摘要:
Distribution processing control unit determines a main processing range and a sub-processing range whose charges are taken by a cluster member to which the unit belongs. Among packets multicast to a cluster system, a filter hands over packets matching with the main processing range and the sub-processing range to a session processing unit. The session processing unit conducts session processing (including processing of updating session information stored in a holding unit). Thereafter, when the packet matches with the main processing range, the session processing unit hands the packet over to a packet forwarding unit and when the packet matches with the sub-processing range, abandons the packet. When a cluster member in charge of main processing of a packet whose sub-processing is taken charge of by the cluster member in question develops a failure, a failure recovery unit changes the sub-processing range to the main processing range.
摘要:
Distribution processing control unit determines a main processing range and a sub-processing range whose charges are taken by a cluster member to which the unit belongs. Among packets multicast to a cluster system, a filter hands over packets matching with the main processing range and the sub-processing range to a session processing unit. The session processing unit conducts session processing (including processing of updating session information stored in a holding unit). Thereafter, when the packet matches with the main processing range, the session processing unit hands the packet over to a packet forwarding unit and when the packet matches with the sub-processing range, abandons the packet. When a cluster member in charge of main processing of a packet whose sub-processing is taken charge of by the cluster member in question develops a failure, a failure recovery unit changes the sub-processing range to the main processing range.
摘要:
Load balancing manager assigns to each cluster member a filter rule so as to divide traffic processing by a predetermined rule. According to the assigned rule, each cluster member obtains a packet multicast by a neighbor node, on a data link with the neighbor node. Each cluster member detects a session of the obtained packet to perform predetermined processing such as recording and updating of a state and application of a firewall packet filter.
摘要:
Each of cluster members (1-1) constituting a cluster system which functions as a router includes a session processor (15) and session state synchronization unit (16). If the session state of a session to which a packet input via a spare processing packet filter (13) belongs is not held in a session state holding unit (18), the session processor (15) newly registers the session state. When receiving a transfer rejection notification containing a session identifier of an unauthorized packet from a paired current cluster member, the session state synchronization unit (16) deletes a session state represented by the session identifier from the session state holding unit. If a cluster member which performs spare processing in a certain partial range has failed, the session state of this cluster member can be restored on a new cluster member added instead of the faulty cluster member, without largely increasing the communication cost.
摘要:
Load balancing manager assigns to each cluster member a filter rule so as to divide traffic processing by a predetermined rule. According to the assigned rule, each cluster member obtains a packet multicast by an neighbor node on a data link with the neighbor node. Each cluster member detects a session of the obtained packet to perform predetermined processing such as recording and updating of a state and application of a firewall packet filter.
摘要:
A protocol process to a reception traffic is executed by cluster members of a current use system and a backup system. The backup system discards the reception traffic subjected to the protocol process and only the current use system transfers the reception traffic to an AP. The AP makes an application process redundant in an independent method. The cluster member in charge of the protocol process to the reception traffic is determined by using a data in a lower layer and the cluster member in charge of the application process is determined by using a data in a higher layer after the protocol process.
摘要:
A protocol process to a reception traffic is executed by cluster members of a current use system and a backup system. The backup system discards the reception traffic subjected to the protocol process and only the current use system transfers the reception traffic to an AP. The AP makes an application process redundant in an independent method. The cluster member in charge of the protocol process to the reception traffic is determined by using a data in a lower layer and the cluster member in charge of the application process is determined by using a data in a higher layer after the protocol process.
摘要:
In order to more efficiently use port resources, which are finite global address resources assigned to an address translation device, the address translation device holds a session-port assignment table showing a correspondence between an existing session and a local endpoint (port resource) in the address translation device, and a port assignment rule indicating port usage about assignable ports. An address translation unit translates address information of a packet received according to the correspondence between the existing session and the port resource shown in the session-port assignment table, and assigns the port according to the port usage indicated by the port assignment rule for a packet for opening a new session. An assignment rule update unit changes a ratio of the port usage in the port assignment rule while the correspondence between the existing session and the port resource in the session-port assignment table is not changed.
摘要:
From a time point of last confirmation of operation of the working device 51 until a time point of next confirmation, the standby device 52 receives the same packet as that whose transfer processing is executed by the working device from the interface units 521-1˜521-n, processes the packet by the transfer unit 522 and holds the processed packet in the accumulation units 525-1˜525-n. The device monitors an operation state of the working device 51 by an advertisement transmitted by the working device 51 and upon reception of the advertisement, responsively abandons the packet held in the accumulation units 525-1˜525-n. When determining that the working device 51 stops by non-arrival of an advertisement for a predetermined time period, the device sends out the packet held in the accumulation units 525-1˜525-n and switches processing so as to itself operate as a working device.
摘要:
From a time point of last confirmation of operation of the working device 51 until a time point of next confirmation, the standby device 52 receives the same packet as that whose transfer processing is executed by the working device from the interface units 521-1˜521-n, processes the packet by the transfer unit 522 and holds the processed packet in the accumulation units 525-1˜525-n. The device monitors an operation state of the working device 51 by an advertisement transmitted by the working device 51 and upon reception of the advertisement, responsively abandons the packet held in the accumulation units 525-1˜525-n. When determining that the working device 51 stops by non-arrival of an advertisement for a predetermined time period, the device sends out the packet held in the accumulation units 525-1˜525-n and switches processing so as to itself operate as a working device.