Invention Grant
- Patent Title: Load balancing among a cluster of firewall security devices
-
Application No.: US15232691Application Date: 2016-08-09
-
Publication No.: US09853942B2Publication Date: 2017-12-26
- Inventor: Edward Lopez , Joe Mihelich , Matthew F. Hepburn
- Applicant: Fortinet, Inc.
- Applicant Address: US CA Sunnyvale
- Assignee: Fortinet, Inc.
- Current Assignee: Fortinet, Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: Hamilton, DeSanctis & Cha LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F17/30 ; H04L29/08 ; H04L29/12 ; H04L12/801 ; H04L12/741 ; H04L12/803 ; H04L12/931 ; H04L12/911

Abstract:
A method for balancing load among firewall security devices (FSDs) is provided. According to one embodiment, imminent shutdown of a first cluster unit of an HA cluster of FSDs is gracefully handled by a switching device. A load balancing (LB) table, forming associations between hash values output by the LB function and corresponding ports of the switching device to which the cluster units are coupled, is maintained. The first cluster unit is coupled to a first port. Responsive to imminent shutdown of the first cluster unit: (i) a second cluster unit, coupled to a second port, is selected to perform security services on traffic sessions handled by the first cluster unit; and (ii) the LB table is updated by replacing reference(s) to the first port with reference(s) to the second port. Security services for subsequently received network traffic associated with the traffic sessions is performed by the second cluster unit.
Public/Granted literature
- US20160359806A1 LOAD BALANCING AMONG A CLUSTER OF FIREWALL SECURITY DEVICES Public/Granted day:2016-12-08
Information query