Network Switch Load Balancing Firewall Offloading

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data center networks face inefficiencies and bottlenecks due to the resource-intensive nature of traditional load balancers and firewalls, which hinder scalability and performance, especially as network traffic increases beyond terabit-class levels.

Innovation Solution

Implementing a system where network switches, equipped with programmable hardware and ternary content-addressable memory, share load balancing and firewall functionalities with service appliances, offloading tasks such as access control lists and trusted flows to reduce the burden on security devices and enhance scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional load balancers and firewalls are used to provide security and load balancing functionalities, then service reliability is maintained, but resource consumption increases and scalability deteriorates as network traffic exceeds terabit-class levels

Engineering Contradiction:
Improvenetwork throughputVSAvoidresource consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent combines load balancing and firewall security functionalities into a single integrated service appliance platform. This merging eliminates the need for separate appliances handling each function, reducing overall resource consumption while maintaining service reliability at terabit-class network throughput levels.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The service appliance is designed with multi-functionality, capable of performing both load balancing and security functions simultaneously. This universal platform handles diverse network services including traffic management, security enforcement, and protocol handling within a single system, improving productivity without proportionally increasing resource usage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If traditional firewalls handle all security operations, then security coverage is comprehensive, but device complexity and processing overhead increase

Engineering Contradiction:
Improvesecurity enforcementVSAvoidfirewall processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The firewall processing is segmented into different functional modules within the service appliance, including access control list processing, trusted flow identification, and security policy enforcement. This segmentation allows each component to handle specific tasks efficiently, maintaining comprehensive security coverage while reducing overall processing complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If service appliances handle all network services independently, then service functionality is complete, but resource utilization efficiency decreases

Engineering Contradiction:
Improveservice functionalityVSAvoidresource utilization efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

Multiple network service functions are merged within the service appliance cluster, allowing shared processing resources for tasks such as flow table management, hashing operations, and packet forwarding. This combining approach maintains complete service functionality while improving resource utilization efficiency through centralized resource pools that serve multiple services simultaneously.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10491522B2Data plane integration
Publication Date: 2019.11.26 CISCO TECHNOLOGY INC
  • US10491522B2 patent drawing
  • US10491522B2 patent drawing
  • US10491522B2 patent drawing

AI summary

In an example, a system and method for data plane integration is described. Aspects of the embodiments are directed to a service application connected to a switch of a network fabric and a method of data plane integration performed at a service appliance, the service appliance providing firewall functionality. The service appliance can receive a data packet from a network location; determine a flow owner of the data packet based on a hashing table; and transmit the data packet based on the determined flow owner of the data packet.