US 7,475,162 B2
Preserving symmetrical routing in a communication system based upon a server farm
Jean-Marc Berthaud, Villeneuve Loubet (France); Pascal Chauffour, Cagnes sur Mer (France); Jean-Claude Dispensa, Saint Jeannet (France); and Valerie Mahe, Nice (France)
Assigned to International Business Machines Corporation, Armonk, N.Y. (US)
Filed on Dec. 13, 2007, as Appl. No. 11/955,479.
Application 11/955479 is a continuation of application No. 10/317397, filed on Dec. 12, 2002, granted, now 7,359,992.
Claims priority of application No. 01480134 (EP), filed on Dec. 21, 2001.
Prior Publication US 2008/0109892 A1, May 08, 2008
This patent is subject to a terminal disclaimer.
Int. Cl. G06F 15/16 (2006.01); H04L 12/28 (2006.01)
U.S. Cl. 709—249  [709/223; 709/224; 709/229; 370/401] 3 Claims
OG exemplary drawing
 
1. A computer program product stored on a computer readable medium for preserving the symmetrical routing in a communication system comprising instructions configured to implement a method, said method comprising:
providing a server farm connected to an Internet by an Internet front-end including at least an Internet access router, said server farm further comprising:
a plurality of customer cabinets with each customer cabinet including at least one WEB server and server farm resources enabling users connected to the Internet to access the at least one WEB server in each of the plurality of customer cabinets;
a plurality of firewalls for controlling communication between users and the at least one WEB server, said plurality of firewalls using Virtual Router Redundancy Protocol (VRRP) to set one of the plurality of firewalls a primary firewall which owns a primary interface of a VRRP group of interfaces to at least one of the plurality of customer cabinets and to establish communication between an Internet user and said at least one WEB server;
checking in each of said plurality of firewalls whether there is a change of VRRP state from primary to secondary or from secondary to primary; and
disabling an interface from said Internet to said firewall if the VRRP state has changed from primary to secondary, or enabling an interface from said Internet to said firewall if the VRRP state has changed from secondary to primary.