首页> 外国专利> METHODS, SYSTEMS, AND COMPUTER READABLE MEDIA FOR MAINTAINING FLOW AFFINITY TO INTERNET PROTOCOL SECURITY (IPSEC) SESSIONS IN A LOAD-SHARING SECURITY GATEWAY

METHODS, SYSTEMS, AND COMPUTER READABLE MEDIA FOR MAINTAINING FLOW AFFINITY TO INTERNET PROTOCOL SECURITY (IPSEC) SESSIONS IN A LOAD-SHARING SECURITY GATEWAY

机译:在负载分担安全网关中维护流对Internet协议安全(IPSEC)会话的适应性的方法,系统和计算机可读介质

摘要

Methods, systems, and computer readable media for maintaining flow affinity to IPSec sessions in a load-sharing security gateway are disclosed. According to one embodiment, the method includes receiving packets at a security gateway that provides communications of packet flows between source and destination entities using IPSec sessions. For each packet, it is determined whether the packet is assigned to an existing packet flow between a source and a destination entity that is being processed by the SG. In response to determining that the packet belongs to an existing flow, the packet is forwarded to a processing element associated with that flow and IPSec processing is performed at the processing element. In response to determining that the packet does not belong to an existing flow, a new flow is defined and assigned to a next available processing element. IPSec processing is performed for the flow at the next available processing element.
机译:公开了用于在负载共享安全网关中维持与IPSec会话的流亲和性的方法,系统和计算机可读介质。根据一个实施例,该方法包括在安全网关处接收分组,该安全网关使用IPSec会话提供源实体与目的地实体之间的分组流的通信。对于每个分组,确定该分组是否被分配给SG正在处理的源实体和目的地实体之间的现有分组流。响应于确定该分组属于现有流,将该分组转发到与该流相关联的处理元件,并且在该处理元件处执行IPSec处理。响应于确定该分组不属于现有流,定义了新流并将其分配给下一可用处理元件。在下一个可用处理元素处对流执行IPSec处理。

著录项

  • 公开/公告号US2010268935A1

    专利类型

  • 公开/公告日2010-10-21

    原文格式PDF

  • 申请/专利权人 RICHARD RODGERS;JAMES CERVANTES;

    申请/专利号US20090467242

  • 发明设计人 RICHARD RODGERS;JAMES CERVANTES;

    申请日2009-05-15

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 18:56:12

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号