METHOD AND ARRANGEMENT FOR PROVIDING SECURITY THROUGH NETWORK ADDRESS TRANSLATIONS USING TUNNELING AND COMPENSATIONS
1 Assignment
0 Petitions
Accused Products
Abstract
This invention provides a method for providing network security services, such as those provided by the IPSEC protocol, through network address translation (NAT). The method is based on determining the transformations that occur on a packet and compensating for the transformations. Because only TCP and UDP protocols work through NATs, the IPSEC AH/ESP packets are encapsulated into UDP packets for transport. Special operations are performed to allow reliable communications in such environments.
70 Citations
26 Claims
-
1-23. -23. (canceled)
-
24. An apparatus comprising at least one processor, and at least one memory including computer program code, the at least one memory and the computer program code being configured to, with the at least one processor, cause the apparatus to
receive a packet comprising a an encoding of a source port number; - and
determine whether a network address translation occurred on the packet by comparing the source port number against a predetermined port number.
- and
-
25. A method comprising:
-
receiving, by a computer device, a packet comprising an encoding of a source port number; and determining whether a network address translation occurred on the packet by comparing the source port number against a predetermined port number.
-
-
26. A non-transitory computer readable media for revealing occurrence of network address translations, comprising program code for causing a processor to perform instructions for
receiving a packet comprising an encoding of a source port number; - and
determining whether a network address translation occurred on the packet by comparing the source port number against a predetermined port number.
- and
Specification