The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Sep. 25, 2018

Filed:

Nov. 19, 2017
Applicant:

Fortinet, Inc., Sunnyvale, CA (US);

Inventors:

Edward Lopez, Herndon, VA (US);

Joe Mihelich, Folsom, CA (US);

Matthew F. Hepburn, Vancouver, CA;

Assignee:

Fortinet, Inc., Sunnyvale, CA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); H04L 12/931 (2013.01); H04L 29/08 (2006.01); H04L 29/12 (2006.01); G06F 17/30 (2006.01); H04L 12/911 (2013.01); H04L 12/801 (2013.01); H04L 12/803 (2013.01); H04L 12/741 (2013.01);
U.S. Cl.
CPC ...
H04L 63/0236 (2013.01); G06F 17/30589 (2013.01); G06F 17/30952 (2013.01); H04L 45/74 (2013.01); H04L 47/125 (2013.01); H04L 47/196 (2013.01); H04L 47/726 (2013.01); H04L 49/354 (2013.01); H04L 61/2007 (2013.01); H04L 63/02 (2013.01); H04L 63/029 (2013.01); H04L 63/0218 (2013.01); H04L 63/1408 (2013.01); H04L 63/1458 (2013.01); H04L 67/1002 (2013.01); H04L 67/1004 (2013.01); H04L 67/1027 (2013.01); H04L 67/142 (2013.01); H04L 63/0227 (2013.01); H04L 63/0272 (2013.01);
Abstract

A method for balancing load among firewall security devices (FSDs) is provided. According to one embodiment, a switching device performs adaptive load balancing among cluster units of an HA cluster of firewall security devices. A load balancing (LB) function implemented by the switching device is configured based on information received from a network administrator. A LB table is maintained that forms associations between hash values output by the LB function and corresponding ports of the switching device to which the cluster units are coupled. Network traffic received by the switching device is directed to appropriate cluster units based on the LB function and the LB table. A traffic load on each of the cluster units is monitored. Responsive to a deviation from a predefined ideal traffic distribution, an attempt is made to improve performance of the HA cluster by dynamically adjusting the LB balancing table to address the deviation.


Find Patent Forward Citations

Loading…