首页> 外国专利> Secure IPsec tunnels with a background system accessible via a gateway implementing NAT

Secure IPsec tunnels with a background system accessible via a gateway implementing NAT

机译:具有可通过实现NAT的网关访问的后台系统的安全IPsec隧道

摘要

A method and system for enabling secure IPsec tunnels within NAT without compromising security. A local network is configured with a gateway machine connected to the Internet and having an IPsec ID for interfacing with the Internet and a local IP/interface address for interfacing with the local network. Client machines are connected to the gateway machine and communicate with the Internet via the gateway and network address translation (NAT) techniques. Each client machine is configured with a local IP/interface address. The client machines are also provided with an alias of the IPsec ID for the gateway machine. When an IPsec request is received by the gateway machine to establish a tunnel (secure communication) with one of the clients, the gateway machine forwards the packet to the particular client using NAT. The client machine receives the request and since it has an alias of the gateway's IPsec ID, the client machine will confirm that it has one of the IPsec IDs in the packet. The client machine sends the reply packet back to the gateway machine, which then forwards it to the requesting machine over the Internet. The requesting machine receives the packet and a confirmation that it has reached its intended recipient and opens the secure IKE tunnel with the particular client via the gateway machine. In this manner authentication of the IKE tunnel and establishment of a secure IPsec session is completed with a client machine that is accessible only via a gateway implementing NAT.
机译:在不损害安全性的情况下在NAT中启用安全IPsec隧道的方法和系统。局域网配置有网关计算机,该网关计算机连接到Internet,并具有用于与Internet接口的IPsec ID和用于与本地网络接口的本地IP /接口地址。客户端计算机连接到网关计算机,并通过网关和网络地址转换(NAT)技术与Internet通信。每台客户端计算机都配置有本地IP /接口地址。客户端计算机还为网关计算机提供了IPsec ID的别名。当网关机器接收到与客户端之一建立隧道(安全通信)的IPsec请求时,网关机器将使用NAT将数据包转发到特定客户端。客户端计算机接收到该请求,并且由于它具有网关IPsec ID的别名,因此客户端计算机将确认其在数据包中具有IPsec ID之一。客户端计算机将答复数据包发送回网关计算机,然后网关计算机通过Internet将其转发到请求计算机。请求机器接收到该数据包,并确认它已到达其预期的接收者,并通过网关计算机与特定客户端打开安全IKE隧道。以这种方式,使用仅可通过实现NAT的网关访问的客户端计算机完成IKE隧道的身份验证和安全IPsec会话的建立。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号