首页> 外国专利> A METHOD AND SYSTEM FOR AUTOMATICALLY CONFIGURING AN IPSEC-BASED VIRTUAL PRIVATE NETWORK

A METHOD AND SYSTEM FOR AUTOMATICALLY CONFIGURING AN IPSEC-BASED VIRTUAL PRIVATE NETWORK

机译:一种基于ipsec的虚拟专用网自动配置的方法和系统

摘要

A method and system for automatically configuring an IPsec-based VirtualPrivateNetwork. Each node in the Virtual Private Network is configured as an IPsecpeer node andmaintains a Security Policy Database (SPD) that includes information about thedata flowbetween each pair of networks known to the node. An advertisement packet isdistributedwhenever a node detects a new network connected to the node, a change in itsnetworkconfiguration or in the list of trusted networks known to the node. If theadvertisementconcerns a new network, then the receiving node adds the new network to itsSPD if it is notalready in the SPD. The receiving node also updates its SPD with the networkpath between thenew network and the sending node if the network path is shorter than what iscurrently in thedatabase. If the advertisement concerns a new host in a trusted networkconnected to thesending node, then the new host name is added to the list of known host namesmaintained bythe receiving node.
机译:自动配置基于IPsec的虚拟的方法和系统私人的网络。虚拟专用网络中的每个节点都配置为IPsec对等节点和维护一个安全策略数据库(SPD),其中包含有关数据流节点已知的每对网络之间。广告包是分散式每当节点检测到连接到该节点的新网络时,其节点的变化网络配置或该节点已知的受信任网络列表中。如果广告有关一个新网络,则接收节点将新网络添加到其如果不是SPD已经在SPD中。接收节点还通过网络更新其SPD之间的路径新网络和发送节点(如果网络路径短于发送路径)目前在数据库。如果广告涉及可信网络中的新主机连接到发送节点,然后将新的主机名添加到已知主机名列表中由...维护接收节点。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号