Load Balancing across Multiple Network Address Translation (NAT) Instances and/or Processors
    41.
    发明申请
    Load Balancing across Multiple Network Address Translation (NAT) Instances and/or Processors 有权
    多个网络地址转换(NAT)实例和/或处理器之间的负载平衡

    公开(公告)号:US20100061380A1

    公开(公告)日:2010-03-11

    申请号:US12205848

    申请日:2008-09-05

    IPC分类号: H04L12/56

    摘要: Disclosed are, inter alia, methods, apparatus, computer-storage media, mechanisms, and means associated with load balancing across multiple network address translation (NAT) instances and/or processors. N network address translation (NAT) processors and/or instances are each assigned a portion of the source address traffic in order to load balance the network address translation among them. Additionally, the address space of translated addresses is partitioned and uniquely assigned to the NAT processors and/or instances such that the identification of the assigned NAT processor and/or instance associated with a received translated address can be readily determined there from, and then used to network address translate that received packet.

    摘要翻译: 公开了尤其涉及与多个网络地址转换(NAT)实例和/或处理器之间的负载平衡相关联的方法,装置,计算机存储介质,机制和装置。 N网络地址转换(NAT)处理器和/或实例各自被分配一部分源地址流量,以便在它们之间平衡网络地址转换。 另外,翻译的地址的地址空间被分割并且被唯一地分配给NAT处理器和/或实例,使得可以容易地确定所分配的NAT处理器和/或与所接收的转换地址相关联的实例的标识,然后使用 到网络地址转换收到的数据包。

    METHOD AND SYSTEM FOR DISTRIBUTING LOAD BY REDIRECTING TRAFFIC
    42.
    发明申请
    METHOD AND SYSTEM FOR DISTRIBUTING LOAD BY REDIRECTING TRAFFIC 有权
    通过重定向交通分配负载的方法和系统

    公开(公告)号:US20090282149A1

    公开(公告)日:2009-11-12

    申请号:US12368969

    申请日:2009-02-10

    IPC分类号: G06F15/173 G06F15/16

    摘要: Disclosed is a system for servers to redirect client requests to other servers in order to distribute client traffic among the servers. A client is assigned to a server although the client may be unaware of that assignment. When the client accesses a server, a server possibly identified to the client by a name service, the server checks the client's assignment. If the client is not assigned to this server, then in some scenarios this server redirects the client to its assigned server. The client responds by sending its request to the assigned server. In other scenarios, the first server accessed by the client proxies the client's traffic to the assigned server. A database is kept of client-to-server assignments. If the present load distribution is less than ideal (e.g., clients are assigned to an unavailable server), then the assignment database is updated to reflect how the load should be distributed.

    摘要翻译: 公开了一种用于服务器的系统,用于将客户端请求重定向到其他服务器,以便在服务器之间分发客户端流量。 客户端被分配给服务器,尽管客户端可能不知道该分配。 当客户端访问服务器时,可能通过名称服务识别给客户端的服务器,服务器检查客户端的分配。 如果客户端未分配给此服务器,那么在某些情况下,此服务器将客户端重定向到其分配的服务器。 客户端通过将其请求发送到分配的服务器进行响应。 在其他情况下,客户端访问的第一台服务器会将客户端的流量代理到分配的服务器。 客户端到服务器分配的数据库被保留。 如果当前的负载分布不理想(例如,客户端被分配给不可用的服务器),则更新分配数据库以反映如何分布负载。

    Method and system for forwarding messages received at a traffic manager
    43.
    发明授权
    Method and system for forwarding messages received at a traffic manager 有权
    用于转发在交通管理器处接收的消息的方法和系统

    公开(公告)号:US07490162B1

    公开(公告)日:2009-02-10

    申请号:US10172411

    申请日:2002-06-13

    摘要: A method and system for forwarding messages received at a traffic manager. A traffic manager receives a message from a first connection to a client computer. At least a part of the message is to be forwarded to a server. If a connection exists to the server that matches the first connection, at least a part of the message is forwarded to the server by employing the existing connection. Otherwise, a source address is selected with which to communicate with the server. A new connection that includes the source address and a destination address associated with the server is opened. In addition, information associating the source address and the destination address with the first connection is stored. This information may then be used to map a response received from the server to the first connection.

    摘要翻译: 一种在业务管理器处转发消息的方法和系统。 流量管理器从第一个连接到客户端计算机接收消息。 消息的至少一部分将被转发到服务器。 如果与第一个连接匹配的服务器存在连接,那么通过使用现有的连接将消息的至少一部分转发到服务器。 否则,选择与服务器进行通信的源地址。 将打开包含源地址和与服务器关联的目标地址的新连接。 此外,存储将源地址和目的地地址与第一连接相关联的信息。 然后可以将该信息用于将从服务器接收的响应映射到第一连接。

    Network data storage system
    44.
    发明申请
    Network data storage system 失效
    网络数据存储系统

    公开(公告)号:US20090019054A1

    公开(公告)日:2009-01-15

    申请号:US11801376

    申请日:2007-05-09

    摘要: The inventions concerns a network data storage system comprising a storage unit, at least one network client and an intermediate network switch.The storage unit contains at least two data storage servers each comprises a local storage component containing digital file segments of at least one digital file and is adapted to execute a local digital file management method organising the physical location of the digital file segments.Each data storage server is adapted to communicate with the other data storage servers and to execute a distributed digital file management method.The distributed digital file management method maintains a record of operations and communicates internally with the other data storage servers to obtain information concerning the digital file segments contained on the other data storage servers and an overview of all information concerning all digital files stored on the storage unit.

    摘要翻译: 本发明涉及包括存储单元,至少一个网络客户端和中间网络交换机的网络数据存储系统。 存储单元包含至少两个数据存储服务器,每个数据存储服务器包括包含至少一个数字文件的数字文件段的本地存储组件,并且适于执行组织数字文件段的物理位置的本地数字文件管理方法。 每个数据存储服务器适于与其他数据存储服务器通信并执行分布式数字文件管理方法。 分布式数字文件管理方法维护操作记录并与其他数据存储服务器内部通信,以获得关于其他数据存储服务器上包含的数字文件段的信息,以及关于存储在存储单元上的所有数字文件的所有信息的概述 。

    Active-active operation for a cluster of SSL virtual private network (VPN) devices with load distribution
    45.
    发明申请
    Active-active operation for a cluster of SSL virtual private network (VPN) devices with load distribution 有权
    对具有负载分配的SSL虚拟专用网(VPN)设备的集群进行主动 - 主动操作

    公开(公告)号:US20080263209A1

    公开(公告)日:2008-10-23

    申请号:US11801804

    申请日:2007-05-10

    IPC分类号: G06F15/16

    摘要: A method of load distribution for a cluster of two or more nodes. The method comprises receiving an initial request packet on a network device having a virtual IP address; forwarding the request packet from the network device to a cluster of at least two nodes, wherein each of the at least two nodes has an internal dispatcher module and an unique and non-conflicting virtual IP address; establishing one of the at least two nodes as a priority dispatcher or dispatcher endpoint, wherein if any one node fails, the virtual IP address of the one node which is no longer active falls back to another node within the cluster based on cluster priorities; dispatching the request packet to one of the nodes associated with the cluster; and forwarding the request from one of the nodes to a switching device.

    摘要翻译: 两个或多个节点的集群的负载分配方法。 该方法包括在具有虚拟IP地址的网络设备上接收初始请求分组; 将所述请求分组从所述网络设备转发到至少两个节点的集群,其中所述至少两个节点中的每一个具有内部分派器模块和唯一且非冲突的虚拟IP地址; 将所述至少两个节点中的一个建立为优先级调度器或调度终端,其中如果任何一个节点发生故障,则不再有效的一个节点的虚拟IP地址基于簇优先级返回到群集内的另一个节点; 将所述请求分组分派到与所述集群相关联的节点之一; 以及将所述请求从所述节点之一转发到交换设备。

    Virtual server recirculation
    46.
    发明申请
    Virtual server recirculation 有权
    虚拟服务器再循环

    公开(公告)号:US20080263205A1

    公开(公告)日:2008-10-23

    申请号:US11788725

    申请日:2007-04-19

    申请人: Zeeshan Naseh

    发明人: Zeeshan Naseh

    IPC分类号: G06F15/173

    摘要: In one embodiment, a method can include: (i) classifying a packet in a server load balancer (SLB) for determining if the packet is destined for a virtual Internet protocol (VIP) address hosted on the SLB; (ii) selecting a server from a group of servers representing the VIP address; (iii) changing a destination IP address of the packet from the VIP address to a real IP address of the selected server; and (iv) recirculating the packet for repeating the classifying.

    摘要翻译: 在一个实施例中,一种方法可以包括:(i)对服务器负载平衡器(SLB)中的分组进行分类,以确定该分组是否注定到在SLB上托管的虚拟因特网协议(VIP)地址; (ii)从代表VIP地址的一组服务器中选择服务器; (iii)将所述分组的目的地IP地址从所述VIP地址更改为所选服务器的真实IP地址; 和(iv)使分组物再循环以重复分类。

    Method for encrypted communication with a computer system and system therefor
    48.
    发明申请
    Method for encrypted communication with a computer system and system therefor 失效
    用于与计算机系统及其系统进行加密通信的方法

    公开(公告)号:US20080098221A1

    公开(公告)日:2008-04-24

    申请号:US11907260

    申请日:2007-10-10

    IPC分类号: H04L9/32

    摘要: To solve problems in that a load on a VPN device is large in a case where the number of terminal devices increases in encrypted communication using a VPN technique, and that only communication between the terminal device and the VPN device is encrypted, thus disabling end-to-end encrypted communication, a communication system is provided, including: a terminal device; a plurality of blades; and a management server that manages the blades, in which: the management server selects a blade, authenticates the terminal device and the selected blade, and mediates encrypted communication path establishment between the terminal device and the selected blade; the terminal device and the blade perform encrypted communication without the mediation of the management server; and the management server requests a validation server to authenticate each terminal.

    摘要翻译: 为了解决在使用VPN技术的加密通信中终端装置的数量增加,VPN终端装置与VPN装置之间的通信被加密的情况下,VPN装置的负载大的问题, 端到端加密通信,提供通信系统,包括:终端装置; 多个叶片; 以及管理服务器,其中:所述管理服务器选择刀片,对所述终端设备和所选择的刀片进行认证,并且中介所述终端设备与所选刀片之间的加密通信路径建立; 终端设备和刀片在没有管理服务器的中介的情况下执行加密的通信; 并且管理服务器请求验证服务器来认证每个终端。

    Encryption load balancing and distributed policy enforcement
    49.
    发明申请
    Encryption load balancing and distributed policy enforcement 审中-公开
    加密负载平衡和分布式策略执行

    公开(公告)号:US20080022136A1

    公开(公告)日:2008-01-24

    申请号:US11644106

    申请日:2006-12-21

    IPC分类号: G06F11/30

    摘要: To achieve encryption load balancing, a dispatcher, in communication with one or more engines, delegates one or more requests to the one or more engines. The engines execute cryptographic operations on data. The dispatcher may implement one or more load balancing algorithms to delegate requests to engines in accordance with data protection classes and rules for improved efficiency, performance, and security. To achieve distributed policy enforcement, the engines may also analyze whether the request violates an item access rule.

    摘要翻译: 为了实现加密负载平衡,与一个或多个引擎通信的调度员将一个或多个请求委托给一个或多个引擎。 引擎对数据执行加密操作。 调度员可以实施一个或多个负载平衡算法,以根据数据保护等级和规则将请求委托给引擎,以提高效率,性能和安全性。 为了实现分布式策略实施,引擎还可以分析该请求是否违反了项目访问规则。

    Transparent load balancer for network connections
    50.
    发明授权
    Transparent load balancer for network connections 有权
    用于网络连接的透明负载均衡器

    公开(公告)号:US07290050B1

    公开(公告)日:2007-10-30

    申请号:US10252061

    申请日:2002-09-20

    IPC分类号: G06F15/173 G06F9/46

    摘要: A transparent load balancer receives incoming Ethernet frames having incoming source and destination IP and MAC addresses. The load balancer diverts the incoming frames to one of several multi-application platforms. The incoming frames are communicated across a first TCP connection that terminates on a multi-application platform. The first TCP connection is defined by TCP source and destination ports. The transparent load balancer receives outgoing frames from the multi-application platform and outputs the outgoing frames with source and destination IP and MAC addresses that are identical to the incoming source and destination IP and MAC addresses. The outgoing frames are communicated across a second TCP connection, the second TCP connection being defined by the same TCP source port and TCP destination port of the first TCP connection. The transparent load balancer and multi-application platforms can be inserted into a running network without noticeable interruption to devices on the network.

    摘要翻译: 透明负载平衡器接收具有传入源和目标IP和MAC地址的入站以太网帧。 负载平衡器将进入的帧转移到几个多应用平台之一。 传入的帧通过在多应用平台上终止的第一TCP连接进行通信。 第一个TCP连接由TCP源端口和目标端口定义。 透明负载平衡器从多应用平台接收输出帧,并输出与源IP和MAC地址相同的源IP和MAC地址的出站帧。 输出帧通过第二TCP连接进行通信,第二TCP连接由第一TCP连接的相同TCP源端口和TCP目标端口定义。 透明负载平衡器和多应用平台可以插入到正在运行的网络中,而不会明显地中断网络上的设备。