Switch-Based Load Balancing for Firewall Clusters
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current load balancing systems for firewall clusters face limitations in handling asymmetric traffic flows, achieving high session-based performance, and managing geographically distributed firewall systems, particularly due to insufficient processing capabilities and difficulty in adapting to varying traffic demands.
Innovation Solution
A switching device within a network is used to manage load balancing among firewall security devices by sending control messages to enter them into a load balancing mode, maintaining a load balancing table that maps outputs of a load balancing function to ports, and forwarding packets based on configurable bit values from packet headers, enabling adaptive distribution of traffic across multiple firewall systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single network switch is used for load balancing among firewall systems, then the system structure is simple, but the number of firewall systems that can be handled is limited
Solution Approach 1:
The patent divides the load balancing function into multiple specialized load balancing switches, where each switch handles a specific subset of firewall systems. This segmentation allows the system to scale to handle more firewall systems while keeping each individual switch's complexity manageable.
2Ease of operation
If traditional load balancing systems are used, then the system is easy to manage, but processing capability is insufficient for varying traffic requirements
Solution Approach 1:
The patent implements dynamic load balancing capabilities where the system can adapt to varying traffic requirements in real-time. The load balancing switches can dynamically adjust traffic distribution based on current system conditions, enabling the system to handle peak loads effectively while maintaining ease of management through automated adjustments.
3Device complexity
If static load balancing is implemented, then the configuration is simple, but asymmetric traffic flows cannot be effectively managed
Solution Approach 1:
The patent incorporates feedback mechanisms where load balancing switches monitor traffic patterns and system performance, then use this information to dynamically adjust load distribution. This feedback loop enables effective handling of asymmetric traffic flows while maintaining manageable configuration complexity through automated adaptation.
4Area of stationary object
If geographically distributed firewall systems are connected, then system coverage is expanded, but load balancing difficulty increases due to limited processing capabilities
Solution Approach 1:
The patent introduces an additional hierarchical dimension to the load balancing architecture by deploying multiple layers of load balancing switches. This dimensional expansion allows geographically distributed firewall systems to be managed effectively, as the hierarchical structure breaks down the complex global load balancing problem into smaller, more manageable regional segments.
Data Source
AI summary
A method for balancing load among firewall security devices in a network is disclosed. According to one embodiment, a switch causes firewall security devices (FSDs) of a cluster to enter into a load balancing mode. Responsive to receiving a heartbeat signal from an FSD, information regarding the FSD and the port on which the heartbeat signal was received are added to a table maintained by the switch that maps outputs of a load balancing function to ports of the switch. A received packet is forwarded to an FSD of the cluster by: (i) extracting a configurable number of bit values from a configurable set of bit positions within the packet; (ii) determining the output of the load balancing function; (iii) identifying the port to which the FSD is coupled based on the output and the table; and (iv) transmitting the packet to the FSD via the identified port.


