WLAN Firewall ESSID Policy Session Migration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current stateful firewalls in Wireless Local Area Networks (WLANs) face challenges in managing network security and session synchronization when wireless client devices roam between access points, leading to inefficiencies and potential security breaches due to the complexity of managing firewall policies and session information across multiple access points.
Innovation Solution
Implementing a stateful firewall system at the WLAN infrastructure device that uses Extended Service Set Identifier (ESSID) parameters to define firewall policies, allows selective flooding of packets to wired ports while blocking wireless ports, and employs predictive and on-demand session migration techniques to maintain session statefulness during client roaming.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a stateful firewall is implemented at each access point to provide granular traffic control and security, then network security is improved, but device complexity and management difficulty increase significantly
Solution Approach 1:
The patent segments the firewall functionality by introducing a centralized controller that manages firewall policies for multiple access points. The controller divides the complex task of firewall management into smaller components: policy creation, policy distribution, and policy enforcement at individual APs. This allows each AP to implement stateful firewalling with reduced complexity since the policy management burden is shared centrally.
Solution Approach 2:
The centralized controller acts as an intermediary between network administrators and access points. It mediates the complex interactions by centralizing policy management, automatically distributing firewall rules to appropriate APs, and coordinating state information across the network. This intermediary layer shields individual APs from the full complexity of multi-AP firewall coordination.
2Stability of the object's composition
If stateful firewall policies are enforced across multiple access points to maintain session statefulness during client roaming, then session continuity is improved, but overhead in session synchronization increases
Solution Approach 1:
The controller performs preliminary actions by pre-establishing session state information at the centralized level before clients roam between access points. When a client associates with an AP, the controller proactively prepares and distributes relevant session state to potential target APs in advance, reducing the synchronization overhead that would occur during actual roaming events.
Solution Approach 2:
The patent merges session state management across multiple access points by consolidating it at the centralized controller. Instead of each AP maintaining separate, isolated session tables that require complex synchronization, the controller maintains a unified view of all session states and distributes only the necessary portions to each AP, reducing redundant synchronization overhead.
3Adaptability or versatility
If firewall session information is synchronized across all access points to enable seamless roaming, then client mobility is improved, but network traffic overhead and processing load increase
Solution Approach 1:
The patent applies local quality by having each access point maintain only the session state information locally relevant to its current and potential clients, rather than synchronizing all session information across all APs. The centralized controller determines which session states need to be distributed to which APs based on client location and roaming patterns, reducing unnecessary network traffic and processing load.
Solution Approach 2:
Instead of fully synchronizing all session information across all access points (excessive action), the system implements partial synchronization where only the specific session states needed for current and potential roaming clients are distributed to each AP. This partial action approach maintains client mobility while significantly reducing network overhead and processing requirements.
Data Source
AI summary
Methods and systems are provided for improving a firewall implemented at a WLAN infrastructure device (WID). The WID includes a stateful firewall that implements firewall rules based on an ESSID of the WID to specify whether traffic is allowed to or from the ESSID. For example, in one implementation of such a firewall rule, packets that are required to be sent out on all wired ports can be blocked from being flooded out on WLANs (e.g., the packet is allowed to pass only to the wired ports). A method and system are provided for preventing a malicious wireless client device (WCD) that is transmitting undesirable traffic from using RF resources by deauthenticating the malicious WCD to remove it from the WLAN and blacklisting it to prevent it from rejoining the WLAN for a time period. Method and systems are also provided for either “on-demand” and/or predicatively communicating state information regarding an existing firewall session.


