewall policies to extend network security from virtual firewalls to perimeter firewalls is challenging due to the lack of integration between virtual and physical network security systems, leading to inconsistent security policies across different layers of the network.

Innovation Solution

A security management system interfaces with a centralized network controller to obtain security group information from virtual firewalls and automatically configures perimeter firewalls with security policies, mapping address group information to apply consistent security policies for both east-west and north-south traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If security policies are configured separately for virtual firewalls and perimeter firewalls, then each firewall can be independently managed, but security policy consistency across different network layers deteriorates

Engineering Contradiction:
ImproveIndependent firewall managementVSAvoidSecurity policy consistency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges the security policy management of virtual firewalls and perimeter firewalls by having the perimeter firewall inherit security group information from the virtual firewall. The security management system collects security group information from the virtual firewall and automatically configures the perimeter firewall with matching policies, creating a unified security management approach that ensures consistency across both firewalls while maintaining independent operational capabilities.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If security group information from virtual firewall is automatically mapped to perimeter firewall, then security policy consistency is improved, but system complexity increases

Engineering Contradiction:
ImproveSecurity policy consistencyVSAvoidIntegration between virtual and physical security systems
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security management system as an intermediary component that bridges the virtual firewall and perimeter firewall. This mediator collects security group information from the virtual firewall, performs automatic mapping and translation of security policies, and configures the perimeter firewall accordingly. This intermediary approach simplifies the overall system architecture by centralizing the integration logic in a dedicated management system rather than creating direct complex connections between virtual and physical security systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11159487B2Automatic configuration of perimeter firewalls based on security group information of SDN virtual firewalls
Publication Date: 2021.10.26 JUNIPER NETWORKS INC
  • US11159487B2 patent drawing
  • US11159487B2 patent drawing
  • US11159487B2 patent drawing

AI summary

Techniques are described for configuring a one or more perimeter firewalls positioned on the perimeter of a data center based on security group information associated with an internal virtual firewall operating within one or more software defined networks (SDN) within the data center. For example, a Security Management System (SMS) may access a centralized network controller (CNC) for an SDN within the data center to obtain security group information for a virtual firewall of the SDN, wherein the security group information specifies a cluster of virtual machines of the software defined network that is protected by the virtual firewall; and automatically configuring, with the SMS, a perimeter firewall positioned on the edge of the data center with one or more security policies based on the security group information from the virtual firewall of the SDN.