发明名称 |
Detecting network topology when negotiating IPsec security associations that involve network address translation |
摘要 |
The invention determines if a security association (SA) extends end-to-end between a source node originating a connection and a destination node. In such a case, there will be no ambiguities in routing due to network address translation, and the SA is allowed. In the preferred embodiment, both end nodes of a security connection test themselves and the remote node for gateway status to determine if any ambiguities might exist in network routing due to the presence of a network address translator.
|
申请公布号 |
US7962652(B2) |
申请公布日期 |
2011.06.14 |
申请号 |
US20060307598 |
申请日期 |
2006.02.14 |
申请人 |
INTERNATIONAL BUSINESS MACHINES CORPORATION |
发明人 |
JONG WUCHIEH JAMES;OVERBY, JR. LINWOOD HUGH;PORTER JOYCE ANNE;WIERBOWSKI DAVID JOHN |
分类号 |
H06F0015/000016 |
主分类号 |
H06F0015/000016 |
代理机构 |
|
代理人 |
|
主权项 |
|
地址 |
|