摘要:
A virtual network device may identify a cloud provider associated with the virtual network device, and may provide a request for public network addresses and private network addresses associated with the cloud provider. The virtual network device may receive the public network addresses and the private network addresses from the cloud provider based on the request, and may generate a translation table that maps the public network addresses and the private network addresses. The virtual network device may utilize the translation table to establish a secure communication between an endpoint device and a server device, where the secure communication is associated with at least one packet that requires an inner payload network address change.
摘要:
In accordance with an example embodiment of the present invention, there is provided a method, comprising receiving in an apparatus a first message from a second apparatus located in a different domain as the apparatus, the first message comprising a logical name of the second apparatus and a first global address, receiving a second message from a third apparatus, the second message comprising a second global address, and determining whether the first and second global addresses are the same address, or where the first and second global addresses are IPv6 addresses, whether they belong to the same network, and responsive to the first and second global addresses being the same address, or in the case of IPv6 belonging to the same network, causing transmission of information comprising at least one of a logical name and a local address of the second apparatus to the third apparatus.
摘要:
Procédé pour l'établissement d'une session de communication entre un premier client (C 1 ) situé au sein d'un premier réseau (N 1 ) et un second client (C 2 ) par l'intermédiaire d'un serveur de signalisation (S) situé dans un deuxième réseau (N), consistant en une étape de maintien de l'association entre une première adresse et une deuxième adresse du premier client au sein d'un équipement de traduction d'adresse, par la transmission de messages de signalisation d'enregistrement par le premier client. Le serveur : - mémorise un message de signalisation entrant provenant du second client, - répond au message d'enregistrement suivant par un message de réponse (R N ) requérant l'émission d'un nouveau message d'enregistrement (M N+1 ) utilisant le protocole TCP, et - délivre le message de signalisation (MI) entrant après que le nouveau message d'enregistrement est reçu.
摘要:
Disclosed are an interworking system between IP networks using different IP addressing scheme, an application layer gateway (ALG), a network address translator, an interworking method, and a SIP message routing method. The interworking system between a local network using a private IP and a global network using a global IP includes a STUN server and an application layer gateway (ALG). The STUN server provides binding information of header information of a global IP binding request. The application layer gateway (ALG) performs a global IP binding request with header information changed by IP masquerading, and performs routing by applying the received binding information to media receiving address information of a SIP message.
摘要:
For achieving packet authentication according to an applicable security policy between a sending node (903) and a receiving node (902) in a network, the following steps are taken: the transformations occurring to a packet en route between the sending node and the receiving node are discovered dynamically (1003, 1004), the discovered transformations are checked (1004) to be acceptable based on the applicable security policy, and the dynamically discovered, acceptable transformations are compensated for (1004, 1006) before authenticating packets transmitted from the sending node to the receiving node.
摘要:
For achieving packet authentication according to an applicable security policy between a sending node (903) and a receiving node (902) in a network, the following steps are taken: the transformations occurring to a packet en route between the sending node and the receiving node are discovered dynamically (1003, 1004), the discovered transformations are checked (1004) to be acceptable based on the applicable security policy, and the dynamically discovered, acceptable transformations are compensated for (1004, 1006) before authenticating packets transmitted from the sending node to the receiving node.