PERFORMANCE IMPROVEMENT OF IPSEC TRAFFIC USING SA-GROUPS AND MIXED-MODE SAS

    公开(公告)号:US20240364657A1

    公开(公告)日:2024-10-31

    申请号:US18765149

    申请日:2024-07-05

    申请人: VMware LLC

    发明人: Sudesh Pawar

    摘要: Some embodiments provide a method of load balancing data message flows across multiple secure connections. The method receives a data message having source and destination addresses formatted according to a first protocol. Based on the source and destination addresses, the method selects one of the multiple secure connections for the data message. Each of the secure connections handles a first set of connections formatted according to the first protocol and a second set of connections formatted according to a second protocol that is an alternative to the first protocol. The method securely encapsulates the data message and forwards the encapsulated data message onto a network. The encapsulation includes an identifier for the selected secure connection.

    AUTOMATIC CONFIGURATION OF NETWORK ADDRESS TRANSLATION FOR DEVICES HAVING AN INCOMPATIBLE NETWORK ADDRESS

    公开(公告)号:US20240333676A1

    公开(公告)日:2024-10-03

    申请号:US18193857

    申请日:2023-03-31

    摘要: A computer program product includes program instructions configured to be executable by a processor of a networking hardware device to cause the processor to perform various operations. The operations include monitoring network communications on a first port of the networking hardware device to identify a first network address of a first device attached to the first local port and determining that the first network address is incompatible with communication on an external network. The operations further include automatically configuring, in response to determining that the first network address is incompatible with communication on an external network, independent network address translation for the first local port to translate the incompatible first network address to a compatible network address for all egress traffic from the first device and to translate the compatible network address to the incompatible first network address for all ingress traffic to the first device.

    SYSTEM FOR SCALING NETWORK ADDRESS TRANSLATION (NAT) AND FIREWALL FUNCTIONS

    公开(公告)号:US20240250849A1

    公开(公告)日:2024-07-25

    申请号:US18628800

    申请日:2024-04-08

    发明人: Xiaobo Sherry Wei

    摘要: According to one embodiment, a network device may be adapted to operate within a virtual private cloud where network address translation (NAT) is performed through virtual machines and each network address translation is handled differently by a different NAT control logic unit. The network device features one or more hardware processors, and a memory that stores at least a plurality of network address translation (NAT) control logic unit and demultiplexer logic. The demultiplexer logic, when executed, receives an incoming message and, based at least in part on information within the incoming message, determines a selected NAT control logic unit to receive at least a portion of the information within the incoming message. The selected NAT control logic unit handles address translation for routing of a message based on the incoming message to a public network.

    Communication method and related device

    公开(公告)号:US12003477B2

    公开(公告)日:2024-06-04

    申请号:US17615324

    申请日:2020-06-23

    摘要: Embodiments of this application disclose a communication method and a related device. The method includes: A symmetric device listens on N local public ports, where N is a natural number greater than 1; and when the symmetric device receives a hole punching packet from the N local public ports, the symmetric device sends a response packet to a cone device based on the hole punching packet, so that the symmetric device establishes a communication connection to the cone device, where the hole punching packet is sent by the cone device, and the response packet carries a first network information mapping relationship. The cone device may directly communicate with the symmetric device, so that there is no need for a server having a data relay function, and costs of deploying the server are reduced.