SE520437C2 - Method for minimizing the number of openings in a firewall located between a private and a public network - Google Patents
Method for minimizing the number of openings in a firewall located between a private and a public networkInfo
- Publication number
- SE520437C2 SE520437C2 SE0101007A SE0101007A SE520437C2 SE 520437 C2 SE520437 C2 SE 520437C2 SE 0101007 A SE0101007 A SE 0101007A SE 0101007 A SE0101007 A SE 0101007A SE 520437 C2 SE520437 C2 SE 520437C2
- Authority
- SE
- Sweden
- Prior art keywords
- computer unit
- computer
- communication
- unit
- units
- Prior art date
Links
- 238000000034 method Methods 0.000 title claims abstract description 18
- 238000004891 communication Methods 0.000 claims abstract description 40
- 238000004590 computer program Methods 0.000 claims abstract description 23
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/029—Firewall traversal, e.g. tunnelling or, creating pinholes
Landscapes
- Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
Abstract
Description
.~. 2:-- (Il N) (I) . ~ » » »- 2 en gemensam lP-adress och där kommunikationen sker via en gemensam TCP port. . ~. 2: - (Il N) (I). ~ »» »- 2 a common LP address and where the communication takes place via a common TCP port.
EP-Al-O 909 074 beskriver hur en brandvägg kan hantera olika säkerhetsnivåer för olika användare genom att applicera olika uppsättningar av tillgänglighetsregler. Brandvaggen kan även omdirigera vissa sessioner till en annan server för processering.EP-Al-0 909 074 describes how a firewall can handle different security levels for different users by applying different sets of accessibility rules. The cradle can also redirect some sessions to another server for processing.
JP-A-10135982 beskriver hur två olika IP-adresser kan dela på en gemensam MAC-adress.JP-A-10135982 describes how two different IP addresses can share a common MAC address.
Redogörelse för föreliggande uppfinning Tekniska problem Under beaktande av teknikens tidigare ståndpunkt såsom den beskrivs ovan, och med utgångspunkt från ett tekniskt område enligt ovan, så är det ett tekniskt problem att minimera antalet öppningar i använd brandvägg.Disclosure of the present invention Technical problems Taking into account the prior art as described above, and starting from a technical area as above, it is a technical problem to minimize the number of openings in the firewall used.
Det är ett tekniskt problem att erbjuda möjlligheten att kommunicera med ett flertal olika användare, användande ett flertal olika protokoll, med endast en öppning i brandväggen.It is a technical problem to offer the possibility to communicate with a number of different users, using a number of different protocols, with only one opening in the firewall.
Det är ett tekniskt problem att låta ett flertal olika andra datorenheter kommunicera med sinsemellan ett flertal olika första datorenheter enligt olika protokoll via en gemensam tredje datorenhet, där samtliga andra datorenheter endast fordrar en öppning genom sina respektive brandväggar.It is a technical problem to allow a plurality of different other computer units to communicate with each other a plurality of different first computer units according to different protocols via a common third computer unit, where all other computer units only require an opening through their respective firewalls.
Lösningen Med avsikten att erbjuda en lösning till ett eller flera av de ovan angivna problemen utgår föreliggande uppfinning från en metod, datorprogramprodukter, samt ett datorläsbart medium, för att, via ett nätverk, erhålla en kommunikation mellan en första datorenhet och en andra datorenhet, vilken kommunikation sker via en tredje datorenhet. En brandvägg är upprättad mellan den andra datorenheten och den tredje datorenheten, och all kommunikation mellan den andra datorenheten och den tredje datorenheten sker genom denna brandvägg.The Solution In order to provide a solution to one or more of the above problems, the present invention is based on a method, computer program products, and a computer readable medium, for obtaining, via a network, a communication between a first computer unit and a second computer unit, which communication takes place via a third computer unit. A firewall is established between the second computer unit and the third computer unit, and all communication between the second computer unit and the third computer unit takes place through this firewall.
Föreliggande uppfinning anvisar att, med avsikten att minimera antalet öppningar i en brandvägg, all kommunikation mellan den andra datorenheten och 10 20 25 30 0"! 'i Ci -b- CN \'l 3 den tredje datorenheten sker viaportar som initierats eller öppnats av nämnda andra datorenhet.The present invention provides that, for the purpose of minimizing the number of openings in a firewall, all communication between the second computer unit and the third computer unit takes place via ports initiated or opened by said second computer unit.
Med avsikten att minimera antalet använda portar anvisar förelliggande uppfinning att den andra datorenheten endast öppnar en port för kommunikation med den tredje datorenheten, och att all kommunikation via denna enda port sker enligt ett specifikt protokoll. Enligt denna utföringsform skall den tredje datorenheten, i kommunikationen med den första datorenheten, översätta mellan det protokoll enligt vilket den första datorenheten kommunicerar med den tredje datorenheten och det specifika protokollet enligt vilket den tredje datorenheten kommunicerar med den andra datorenheten. l det fall som ett flertal olika första datorenheter kommunicerar med den andra datorenheten via den tredje datorenheten, och där dessa första datorenheter kommunicerar enligt samma eller sinsemellan olika, från varandra oberoende, protokoll, vidarebefordrar den tredje datorenheten kommunikationen från det flertalet olika första datorenheterna till den andra datorenheten via den enda porten och enligt det specifika protokollet.With the intention of minimizing the number of ports used, the present invention provides that the second computer unit only opens one port for communication with the third computer unit, and that all communication via this single port takes place according to a specific protocol. According to this embodiment, in the communication with the first computer unit, the third computer unit shall translate between the protocol according to which the first computer unit communicates with the third computer unit and the specific protocol according to which the third computer unit communicates with the second computer unit. In the case where a plurality of different first computer units communicate with the second computer unit via the third computer unit, and where these first computer units communicate according to the same or mutually different, independent, protocols, the third computer unit forwards the communication from the plurality of different first computer units to the the second computer unit via the single port and according to the specific protocol.
Det är även möjligt att låta ett flertal andra datorenheter kommunicera med sina respektive en eller flera första datorenheter via den tredje datorenheten.It is also possible to have a plurality of other computer units communicate with their respective one or more first computer units via the third computer unit.
Med avsikten att tillåta ett flertal olika andra datorenheter kommunicera med sina respektive första datorenheter anvisar föreliggande uppfinning att respektive andra datorenhet tilldelas en eller flera adresser eller portar hos den tredje datorenheten för mottagande av kommunikation från sina respektive en eller flera första datorenheter, och att den tredje datorenheten, vid en kontakt från en första datorenhet med den tredje datorenheten, identifierar korrekt andra datorenhet för den kontaktande första datorenheten genom den adress eller port som den första datorenheten använder vid kontakten.With the intention of allowing a plurality of different computer units to communicate with their respective first computer units, the present invention provides that each second computer unit is assigned one or more addresses or ports of the third computer unit for receiving communication from its respective one or more first computer units, and that the third the computer unit, in a contact from a first computer unit with the third computer unit, correctly identifies the second computer unit of the contacting first computer unit by the address or port that the first computer unit uses at the contact.
Föreliggande uppfinning anvisar att det inte finns något som hindrar att använd kommunikation mellan den första och andra datroenheten är krypterad.The present invention teaches that there is nothing to prevent used communication between the first and second computer units from being encrypted.
Enligt en föredragen utföringsform av föreliggande uppfinning utgörs det specifika protokollet av TCP-protokollet.According to a preferred embodiment of the present invention, the specific protocol is the TCP protocol.
Den tredje datorenheten kan således översätta mellan det specifika protokollet och ett flertal andra protokoll, såsom UDP och WAP.The third computer unit can thus translate between the specific protocol and a number of other protocols, such as UDP and WAP.
Föreliggande uppfinning är speciellt fördelaktig då nätverket i fråga utgörs av det globala nätverket lnternet. 20 25 30 52Û 437 4 Föreliggande uppfinning avser även två datorprogramprodukter där en första datorprogramprodukt omfattar datorprogramkod vilken, då den exekveras av en datorenhet, utför funktionerna för en tredje datorenhet enligt den uppfinningsenliga metoden och där en andra datorprogramprodukt omfattar datorprogramkod vilken, då den exekveras av en datorenhet, utför funktionerna för en andra datorenhet enligt den uppfinningsenliga metoden.The present invention is particularly advantageous when the network in question consists of the global network Internet. The present invention also relates to two computer program products wherein a first computer program product comprises computer program code which, when executed by a computer unit, performs the functions of a third computer unit according to the method according to the invention and wherein a second computer program product comprises computer program code which, when executed a computer unit, performs the functions of a second computer unit according to the method according to the invention.
Vidare omfattar föreliggande upppfinning ett datoriäsbart medium varpå finns lagrat datorprogramkod enligt den första eller andra datorprogramprodukten.Furthermore, the present invention comprises a computer-readable medium on which is stored computer program code according to the first or second computer program product.
Fördelar De fördelar som främst kan förknippas med en metod, datorprogramprodukter eller ett datoriäsbart medium enligt föreliggande uppfinning är att härigenom är det möjligt att erbjuda en tredje datorenhet, eller en Web- server, varigenom en kommunikation med en andra datorenhet, eller en företagsintern server, erbjuds med ett flertal olika första datorenheter, eller användare, enligt ett flertal olika protokoll, utan någon egentlig öppning genom använd brandvägg.Advantages The advantages which can be mainly associated with a method, computer software products or a computer readable medium according to the present invention are that in this way it is possible to offer a third computer unit, or a Web server, whereby a communication with a second computer unit, or an internal server, offered with a number of different first computer units, or users, according to a number of different protocols, without any actual opening through the used firewall.
Kort figurbeskrivning En metod, datorprogramprodukter, och ett datoriäsbart medium uppvisande de med föreliggande uppfinning förknippade särdragen skall i exemplifierande syfte nu närmare beskrivas med hänvisning till bifogad ritning, där; Figur 1 schematiskt och mycket förenklat visar kommunikation via ett nätverk enligt känd teknik, Figur 2 schematiskt och mycket förenklat visar hur en andra datorenhet kommunicerar med ett flertal olika första datorenheter enligt grundprincipen för föreliggande uppfinnning, Figur 3 schematiskt och mycket förenklat visar hur en andra datorenhet kommunicerar med ett flertal olika första datorenheter enligt en utföringsform av föreliggande uppfinnning, och Figur 4 schematiskt och mycket förenklat visar hur ett flertal andra datorenhet kommunicerar med ett flertal olika första datorenheter enligt föreliggande uppfinnning. 20 25 30 U"l 'i co -ß CN \l Beskrivning av nu föredragna utföringsformer Med hänvisning till figur 1 visas således känd teknik för kommunikation mellan en första och en andra datorenhet 11, 2 via ett nätverk A, där kommunikationen sker via en tredje datorenhet 3.Brief Description of the Figures A method, computer program products, and a computer readable medium having the features associated with the present invention will now be described in more detail, by way of example, with reference to the accompanying drawings, in which; Figure 1 schematically and very simply shows communication via a network according to the prior art, Figure 2 schematically and very simply shows how a second computer unit communicates with a plurality of different first computer units according to the basic principle of the present invention, Figure 3 schematically and very simply shows how a second computer unit communicates with a plurality of different first computer units according to an embodiment of the present invention, and Figure 4 schematically and very simply shows how a plurality of second computer units communicate with a plurality of different first computer units according to the present invention. Description of Now Preferred Embodiments Referring to Figure 1, there is thus shown prior art for communication between a first and a second computer unit 11, 2 via a network A, where the communication takes place via a third computer unit 3.
För att erhålla säkerhet hos den andra datorenheten 2 finns en brandvägg 21 upprättad mellan den andra datorenheten 2 och den tredje datorenheten 3, och där all kommunikation mellan dessa datorenheter 2, 3 sker genom denna brandvägg 21.In order to obtain security of the second computer unit 2, a firewall 21 is established between the second computer unit 2 and the third computer unit 3, and where all communication between these computer units 2, 3 takes place through this firewall 21.
Detta är vanligt då exempelvis den andra datorenheten 2 utgör en företagsintern server och man vill skydda sig mot intrång i företagets server och interna nätverk.This is common when, for example, the second computer unit 2 constitutes a company-internal server and one wants to protect oneself against intrusion into the company's server and internal networks.
Den andra datorenheten har ett flertal anslutningar gentemot den tredje datorenheten 3 eftersom olika första datorenheter 11, 12, 13, 14 möjligen kommunicerar enligt sinsemellan olika protokoll A1, A2, A3, A4, vilket gör att dom behöver accessa den andra datorenheten via sinsemellan olika portar 41, 42, 43, 44. Detta medför även att det blir ett flertal öppningar genom den andra datorenhetens brandvägg 21, en för varje port 41, 42, 43, 44.The second computer unit has a plurality of connections to the third computer unit 3 because different first computer units 11, 12, 13, 14 possibly communicate according to different protocols A1, A2, A3, A4, which means that they need to access the second computer unit via different ports. 41, 42, 43, 44. This also means that there will be a plurality of openings through the firewall 21 of the other computer unit, one for each port 41, 42, 43, 44.
Figur 2 avser att illustrera föreliggande uppfinning där all kommunikation mellan den andra datorenheten 2 och den tredje datorenheten 3 sker via portar 41', 42', 43', 44' som initierats eller öppnats av den andra datorenheten 2, vilket schematiskt visas med rlktningspilar 51, 52, 53, 54 på anslutningarna mellan den andra datorenheten 2 och den tredje datorenheten 3.Figure 2 intends to illustrate the present invention where all communication between the second computer unit 2 and the third computer unit 3 takes place via ports 41 ', 42', 43 ', 44' initiated or opened by the second computer unit 2, which is schematically shown by directional arrows 51 , 52, 53, 54 on the connections between the second computer unit 2 and the third computer unit 3.
Denna bestämning att den andra datorenheten 2 skall initiera eller öppna dessa anslutningar, och att inga andra anslutningar tillåts, medför att den andra datorenheten har fullständig kontroll över dessa anslutningar. En sådan anslutning kan i princip sägas gå igenom brandväggen utan att en öppning sker i brandväggen 21. Ingen första datorenhet 11, 12, 13, 14 tillåts etablera en kontakt med den andra datorenheten 2 utom via en anslutning som den andra datorenheten 2 själv har initierat eller öppnat, vilket medför att all kommunikation genom brandväggen 21 sker utan några öppningar i brandväggen.This determination that the second computer unit 2 should initiate or open these connections, and that no other connections are allowed, means that the second computer unit has complete control over these connections. Such a connection can in principle be said to pass through the firewall without an opening being made in the firewall 21. No first computer unit 11, 12, 13, 14 is allowed to establish a contact with the second computer unit 2 except via a connection which the second computer unit 2 itself has initiated or opened, which means that all communication through the firewall 21 takes place without any openings in the firewall.
Figur 3 avser att visa att, enligt föreliggande uppfinning, den andra datorenheten 2 endast öppnar 5 en port 4 för kommunikation med den tredje datorenheten 3, och att all kommunikation mellan den andra datorenheten 2 och 15 20 25 30 520 437 6 den tredje datorenheten 3 sker via denna enda port 4 enligt ett specifikt protokoll AS.Figure 3 is intended to show that, according to the present invention, the second computer unit 2 only opens a port 4 for communication with the third computer unit 3, and that all communication between the second computer unit 2 and the third computer unit 3 takes place via this single port 4 according to a specific protocol AS.
Enligt denna utföringsform skall den tredje datorenheten 3, i kommunikationen med den första datorenheten 11, översätta mellan det protokoll A1 enligt vilket den första datorenheten 11 kommunicerar med den tredje datorenheten 3, och det specifika protokollet As enligt vilket den tredje datorenheten 3 kommunicerar med den andra datorenheten 2.According to this embodiment, the third computer unit 3, in communication with the first computer unit 11, translates between the protocol A1 according to which the first computer unit 11 communicates with the third computer unit 3, and the specific protocol As according to which the third computer unit 3 communicates with the second computer units 2.
Figur 3 visar även att ett flertal olika första datorenheter 11, 12, 13, 14 kan kommunicera med den andra datorenheten 2 via den tredje datorenheten 3, där dessa flera första datorenheter 11, 12, 13, 14 kommunicerar enligt samma eller sinsemellan olika, från varandra oberoende, protokoll A1, A2, A3, A4.Figure 3 also shows that a plurality of different first computer units 11, 12, 13, 14 can communicate with the second computer unit 2 via the third computer unit 3, where these several first computer units 11, 12, 13, 14 communicate according to the same or mutually different, from independently, protocols A1, A2, A3, A4.
I detta fall vidarebefordrar den tredje datorenheten 3 kommunikationen från det flertalet olika första datorenheterna 11, 12, 13, 14 till den andra datorenheten via den enda porten 4 enligt det specifika protokollet As.In this case, the third computer unit 3 forwards the communication from the plurality of different first computer units 11, 12, 13, 14 to the second computer unit via the single port 4 according to the specific protocol As.
Figur 4 visar en utföringsform där ett flertal andra datorenheter 2a, 2b, 20 kommunicerar med sina respektive en eller flera första datorenheter 11a, 12a, 13a, 11b, 12b, 13b, 110, 120, 130 via den tredje datorenheten 3.Figure 4 shows an embodiment where a plurality of second computer units 2a, 2b, 20 communicate with their respective one or more first computer units 11a, 12a, 13a, 11b, 12b, 13b, 110, 120, 130 via the third computer unit 3.
Varje andra datorenhet 2a, 2b, 20 har själva öppnat 5a, 5b, 50 den port 4a, 4b, 40 som används vid kommunikationen med den tredje datorenheten 3.Each second computer unit 2a, 2b, 20 has itself opened 5a, 5b, 50 the port 4a, 4b, 40 used in the communication with the third computer unit 3.
Enligt en föredragen utföringsform tilldelas respektive andra datorenhet 2a, 2b, 20 en ellerflera adresser eller portar 31a, 31b, 310, 32a, 32b, 320, 33a, 33b, 330 hos den tredje datorenheten 3 för mottagande av kommunikation från en ellerflera första datorenheter11a, 12a, 13a, 11b, 12b, 13b, 110, 120, 130.According to a preferred embodiment, the respective second computer unit 2a, 2b, 20 is assigned one or more addresses or ports 31a, 31b, 310, 32a, 32b, 320, 33a, 33b, 330 of the third computer unit 3 for receiving communication from one or more first computer units 11a, 12a, 13a, 11b, 12b, 13b, 110, 120, 130.
Detta erbjuder möjligheten för den tredje datorenheten 3 att, vid en kontakt från en första datorenhet 12b, identifierar korrekt andra datorenhet 2b för den kontaktande första datorenheten 12b genom den adress eller port 32b som den första datorenheten 12b använder vid kontakten.This offers the possibility for the third computer unit 3 to, in the event of a contact from a first computer unit 12b, correctly identify the second computer unit 2b of the contacting first computer unit 12b by the address or port 32b used by the first computer unit 12b at the contact.
Enligt föreliggande uppfinning finns det inget som hindrar att kommunikationen mellan en andra datorenhet 2 och en ellerflera av dess första datorenheter 11, 12, 13 är krypterad. l-...:... ...Å Ix ...AR .. :4-2 .-. I ...u U-IÅ-nlif-f-.nn n H i I " E ilrgt en i ge r uu i. i i i .eirggaiide uppfmnrrm utgors det specifika protokollet As av IPSEC TCP-protokollet. Det är även möjligt att använda ett annat protokoll, såsom vanlig TCP. 15 20 320 437 7 Den tredje datorenheten 3 kan översätta mellan det specifika protokollet As och ett flertal andra protokoll, såsom UDP och WAP.According to the present invention, there is nothing to prevent the communication between a second computer unit 2 and one or more of its first computer units 11, 12, 13 from being encrypted. l -...: ... ... Å Ix ... AR ..: 4-2 .-. In ... u U-IÅ-nlif-f-.nn n H i I "E ilrgt en i ge r uu i. Iii .eirggaiide opgmnrrm the specific protocol As is made up of the IPSEC TCP protocol. another protocol, such as ordinary TCP The third computer unit 3 can translate between the specific protocol As and a plurality of other protocols, such as UDP and WAP.
Föreliggande uppfinnning lämpar sig väl för kommunikation inom det globala nätverket Internet eftersom det förekommer många olika protokoll för kommunikation inom Internet.The present invention is well suited for communication within the global Internet network as there are many different protocols for communication within the Internet.
Figurerna visar även mycket schematiskt att föreliggande uppfinning även avser en första datorprogramprodukt 61, vilken omfattar datorprogramkod som, då den exekveras av en datorenhet, utför funktionerna för en tredje datorenhet 3 enligt den uppfinningsenliga metoden.The figures also show very schematically that the present invention also relates to a first computer program product 61, which comprises computer program code which, when executed by a computer unit, performs the functions of a third computer unit 3 according to the method according to the invention.
Vidare avser föreliggande uppfinning en andra datorprogramprodukt 62, vilken omfattar datorprogramkod som, då den exekveras av en datorenhet, utför funktionerna för en andra datorenhet 2 enligt den uppfinningsenliga metoden.Furthermore, the present invention relates to a second computer program product 62, which comprises computer program code which, when executed by a computer unit, performs the functions of a second computer unit 2 according to the method according to the invention.
Figur 3 visar även schematiskt att föreliggande uppfinning även avser ett datorläsbart medium 7, på vilket datorprogramkod enligt någon av den första eller andra datorprogramprodukten finns lagrad.Figure 3 also shows schematically that the present invention also relates to a computer-readable medium 7, on which computer program code according to any of the first or second computer program product is stored.
Uppfinningen är naturligtvis inte begränsad till de ovan såsom exempel angivna utföringsformerna utan kan öppni modifikationer inom ramen för uppfinningstanken illustrerad i efterföljande patentkrav.The invention is of course not limited to the embodiments given above as examples, but may open modifications within the scope of the inventive concept illustrated in the appended claims.
Claims (12)
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| SE0101007A SE520437C2 (en) | 2001-03-22 | 2001-03-22 | Method for minimizing the number of openings in a firewall located between a private and a public network |
| PCT/SE2002/000556 WO2002078267A1 (en) | 2001-03-22 | 2002-03-21 | A method of communication between a first computer device and a second computer device; via a third device |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| SE0101007A SE520437C2 (en) | 2001-03-22 | 2001-03-22 | Method for minimizing the number of openings in a firewall located between a private and a public network |
Publications (3)
| Publication Number | Publication Date |
|---|---|
| SE0101007D0 SE0101007D0 (en) | 2001-03-22 |
| SE0101007L SE0101007L (en) | 2002-09-23 |
| SE520437C2 true SE520437C2 (en) | 2003-07-08 |
Family
ID=20283479
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| SE0101007A SE520437C2 (en) | 2001-03-22 | 2001-03-22 | Method for minimizing the number of openings in a firewall located between a private and a public network |
Country Status (2)
| Country | Link |
|---|---|
| SE (1) | SE520437C2 (en) |
| WO (1) | WO2002078267A1 (en) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2004090675A2 (en) * | 2003-04-03 | 2004-10-21 | Commvault Systems, Inc. | System and method for performing storage operations through a firewall |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7143438B1 (en) * | 1997-09-12 | 2006-11-28 | Lucent Technologies Inc. | Methods and apparatus for a computer network firewall with multiple domain support |
-
2001
- 2001-03-22 SE SE0101007A patent/SE520437C2/en not_active IP Right Cessation
-
2002
- 2002-03-21 WO PCT/SE2002/000556 patent/WO2002078267A1/en not_active Ceased
Also Published As
| Publication number | Publication date |
|---|---|
| SE0101007D0 (en) | 2001-03-22 |
| WO2002078267A1 (en) | 2002-10-03 |
| SE0101007L (en) | 2002-09-23 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US7782902B2 (en) | Apparatus and method for mapping overlapping internet protocol addresses in layer two tunneling protocols | |
| AU770584B2 (en) | Secured session sequencing proxy system and method therefor | |
| CN100571188C (en) | A method for improving the processing efficiency of SSL gateway and SSL gateway | |
| US8601567B2 (en) | Firewall for tunneled IPv6 traffic | |
| US8364847B2 (en) | Address management in a connectivity platform | |
| US20020133594A1 (en) | Handling state information in a network element cluster | |
| US20030149766A1 (en) | Firewall configuration validation | |
| US20030079146A1 (en) | Method and apparatus for regulating access to a computer via a computer network | |
| US10795717B2 (en) | Hypervisor flow steering for address sharing | |
| CA2761983A1 (en) | Method and apparatus to permit data transmission to traverse firewalls | |
| US20160149748A1 (en) | Network address translation | |
| CN112769850B (en) | Network message filtering method, electronic equipment and storage medium | |
| WO1999012298A3 (en) | Arrangement in a data communication system | |
| WO1997000471A3 (en) | A system for securing the flow of and selectively modifying packets in a computer network | |
| Wool | The use and usability of direction-based filtering in firewalls | |
| KR20060028390A (en) | Method and system, computer readable storage medium for determining if multiple networks are authenticated and communicating with each other and what IP protocol is used for communication between each combination of two of these networks | |
| US20250358214A1 (en) | Deploying symmetric routing | |
| WO2002069566A2 (en) | Proxy-less packet routing between private and public address realms | |
| WO2018209745A1 (en) | Traffic directing method and device | |
| EP1425880B1 (en) | Network application association | |
| KR101323852B1 (en) | Virtual firewall system based on public security policy and its control method | |
| SE520393C2 (en) | Method of communication through firewall | |
| US7715326B2 (en) | Webserver alternative for increased security | |
| WO2009087382A1 (en) | Automatic proxy detection and traversal | |
| JP3310851B2 (en) | Filtering condition setting method for filtering device |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| NUG | Patent has lapsed |