Virtual Firewall Configuration for Secure Cluster Node Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge of implementing network isolation between a master and a node in a cluster during telecommunication service deployment is complicated by the need to initially configure the firewall to be completely open, leading to potential safety hazards and errors due to frequent modifications.

Innovation Solution

A method involving creating and configuring virtual firewalls based on network information to establish isolation between the master and node, allowing for accurate and quick network separation without frequent modifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the firewall is configured to be completely open in the initial stage, then the master can communicate with the node, but there are potential safety hazards

Engineering Contradiction:
Improvecommunication capabilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-configuring the firewall rules in the NFVO before cluster creation. The NFVO automatically obtains node network information after creation and configures the firewall accordingly, eliminating the need for manual post-creation configuration and avoiding the security risks of completely open firewalls.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the firewall configuration is modified frequently after node creation, then network isolation is implemented, but the operations are complicated and prone to errors

Engineering Contradiction:
Improvenetwork isolationVSAvoidfirewall configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the NFVO to automatically obtain node network information after cluster creation and autonomously configure the firewall rules. This automated approach eliminates manual intervention, reduces operational complexity, and minimizes configuration errors while ensuring proper network isolation.

Inventive Principle:
Principle #25Self-service

3Reliability

If the firewall is configured before cluster creation, then network isolation can be implemented, but the master lacks network information of the node

Engineering Contradiction:
Improvenetwork isolationVSAvoidnode network information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent resolves this contradiction by performing preliminary configuration of the firewall framework in the NFVO before cluster creation, then obtaining the node network information automatically after creation. This two-stage approach allows the firewall to be pre-configured while still having access to complete network information when needed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4723552A1Firewall configuration method, NFVO, server, and storage medium
Publication Date: 2026.04.08 ZTE CORP
  • EP4723552A1 patent drawingFigure 1~2
  • EP4723552A1 patent drawingFigure 3~5
  • EP4723552A1 patent drawingFigure 6~7

AI summary

Embodiments of the present application relate to the field of communications, and provide a firewall configuration method, a network function virtualization orchestrator, a server, and a computer-readable storage medium. The firewall configuration method includes: acquiring a cluster creation request including network information of a master of a target cluster to be created; creating and configuring, based on the network information of the master, a first virtual firewall between the master and a network function virtualization orchestrator; creating the master, and creating at least one node after the master is created and enters an operation state; and creating and configuring, based on network information of each node having been created and the network information of the master, a second virtual firewall between the master and the node.