发明名称 Remote access manager for virtual computing services
摘要 A remote access manager in a virtual computing services environment negotiates a time limited NAT routing rule to establish a connection between a remote device and virtual desktop resource providing user computing services. A series of NAT connection rules are revised in a dynamic manner such that a pool of ports is available to connect a plurality of remote users to local virtual compute resources over one or more public IP addresses. Once a connection is established, an entry is made in a firewall state table such that the firewall state table allows uninterrupted use of the established connection. After an entry has been made in the state table, or the routing rule has timed out, the port associated with the original NAT routing rule is removed and the same port can be re-used to establish another connection without disrupting active connections.
申请公布号 US9237147(B2) 申请公布日期 2016.01.12
申请号 US201514623228 申请日期 2015.02.16
申请人 VMware, Inc. 发明人 Snow James;Hobgood Andrew W.;Battersby Clinton B.
分类号 H04L29/06;H04N21/414;H04N21/4143;H04L29/08 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method of network port reuse for establishing network connections between local hosts and remote user devices comprising: receiving, at a gateway node, an indication of authentication of a user for receipt of computing services, the user having a user device address; sending, to the user device, a port identifier generated for establishing a virtual computing session with the user; establishing, in an address mapping table at the gateway node, a rule responsive to the port identifier and user device address, the rule indicative of a compute session for providing computing services to the user; receiving, at the gateway node, the connection request from the user, the connection request including the port identifier and emanating from the user device address; establishing a connection between the user device address and an address indicative of the compute session; generating an entry in a firewall state table, the firewall state table for controlling access to the gateway node, the generated entry defining an allowed connection between the user device address and the address of the compute session, the firewall state table having a higher routing precedence than the address mapping table; removing the established rule from the address mapping table, the removed rule preventing access via the user address and sent port number, the port number remaining available for successive connection requests; maintaining the generated entry for permitting successive communications between the user device address and the compute session; and at least one of the method steps is implemented by a hardware processor.
地址 Palo Alto CA US