WLAN Firewall ESSID Policy Session Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current stateful firewalls in Wireless Local Area Networks (WLANs) face challenges in managing network security and session synchronization when wireless client devices roam between access points, leading to inefficiencies and potential security breaches due to the complexity of managing firewall policies and session information across multiple access points.

Innovation Solution

Implementing a stateful firewall system at the WLAN infrastructure device that uses Extended Service Set Identifier (ESSID) parameters to define firewall policies, allows selective flooding of packets to wired ports while blocking wireless ports, and employs predictive and on-demand session migration techniques to maintain session statefulness during client roaming.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a stateful firewall is implemented at each access point to provide granular traffic control and security, then network security is improved, but device complexity and management difficulty increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidfirewall management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the firewall functionality by introducing a centralized controller that manages firewall policies for multiple access points. The controller divides the complex task of firewall management into smaller components: policy creation, policy distribution, and policy enforcement at individual APs. This allows each AP to implement stateful firewalling with reduced complexity since the policy management burden is shared centrally.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The centralized controller acts as an intermediary between network administrators and access points. It mediates the complex interactions by centralizing policy management, automatically distributing firewall rules to appropriate APs, and coordinating state information across the network. This intermediary layer shields individual APs from the full complexity of multi-AP firewall coordination.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Stability of the object's composition

If stateful firewall policies are enforced across multiple access points to maintain session statefulness during client roaming, then session continuity is improved, but overhead in session synchronization increases

Engineering Contradiction:
Improvesession statefulnessVSAvoidsession synchronization overhead
Core Design Contradiction:
Stability of the object's compositionVSLoss of energy

Solution Approach 1:

The controller performs preliminary actions by pre-establishing session state information at the centralized level before clients roam between access points. When a client associates with an AP, the controller proactively prepares and distributes relevant session state to potential target APs in advance, reducing the synchronization overhead that would occur during actual roaming events.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent merges session state management across multiple access points by consolidating it at the centralized controller. Instead of each AP maintaining separate, isolated session tables that require complex synchronization, the controller maintains a unified view of all session states and distributes only the necessary portions to each AP, reducing redundant synchronization overhead.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If firewall session information is synchronized across all access points to enable seamless roaming, then client mobility is improved, but network traffic overhead and processing load increase

Engineering Contradiction:
Improveclient roaming capabilityVSAvoidnetwork efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent applies local quality by having each access point maintain only the session state information locally relevant to its current and potential clients, rather than synchronizing all session information across all APs. The centralized controller determines which session states need to be distributed to which APs based on client location and roaming patterns, reducing unnecessary network traffic and processing load.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Instead of fully synchronizing all session information across all access points (excessive action), the system implements partial synchronization where only the specific session states needed for current and potential roaming clients are distributed to each AP. This partial action approach maintains client mobility while significantly reducing network overhead and processing requirements.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8826413B2Wireless local area network infrastructure devices having improved firewall features
Publication Date: 2014.09.02 EXTREME NETWORKS INC
  • US8826413B2 patent drawing
  • US8826413B2 patent drawing
  • US8826413B2 patent drawing

AI summary

Methods and systems are provided for improving a firewall implemented at a WLAN infrastructure device (WID). The WID includes a stateful firewall that implements firewall rules based on an ESSID of the WID to specify whether traffic is allowed to or from the ESSID. For example, in one implementation of such a firewall rule, packets that are required to be sent out on all wired ports can be blocked from being flooded out on WLANs (e.g., the packet is allowed to pass only to the wired ports). A method and system are provided for preventing a malicious wireless client device (WCD) that is transmitting undesirable traffic from using RF resources by deauthenticating the malicious WCD to remove it from the WLAN and blacklisting it to prevent it from rejoining the WLAN for a time period. Method and systems are also provided for either “on-demand” and/or predicatively communicating state information regarding an existing firewall session.