发明名称 FIREWALL INTERFACE CONFIGURATION TO ENABLE BI-DIRECTIONAL VOIP TRAVERSAL COMMUNICATIONS
摘要 Methods and systems for an intelligent network protection gateway (NPG) and network architecture are provided. According to one embodiment, a firewall provides network-layer protection to hosts of a private network against unauthorized access by hosts of an external network by performing network address translation (NAT) processing of Internet Protocol (IP) addresses. The firewall also provides application-layer protection on behalf of the hosts and supports Voice over IP (VoIP) services by processing signaling protocols associated with VoIP sessions. An external VoIP interface of the firewall receives incoming VoIP packets each associated with a VoIP port of the external interface. The packets are directed to an appropriate host by the firewall performing port address forwarding based on a mapping of VoIP ports to private addresses of the hosts.
申请公布号 US2017063803(A1) 申请公布日期 2017.03.02
申请号 US201615334971 申请日期 2016.10.26
申请人 Fortinet, Inc. 发明人 Xie Michael
分类号 H04L29/06;H04L29/12 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method comprising: providing, by a firewall interposed between a private network and an external network, network-layer protection against unauthorized access by external hosts associated with the external network to a plurality of hosts associated with the private network by performing network address translation (NAT) processing of Internet Protocol (IP) addresses associated with the plurality of hosts; providing, by the firewall, application-layer protection from the external network on behalf of the plurality of hosts and supporting Voice over IP (VoIP) services by processing signaling protocols associated with VoIP sessions, including distinguishing among VoIP packets and non-VoIP packets,parsing the VoIP packets, andenabling bi-directional VoIP communications among one or more of the plurality of hosts and one or more of the external hosts by performing content-aware NAT, including changing data in headers of the VoIP packets and also changing data contents in the VoIP packets corresponding to the data changed in the headers; receiving, by an external VoIP interface of the firewall, a plurality of incoming VoIP packets each being associated with one of a plurality of VoIP ports; causing each of the plurality of incoming VoIP packets to be directed to an appropriate host of the plurality of hosts by performing by the firewall port address forwarding based on a mapping of the plurality of VoIP ports to corresponding private addresses of the plurality of hosts.
地址 Sunnyvale CA US