摘要:
A method of synchronizing firewalls in a communication system comprising a server farm wherein any user connected to the Internet can access customer servers, and at least two firewalls using a Virtual Router Redundancy Protocol (VRRP) to set up as primary interface firewall the firewall which owns the primary interface of the VRRP group of interfaces to at least one customer server. The method includes initializing, in a secondary interface firewall, a synchronization message exchange with the primary firewall after receiving a packet for a connection having a state which is incompatible with the received packet or after the standard firewall processing of a packet corresponding to a new connection, and registering in a common connection table the state of any connection if the connection is new or if the connection state has changed.
摘要:
A method of preserving symmetrical routing in a communication system comprising a server farm connected to the Internet through an Internet access router. The server farm includes at least two customer cabinets with at least a WEB server and at least two firewalls. The firewalls use a Virtual Router Redundancy Protocol (VRRP) to set up one firewall as being the primary firewall. The method includes checking in each firewall whether there is a change of the VRRP state from primary to secondary or reciprocally. Such a change indicates that a link between the primary firewall and one of the customer cabinets has failed. The link is disabled from the network to the firewall the state of which has changed from primary to secondary or the link is enabled from the Internet network to the firewall the state of which has changed from secondary to primary.
摘要:
A method of preserving symmetrical routing in a communication system comprising a server farm connected to the Internet through an Internet access router. The server farm includes at least two customer cabinets with at least a WEB server and at least two firewalls. The firewalls use a Virtual Router Redundancy Protocol (VRRP) to set up one firewall as being the primary firewall. The method includes checking in each firewall whether there is a change of the VRRP state from primary to secondary or reciprocally. Such a change indicates that a link between the primary firewall and one of the customer cabinets has failed. The link is disabled from the network to the firewall the state of which has changed from primary to secondary or the link is enabled from the Internet network to the firewall the state of which has changed from secondary to primary.
摘要:
A method of preserving symmetrical routing in a communication system comprising a server farm connected to the Internet by an Internet access router IAR. The server farm includes at least two customer cabinets each having a WEB server, and at least two firewalls. The firewalls use Virtual Router Redundancy Protocol (VRRP) to set up a primary firewall that supports communication between a customer server and an Internet user. The IAR selects the firewall to be used as being the firewall corresponding to the interface having the lowest weight in a routing table. The cost assigned to each interface associated with a firewall is automatically generated, at the initial time, according to the priority assigned by the VRRP protocol to said interface associated with said firewall.
摘要:
A method of preserving symmetrical routing in a communication system comprising a server farm connected to the Internet through an Internet access router. The server farm includes at least two customer cabinets with at least a WEB server and at least two firewalls. The firewalls use a Virtual Router Redundancy Protocol (VRRP) to set up one firewall as being the primary firewall. The method includes checking in each firewall whether there is a change of the VRRP state from primary to secondary or reciprocally. Such a change indicates that a link between the primary firewall and one of the customer cabinets has failed. The link is disabled from the network to the firewall the state of which has changed from primary to secondary or the link is enabled from the Internet network to the firewall the state of which has changed from secondary to primary.
摘要:
A method and system for generating alerts based on predicted wireless connection losses. A message is received that includes a first position of a mobile device, an indication of a service being provided to the mobile device via a wireless connection provided by a first bearer, and an mobile device identifier. A direction and speed of the mobile device is received. An amount of time elapsing before the mobile device moves to a second position at which the mobile device experiences a loss of the wireless connection via the first bearer is predicted. An alert that indicates that the loss is occurring in the amount of time is generated. The alert is sent to the mobile device as a response to the message.
摘要:
Network services are routed responsive to receiving a datagram. The datagram requests a certain network-delivered service and includes a virtual address for the service. An apparatus selects a physical address for a certain server from among a number of a physical addresses of respective servers associated by the apparatus with the virtual address. Performance of the respective servers is ranked so that the physical address are selected responsive to the performance ranks. The apparatus forwards the datagram, which includes the selected physical address for directing the datagram to the certain server.
摘要:
A communication system speeds up digital traffic between nodes. The traffic is organized into data frames flowing over network high and low speed links attached to entry and exit ports of the nodes. Low speed modules connect the low speed links to a high speed switch. Router dispatch modules connect the high speed switch to a node attached to a high speed link for forwarding each data frame toward a dynamically selected target low speed module via the high speed switch, such that the dynamic selection of the target low speed module is based on detection of the module with the least load. At least one main router is attached to the high speed switch for storing a routing table to enable the targeted low speed module to orient one of the frames toward a right node exit port.
摘要:
A method and system for preventing unauthorized card transactions via dynamic itinerary-driven profiling. Authorization record(s) including authorized geographic locations and authorized periods of time are received from a travel reservation system (TRS). The authorization record(s) identify an itinerary specified by a travel booking(s) purchased via the TRS using a debit or credit card. The itinerary specifies that the cardholder is scheduled to be in the authorized geographic locations for the authorized periods of time. In response to receiving a request for an authorization of a card transaction, a location and date associated with the card transaction are retrieved from the request. The card transaction is rejected based on a determination that the retrieved location is not within the authorized geographic locations and/or the retrieved date is not within the authorized periods of time. A notification of the retrieved location and retrieved date is logged and displayed.
摘要:
In a network having nodes, N nodes are members of a virtual communications ring for multicast communication among the N Nodes, each of the N Nodes being associated with only an upstream and a downstream one of the other N nodes. One of the N nodes manages changes in ring membership, including requesting the others of the N nodes to participate in measuring distances to a N+1th, node responsive to receiving an insertion request message. The manager node inserts the N+1th node in the communications ring responsive to receiving replies, which includes inserting the N+1th node in a selected location between two selected ones of the N Nodes, such that the N nodes and the N+1th node are enabled to multicast messages around the ring. Due to the selected location of the N+1th node, communication distances for multicasted messages tend to be shorter than such distances that would otherwise occur.