Tel: +86(10)-4000581019-8003
Email: service@grt.ink

Sign in

USD-DOLLAR

Currency

USD-DOLLAR
  • USD-DOLLAR
  • EUR-EURO

The Key Role of Bypass Network Cards in Firewalls

< Back

 When building enterprise-grade network architectures, security and availability are often conflicting factors that require trade-offs. We usually deploy security devices such as firewalls into the network in a serial manner to perform in-depth inspection of incoming and outgoing data flows. However, this serial mode also introduces a single point of failure risk: once the firewall itself goes down due to power failure, system crash or software malfunction, the entire network channel will be cut off, resulting in service interruption and more direct losses than security incidents.

  So is there a technology that can keep security policies running normally and maintain uninterrupted network links when security devices fail? The answer is yes — the Bypass network adapter.

1. Severe Challenge: When the "Guardian" Fails

  Imagine a typical network topology: External Network <---> Firewall <---> Core Switch <---> Internal Servers. In this serial architecture, the firewall is the mandatory path for all traffic. It works consistently, but failures can occur unexpectedly:   

● Hardware faults: power supply damage, mainboard failure.   

● Software faults: OS kernel panic, crash of firewall service processes.   

● Human errors: system freeze caused by incorrect configuration or maintenance operations.

  Once any of the above occurs, traditional firewall NICs stop working. Packets cannot be received or processed, and network connections drop. For finance, e-commerce and online service businesses, such outages lead to massive economic losses and reputational damage.

2. Bypass NIC: Emergency Channel at the Moment of Failure

  The Bypass network adapter is a hardware-level solution designed to solve this pain point. It is more than an ordinary network card; it acts as an intelligent physical network switch. Taking Guangruntong (GRT) GF-1002EBP series Bypass NIC as an example, let’s see how it works. It supports three core operating modes:

  1. Normal Working Mode   At this time, it works as a standard 10G dual-port NIC. Data enters via Port 0, passes through the PCIe bus to the server CPU and firewall software for processing, then exits from Port 1. All security policies take effect under this mode.

  2. Bypass Mode   This is its core value. When trigger conditions are met (such as host power loss, system crash, watchdog timeout), independent hardware circuits on the NIC activate instantly and physically connect Port 0 and Port 1 directly.

  The key point: this switching does not rely on the server operating system or power supply. Data traffic no longer enters the server; it flows directly from Port 0 to Port 1 just like through a short wire. For the network, it temporarily bypasses the faulty firewall while basic connectivity remains intact.

  3. Disconnect Mode   Under this mode, the NIC simulates a disconnected network cable and forcibly cuts off the two ports. This is used under certain specific security policies.

  The intelligence of Guangruntong (GRT) GF-1002EBP also lies in its programmable watchdog timer. The driver or application periodically feeds the watchdog. If the watchdog is not fed upon timeout (indicating a frozen system or application), the NIC automatically switches to Bypass mode to detect and respond to software-level failures.

3. Essential Difference from NIC Teaming

  Many people ask: can server NIC port aggregation or failover also deliver high availability? A critical concept must be clarified: they operate at different layers.   

● NIC Teaming: software fault tolerance implemented at the OS driver layer. It handles failures of NIC ports, cables or switch ports. If the whole server crashes and the OS stops running, this function fails.   

● Bypass function: physical bypass implemented at the hardware layer. It addresses the ultimate failure scenario: complete server downtime.

  In short, Bypass is a lower-level and more thorough "last line of defense" than NIC Teaming. Bypass NICs are indispensable for serial nodes deployed with firewalls.

4. Typical Application Scenarios & Values

  The core scenario covers all security devices deployed in serial within the network.   

● Next-generation firewalls   

● Intrusion Detection / Prevention Systems   

● Internet behavior management   

● Video conference optimization equipment   

● Link load balancing devices

  Core values:   

● Business continuity: minimize service downtime caused by single-point hardware/software faults, ensuring 7×24 non-stop network operation.  

● Fail-safe design: follows the principle that disconnection is worse than insecurity. It prioritizes link connectivity under extreme conditions.   

● Maintenance convenience: manual Bypass trigger is available during firewall OS upgrade or patching, enabling smooth maintenance without service perception.

5. Summary

  In this digital era where businesses heavily rely on networks, network resilience is critical. For serially deployed security devices, they must not become reliability weak points. With its unique hardware bypass mechanism, the Bypass NIC provides a reliable fallback solution for firewalls and becomes a true guardian in high-availability network architectures.

  When selecting Bypass NICs, focus on switching mechanisms, reliability, and products such as Guangruntong (GRT) GF-1002EBP that support multiple hardware & software trigger modes and advanced watchdog functions, to build a robust and flexible line of defense for your core network.