Remote Access Firewall Routing to Reduce Cross-Region Latency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing remote access systems experience degraded performance and increased latency due to the overload of back-end firewalls caused by the additional load of routing out-region access requests, leading to resource allocation and complexity issues.
Innovation Solution
Implementing distribution firewalls between front-end and back-end firewalls in the cloud platform to offload the routing of out-region access requests, reducing the load on back-end firewalls and eliminating latency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If back-end firewalls route out-region access requests directly, then access control is simplified, but latency increases and performance degrades due to overload
Solution Approach 1:
The patent segments the firewall architecture by introducing distribution firewalls between front-end and back-end firewalls. These distribution firewalls handle out-region access requests separately, dividing the routing workload and preventing back-end firewalls from becoming overloaded, thereby reducing latency while maintaining structured access control.
Solution Approach 2:
The distribution firewalls act as intermediary components that receive access requests from front-end firewalls and route them to appropriate back-end firewalls. This intermediary layer offloads the routing function from back-end firewalls, eliminating the latency caused by direct routing while preserving the hierarchical access control structure.
2Device complexity
If back-end firewalls handle all routing functions, then system structure is simplified, but resource utilization becomes inefficient and latency increases
Solution Approach 1:
The routing function is segmented and distributed across multiple firewalls. Distribution firewalls handle out-region routing, while back-end firewalls focus on regional access control. This segmentation improves resource utilization by preventing any single component from becoming a bottleneck, thereby enhancing overall system productivity.
Solution Approach 2:
Distribution firewalls serve as intermediaries that specialize in routing out-region traffic. By assigning this specific function to intermediary components, the system achieves better resource allocation and processing efficiency, as each component handles only its designated workload rather than all routing functions.
3Loss of time
If distribution firewalls are added between front-end and back-end firewalls, then latency is reduced and performance is enhanced, but device complexity increases
Solution Approach 1:
The firewall architecture is segmented into three functional layers: front-end firewalls for user authentication, distribution firewalls for out-region routing, and back-end firewalls for regional access control. This segmentation reduces latency by assigning specific functions to appropriate layers, while the modular structure makes the increased complexity manageable through clear functional separation.
Solution Approach 2:
The distribution firewalls provide multi-functionality by handling both routing decisions and access control policies for out-region traffic. This universal approach consolidates certain functions into dedicated components, reducing the overall complexity burden on individual firewalls while maintaining enhanced performance and reduced latency.
Data Source
AI summary
Systems and methods are provided for use in providing remote access across multiple regions. One example method includes receiving a remote access request from a user terminal associated with a remote user, where the request is specific to a first data center of a network, and opening, by a front-end firewall, a first IP security (IPSec) tunnel with the user terminal. The method also includes forwarding, by the front-end firewall, the request to a distribution firewall and routing, by the distribution firewall, the request to a back-end firewall, which is specific to the first data center. The method then further includes opening, by the back-end firewall, a second IPSec tunnel with the network and forwarding the request, through the second IPSec tunnel, to the network to thereby support communication between the user terminal and the network, via the first and second IPSec tunnels.


