Split-Terminated Firewall Connection via Network Intermediaries

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network optimization techniques, such as transaction accelerators, often compromise network transparency, making it difficult for organizations to monitor and manage network traffic effectively due to the use of intermediary network addresses, which can lead to data corruption and limited firewall functionality.

Innovation Solution

A method and apparatus for establishing a split-terminated client-server communication connection through a stateful firewall, using a pair of network intermediaries that temporarily store and probe client requests, allowing network monitoring and optimizing communications while maintaining network transparency by using the client and server addresses, and ensuring data integrity through distinct tags and sequence numbers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If transaction accelerators use their own network addresses for communication, then communication optimization is achieved, but network transparency is compromised

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidnetwork transparency
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent uses the client's and server's existing network addresses as intermediaries in the communication path. Instead of accelerators using their own addresses, the system routes optimized communications through the original endpoint addresses, allowing firewalls to recognize and track the connections while still enabling acceleration functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If accelerators proxy for endpoints using endpoint addresses, then network transparency is maintained, but firewall connection tracking is limited

Engineering Contradiction:
Improvenetwork transparencyVSAvoidfirewall functionality
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing the accelerator connection with proper tagging before actual data transmission begins. The firewall is pre-configured to recognize the tagged packets as part of an existing authorized connection, so when optimized data flows through with the same tags, the firewall already has the connection context and will permit the traffic.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If accelerators establish multiple sessions with same addresses, then optimization flexibility increases, but stateful firewall blocking occurs

Engineering Contradiction:
Improvesession management flexibilityVSAvoidfirewall blocking
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by adding specific identification tags to packets at specific points in the communication flow. Rather than changing the fundamental address structure globally, the system locally modifies individual packets by inserting recognition tags that allow the firewall to distinguish optimized traffic from other traffic using the same network addresses.

Inventive Principle:
Principle #3Local quality

4Productivity

If accelerators manipulate communications for optimization, then data transit efficiency improves, but data corruption risk increases

Engineering Contradiction:
Improvedata transit efficiencyVSAvoiddata integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements feedback mechanisms where the accelerators send tagged probe packets to verify connection availability and proper routing before committing to optimized data transmission. The tags allow the receiving accelerator to confirm it can properly handle and forward the optimized data, creating a feedback loop that ensures data integrity before efficiency optimization is fully engaged.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8255544B2Establishing a split-terminated communication connection through a stateful firewall, with network transparency
Publication Date: 2012.08.28 RIVERBED TECH LLC
  • US8255544B2 patent drawing
  • US8255544B2 patent drawing
  • US8255544B2 patent drawing

AI summary

A method and apparatus are provided for establishing a split-terminated client-server communication connection through a stateful firewall, with network transparency. In an environment in which a pair of network intermediaries is employed to optimize client-server communications, a first intermediary intercepts a client request for a new connection. The first intermediary probes the network for a counterpart near the server, and opens an optimized communication session with a second intermediary that responds affirmatively. Some or all client-server communications that transit the intermediaries' session are accelerated or otherwise optimized. The first intermediary's probe uses the client's source address, but a different port number, while the optimized intermediary session is opened using the client's source address and source port. Therefore, a network monitoring tool can monitor the end-to-end connection, and the stateful firewall will not reject the optimized session.