Switch-Based Load Balancing for Firewall Clusters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current load balancing systems for firewall clusters face limitations in handling asymmetric traffic flows, achieving high session-based performance, and managing geographically distributed firewall systems, particularly due to insufficient processing capabilities and difficulty in adapting to varying traffic demands.

Innovation Solution

A switching device within a network is used to manage load balancing among firewall security devices by sending control messages to enter them into a load balancing mode, maintaining a load balancing table that maps outputs of a load balancing function to ports, and forwarding packets based on configurable bit values from packet headers, enabling adaptive distribution of traffic across multiple firewall systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single network switch is used for load balancing among firewall systems, then the system structure is simple, but the number of firewall systems that can be handled is limited

Engineering Contradiction:
Improvesystem structureVSAvoidnumber of firewall systems
Core Design Contradiction:
Device complexityVSQuantity of substance

Solution Approach 1:

The patent divides the load balancing function into multiple specialized load balancing switches, where each switch handles a specific subset of firewall systems. This segmentation allows the system to scale to handle more firewall systems while keeping each individual switch's complexity manageable.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If traditional load balancing systems are used, then the system is easy to manage, but processing capability is insufficient for varying traffic requirements

Engineering Contradiction:
Improvesystem managementVSAvoidprocessing capability
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent implements dynamic load balancing capabilities where the system can adapt to varying traffic requirements in real-time. The load balancing switches can dynamically adjust traffic distribution based on current system conditions, enabling the system to handle peak loads effectively while maintaining ease of management through automated adjustments.

Inventive Principle:
Principle #15Dynamics

3Device complexity

If static load balancing is implemented, then the configuration is simple, but asymmetric traffic flows cannot be effectively managed

Engineering Contradiction:
Improveconfiguration complexityVSAvoidasymmetric traffic handling
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent incorporates feedback mechanisms where load balancing switches monitor traffic patterns and system performance, then use this information to dynamically adjust load distribution. This feedback loop enables effective handling of asymmetric traffic flows while maintaining manageable configuration complexity through automated adaptation.

Inventive Principle:
Principle #23Feedback

4Area of stationary object

If geographically distributed firewall systems are connected, then system coverage is expanded, but load balancing difficulty increases due to limited processing capabilities

Engineering Contradiction:
Improvesystem coverageVSAvoidload balancing difficulty
Core Design Contradiction:
Area of stationary objectVSDevice complexity

Solution Approach 1:

The patent introduces an additional hierarchical dimension to the load balancing architecture by deploying multiple layers of load balancing switches. This dimensional expansion allows geographically distributed firewall systems to be managed effectively, as the hierarchical structure breaks down the complex global load balancing problem into smaller, more manageable regional segments.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9288183B2Load balancing among a cluster of firewall security devices
Publication Date: 2016.03.15 FORTINET INC
  • US9288183B2 patent drawing
  • US9288183B2 patent drawing
  • US9288183B2 patent drawing

AI summary

A method for balancing load among firewall security devices in a network is disclosed. According to one embodiment, a switch causes firewall security devices (FSDs) of a cluster to enter into a load balancing mode. Responsive to receiving a heartbeat signal from an FSD, information regarding the FSD and the port on which the heartbeat signal was received are added to a table maintained by the switch that maps outputs of a load balancing function to ports of the switch. A received packet is forwarded to an FSD of the cluster by: (i) extracting a configurable number of bit values from a configurable set of bit positions within the packet; (ii) determining the output of the load balancing function; (iii) identifying the port to which the FSD is coupled based on the output and the table; and (iv) transmitting the packet to the FSD via the identified port.