Virtual Firewall via Switch and Virtual Function
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Migrating services to virtualized networks poses challenges due to increased complexity in accommodating message routing and scaling, especially when transitioning from dedicated infrastructure to virtualized environments.
Innovation Solution
A basic firewall is created using a virtual networking function, comprising a virtual switch and a basic firewall virtual function, which can be instantiated and managed by a control system, allowing for flexible configuration and filtering of traffic at the transport layer without application layer involvement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If services are migrated to virtualized networks, then flexibility in scaling and locating services is improved, but complexity in accommodating message routing and maintaining services increases
Solution Approach 1:
The patent introduces a virtual switch as an intermediary component that mediates message routing between service components in the virtualized network. The virtual switch handles the complexity of routing, filtering, and forwarding traffic between virtual machines and external networks, thereby reducing the routing complexity burden on individual services while maintaining the flexibility benefits of virtualization.
2Ease of manufacture
If a basic firewall is created using virtual networking functions, then ease of creation and management is improved, but potential loss of filtering precision compared to dedicated infrastructure may occur
Solution Approach 1:
The patent implements a basic firewall virtual function that provides universal firewall capabilities across multiple services and virtual machines. The virtual switch incorporates firewall functionality that can be applied consistently across different service components, enabling easy creation and management of firewall rules while maintaining adequate filtering precision for general security requirements through standardized rule sets.
3Device complexity
If firewall functionality is integrated into virtual networking functions, then device complexity is reduced, but potential loss of specialized firewall performance may occur
Solution Approach 1:
The patent merges firewall functionality with virtual networking functions by integrating the basic firewall virtual function into the virtual switch infrastructure. This consolidation reduces overall device complexity by eliminating separate dedicated firewall appliances while maintaining adequate filtering performance through the combined networking and security functions provided by the virtual switch.
Data Source
AI summary
Concepts and technologies are disclosed herein for providing a basic firewall using a virtual networking function. A control system having a processor can detect a firewall request that can include a request to create a basic firewall. The processor can analyze a recipe to determine a virtual switch and a basic firewall virtual function that are to provide the functionality of the basic firewall. The processor can trigger instantiation of the virtual switch via a network control function and instantiation of the basic firewall virtual function via a service control function. The processor also can validate the basic firewall. The basic firewall can provide filtering of traffic at the network transport layer using the virtual switch, and as such, the virtual switch may not operate on the application layer.


