Mechanisms for providing connectivity in NAT redundant/fail-over scenarios in unshared address-space
    2.
    发明申请
    Mechanisms for providing connectivity in NAT redundant/fail-over scenarios in unshared address-space 有权
    在非共享地址空间中的NAT冗余/故障转移场景中提供连接的机制

    公开(公告)号:US20070019540A1

    公开(公告)日:2007-01-25

    申请号:US11189478

    申请日:2005-07-25

    IPC分类号: H04J3/14 H04L12/56

    摘要: Disclosed are methods and apparatus for facilitating reliable session based communication with a local host via a subnet of redundant network devices that also implement network address translation (NAT) or the like. In general, embodiments of the present invention include mechanisms for reestablishing access to a local host after the local host's active network device has failed and been replaced by a new active network device with an address space that differs from the failed network device. In this invention, the network devices associated with the same local host also implement NAT, or the like. In brief, for each of its associated local hosts, the new active network device causes an address server to be updated with a new public address that is assigned from its address space to the local host. This update allows other remote hosts access to the local hosts by obtaining the updated address information from the address server. Communication sessions that were established prior to the failing active network device may also be retained by the new active network device. In this aspect, for each ongoing particular session between a remote host and a local host of the new active network device, the new active network device updates the remote host with a new public address assigned to local host for use in the particular session.

    摘要翻译: 公开了用于通过还实现网络地址转换(NAT)等的冗余网络设备的子网来促进与本地主机的基于会话的通信的方法和装置。 通常,本发明的实施例包括在本地主机的活动网络设备发生故障之后重新建立对本地主机的访问的机制,并且被具有不同于故障网络设备的地址空间的新的活动网络设备所替代。 在本发明中,与同一本地主机相关联的网络设备也实现NAT等。 简而言之,对于每个相关联的本地主机,新的活动网络设备使得使用从其地址空间分配给本地主机的新的公共地址来更新地址服务器。 此更新允许其他远程主机通过从地址服务器获取更新的地址信息来访问本地主机。 在故障的活动网络设备之前建立的通信会话也可以由新的活动网络设备保留。 在这方面,对于远程主机和新的活动网络设备的本地主机之间的每个正在进行的特定会话,新的活动网络设备使用分配给本地主机的新的公共地址来更新远程主机以在特定会话中使用。

    Mechanisms for detection of non-supporting NAT traversal boxes in the path
    4.
    发明申请
    Mechanisms for detection of non-supporting NAT traversal boxes in the path 有权
    在路径中检测不支持的NAT穿越框的机制

    公开(公告)号:US20060146813A1

    公开(公告)日:2006-07-06

    申请号:US11026891

    申请日:2004-12-30

    IPC分类号: H04L12/56 H04J3/16

    摘要: Disclosed are methods and apparatus for facilitating translation of packet addresses (or ports) by one or more translation devices (e.g., NAT devices) using a specialized protocol to handle an address (or port) that is used to form part of a payload. In one implementation, this specialized protocol is referred to as Network Layer Signaling (NLS). As a packet traverses along a path containing one or more translation devices, each translation device is configured to translate an address (or port) of such packet's IP header if the packet is traversing between different domains (e.g., traversing between a private and public domain or between two different private domains). One or more of these translation devices may also be configured to implement the specialized protocol which includes translation device traversal mechanisms for detecting whether the traversal path contains a translation device that fails to implement such specialized protocol. When such a failure is detected, recovery mechanisms are also triggered.

    摘要翻译: 公开了用于利用专用协议来利用一个或多个翻译设备(例如,NAT设备)来转换分组地址(或端口)以处理用于形成有效载荷的一部分的地址(或端口)的方法和装置。 在一个实现中,该专用协议被称为网络层信令(NLS)。 当分组沿着包含一个或多个翻译设备的路径穿越时,如果分组在不同域之间遍历(例如,在私有域和公共域之间遍历),则每个翻译设备被配置为转换该分组的IP报头的地址(或端口) 或两个不同的私有域之间)。 这些翻译装置中的一个或多个还可以被配置为实现专用协议,其包括用于检测穿越路径是否包含不能实现这种专用协议的翻译装置的翻译装置遍历机制。 当检测到这种故障时,还会触发恢复机制。

    Method and apparatus for handling embedded addresses in data sent through multiple network address translation (NAT) devices
    6.
    发明授权
    Method and apparatus for handling embedded addresses in data sent through multiple network address translation (NAT) devices 有权
    用于处理通过多个网络地址转换(NAT)设备发送的数据中的嵌入式地址的方法和装置

    公开(公告)号:US07957382B1

    公开(公告)日:2011-06-07

    申请号:US11549341

    申请日:2006-10-13

    IPC分类号: H04L12/28

    CPC分类号: H04L29/1233 H04L61/25

    摘要: Disclosed are methods and apparatus for handling data containing embedded addresses. In general terms, prior to transmission of data having an embedded address or port, an initiating host sends a NAT Probe to an end-host with which the initiating host wishes to communicate. The NAT Probe includes the embedded address or port and a type indicating that translation of the address and/or port is requested if needed. As the NAT Probe traverses through one or more NAT devices as it is transmitted to the end-host, each NAT device is enabled to recognize the NAT Probe type and translate the embedded address and/or port, depending upon the individual NAT device's configuration. When the NAT Probe reaches the final hop NAT device or end-host, a NAT Probe Reply is sent back to the initiating host. The NAT Probe Reply contains a translated embedded address and/or port which is compatible with the end-host's network. The NAT Probe Reply also contains a type which differs from the type of the NAT Probe. As the NAT Probe Reply traverses back through the same NAT devices, the NAT device recognize the type of the NAT Probe Reply and do not translate the embedded address and/or port.

    摘要翻译: 公开了用于处理包含嵌入地址的数据的方法和装置。 一般来说,在传输具有嵌入式地址或端口的数据之前,发起主机向发起主机希望通信的终端主机发送NAT探测器。 NAT探测器包括嵌入式地址或端口以及指示如果需要,请求转换地址和/或端口的类型。 由于NAT探测器通过一个或多个NAT设备传输到终端主机时,每个NAT设备都可以识别NAT探测器类型,并根据各个NAT设备的配置转换嵌入式地址和/或端口。 当NAT探测器到达最终跳转NAT设备或终端主机时,NAT探测回复将发送回发起主机。 NAT探测回复包含与终端主机网络兼容的已翻译的嵌入式地址和/或端口。 NAT探测应答还包含一种不同于NAT探测器类型的类型。 由于NAT探测回复通过相同的NAT设备,NAT设备识别NAT探测回复的类型,并且不转换嵌入式地址和/或端口。

    Preventing network denial of service attacks by early discard of out-of-order segments
    8.
    发明授权
    Preventing network denial of service attacks by early discard of out-of-order segments 有权
    通过早期丢弃无序段来防止网络拒绝服务攻击

    公开(公告)号:US08074275B2

    公开(公告)日:2011-12-06

    申请号:US11345999

    申请日:2006-02-01

    IPC分类号: H04L12/00 H04L12/28 H04L29/14

    摘要: A method of preventing network denial of service attacks by early discard of out-of-order segments comprises creating a reassembly queue for a connection between a first network node and a second network node, wherein the connection has been established based on a transport-layer network protocol, the reassembly queue having a size based on a buffer size of an input interface with which the connection is associated. As out-of-order data segments arrive on the connection, and before other processing of the segments, whether the reassembly queue is full is determined, and the out-of-order segments are discarded if the reassembly queue is full. The size of the reassembly queue is automatically changed in response to one or more changes in any of network conditions and device resources.

    摘要翻译: 通过早期丢弃无序段来防止网络拒绝服务攻击的方法包括为第一网络节点和第二网络节点之间的连接创建重组队列,其中已经基于传输层建立了连接 网络协议,所述重组队列具有基于与所述连接相关联的输入接口的缓冲器大小的大小。 由于无序数据段到达连接,并且在段的其他处理之前,确定重新组装队列是否已满,并且如果重新组装队列已满,则会丢弃无序段。 响应于任何网络条件和设备资源中的一个或多个更改,自动更改重组队列的大小。

    Minimizing Latency in Live Virtual Server Migration
    9.
    发明申请
    Minimizing Latency in Live Virtual Server Migration 有权
    最小化实时虚拟服务器迁移中的延迟

    公开(公告)号:US20110225285A1

    公开(公告)日:2011-09-15

    申请号:US12722596

    申请日:2010-03-12

    IPC分类号: G06F15/16

    CPC分类号: G06F9/4856 H04L67/148

    摘要: Techniques are provided to facilitate faster live migration of a virtual server from one physical server to another physical server by pausing TO activity of the virtual server and slowing memory state changes for CPU-bound activity of the virtual server during the live migration.

    摘要翻译: 提供了技术,以便通过暂停虚拟服务器的TO活动来减慢虚拟服务器从一个物理服务器到另一个物理服务器的实时迁移,并减缓实时迁移期间虚拟服务器的CPU限制活动的内存状态更改。

    Minimizing latency in live virtual server migration
    10.
    发明授权
    Minimizing latency in live virtual server migration 有权
    实时虚拟服务器迁移中的延迟最小化

    公开(公告)号:US08745204B2

    公开(公告)日:2014-06-03

    申请号:US12722596

    申请日:2010-03-12

    IPC分类号: G06F15/173

    CPC分类号: G06F9/4856 H04L67/148

    摘要: Techniques are provided to facilitate faster live migration of a virtual server from one physical server to another physical server by pausing IO activity of the virtual server and slowing memory state changes for CPU-bound activity of the virtual server during the live migration.

    摘要翻译: 提供了技术,通过暂停虚拟服务器的IO活动,减慢虚拟服务器在实时迁移期间CPU限制活动的内存状态更改,从而实现虚拟服务器从一个物理服务器到另一个物理服务器的实时迁移。