×

Method for mapping security associations to clients operating behind a network address translation device

  • US 7,386,881 B2
  • Filed: 01/21/2003
  • Issued: 06/10/2008
  • Est. Priority Date: 01/21/2003
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method of tracking a plurality of security protocol sessions between at least a first and second initiator and a responder, whereby the responder maintains a plurality of security associations having security parameters, one of the plurality of security associations corresponding to each of the security protocol sessions, comprising:

  • receiving a first packet from the first initiator of a first session, the first packet including first parameters comprising first source and destination IP addresses, first source and destination application ports, and a first protocol type, and creating a first mapped port;

    associating the first parameters and the first mapped port to a first security association;

    receiving a second packet from the second initiator of a second session, the second packet including second parameters comprising second source and destination IP addresses, second source and destination application ports, and a second protocol type; and

    if the first source IP address is identical to the second source IP address, the first destination IP address is identical to the second destination IP address, the first application port is identical to the second application port, the first destination port is identical to the second destination port, and the first protocol type is identical to the second protocol type, creating a second mapped port wherein the second mapped port is distinct from the first mapped port; and

    associating the second packet parameters and the second mapped port to a second security association.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×