发明名称 System and method for distributed multi-processing security gateway
摘要 A system and method for a distributed multi-processing security gateway establishes a host side session, selects a proxy network address for a server based on network information, and using the proxy network address to establish a server side session. The proxy network address is selected such that a same processing element is assigned to process data packets from the server side session and the host side session. The network information includes a security gateway network address and a host network address. By assigning processing elements in this manner, higher capable security gateways are provided.
申请公布号 US9032502(B1) 申请公布日期 2015.05.12
申请号 US201314044673 申请日期 2013.10.02
申请人 A10 Networks, Inc. 发明人 Chen Lee;Szeto Ronald Wai Lun
分类号 G06F21/00;H04L29/08;H04L29/06 主分类号 G06F21/00
代理机构 Carr & Ferrell LLP 代理人 Carr & Ferrell LLP
主权项 1. A method for providing a network gateway, comprising: receiving by the network gateway a session request for a session between a host and a server, the session request comprising a host network address and a server network address; establishing by the network gateway a host side session between the network gateway and the host, the network gateway comprising a plurality of processors; selecting by the network gateway a proxy network address for the host based on network information, the network information comprising the host network address and a network gateway network address, wherein the proxy network address is selected such that a calculated first processor identity by the network gateway is the same as a calculated second processor identity by the network gateway; establishing by the network gateway a server side session between the network gateway and the server using the selected proxy network address; in response to receiving a first data packet from the host side session, calculating by the network gateway the first processor identity, comprising: assigning a first processor with the first processor identity to process the first data packet,modifying the first data packet by substituting the host network address in the first data packet with the selected proxy network address, andsending the modified first data packet to the server side session; and in response to receiving a second data packet from the server side session, calculating by the network gateway the second processor identity, comprising: assigning a second processor with the second processor identity to process the second data packet.
地址 San Jose CA US