Hybrid firewall for data center security
First Claim
1. A method for managing firewall requirements related to avirtualized application by a cloud management entity having a processing engine, comprising:
- responsive to determining, by the processing engine, that a virtualized application, associated with a first plurality of application virtual machines and a second plurality of firewall virtual machines, requires an increased number of application virtual machines in the first plurality, instantiating an application virtual machine;
comparing a bandwidth capacity of the required increased number of application virtual machines in the first plurality to a bandwidth capacity of the firewall virtual machines in the second plurality to determine whether a firewall ratio is exceeded by the increased number of application virtual machines; and
responsive to determining, by the processing engine, that the firewall ratio is exceeded, instantiating a firewall virtual machine.
1 Assignment
0 Petitions
Accused Products
Abstract
A system and method for managing a hybrid firewall solution, employing both hardware and software firewall components, for a cloud computing data center is provided. A virtual application is hosted by a first plurality of application virtual machines and a second plurality of firewall virtual machines provides firewalling services for traffic associated with the virtual application. A cloud management entity determines that the virtual application requires an increased number of application virtual machines. A security profile for the virtual application is verified to determine if an increased number of firewall virtual machines is required by the increased number of application virtual machines. The cloud management entity can instantiate additional application virtual machines and firewall virtual machines as required.
15 Citations
16 Claims
-
1. A method for managing firewall requirements related to a
virtualized application by a cloud management entity having a processing engine, comprising: -
responsive to determining, by the processing engine, that a virtualized application, associated with a first plurality of application virtual machines and a second plurality of firewall virtual machines, requires an increased number of application virtual machines in the first plurality, instantiating an application virtual machine; comparing a bandwidth capacity of the required increased number of application virtual machines in the first plurality to a bandwidth capacity of the firewall virtual machines in the second plurality to determine whether a firewall ratio is exceeded by the increased number of application virtual machines; and responsive to determining, by the processing engine, that the firewall ratio is exceeded, instantiating a firewall virtual machine. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
-
10. A cloud management entity, comprising:
-
a memory for storing instructions; and a processing engine, configured to execute the instructions, for, responsive to determining that a virtualized application, associated with a first plurality of application virtual machines and a second plurality of firewall virtual machines, requires an increased number of application virtual machines in the first plurality, instantiating an application virtual machine;
for comparing a bandwidth capacity of the required increased number of application virtual machines in the first plurality to a bandwidth capacity of the firewall virtual machines in the second plurality to determine whether a firewall ratio is exceeded by the increased number of application virtual machines; and
for, responsive to determining that the firewall ratio is exceeded, instantiating a firewall virtual machine. - View Dependent Claims (11, 12, 13, 14, 15, 16)
-
Specification