Zone-Based Firewall Policy for Virtualized Data Centers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized data centers, inter-virtual machine communication remains unprotected by physical network security appliances, posing a key security concern, especially in multi-tenant cloud environments where a segmentation firewall is required for managed virtual machines.

Innovation Solution

Implementing a zone-based firewall policy model that defines security management zones with specific attributes and rules for virtual firewalls, allowing enforcement of traffic policies across virtual machines regardless of their physical location, using a policy engine that caches results for efficient rule evaluation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical network security appliances are used, then network traffic security is protected, but inter-virtual machine communication remains unprotected as a blind spot

Engineering Contradiction:
Improvenetwork security protectionVSAvoidcoverage of security protection
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent divides the security protection function into separate virtual firewall instances that can be deployed independently within the virtualized environment. Each virtual firewall protects specific virtual machines or groups of virtual machines, allowing security coverage to extend into the previously unprotected inter-VM communication space while maintaining the benefits of physical security appliances for external traffic.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If a segmentation firewall is deployed for each virtual machine, then inter-VM traffic is protected, but management overhead increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidfirewall management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal firewall management system that can manage multiple virtual firewall instances through a single interface. The virtual firewall service implements common functions and policies that can be applied across multiple virtual machines, allowing administrators to manage segmented firewall protection without proportionally increasing management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables firewall policies and configurations to be copied and replicated across multiple virtual machines. Once a firewall rule set is created for one virtual machine, it can be efficiently copied to protect other virtual machines with similar requirements, significantly reducing the time and effort needed to deploy security across the entire virtualized environment.

Inventive Principle:
Principle #26Copying

3Reliability

If firewall policies are enforced at physical network level, then external traffic is secured, but virtual machine mobility and flexibility are reduced

Engineering Contradiction:
Improvetraffic securityVSAvoidvirtual machine mobility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces virtual firewalls as intermediary security components that operate within the virtualized environment between the virtual machines and the physical network. These virtual firewalls provide the necessary security enforcement while allowing virtual machines to move freely between physical hosts, as the security policies are enforced at the virtual level rather than being tied to specific physical network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9906496B2Zone-based firewall policy model for a virtualized data center
Publication Date: 2018.02.27 CISCO TECHNOLOGY INC
  • US9906496B2 patent drawing
  • US9906496B2 patent drawing
  • US9906496B2 patent drawing

AI summary

Techniques are provided for implementing a zone-based firewall policy. At a virtual network device, information is defined and stored that represents a security management zone for a virtual firewall policy comprising one or more common attributes of applications associated with the security zone. Information representing a firewall rule for the security zone is defined and comprises first conditions for matching common attributes of applications associated with the security zone and an action to be performed on application traffic. Parameters associated with the application traffic are received that are associated with properly provisioned virtual machines. A determination is made whether the application traffic parameters satisfy the conditions of the firewall rule and in response to determining that the conditions are satisfied, the action is performed.