Abstract:
A source endpoint includes a security association database; a processing device and an interface operatively coupled to: receive (306) a first packet requiring security processing; retrieve (308) from the first packet a destination endpoint data address for a destination endpoint that is to receive the first packet; determine (318) an address translation; apply (320) the address translation to the retrieved destination endpoint data address to generate a destination endpoint security address, and create (322) an entry in a storage device, wherein the entry corresponds only to the destination endpoint and comprises the generated destination endpoint security address and a set of security parameters. The source endpoint further indexes (324) the storage device to obtain the security parameters for security processing of the first packet to generate (326) a secured first packet; and sends (328) the secured first packet to the destination endpoint.
Abstract:
The present invention relates to methods and apparatuses for providing network access, wherein a connection to a core network is established via a wireless access device (20) and a gateway device (42). Connectivity of the wireless access device (20) is restricted to a pre-defined group of core network address of a pool of gateway devices (42) with multi-node connectivity to the core network, and a single address is selected to establish the connection to a one of the gateway de¬ vices (42). The gateway device (42) is provided with a relay function for mapping a single input address to a plurality of core network addresses based on a location information of the wireless access device (10) and with at least one co-located decentralized core network functionality.
Abstract:
Disclosed is a device, system and method for detecting a Network Address Transalation ("NAT") gateway on a network According to some embodiments of the present invention a detector including a network communication module (Fig 2, 10)may transmit one or more interrogation packets to a suspected NAT gateway.
Abstract:
A system and method for providing security for a network connecting a source and a destination. The system and method provide a security and management system between the source and the destination which is configured to apply rules and policies which are specific to the user to the connection between the source and the destination. The user- specific policies are used to govern.
Abstract:
The invention discloses a Home Virtual Private Network server (250), a Home VPN server, for use in a communications operator network (120), which network (120) can communicate with a subscriber network (130), and in which operator network a first protocol on a first level is used. The subscriber network (130) can accommodate at least one subscriber with one subscriber device (131-135) and a communications device (140) which can connect the subscriber to the operator network (120). The Home VPN server (250) comprises functions for: translating IP-addresses and port numbers of IP-packets which are sent between the operator network and the subscriber network, assigning individual IP-addresses to devices in the subscriber network, routing IP-traffic from the operator network to devices in the subscriber network, to which functions the subscriber can connect via said communications device (140) in order to utilize his network (130) as a Home VPN.
Abstract:
Erläutert wird unter anderem ein Verfahren, bei dem aufgrund eines in weiterzuleitenden Datenpaketen enthaltenen Gerätekennzeichens die von oder zu einer Datenverarbeitungsanlage (22) übertragene Datenmenge erfasst wird. Durch Prüfen der erfassten Datenmenge unter Verwendung einer vorgegebenen Datenmenge lässt sich eine zur Verfügung stehende Datenmenge in einem lokalen Datenübertragungsnetz (20) aufteilen.
Abstract:
Simultaneous transmission and reception of voice, data and video to and from an end - point of a IP network is facilitated by the use of HTTP (hypertext transfer protocol). A first end - point forms two HTTP connections with a HTTP tunneling server. A second end - point of the same network forms also two HTTP connections with the same tunneling server. Videoconferencing protocols, notably SIP and H.323 are tunneled though the HTTP connections to form a full - duplex connection unhindered by firewalls, NAT and PAT processes or by HTTP proxies.
Abstract:
Apparatus and methods are provided for a Network Address Translation (NAT)- aware unified cache. According to one embodiment, multiple packet-processing applications distributed among one or more processors of a network device share one or more unified caches without requiring a cache synchronization protocol. When a packet is received at the network device, a first packet-processing application, such as NAT or another application that modifies part of the packet header upon which a cache lookup key is based, tags the packet with a cache lookup key based upon the original contents of the packet header. Then, other packet-processing applications attempting to access the cache entry from the unified cache subsequent to the tagging by the first packet-processing application use the tag (the cache lookup key generated by the first packet-processing application) rather than determining the cache lookup key based upon the current contents of the packet header.