Split-Terminated Firewall Connection via Network Intermediaries
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network optimization techniques, such as transaction accelerators, often compromise network transparency, making it difficult for organizations to monitor and manage network traffic effectively due to the use of intermediary network addresses, which can lead to data corruption and limited firewall functionality.
Innovation Solution
A method and apparatus for establishing a split-terminated client-server communication connection through a stateful firewall, using a pair of network intermediaries that temporarily store and probe client requests, allowing network monitoring and optimizing communications while maintaining network transparency by using the client and server addresses, and ensuring data integrity through distinct tags and sequence numbers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If transaction accelerators use their own network addresses for communication, then communication optimization is achieved, but network transparency is compromised
Solution Approach 1:
The patent uses the client's and server's existing network addresses as intermediaries in the communication path. Instead of accelerators using their own addresses, the system routes optimized communications through the original endpoint addresses, allowing firewalls to recognize and track the connections while still enabling acceleration functionality.
2Loss of information
If accelerators proxy for endpoints using endpoint addresses, then network transparency is maintained, but firewall connection tracking is limited
Solution Approach 1:
The system performs preliminary actions by establishing the accelerator connection with proper tagging before actual data transmission begins. The firewall is pre-configured to recognize the tagged packets as part of an existing authorized connection, so when optimized data flows through with the same tags, the firewall already has the connection context and will permit the traffic.
3Adaptability or versatility
If accelerators establish multiple sessions with same addresses, then optimization flexibility increases, but stateful firewall blocking occurs
Solution Approach 1:
The patent applies local quality by adding specific identification tags to packets at specific points in the communication flow. Rather than changing the fundamental address structure globally, the system locally modifies individual packets by inserting recognition tags that allow the firewall to distinguish optimized traffic from other traffic using the same network addresses.
4Productivity
If accelerators manipulate communications for optimization, then data transit efficiency improves, but data corruption risk increases
Solution Approach 1:
The system implements feedback mechanisms where the accelerators send tagged probe packets to verify connection availability and proper routing before committing to optimized data transmission. The tags allow the receiving accelerator to confirm it can properly handle and forward the optimized data, creating a feedback loop that ensures data integrity before efficiency optimization is fully engaged.
Data Source
AI summary
A method and apparatus are provided for establishing a split-terminated client-server communication connection through a stateful firewall, with network transparency. In an environment in which a pair of network intermediaries is employed to optimize client-server communications, a first intermediary intercepts a client request for a new connection. The first intermediary probes the network for a counterpart near the server, and opens an optimized communication session with a second intermediary that responds affirmatively. Some or all client-server communications that transit the intermediaries' session are accelerated or otherwise optimized. The first intermediary's probe uses the client's source address, but a different port number, while the optimized intermediary session is opened using the client's source address and source port. Therefore, a network monitoring tool can monitor the end-to-end connection, and the stateful firewall will not reject the optimized session.


