发明申请
- 专利标题: MIGRATING A NETWORK TO TUNNEL-LESS ENCRYPTION
- 专利标题(中): 移动网络进行隧道加密
-
申请号: US12337315申请日: 2008-12-17
-
公开(公告)号: US20100154028A1公开(公告)日: 2010-06-17
- 发明人: W. Scott Wainner , Brian E. Weis
- 申请人: W. Scott Wainner , Brian E. Weis
- 主分类号: G06F21/00
- IPC分类号: G06F21/00
摘要:
A method comprises, in a network comprising VPN gateway devices configured only for plaintext data communication, configuring a policy server with a security policy including DO NOT ENCRYPT statements temporarily overriding PERMIT statements defining which packets should be encrypted; selecting one sub-group of the VPN gateway devices in which tunnel-less encryption is not configured; configuring of the VPN gateway devices in the sub-group for tunnel-less encryption by: configuring each device in a passive mode of operation in which the device is configured to receive either encrypted packets or plaintext packets matching encryption policy; configuring local DO NOT ENCRYPT statements matching traffic that is currently being converted to ciphertext; removing, from the access control list of the policy server, DO NOT ENCRYPT statements referring to protected LAN CIDR blocks behind the VPN gateway devices in the selected sub-group; configuring the sub-group to send encrypted packets by removing, from each of the VPN gateway devices in the selected sub-group, the local DO NOT ENCRYPT statements for the CIDR blocks currently being converted and protected by the selected sub-group; repeating the configuring each of the VPN gateway devices in the selected sub-group for tunnel-less encryption, and the configuring the sub-group to send encrypted packets, for each other one of the sub-groups; and removing the passive mode on each of the VPN gateway devices.
公开/授权文献
- US08307423B2 Migrating a network to tunnel-less encryption 公开/授权日:2012-11-06
信息查询