System and method for providing recovery and resynchronization for a tunneling protocol
    3.
    发明授权
    System and method for providing recovery and resynchronization for a tunneling protocol 有权
    为隧道协议提供恢复和重新同步的系统和方法

    公开(公告)号:US08018956B1

    公开(公告)日:2011-09-13

    申请号:US12251625

    申请日:2008-10-15

    IPC分类号: H04L12/56

    摘要: An apparatus is provided in one example embodiment and it includes a first node coupled to an active endpoint and a standby endpoint. The first node communicates with a second node. When the active endpoint experiences a failure, the standby endpoint is activated such that a communication involving the second node continues. The standby endpoint communicates a complete window's worth of packets to the second node after the failure, the window's worth of packets including a last known sequence number acknowledged by the second node. In more specific embodiments, the first node is an L2TP network server (LNS) and the second node is an L2TP access concentrator (LAC). The last known sequence number was check pointed by the active endpoint to the standby endpoint.

    摘要翻译: 在一个示例性实施例中提供了一种装置,并且其包括耦合到活动端点和备用端点的第一节点。 第一节点与第二节点通信。 当活动端点经历故障时,激活备用端点使得涉及第二节点的通信继续。 备用端点在故障之后将完整窗口的数据包传送到第二节点,该窗口的值包括由第二节点确认的最后一个已知序列号。 在更具体的实施例中,第一节点是L2TP网络服务器(LNS),第二节点是L2TP接入集中器(LAC)。 最后知道的序列号是活动端点指向备用端点的检查。

    Remote system administration and seamless service integration of a data communication network management system
    4.
    发明授权
    Remote system administration and seamless service integration of a data communication network management system 有权
    远程系统管理和数据通信网络管理系统的无缝服务集成

    公开(公告)号:US07580999B1

    公开(公告)日:2009-08-25

    申请号:US10682751

    申请日:2003-10-08

    IPC分类号: G06F15/173

    摘要: A method for providing remote management and maintenance of a node or service within a data communications network that is activated by the data communications network management system's receipt of signals of an abnormal condition at a node or service or failure to receive operational status signals from a node or service. A control adapter running on a node within a Point of Presence is started. The control adapter is capable of starting all service adapters associated with all services running on the node. Operational status signals and abnormal condition signals are transmitted from the control adapter and service adapters on to an information bus. If a network management control host receives abnormal condition signals, notification is sent to a remote system administrator that alerts of an error experienced by a node or service. If a network management control host fails to receive operational status signals, notification is sent to a remote system administrator that no signals are being received from a node or service. The system administrator can take appropriate remote action to rectify the problem. The integration of a manually started node or service into a data communications network management system is achieved by manually implementing, at a Point of Presence within a data communications network, a node or service that has an adapter running on it and is in communication with an information bus. The node or service begins signalling operational status upon implementation. These signals are not recognized by network management control hosts. The network management control host transmits signals asking the newly started node or service for identification. The node or service receives the identity request and transmits signals back to the network management control host.

    摘要翻译: 一种在由数据通信网络管理系统在节点或服务处接收到异常状况的信号或从节点接收操作状态信号的信号被激活的数据通信网络内提供远程管理和维护节点或服务的方法 或服务。 启动在“存在点”中的节点上运行的控制适配器。 控制适配器能够启动与节点上运行的所有服务相关联的所有服务适配器。 操作状态信号和异常状态信号从控制适配器和服务适配器发送到信息总线。 如果网络管理控制主机接收到异常状况信号,则向远程系统管理员发送通知节点或服务遇到的错误的通知。 如果网络管理控制主机无法接收到操作状态信号,则向远程系统管理员发送通知,即不从节点或服务接收信号。 系统管理员可以采取适当的远程操作来解决问题。 手动启动的节点或服务到数据通信网络管理系统的集成通过在数据通信网络内的存在点处手动实现具有在其上运行的适配器并与其通信的节点或服务来实现 信息总线。 节点或服务在实现时开始发信号通知操作状态。 这些信号不被网络管理控制主机识别。 网络管理控制主机发送要求新启动的节点或服务进行识别的信号。 节点或服务接收身份请求并将信号发送回网络管理控制主机。

    Method and apparatus for identifying a data communications session
    5.
    发明授权
    Method and apparatus for identifying a data communications session 失效
    用于识别数据通信会话的方法和装置

    公开(公告)号:US06742126B1

    公开(公告)日:2004-05-25

    申请号:US09414386

    申请日:1999-10-07

    IPC分类号: G06F1130

    CPC分类号: H04L63/08 H04L63/102

    摘要: A method and apparatus for using a session identifier to identify a specific data communications session between an apparatus and an external apparatus is disclosed. When a data communications session is initiated between the apparatus and an external apparatus, the external apparatus sends authenticating information to the apparatus. The apparatus uses the authenticating information to determine the identity and the privileges of the external apparatus for the particular session. A unique session identifier is created by the apparatus, and the session identifier is associated with the external apparatus's identity and privileges. The session identifier is passed between the apparatus and the external apparatus with each subsequent data communication in the session until the session is terminated. The apparatus uses the session identifier received with the data communications to identify the external apparatus and its privileges and allocate resources accordingly. The session identifier is encoded using a six bit code, thereby making it compatible with the Internet e-mail protocol and while also optimizing data compression. The encoded session identifier may be transmitted by appending it to a URL like a query string.

    摘要翻译: 公开了一种使用会话标识符来识别设备和外部设备之间的特定数据通信会话的方法和装置。 当在设备和外部设备之间启动数据通信会话时,外部设备向设备发送认证信息。 该设备使用认证信息来确定特定会话的外部设备的身份和特权。 该设备创建唯一的会话标识符,并且会话标识符与外部设备的身份和特权相关联。 会话标识符在设备和外部设备之间通过会话中的每个后续数据通信直到会话终止。 该装置使用与数据通信接收的会话标识符来识别外部设备及其特权并相应地分配资源。 会话标识符使用六位代码进行编码,从而使其与Internet电子邮件协议兼容,同时优化数据压缩。 可以通过将编码的会话标识符附加到诸如查询字符串的URL来发送。

    Selectively passing network addresses through a server
    6.
    发明授权
    Selectively passing network addresses through a server 有权
    通过服务器选择性地传递网络地址

    公开(公告)号:US07016964B1

    公开(公告)日:2006-03-21

    申请号:US09636392

    申请日:2000-08-09

    IPC分类号: G06F15/16

    摘要: A method of securely communicating a network address of a client that issues service requests to a first server that proxies the service requests for a second server. A network address of the client is received. A processor determines whether a first network address of the first server is equal to a second network address of the second server. The network address of the client is sent from the first server to the second server in a secure request message only when the first network address of the first server is equal to the second network address of the second server. Accordingly, a secure communications protocol is provided in which an address of a requesting client, e.g., an IP address, is passed in the protocol only among a responding server and its proxy, thereby preventing interception of the client IP address by unauthorized processes. By enforcing a policy that permits the network address of an originating host to pass from a first server to a second server only when the network address of the second server meets specified criteria (e.g., it is the same network address as that of the first server), the originating host address can be passed securely through a proxy server.

    摘要翻译: 一种将向服务请求发出服务请求的网络地址安全地传送给代理对第二服务器的服务请求的第一服务器的方法。 收到客户端的网络地址。 处理器确定第一服务器的第一网络地址是否等于第二服务器的第二网络地址。 仅当第一服务器的第一网络地址等于第二服务器的第二网络地址时,客户端的网络地址才会以安全请求消息从第一服务器发送到第二服务器。 因此,提供了一种安全通信协议,其中请求客户端(例如IP地址)的地址仅在响应服务器及其代理之间在协议中传递,从而防止未经授权的处理来拦截客户端IP地址。 只有当第二个服务器的网络地址满足指定的标准(例如,它与第一个服务器的网络地址相同)时,才执行允许始发主机的网络地址从第一个服务器传递到第二个服务器的策略 ),始发主机地址可以通过代理服务器安全地传递。

    Remote system administration and seamless service integration of a data communication network management system

    公开(公告)号:US06654801B2

    公开(公告)日:2003-11-25

    申请号:US09225255

    申请日:1999-01-04

    IPC分类号: G06F15173

    摘要: A method for providing remote management and maintenance of a node or service within a data communications network that is activated by the data communications network management system's receipt of signals of an abnormal condition at a node or service or failure to receive operational status signals from a node or service. A control adapter running on a node within a Point of Presence is started. The control adapter is capable of starting all service adapters associated with all services running on the node. Operational status signals and abnormal condition signals are transmitted from the control adapter and service adapters on to an information bus. If a network management control host receives abnormal condition signals, notification is sent to a remote system administrator that alerts of an error experienced by a node or service. If a network management control host fails to receive operational status signals, notification is sent to a remote system administrator that no signals are being received from a node or service. The system administrator can take appropriate remote action to rectify the problem. The integration of a manually started node or service into a data communications network management system is achieved by manually implementing, at a Point of Presence within a data communications network, a node or service that has an adapter running on it and is in communication with an information bus. The node or service begins signalling operational status upon implementation. These signals are not recognized by network management control hosts. The network management control host transmits signals asking the newly started node or service for identification. The node or service receives the identity request and transmits signals back to the network management control host.