WO2004071038A1 - ファイアウォール装置 - Google Patents
ファイアウォール装置 Download PDFInfo
- Publication number
- WO2004071038A1 WO2004071038A1 PCT/JP2004/001124 JP2004001124W WO2004071038A1 WO 2004071038 A1 WO2004071038 A1 WO 2004071038A1 JP 2004001124 W JP2004001124 W JP 2004001124W WO 2004071038 A1 WO2004071038 A1 WO 2004071038A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- user
- filtering
- user terminal
- firewall
- individual
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0227—Filtering policies
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1466—Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks
Definitions
- firewall also called FW
- the security policy is a combination of address; protocol type, port number, direction, pass / fail, or other conditions, and forms one rule.
- firewalls can be divided into three types according to their installation locations.
- the source IP address [a. a.a.a] is used as a search key to refer to the distribution management table 201 to search for the virtual firewall ID 202 associated with the source IP address [a.a.a.a].
- the bucket 22 1 is distributed to the virtual firewall end wall 202.
- the destination IP address b.b.b.b.b is used as a search key to refer to the distribution management table 201, and the destination IP address A virtual firewall ID 203 associated with b.b.b.b is searched, and the packet 222 is allocated to the virtual firewall 203.
- This conventional technology is mainly applied to data centers and the like, in which a fixed user ID is used. Therefore, the user ID can be registered in the distribution management table 201 in advance. is there.
- the user ID (user IP address) is granted only when the connection between the user terminal and the network is established. Specifically, it is provided for the first time when a PPP (Point to Point Protocol) session is established. Also, the user IP address is generally variable.
- the other is to maintain the security policy 15 outside the firewall 10 and distribute this security policy to multiple firewalls 10 as shown in Figs. 5, 6, and 7. You.
- Japanese Patent Application Laid-Open No. 2002-54044,077 shows application to terminal-based firewalls.
- “Distributed Firewal ls” (Nov. 1999, Special Issue on Security, ISSN 1044-63971)) shows its application to CPE-based firewalls.
- the accommodated network or terminal dynamically connects / disconnects or changes the accommodated NW-based firewall in the NW-based firewall, there is no way to maintain the security policy inside the firewall. It is not useful because the firewall must maintain all the security policies regarding the network or terminal that may be accommodated by the firewall regardless of the connection or disconnection of the network or terminal.
- Means for holding a user ID to be assigned to the user terminal
- the search processing time can be prevented from becoming unnecessarily long.
- the above-mentioned filtering ID is further divided into an individual filtering ID and a common filtering ID, and a filtering policy for each user is described in an individual filtering table, and is shared by a plurality of users. Filtering policies that can be used can be described in the common filtering table.
- the third object is a firewall device that is installed between a plurality of user terminals and a network and performs packet filtering for a plurality of user terminals.
- a distribution management table that manages user terminal information, a common filtering table ID, and an individual filtering table ID, a communication method with an authentication server that determines whether a user terminal can be connected, and a common filtering that is linked to the user Means of communication with an identifier management server that manages table IDs and individual filtering table IDs;
- the filtering device comprises:
- a connection request to which authentication information including a user name is added is received from a user terminal, the user name is held, and the held user name is notified to an authentication server.
- the common filtering table ID received from the identifier management server, the individual filtering table ID, and the user terminal information are associated with each other and described in the distribution management table,
- the firewall device of the present invention divides the security policy into an individual security policy and a common security policy, always keeps the common security policy in the firewall device, and starts the connection of the network or the terminal only with the individual security policy. Since it can be loaded at any time, the amount of security policy to be loaded can be reduced.
- the firewall device of the present invention can connect the device for distributing the security policy and the device whose identifier is checked to all the firewall devices, and can load the security policy. Even if the network connection is started or disconnected by changing the firewall device that accommodates the terminal, the firewall device can load the security policy appropriately.
- FIG. 3 is a block diagram showing another example of a conventional firewall device.
- FIG. 7 is a block diagram showing another example of a conventional firewall device that holds a security policy externally.
- FIG. 9 is a sequence diagram illustrating an operation of the firewall device according to the embodiment 11.
- FIG. 13 is a diagram illustrating an example of the distribution management table according to the first to fourth embodiments.
- FIG. 15 is a sequence diagram illustrating an operation of the firewall device according to the embodiment 15;
- FIG. 16 is a diagram illustrating an example of the distribution management table according to the first embodiment.
- FIG. 17 is a block diagram illustrating a schematic configuration of the firewall device according to the embodiment 2-1 of the present invention.
- FIG. 23 is a diagram illustrating a state in which the IP address of the distribution management table according to the embodiment 2-3 is registered.
- FIG. 27 is a sequence diagram illustrating an operation of the firewall device according to the second to fifth embodiments.
- FIG. 39 is a diagram showing details of the distribution management table in the initial state in the firewall device shown in FIG. 34.
- FIG. 43 is a diagram illustrating an example of a sequence illustrating the operation of the network model in FIG.
- FIG. 58 is a diagram showing details of the security policy table in the security policy server shown in FIG. 50.
- FIG. 59 is a diagram showing an example of a sequence showing the operation of the network model in FIG. 50.
- the terminal 111 of user #a makes a network connection to the internet 110 and then performs IP communication with the terminal 113 of the connection partner.
- LCP Link Control Protocol
- the firewall apparatus 1 0 0 extracts the user name # a transmitted from the user terminal 1 1 1, to hold the user name # a (process point 1 5 0).
- the firewall device 100 exchanges NCP (Network Control Protocol) information between the user terminal 111 and the firewall device 100 (143).
- NCP Network Control Protocol
- user IP address Ri feed [a. a. a. a ] to the user terminal 1 1 1, the user terminal 1 1 1 recognizes that the own user IP address power S [a. a. a. a].
- ⁇ b terminal 1 1 2 is connected to the Internet 1 110 via the network, and then performs IP communication with the connection partner terminal 1 13.
- the packet transmitted and received by the server is distributed to the virtual firewall 103, and the passing or discarding process is applied according to the filtering rule according to the security policy determined by the user #b.
- the firewall device 100 sends an authentication error notification 643 to the user terminal 111, and Establishment of PPP The process ends. At this time, the firewall device 100 does not perform any processing on the distribution management table 101.
- the terminal 111 of the firewall service unregistered user #c connects to the Internet 110 via the network in the example 11-11, and then performs IP communication with the connection partner terminal 113. It is shown. Note that the user #c who is not registered as a firewall service has no user name and virtual firewall registered in the distribution management table 101_3, but has access to the Internet 110 via the terminal 114. The user enjoys the communication service, and the user name and password are registered in the RAD IUS server 130.
- the firewall apparatus 1000 Upon receiving the notification of the user IP address 142, the firewall apparatus 1000 receives the user IP address [cc.c.] to be assigned to the user terminal described in the notification of the user IP address 142. c. c]. Then, using the user name as a search key, a search is performed for the user name #c in the distribution management table 101-3, but since the user name #c does not exist, the user IP address [c ⁇ c c. c] is not registered in the distribution management table 101-3.
- the firewall device 100 exchanges NCP information between the user terminal 114 and the firewall device 100 (144), and the user IP address [ c. c. c. c] is sent to the user terminal 114, and the user terminal 114 recognizes that the own user IP address power is S [c. c. c. c].
- a PPP connection is established between the user terminal and the network. Then, from the user terminal 1 1 4 to the connection partner terminal 1 When the firewall device 100 receives the bucket 12 1 sent to 13, the distribution is managed using [c.c.c.c] described as the source IP address as a search key. As a result of referring to Table 101, it is found that the source IP address is not registered.
- the virtual firewall to be distributed is described as virtual firewall 104, as shown at the bottom of the distribution management table 101-3 shown in Fig. 11. Therefore, the bucket 122 is allocated to the virtual firewall 104 for the unregistered user (processing point 152).
- the distribution management table 101 is referred to using the destination user IP address [c.c.c.c] as a search key.
- the packet 122 is distributed to the virtual firewall 104 for an unregistered user (processing point 1553).
- a fourth embodiment of the present invention will be described with reference to FIG. 8, FIG. 13 and FIG. In this example, the conditions are the same as in Example 1_3.
- the terminal 114 of the unregistered user #c of the fire service #c connects to the Internet 110 via the network, and then connects to the terminal 1 1 3 This shows the form in which IP and communication are performed.
- the firewall service unregistered user #c has no user name and virtual firewall registered in the distribution management table 101-4, but the communication service to the Internet 110 through the terminal 114 is not available.
- the user name and password are registered in the RAD I US server 130.
- the firewall apparatus 100 Upon receiving the user IP address notification 144, the firewall apparatus 100 receives the user IP address [c.c.c] to be assigned to the user terminal described in the user IP address notification 142. . c].
- the firewall device 100 exchanges NCP information between the user terminal 114 and the firewall device 100 (144).
- ⁇ C. C. C] is sent to the user terminal 114, and the user terminal 114 recognizes that it has its own user IP address power S [c. C. C. C].
- a PPP connection is established between the user terminal and the network.
- the destination user IP address [c.c.c.c]
- the virtual firewall 104 for processing has no filtering rules described in the same way as in the embodiment 13 and allows all packets to pass unconditionally, or is common to all unregistered users. Describes the filtering rules.
- the packet is discarded as shown at the bottom of the distribution management table 101-4 shown in FIG.
- a malicious user sends a large number of buckets having an IP address not assigned to any user due to an IP spoofing attack or the like, these packets are sent to the firewall device 100. Can be discarded.
- Embodiment 15 of the present invention will be described with reference to FIG. 8, FIG. 15 and FIG.
- the terminal 1 15 of the firewall service unregistered user #d is connected to the Internet 110 via the network in the embodiment 1-11, and then performs IP communication with the connection partner terminal 1 13 It shows a form.
- user #d is originally a user who should be registered in the firewall service, but in this example, the administrator of the firewall device 100 has forgotten to register it in the distribution management table 101-5, or The user name #d is not registered correctly in the distribution management table 101-5 due to reasons such as incorrect registration.
- the user name #d and password are correctly registered in the RADUS Server 130.
- the operations up to the notification of the user IP address 144 are the same as those in the embodiment 1-1, and the description is omitted.
- the firewall apparatus 1000 Upon receiving the user IP address notification 142, the firewall apparatus 1000 sends the user IP address [d.d.d to be assigned to the user terminal described in the user IP address notification 142. . d]. Then, the user name #d is searched for the distribution management table 101-5 using the user name as a search key, but the user name #d does not exist. If the user name does not exist, the firewall device 100 transmits an authentication error notification 943 to the user terminal 115, and ends the PPP establishment processing.
- the user IP address is assigned for the first time when the connection between the user terminal and the network is established, as in the always-on service, and the value of the user IP address is provided.
- the dynamic user identifier supporting firewall device of the present invention has a virtual firewall for each user.
- the firewall device does not perform any processing on the distribution management table when the user name or password sent from the user is incorrect and an authentication error notification is sent from the RADIUS server. Send an authentication error notification to the user terminal. This allows sorting when network connections are rejected. Management table search and registration processing can be eliminated, and the remaining processing power can be focused on other processing.
- the firewall devices of Embodiments 13 and 14 can also accommodate user terminals of users who do not enjoy the firewall service. It is possible to eliminate the hassle of replacing the physical connection that occurs each time the user enjoys the service.
- the transmission / reception bucket of the unregistered user is automatically distributed to the virtual firewall for the unregistered user.
- the number of items registered in the distribution management table can be limited to registered users who are currently establishing a network connection, which contributes to shortening the search time.
- the unregistered user is registered in the distribution management table, and the transmission / reception packet of the unregistered user is explicitly distributed to the virtual firewall for the unregistered user. If it is not registered, it will discard the packet. If a malicious user sends out a large number of packets with IP addresses that are not assigned to any of the ITs by IP spoofing attacks, the firewall will fail. These c in the device. The packet can be discarded.
- Embodiments 13 and 14 can be properly used depending on the application.
- Embodiment 11 The firewall device of Example 5 is used when the administrator of the firewall device forgets to register the user name and the virtual firewall in the distribution management table or registers the virtual firewall incorrectly. However, communication that should no longer be established can be forcibly terminated from the viewpoint of security.
- Example 11 By the operation shown in the example 1 and the like, for a communication mode in which the user IP address and the virtual firewall ID cannot be previously correlated, the authentication information for network connection from the user terminal is used and the operation is performed.
- the user IP address can be associated with the virtual firewall ID, and a filtering rule according to a security policy defined by the user can be applied to a bucket transmitted or received by the user terminal.
- the number of accommodated users is several hundred to several thousand, whereas in the case of a constant connection service, the number of accommodated users is several tens to several hundred thousand.
- the issue to provide a virtual firewall device for always-on service is to improve the number of multiplexed users.
- the always-on service has a large number of multiplexed users, if the serviceability of providing an independent security policy for each user is ensured, the total number of filtering rules increases in proportion to the number of multiplexed users.
- each user's filtering rules include Since some rules are common to many users, the rules are duplicated and inefficient when viewed from the perspective of the entire firewall. As a result, the amount of filtering tables increases.
- Embodiments 2_1 to 2-7 describe a firewall device that improves the number of multiplexed users and realizes an efficient filtering table.
- FIG. 17 is a block diagram illustrating a schematic configuration of a firewall device according to the embodiment 2-1 of the present invention.
- FIG. 18 is a diagram illustrating a configuration of a filtering table in a virtual firewall according to the embodiment. is there.
- the network connection method from the user is PPP (Point to Point Protocol), and the authentication communication is RADUS.
- the firewall device 300 includes a plurality of virtual firewalls (302, 303, ..., 304).
- each virtual firewall (302, 303) has a plurality of filtering tables (561, 562, 556) specified by the filtering ID. 3) exists, and each filtering table (561, 562, 563) describes one or more independent filtering policies for each user.
- the security policy defined by the user #a and the user #b is stored in the virtual firewall 302
- the security policy defined by the user #d is stored in the virtual firewall 303.
- the user #a enters the filtering table 561 in the virtual firewall 302 with a filtering ID of ⁇ .
- User #d is in the filtering table 562 with the filtering ID j3, and user #d is in the filtering table 563 with the filtering ID ⁇ in the virtual firewall 303.
- Each security policy is described.
- the distribution management table 301 user names, virtual firewall IDs, and filtering IDs that can be set in advance are registered.
- the user name #a the correspondence between the virtual firewall ID (302) and the filtering ID (a), the user name #b, the virtual firewall ID (3
- FIG. 19 is a sequence diagram showing the operation of the firewall device of this embodiment.
- LCP Link Control Protocol
- the firewall unit 3000 extracts the user name #a transmitted from the user terminal 311, and extracts the user name #a. It is retained (processing point 850 in FIG. 19).
- the authentication information (user name and password) is notified to the RAD IUS server 330 (841 in FIG. 19).
- the firewall device 300 Upon being authenticated by the RAD IUS server 330 and receiving the response (842 in Fig. 19), the firewall device 300 sends the user IP address to be assigned to the user terminal described in the response. Hold. Let this user IP address be [a.a.a.a]. Then, using the user name #a as a search key, the user IP address [a.a.a.a] is registered in the line where the user name is described as #a in the distribution management table 301 ( The processing point 851 in Fig. 19 and the distribution management table 301-2 in Fig. 19). At the same time, the firewall device 300 exchanges NCP (Network Control Protocol) information between the user terminal 311 and the firewall device 300 (843). The IP address [a.a.a.a] is sent to the user terminal 311. The user terminal 311 recognizes that the own user IP address is S [a.a.a.a].
- NCP Network Control Protocol
- a PPP connection is established between the user terminal 311 and the Internet 310.
- the bucket 3 22 to which the filtering ID has been assigned is described in the filtering table 561 having the filtering ID ⁇ in the distributed virtual firewall 302. Passing or discarding is applied according to the filtering rules that follow the security policy of user #a.
- the packet 3 2 4 to which the filtering ID is assigned is a filtering rule according to the security policy of the user #a described in the filtering table 56 1 having the filtering ID ⁇ in the distributed virtual firewall 302. In accordance with this, transit or disposal is applied.
- User # b's terminal 3 1 2 is connected to Internet 3 10
- the filtering According to the filtering rule according to the security policy of the user #b described in Table 562, the passing or discarding processing is applied.
- each virtual firewall (302, 303, 304) has a plurality of independent filtering. Negative policy can be managed, and the number of multiplexed users can be improved.
- the search processing time can be prevented from becoming unnecessarily long.
- the firewall device according to the embodiment 2-2 of the present invention is different from the firewall device according to the above-described embodiment 2-1 in that the firewall device is not provided with a virtual firewall.
- the firewall device of the present embodiment will be described focusing on differences from the firewall device of the above-described Embodiment 2-1.
- the network connection method from the user is PPP
- the authentication communication is RADIUS.
- FIG. 20 is a block diagram showing a schematic configuration of a firewall device according to Embodiment 2-2 of the present invention.
- the firewall device 300 of this embodiment has a plurality of filtering tables (561, 562) specified by the filtering IDs, and each filtering table has Indicates an independent filtering policy for each user.
- the user #a has the filtering ID of ⁇ .
- Each security policy is described in the filtering table 562 with the filtering ID j3 in the filtering table 561 of the user #b.
- the distribution management table 301 user names and filtering IDs that can be set in advance are registered.
- the distribution management table 301 the correspondence between the user name #a and the filtering ID ⁇ and the correspondence between the user name #b and the filtering ID] 3 are registered.
- the filtering ID cannot be given to the packet from each user.
- the terminal 311 of the user #a makes a network connection to the Internet 310, and then performs IP communication with the connection partner terminal 313.
- FIG. 21 is a sequence diagram showing the operation of the firewall device of the present embodiment.
- a PPP connection is established between the user terminal 311 and the Internet 310. Thereafter, when the firewall device 300 receives the bucket 3 21 transmitted from the user terminal 3 11 1 to the connection partner terminal 3 13 3, the source IP address and The [a.a.a.a] described as a search key is used to search the distribution management table (301-1-2 in FIG. 21), and is described in the [a.a.a.a] row.
- Bucket DOO 3 2 2 the filtering ID been given, according to the filter-rings ID is filtering table 5 6 1 user # a security policy to the slave U filtering rules that are described in the alpha, passing or discarding process is applied Is done.
- the terminal 312 of the user #b makes a network connection to the Internet 310 and then performs IP communication with the connection partner terminal 313, the bucket transmitted and received by the terminal 312 The packet is passed or discarded according to the filtering rules according to the security policy of user #b described in the filtering table 562.
- the firewall device uses the filtering ID as the individual filtering ID and the common filtering ID. This is different from the firewall device of the embodiment 2-1 described above in that it is divided into two.
- the schematic configuration of the firewall device of the embodiment 2-3 is the same as that of FIG. Also in this embodiment, the network connection method from the user is PPP and the authentication communication is RAD IUS.
- the filtering ID of the above-described embodiment 2-1 is further divided into an individual filtering ID and a common filtering ID, and the filtering policy for each user is described in the individual filtering table.
- filtering policies that can be shared by multiple users are described in the common filtering table.
- the distribution management table 301 shown in FIG. 17 and the distribution management table (301-1-1) shown in FIG. 19 correspond to the distribution management table 6001 shown in FIG.
- the distribution management table (3 01-2) shown in FIG. 19 is replaced with the distribution management table 1101 in FIG.
- FIG. 24 is a diagram showing a configuration of a filtering table in a virtual firewall of the firewall device of the present embodiment.
- the firewall device 300 of the present embodiment has a plurality of virtual firewalls (3 , 3 0 4) c. Further, as shown in FIG. 24, each virtual firewall (3 0 2, 3 0 3) has an individual filtering ID. There are multiple filtering tables (561, 562, 563) specified and multiple filtering tables (571, 572) specified by a common filtering ID.
- Each user's individual filtering policy is an individual filtering policy.
- the filtering policy that can be shared by multiple users is described in the common filtering table (571, 572). I have.
- the distribution management table 61 manages the user name, the virtual firewall ID, the individual filtering ID, and the common filtering ID.
- the security policy defined by the user #a and the user #b is stored in the virtual firewall 302
- the security policy defined by the user #d is stored in the virtual firewall 303
- the user #a The individual filtering policy of a in the virtual firewall 302 is in the individual filtering table 561 with the filtering ID ⁇
- the individual filtering policy of user #b is the individual filtering policy with the filtering ID j3.
- the individual filtering policy of the user #d is described in the individual filtering table 563 with the filtering ID of ⁇ in the filtering table 562.
- the user # a and user # b is filtering ID are also applied filtering Ngupori sheet according to the common filtering table 5 7 1 I.
- the filtering policy described in the common filtering table 572 with the filtering ID of II is also applied.
- distribution management table 600 user names, virtual firewall IDs, individual filtering IDs, and common filtering IDs that can be set in advance are registered.
- the correspondence between the user name #a , the virtual firewall ID (302), the individual filtering ID (a) and the common filtering ID (I), the user name #b, the virtual name Firewall ID (302), individual filtering Correspondence of ID ( ⁇ ) and common filtering ID (I), user name #d, virtual firewall ID (303), individual filtering ID () and common filtering ID (II) are registered.
- the terminal 311 of the user #a makes a network connection to the Internet 310, and then performs IP communication with the connection partner terminal 313.
- a PPP connection is established between the user terminal 311 and the Internet 310.
- the firewall device 300 receives a packet 3 21 transmitted from the user terminal 3 11 1 to the connection partner terminal 3 13, the source IP address of the packet is received.
- an individual filtering ID of ⁇ and a common filtering ID of I are given (processing point 852 in FIG. 19).
- the packet 32 2 to which the individual filtering ID and the common filtering ID are assigned is used in the virtual firewall 302 as the individual filtering table 56 6 having the individual filtering ID. Passing or discarding is performed according to the filtering rules according to the security policy of user #a described in 1.
- the packet 322 will be replaced by the common filtering table 567 whose common filtering ID is I. According to the filtering policy described in 1, passing or discarding is performed.
- the bucket 32 4 provided with the individual filtering ID and the common filtering ID is based on the security policy of the user #a described in the individual filtering table 56 1 having the individual filtering ID ⁇ , and according to the filtering rules. Passage or disposal is performed. If there is no rule to be applied to the filtering policy described in the individual filtering table 561, the packet 324 will be replaced with the common filtering ID with the common filtering ID of I. In accordance with the filtering policy described in the staples 571, passing or disposal is performed.
- the introduction of the common filtering ID and the common filtering table enables efficient management of the filtering policy.
- the individual filtering table and the common filtering table according to the present embodiment can be introduced even in the embodiment in which the virtual firewall is not used in the embodiment 2-2.
- the filtering management ID is replaced with the individual filtering ID and the common filtering ID similar to the embodiment in the distribution management table, and the filtering table is replaced with the filtering table.
- An individual filtering table and a common filtering table similar to those of the embodiment are provided.
- the firewall device according to the present embodiment is different from the firewall device according to the above-described embodiments 2-1 and 221 in that the user name or password sent from the user #a is incorrect, or the like.
- This is an embodiment in a case where the combination of the user name and the password sent by the notification of the password does not match the combination of the user name and the password registered in the RADIUS server 330.
- the operation of the firewall device of Embodiment 2-4 will be described with reference to FIG.
- FIG. 25 is a sequence diagram illustrating the operation of the firewall device according to the embodiment 2-4. '
- the firewall device 300 does not perform any processing on the distribution management table 301.
- the firewall device according to the embodiment 2-5 of the present invention is the same as the firewall device according to the embodiment 2-1 described above, except that the terminal 314 of the firewall service unregistered user #c is connected to the internet 310.
- This is an embodiment of an embodiment in which a network connection is made, and then IP communication is performed with a connection partner terminal 3 13.
- FIG. 26 is a diagram showing the contents of the distribution management table of this embodiment.
- firewall service unregistered user #c has no user name and virtual firewall registered in the distribution management table (301--3), but has access to the Internet 310 through terminal 314.
- the user enjoys the communication service, and the user name and password are registered in the RAD IUS server 330.
- FIG. 27 is a sequence diagram showing the operation of the firewall device of the present embodiment.
- the firewall device 300 Upon receiving the notification of the user IP address (3422 in FIG. 27), the firewall device 300 sends the user IP address [c ⁇ ⁇ ⁇ ⁇ ] to be given to the user terminal described in the notification of the user IP address.
- a PPP connection is established between the user terminal 314 and the Internet 310. Thereafter, when the firewall device 300 receives a packet 3221 transmitted from the user terminal 314 to the connection partner terminal 313, the packet 3221 is described as the source IP address [c. As a result of searching the distribution management table (301-3) using C.C.C] as a search key, it is found that the source IP address is not registered.
- the virtual firewall to be distributed is the virtual firewall 304, as shown in the bottom line of the distribution management table (301--3) shown in Fig. 26. Since it is described, the packet 3 21 is distributed to the virtual firewall 304 for unregistered users (processing point 35 2 in FIG. 27).
- An authentication-linked distributed firewall device (hereinafter simply referred to as a firewall device) 501 is a user terminal (502-1-1) used by a user (515-1-1) that starts a connection by authentication. And a user terminal (502-2) used by a user (515-2), and is connected to an external network (for example, the Internet) 503.
- an authentication server 506 including a user terminal information unit 514 that holds a pool table including user terminal information to be given to the user terminal at the time of authentication.
- the authentication server is, for example, a remote authentication dial-in user service (RAIDUS) sano force s edible g.
- RAIDUS remote authentication dial-in user service
- the user terminal information stored in the user terminal information section 5 14 Can use the IP address assigned to the user terminal.
- connection start sequence of the user (5 1 5—1) will be described.
- the user (5 15—1) transmits the user name (user 5 15—1) and password ( ⁇ ) to the firewall device 501 via the user terminal (1 in FIG. 40). 1—1, 1 1—2).
- the available user terminal information (IP-1) whose in-use flag is “0” is extracted from the pool table of the user terminal information section 514, the extracted usable flag is set to “1”, and the authentication is performed.
- the extracted user terminal information (IP-1) is notified to the firewall device 501 (11-6, 11-7 in Fig. 40).
- the firewall device 501 holds the received user terminal information (IP-1), connects the user terminal information to the line to which the user terminal is connected (11-18 in FIG. 40), and stores the held user name.
- the user (user 5-15-1) is transmitted to the identifier management server 505 (11-19 in FIG. 40).
- the firewall device 501 holds the received individual filtering table ID (individual 510-1), and receives the received common filtering table ID (common 509) and the individual filtering table ID (individual 51 1). 0-1) and the held user terminal information (IP-1) are written into the distribution management table 507 shown in FIG. 39 (11-1-12 in FIG. 40).
- the firewall device 501 writes the retained individual filtering table ID (individual 510-1) into the identification information of the individual filtering table area 510, and also receives the received individual security policy (notice 1). _ 1 ⁇ 1 1 m) security Write to the policy area (11--16 in Figure 40).
- an authentication success notification including the held user terminal information (IP-1) is sent to the user terminal (502-1) (11-1-17 in Fig. 40). .
- the firewall device 501 of the present embodiment performs filtering processing on the packets transmitted from both directions on the user terminal side and the external network side, and transfers the packets.
- the area of the individual filtering table area 510 and the area of the distribution management table 507 are used, and during disconnection, this area is not used, so that the individual firewall of the firewall device 501 is not used. If the contents of the routing table area 501 and the distribution management table 507 are held for the number of user terminals connected simultaneously, Because it is good, it is possible to reduce the capacity of the security policy to be held.
- a firewall device 1221 and a user terminal 122 connected to the firewall device 1201 are newly added to the network model shown in FIG. Be added.
- a user (5 15-1) can be connected to the firewall device 1 201, and the firewall device 1 201 is connected to the external network 503 and the security policy server 504. It is connected to the identifier management server 505 and the authentication server 506.
- the firewall device 1221 has a distribution management table 1227 that holds information linking the user terminal information attached to the reception bucket and an identifier indicating a table for filtering the reception bucket, and the actual filtering is performed. It has a firewall section 128 for performing the following.
- FIG. 44 is a block diagram illustrating a schematic configuration of the firewall device according to the third embodiment of the present invention and a network model in which the firewall device according to the third embodiment of the present invention is used.
- FIG. 12 is a diagram showing an example of a firewall, in which a communication part with the identifier management server 505 is deleted, and a sequence with the identifier management table 512 held inside the firewall device 501 is newly added. This is different from the sequence shown in FIG.
- This embodiment is different from the above-described embodiment in that the security policy table 511, which is held in the security policy server 504 and associates a user name with an individual security policy, is held inside the firewall device 501. This is different from Example 3-1.
- the firewall device 501 since the firewall device 501 must maintain the security policy table 511 including the individual security policies of all the users that may be accommodated, the memory capacity of the firewall device 501 The number of users that can be accommodated, or the number of users that can be accommodated decreases, and an identifier management table 512 containing various identifiers of all the users that can be accommodated must be maintained. Therefore, the memory capacity of the fire wall device 501 is further required, or the number of users that can be accommodated is further reduced, but without communication with the security policy server and the identifier management server, Operation becomes possible.
- the firewall device 2001 connects to the external network 2003 via the contract network 1 (for example, ISP; Internet Service Provider) (2016-1-1), and establishes this connection by authentication.
- Terminal (200-2-1) used by the user (201-5-1) that initiates the connection and connects to the external network 203 through the contract network 2 (2016-1). It accommodates the user terminal (2002-2) used by the user (2015-2) that starts this connection by authentication.
- the firewall device 2001 includes a user terminal information section that holds a user authentication information (20 13 -2) and a pool table including user terminal information to be assigned to the user terminal at the time of authentication.
- the firewall device 2001 includes a virtual firewall (2014-1-1, 2014-2) for filtering the user packet information and the received packet attached to the received packet, and a filtering device. It has a distribution management table 2007 that links identifiers that point to tables.
- the firewall unit 2008 has a firewall unit 2008 that performs networking.
- the firewall unit 2008 is associated with a user terminal connected to the external network 2003 via the contract network 1 (201-16-1).
- a virtual firewall 1 (20 14-1) that filters buckets, and a bucket related to a user terminal connected to the external network 200 3 via the contract network 2 (20 16-2) It has a virtual firewall 2 (201-4-2) that performs filtering.
- the virtual firewall 1 (2 0 1 4—1) uses a common filtering table (2 0 0 1) that holds a security policy common to a plurality of users who perform filtering by the virtual firewall 1 (20 1 4—1). 9-1), and an individual filtering table area (2010-1), which is an area for holding security policy for each individual user.
- the individual filtering table area (2100_1) is divided into an area for writing identification information and an area for writing a security policy associated with the area for writing this identification information.
- the virtual firewall 2 (20 14—2) also has a common filtering table (20 09—2) and an individual filtering table area (20 1 0—2). -2), and the individual filtering table area (2010-10-2) is divided into an area for writing identification information and an area for writing a security policy associated with the area for writing this identification information.
- FIG. 51 is a diagram showing the details of the authentication information (201 13-1) in the authentication server 1 shown in FIG. 50.
- FIG. 52 is a diagram showing the user terminal in the authentication server 1 shown in FIG. It is a figure which shows the detail of the pool table hold
- FIG. 53 shows the authentication information in the authentication server 2 shown in FIG.
- FIG. 54 is a diagram showing details of (201-13-2), and FIG. 54 is a pool table held in the user terminal information section (201-4-2) in the authentication server 2 shown in FIG. It is a figure which shows the detail of.
- FIG. 55 is a diagram showing the user name transmitted to the firewall device 2001 via the user (2005-1-1) power S and the user terminal (2002-1-1).
- FIG. 4 is a diagram showing a user name transmitted by the user (2015-2) to the firewall device 201 via the user terminal (2002-2).
- FIG. 57 is a diagram showing the details of the identifier management table 201 in the identifier management server shown in FIG. 50.
- FIG. 58 is a diagram showing the security policy in the security policy server shown in FIG.
- FIG. 3 is a diagram showing details of a table 201.
- FIG. 59 and FIG. 60 are diagrams showing an example of a sequence showing the operation of the network model of FIG. 50, in which the user (210-5-1) enters the contract network 1 (210-16— 1), the connection to the external network 2003 and then the disconnection sequence, and the user (2015-12) sends the sequence via the contract network 2 (2016-1-2). This shows a sequence for disconnecting after connecting to the external network 2003 through the network.
- the user (2 0 1 5—1) sends the user name (user 2 0 1 5—1—2 0 1) to the firewall device 200 through the user terminal (200 2—1). 6-1) and the password ( ⁇ ) are transmitted (21-1-1, 21-2 in Fig. 59).
- the firewall unit 2001 which has received this user name (user 201-1-1) and the password ( ⁇ ), receives the first half of the user name (user 201-1-1). ) (Fig. 59, 2 1-3), and from the second half of the user name (2 0 16-1), Server 1 (2006-1—1), and sends the first half of the user name (user 2015-1) and password ( ⁇ (Fig. 59-2). 14) .
- the authentication server 1 searches the first half (user 201-5-1) of the received user and the password ( ⁇ ) for the authentication information (201-3-1) and determines that authentication is possible. (2 1-5 in Fig. 59), and available user terminal information (IP-1) whose busy flag is "0" from the pool table of the user terminal information section (2 0 4 1). Is extracted (2 1-6 in Fig. 59), the extracted usable flag is set to "1", and the user terminal information (IP-1) is notified to the firewall device 2001 together with the authentication approval notification ( 2 1-7 in Figure 59).
- the firewall device 2001 holds the received user terminal information (IP-1) (21-8 in FIG. 59), and stores the received user terminal information (IP-1) and the user terminal (2002-1-1). ) Connects the line to be connected, and transmits the first half (user 201-5-1) of the retained user name to the identifier management server 2005 (2119 in FIG. 59).
- the identifier management server 20005 searches the identifier management table 201 based on the first half of the received user name (user 201-1-1).
- the first half of the user name (user 201 — 1), the virtual firewall ID (virtual 201 4-1), the common filtering table ID (common 2009-1), and the individual filtering table ID (20 1 0-1) is extracted (21-1-10 in FIG. 59), and this identifier is transmitted to the firewall device 2001 (21-1-11 in FIG. 59).
- the firewall device 2001 retains the received individual filtering table ID (individual 201 0—1), and receives the received virtual firewall ID (virtual 201 4—1) and the common filter.
- the routing table ID (common 209—1), the individual filtering table ID (individual 210 0—1), and the held user terminal information (IP_l) are stored in the distribution management table 20 07 (Fig. 59, 21-1 2).
- the first half of the retained user name (user 201-5-1) is transmitted to the security policy server 2004 (21-13 in FIG. 59).
- the security policy server 204 searches the security policy table 201 held based on the first half (user 201-5-1) of the received user name, and searches the first half of the user name (user 201-5). -1) Extracts the individual security policy (Rule 11-1 to Rule 11-m) associated with (1) and sends it to the firewall device 200 (Fig. 59). 2 1— 1 5).
- the firewall device 2001 writes the retained individual filtering table ID (individual 2101—1) into the identification information area of the individual filtering table area (21010—1).
- the individual security policy is written to the security policy area (21--16 in Fig. 59).
- an authentication success notification including the held user terminal information (IP-1) is notified to the user terminal (2002-1) (21-1-17 in Fig. 59).
- the user terminal (2002-1) When a packet is transferred from the user terminal (2002-1) to the external network 203, the user terminal (2002-1) receives the user terminal information (IP1) received at the end of the connection start sequence. Own The packet is given to the bucket and forwarded to the firewall device 200 (21-1-18 in Fig. 59).
- IP1 user terminal information
- the firewall device 2001 extracts the user terminal information (IP-1) from the received bucket, searches the distribution management table 2007 using the user terminal information (IP-1) as a key, and searches for the virtual firewall. Extract the ID (virtual 20 14-1), common filtering table ID (20 9 9-1), and individual filtering table ID (20 1 0-1) (Fig.
- the received packet is distributed to the virtual firewall 1 (2 0 14-1) indicated by the extracted virtual firewall ID (virtual 20 1 4—1), and the extracted virtual firewall Of the filtering table of the virtual firewall indicated by (virtual 20 14—1), the extracted common filtering table ID (common 20 09—1) and the individual filtering table ID (individual 20 1 0)
- the packet is passed through the contract network 1 (20 16-1) to the external network.
- the data is transferred to the network 203 (21-22 in Fig. 59).
- a bucket addressed to the user terminal (2002-1-1) is received from the external network 2003 via the contract network 1 (2016-1) (see 21-1 in FIG. 59). 3)
- the packet from the external network 203 has the user terminal information (IP-1) as the destination address.
- the firewall device 2001 extracts the user terminal information (IP-1) from the received bucket toll (21-2-4 in FIG. 59), and transmits the information from the user terminal (2002-1-1) to the outside. After filtering the packets (21-25, 21-26 in Fig. 59) by the same sequence as the packet to the network 2003, Transfer the bucket to (200 2-1).
- the firewall device 2001 of the present embodiment performs filtering processing on packets transmitted from both directions of the user terminal side and the external network side, and transmits the packets.
- a disconnection request is notified from the user (201-5-1) to the firewall unit 2001 via the user terminal (200-2-1) (21-28, Fig. 59). 2 1—2 9).
- the virtual firewall ID (virtual 2104-1-1) and the individual filtering table are obtained from the entry related to the user terminal information (IP-1) in the distribution management table 20007. After extracting the IDs (individual 210-1-0), delete this entry (21-30 in Fig. 59).
- the extracted individual filter In the individual filtering table area (201-10-1) of the virtual firewall 1 (201-4-1) indicated by the extracted virtual firewall ID (virtual 2104-1-1), the extracted individual filter The identification information on which the security table ID (individual 201 1 0-1) is written and the security policy area related thereto are deleted (2 1- 3 1 in Fig. 59).
- the user terminal information (IP-1) derived upon receiving the disconnection request is transmitted to the authentication server 1 (2006-1) (see 21 in FIG. 59).
- the authentication server 1 (20 06—1) receives the received user terminal information (
- the in-use flag of the entry in the Boolean table of the user terminal information section (210-4-1) associated with IP-1) is reset to "0" (2 1-3 3 in Fig. 59).
- connection start sequence, communication sequence, and disconnection sequence of the user are also implemented by the same means as the user (2015-1) (see Fig. 60-2). 1—34 ⁇ 2 1—66 6).
- the firewall device 2001 operates as a plurality of firewalls, and the user is authenticated by the individual authentication server (2006-1—2, 2006-2) for each firewall. For each firewall, it is possible to connect to an external network 203 via a contract network (210-16-1, 200-16-2) and to load a security policy for each user. It becomes possible.
- the security policy server (504, 204) and the identifier management server (505, 205) have only one power S.
- Each firewall device in the example may be connectable to two security policy servers having the same security policy table or two security policy servers having the same identifier management table.
- the accommodating network or terminal dynamically connects and disconnects, or retains when the accommodated firewall device is changed. It is possible to keep the security policy capacity optimal, and it is possible to reduce the amount of security policy loaded on the firewall device.
- the device can be realized, for example, by mounting a program for executing the processing described in each embodiment on a computer system having a communication device.
- the computer system includes, for example, as shown in FIG. 61, a CPU 600, a memory 61, a node disk 61, an input / output device 603, and a communication device 604. I have.
- the data held in the processing of each embodiment is held, for example, in the memory 601.
- a communication device 604 is used as a communication means with another server. Note that a router and the like are also included in the above computer system.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
Abstract
Description
Claims
Priority Applications (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP04708074A EP1592189A4 (en) | 2003-02-05 | 2004-02-04 | FIREWALL DEVICE |
| JP2005504855A JP3852017B2 (ja) | 2003-02-05 | 2004-02-04 | ファイアウォール装置 |
| US10/544,483 US7735129B2 (en) | 2003-02-05 | 2004-02-04 | Firewall device |
Applications Claiming Priority (6)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2003027828 | 2003-02-05 | ||
| JP2003-027828 | 2003-02-05 | ||
| JP2003044770 | 2003-02-21 | ||
| JP2003-044770 | 2003-02-21 | ||
| JP2003-045222 | 2003-02-24 | ||
| JP2003045222 | 2003-02-24 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2004071038A1 true WO2004071038A1 (ja) | 2004-08-19 |
Family
ID=32854102
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2004/001124 Ceased WO2004071038A1 (ja) | 2003-02-05 | 2004-02-04 | ファイアウォール装置 |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US7735129B2 (ja) |
| EP (1) | EP1592189A4 (ja) |
| JP (1) | JP3852017B2 (ja) |
| WO (1) | WO2004071038A1 (ja) |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101888374A (zh) * | 2010-05-19 | 2010-11-17 | 山东中创软件商用中间件股份有限公司 | 基于内嵌的对响应内容进行缓存过滤的方法、装置及系统 |
| JP2012070225A (ja) * | 2010-09-24 | 2012-04-05 | Hitachi Cable Ltd | ネットワーク中継装置及び転送制御システム |
| US20230283640A1 (en) * | 2022-03-07 | 2023-09-07 | Recolabs Ltd. | Systems and methods for assigning security policies to files and/or records |
Families Citing this family (37)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7475424B2 (en) * | 2004-09-02 | 2009-01-06 | International Business Machines Corporation | System and method for on-demand dynamic control of security policies/rules by a client computing device |
| US7917944B2 (en) | 2004-12-13 | 2011-03-29 | Alcatel Lucent | Secure authentication advertisement protocol |
| WO2006090465A1 (ja) * | 2005-02-24 | 2006-08-31 | Fujitsu Limited | 接続支援装置およびゲートウェイ装置 |
| CN100563246C (zh) | 2005-11-30 | 2009-11-25 | 华为技术有限公司 | 一种基于ip的语音通信边界安全控制系统及方法 |
| JP4545085B2 (ja) * | 2005-12-08 | 2010-09-15 | 富士通株式会社 | ファイアウォール装置 |
| US8234361B2 (en) * | 2006-01-13 | 2012-07-31 | Fortinet, Inc. | Computerized system and method for handling network traffic |
| US8024787B2 (en) * | 2006-05-02 | 2011-09-20 | Cisco Technology, Inc. | Packet firewalls of particular use in packet switching devices |
| US8151337B2 (en) * | 2006-06-30 | 2012-04-03 | Microsoft Corporation | Applying firewalls to virtualized environments |
| US8055760B1 (en) * | 2006-12-18 | 2011-11-08 | Sprint Communications Company L.P. | Firewall doctor |
| US8127347B2 (en) * | 2006-12-29 | 2012-02-28 | 02Micro International Limited | Virtual firewall |
| FR2915598A1 (fr) * | 2007-04-27 | 2008-10-31 | France Telecom | Procede de filtrage de flots indesirables en provenance d'un terminal presume malveillant |
| US8635686B2 (en) * | 2007-05-25 | 2014-01-21 | Apple Inc. | Integrated privilege separation and network interception |
| US7853992B2 (en) * | 2007-05-31 | 2010-12-14 | Microsoft Corporation | Configuring security mechanisms utilizing a trust system |
| US8984620B2 (en) * | 2007-07-06 | 2015-03-17 | Cyberoam Technologies Pvt. Ltd. | Identity and policy-based network security and management system and method |
| US9069599B2 (en) * | 2008-06-19 | 2015-06-30 | Servicemesh, Inc. | System and method for a cloud computing abstraction layer with security zone facilities |
| US20140201017A1 (en) | 2008-06-19 | 2014-07-17 | Servicemesh, Inc. | Systems and methods for providing repeated use of computing resources |
| KR101018435B1 (ko) * | 2008-08-14 | 2011-02-28 | 한국전자통신연구원 | 사용자 단말기의 보안 관리 장치 및 방법 |
| US9531670B2 (en) * | 2009-11-30 | 2016-12-27 | Iwebgate Technology Limited | System and method for network virtualization and security using computer systems and software |
| US20110131648A1 (en) * | 2009-11-30 | 2011-06-02 | Iwebgate Technology Limited | Method and System for Digital Communication Security Using Computer Systems |
| FR2958478B1 (fr) * | 2010-04-02 | 2012-05-04 | Sergio Loureiro | Procede de securisation de donnees et/ou des applications dans une architecture informatique en nuage |
| US8904511B1 (en) * | 2010-08-23 | 2014-12-02 | Amazon Technologies, Inc. | Virtual firewalls for multi-tenant distributed services |
| JP5824911B2 (ja) | 2011-06-29 | 2015-12-02 | 富士通株式会社 | 情報処理装置、情報処理プログラムおよび管理方法 |
| US8887263B2 (en) * | 2011-09-08 | 2014-11-11 | Mcafee, Inc. | Authentication sharing in a firewall cluster |
| US8763106B2 (en) | 2011-09-08 | 2014-06-24 | Mcafee, Inc. | Application state sharing in a firewall cluster |
| EP2575313A1 (en) * | 2011-09-27 | 2013-04-03 | NorCom Information Technology AG | Morphing firewall |
| US9100366B2 (en) * | 2012-09-13 | 2015-08-04 | Cisco Technology, Inc. | Early policy evaluation of multiphase attributes in high-performance firewalls |
| RU2552135C2 (ru) * | 2013-09-09 | 2015-06-10 | Общество с ограниченной ответственностью "СмартТелеМакс" | Устройство защиты от атак для сетевых систем |
| CN103973673B (zh) * | 2014-04-09 | 2017-11-03 | 汉柏科技有限公司 | 划分虚拟防火墙的方法和设备 |
| US9497165B2 (en) * | 2015-03-26 | 2016-11-15 | International Business Machines Corporation | Virtual firewall load balancer |
| US9641485B1 (en) * | 2015-06-30 | 2017-05-02 | PacketViper LLC | System and method for out-of-band network firewall |
| US10051075B1 (en) * | 2015-09-09 | 2018-08-14 | Google Llc | Systems and methods for maintaining an asynchronous communication via an intermediary |
| KR102333028B1 (ko) * | 2017-10-19 | 2021-11-29 | 삼성에스디에스 주식회사 | 방화벽 정책 제어 장치 및 방법 |
| US10728218B2 (en) * | 2018-02-26 | 2020-07-28 | Mcafee, Llc | Gateway with access checkpoint |
| KR102667260B1 (ko) | 2018-09-19 | 2024-05-21 | 삼성전자주식회사 | 패킷을 필터링하는 전자 장치 및 그 작동 방법 |
| US11343228B2 (en) * | 2020-05-13 | 2022-05-24 | Arbor Networks, Inc. | Automatically configuring clustered network services |
| US12506732B2 (en) * | 2022-09-16 | 2025-12-23 | Cisco Technology, Inc. | System, method, and computer-readable storage media for authenticating an endpoint device |
| CN116032575B (zh) * | 2022-12-16 | 2025-08-12 | 北京青云科技集团股份有限公司 | 一种改变防火墙实例容量的方法、装置、设备及存储介质 |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2002003220A2 (en) * | 2000-07-05 | 2002-01-10 | Ernst & Young Llp | Method and apparatus for providing computer services |
| JP2002094508A (ja) * | 2000-09-13 | 2002-03-29 | Nippon Telegr & Teleph Corp <Ntt> | 仮想プライベートネットワーク間通信における接続管理方法及びその装置 |
| JP2002544607A (ja) * | 1999-05-06 | 2002-12-24 | ウォッチガード テクノロジーズ インコーポレイテッド | マネージャデバイスから複数のネットワークセキュリティデバイスを管理する方法 |
Family Cites Families (13)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7272625B1 (en) * | 1997-03-10 | 2007-09-18 | Sonicwall, Inc. | Generalized policy server |
| US6408336B1 (en) * | 1997-03-10 | 2002-06-18 | David S. Schneider | Distributed administration of access to information |
| US6442588B1 (en) * | 1998-08-20 | 2002-08-27 | At&T Corp. | Method of administering a dynamic filtering firewall |
| US6615357B1 (en) * | 1999-01-29 | 2003-09-02 | International Business Machines Corporation | System and method for network address translation integration with IP security |
| US6463474B1 (en) * | 1999-07-02 | 2002-10-08 | Cisco Technology, Inc. | Local authentication of a client at a network device |
| US7181766B2 (en) * | 2000-04-12 | 2007-02-20 | Corente, Inc. | Methods and system for providing network services using at least one processor interfacing a base network |
| JP2001298449A (ja) | 2000-04-12 | 2001-10-26 | Matsushita Electric Ind Co Ltd | セキュリティ通信方法、通信システム及びその装置 |
| US6931437B2 (en) * | 2000-04-27 | 2005-08-16 | Nippon Telegraph And Telephone Corporation | Concentrated system for controlling network interconnections |
| US7093280B2 (en) * | 2001-03-30 | 2006-08-15 | Juniper Networks, Inc. | Internet security system |
| WO2003021978A1 (en) * | 2001-08-10 | 2003-03-13 | Strix Systems, Inc. | Virtual linking using a wireless device |
| US7313606B2 (en) * | 2001-11-27 | 2007-12-25 | The Directv Group, Inc. | System and method for automatic configuration of a bi-directional IP communication device |
| JP3776821B2 (ja) * | 2002-03-28 | 2006-05-17 | 富士通株式会社 | アドレスアクセスシステム及び方法 |
| EP1395015B1 (en) * | 2002-08-30 | 2005-02-02 | Errikos Pitsos | Method, gateway and system for transmitting data between a device in a public network and a device in an internal network |
-
2004
- 2004-02-04 EP EP04708074A patent/EP1592189A4/en not_active Withdrawn
- 2004-02-04 US US10/544,483 patent/US7735129B2/en not_active Expired - Fee Related
- 2004-02-04 WO PCT/JP2004/001124 patent/WO2004071038A1/ja not_active Ceased
- 2004-02-04 JP JP2005504855A patent/JP3852017B2/ja not_active Expired - Fee Related
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2002544607A (ja) * | 1999-05-06 | 2002-12-24 | ウォッチガード テクノロジーズ インコーポレイテッド | マネージャデバイスから複数のネットワークセキュリティデバイスを管理する方法 |
| WO2002003220A2 (en) * | 2000-07-05 | 2002-01-10 | Ernst & Young Llp | Method and apparatus for providing computer services |
| JP2002094508A (ja) * | 2000-09-13 | 2002-03-29 | Nippon Telegr & Teleph Corp <Ntt> | 仮想プライベートネットワーク間通信における接続管理方法及びその装置 |
Non-Patent Citations (1)
| Title |
|---|
| See also references of EP1592189A4 * |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101888374A (zh) * | 2010-05-19 | 2010-11-17 | 山东中创软件商用中间件股份有限公司 | 基于内嵌的对响应内容进行缓存过滤的方法、装置及系统 |
| JP2012070225A (ja) * | 2010-09-24 | 2012-04-05 | Hitachi Cable Ltd | ネットワーク中継装置及び転送制御システム |
| US20230283640A1 (en) * | 2022-03-07 | 2023-09-07 | Recolabs Ltd. | Systems and methods for assigning security policies to files and/or records |
Also Published As
| Publication number | Publication date |
|---|---|
| US7735129B2 (en) | 2010-06-08 |
| US20060143699A1 (en) | 2006-06-29 |
| JPWO2004071038A1 (ja) | 2006-06-01 |
| EP1592189A4 (en) | 2012-05-23 |
| EP1592189A1 (en) | 2005-11-02 |
| JP3852017B2 (ja) | 2006-11-29 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2004071038A1 (ja) | ファイアウォール装置 | |
| JP4327408B2 (ja) | 仮想プライベートボリューム方式及びシステム | |
| JP5398410B2 (ja) | ネットワークシステム,パケット転送装置,パケット転送方法及びコンピュータプログラム | |
| CN100521650C (zh) | 包转发装置以及接入网系统 | |
| JP4587446B2 (ja) | ネットワークシステム、並びにスイッチ装置及び経路管理サーバ及びそれらの制御方法、及び、コンピュータプログラム及びコンピュータ可読記憶媒体 | |
| JP4105722B2 (ja) | 通信装置 | |
| CN100466527C (zh) | 通信设备 | |
| US20090122798A1 (en) | Ip network system and its access control method, ip address distributing device, and ip address distributing method | |
| JP4290198B2 (ja) | 信頼できるプロセスを許可する柔軟なネットワークセキュリティシステム及びネットワークセキュリティの方法 | |
| JPH11205388A (ja) | パケットフィルタ装置、認証サーバ、パケットフィルタリング方法及び記憶媒体 | |
| CN1647451B (zh) | 用于在网络环境中监视信息的装置、方法和系统 | |
| US20060109850A1 (en) | IP-SAN network access control list generating method and access control list setup method | |
| CN101160839A (zh) | 接入控制方法、接入控制系统以及分组通信装置 | |
| EP1563664A1 (en) | Management of network security domains | |
| US9716688B1 (en) | VPN for containers and virtual machines in local area networks | |
| CN100471183C (zh) | 防火墙装置 | |
| JP4873960B2 (ja) | アプリケーションサーバ機能を促進するための方法およびアプリケーションサーバ機能を含むアクセスノード | |
| JP2010239591A (ja) | ネットワークシステム、中継装置、およびネットワーク制御方法 | |
| CN105871749A (zh) | 一种基于路由器的网络访问控制方法、系统及相关设备 | |
| JP5261432B2 (ja) | 通信システム、パケット転送方法、ネットワーク交換装置、アクセス制御装置、及びプログラム | |
| JP2012070225A (ja) | ネットワーク中継装置及び転送制御システム | |
| JP4827868B2 (ja) | ネットワーク接続制御システム、ネットワーク接続制御プログラムおよびネットワーク接続制御方法 | |
| JP3953963B2 (ja) | 認証機能付きパケット通信装置、ネットワーク認証アクセス制御サーバ、および分散型認証アクセス制御システム | |
| JP2002208946A (ja) | 経路情報通知方法、vpnサービス及びエッジルータ装置 | |
| JP3965774B2 (ja) | ネットワークシステム |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| WWE | Wipo information: entry into national phase |
Ref document number: 2005504855 Country of ref document: JP |
|
| AK | Designated states |
Kind code of ref document: A1 Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BW BY BZ CA CH CN CO CR CU CZ DE DK DM DZ EC EE EG ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NA NI NO NZ OM PG PH PL PT RO RU SC SD SE SG SK SL SY TJ TM TN TR TT TZ UA UG US UZ VC VN YU ZA ZM ZW |
|
| AL | Designated countries for regional patents |
Kind code of ref document: A1 Designated state(s): BW GH GM KE LS MW MZ SD SL SZ TZ UG ZM ZW AM AZ BY KG KZ MD RU TJ TM AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IT LU MC NL PT RO SE SI SK TR BF BJ CF CG CI CM GA GN GQ GW ML MR NE SN TD TG |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application | ||
| ENP | Entry into the national phase |
Ref document number: 2006143699 Country of ref document: US Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 10544483 Country of ref document: US |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2004708074 Country of ref document: EP Ref document number: 20048036915 Country of ref document: CN |
|
| WWP | Wipo information: published in national office |
Ref document number: 2004708074 Country of ref document: EP |
|
| WWP | Wipo information: published in national office |
Ref document number: 10544483 Country of ref document: US |