Method for operating a local computer network connected to a remote private network by an IPsec tunnel, software module and IPsec gateway
First Claim
1. A method for operating a local network and a remote network, a local terminal of the local network being connected to a gateway of the remote network by a tunnel established in blocking mode, the method comprising:
- using the gateway, receiving a flow emitted from the local terminal and routed to the gateway through the tunnel, wherein the flow has a destination address equal to an internal address of local equipment located in the local network; and
when the received flow is not intended for the remote network;
using the gateway, sending the received flow to a router of the local network for the router to re-route the received flow to the internal address of the local equipment,the gateway identifying the router using information obtained during the establishment of the tunnel.
9 Assignments
0 Petitions
Accused Products
Abstract
The invention relates to a method in particular enabling the computer terminal (T_L) of a local network (RES_L), connected to a gateway (PASS_D) of a remote network (RES_D) by an IPsec tunnel in blocking mode, to launch a print job on a printer (E_L) belonging to the local network. To do this, the gateway (PASS_D) stores the correspondence between the public address (AD_1) of the local router (ROUT_L) providing the connection of the terminal to the Internet, and the private address (ad_3) assigned to the terminal (T_L) in the addressing plan of the remote network (RES_D) during the establishment of the tunnel, and sends the print flow to the local router (ROUT_L), which directs it to the local printer (E_L) by a port translation technique.
13 Citations
16 Claims
-
1. A method for operating a local network and a remote network, a local terminal of the local network being connected to a gateway of the remote network by a tunnel established in blocking mode, the method comprising:
-
using the gateway, receiving a flow emitted from the local terminal and routed to the gateway through the tunnel, wherein the flow has a destination address equal to an internal address of local equipment located in the local network; and when the received flow is not intended for the remote network; using the gateway, sending the received flow to a router of the local network for the router to re-route the received flow to the internal address of the local equipment, the gateway identifying the router using information obtained during the establishment of the tunnel. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13)
-
-
14. A method of operating a gateway located between a first network and a wide area network, the method comprising:
-
maintaining a table that maps local addresses of the first network to routable addresses of the wide area network; establishing a blocking tunnel with a terminal located in a second network, wherein the terminal communicates with the gateway via a router located between the second network and the wide area network, and wherein the establishing includes; assigning the terminal a first address within the first network; receiving a packet from the terminal via the blocking tunnel where a routable address of the router was stored in a source address field of the packet by the router; and creating an entry in the table that maps the assigned first address to the routable address of the router; receiving packets from the wide area network; identifying received packets that were sent by the terminal through the blocking tunnel and that have a destination address field equal to an internal address of local equipment within the second network; and forwarding the identified packets to the routable address of the router over the wide area network, wherein the routable address of the router is obtained from the table using the assigned first address of the terminal, and wherein the router forwards the identified packets to the internal address of the local equipment via the second network. - View Dependent Claims (15, 16)
-
Specification