METHOD FOR SECURITY GATEWAY CLUSTER OPERATION Russian patent published in 2021 - IPC H04L29/06 H04L12/66 

Abstract RU 2757297 C1

FIELD: network technologies.

SUBSTANCE: method for operation of a cluster of security gateways (SG) includes the following operations: formation of key information for the SG; allocation of two IP and MAC addresses for the SG, ranges of IP addresses tunneled by the SG, IP addresses for cluster devices, seven physical ports on the switch, a unique range of transport ports for each SG, six priority levels for the rules of the switch flow table; formation of traffic filtering rules and rules for translating IP addresses for the SG; selection of the SG as the driving SG of the cluster (DSG) and the controller; selection of a dedicated SB for processing packets with a transport protocol other than TCP/UDP; formation of a set of static rules for processing network packets for the switch; enabling all SG and loading key information for each, configuring IP and MAC addresses, ranges of tunneled IP addresses, traffic filtering rules and IP address translation; setting on all SGs, except for the DSG, the IP-address of the DSG from the service network; setting in the configuration file of the DSG the time interval of inactivity of dynamic rules for processing network packets; turning on the switch and configuring its own IP address and IP address of the DSG from the service network, registering the switch in the controller; loading into the switch flow table sets of static rules for processing network packets; putting the cluster into operation to process traffic between networks 1 and 2.

EFFECT: scalability of network functions; increasing the speed of processing network packets in the switch; and enabling secure communication of the cluster with external security gateways and protected clients.

1 cl, 1 dwg, 1 tbl

Similar patents RU2757297C1

Title Year Author Number
METHOD OF CREATING A SECURE L2-CONNECTION BETWEEN PACKET SWITCHED NETWORKS 2018
  • Guzev Oleg Yurevich
  • Chizhov Ivan Vladimirovich
RU2694585C1
METHOD OF PROCESSING A TCP PROTOCOL IN A CLUSTER OF A NETWORK COMPUTING SYSTEM 2018
  • Tychina Leonid Anatolevich
RU2694584C1
COMMUNICATION SYSTEM, COMMUNICATION EQUIPMENT AND COMMUNICATION CONTROL METHOD 2014
  • Midzukosi Yasukhiro
  • Fudzinami Makoto
  • Yamada Josiyuki
RU2637471C2
METHOD OF CONSTRUCTING DATA NETWORKS WITH HIGH LEVEL OF SECURITY FROM DDoS ATTACKS 2015
  • Krylov Vladimir Vladimirovich
  • Sokolova Eleonora Stanislavovna
  • Lyakhmanov Dmitrij Aleksandrovich
RU2576488C1
METHOD AND SYSTEM FOR TUNNELING TRAFFIC IN DISTRIBUTED NETWORK 2023
  • Mitin Arsenij Viktorovich
RU2820803C1
SOFTWARE AND HARDWARE COMPLEX FOR ENSURING SECURED DATA EXCHANGE BETWEEN TECHNICAL EQUIPMENT OF TERMINAL AUTOMATED SYSTEMS 2023
  • Vasinev Dmitrii Aleksandrovich
  • Semenov Aleksei Konstantinovich
RU2809234C1
METHOD AND SYSTEM FOR TUNNELLING TRAFFIC IN A DISTRIBUTED NETWORK TO DETONATE MALICIOUS SOFTWARE 2022
  • Mitin Arsenij Viktorovich
RU2797264C1
COASTAL FLEET COMMUNICATION UNIT 2019
  • Kashin Aleksandr Leonidovich
  • Katanovich Andrej Andreevich
  • Rimashevskij Adam Adamovich
  • Zinchenko Dmitrij Vladimirovich
  • Tsyvanyuk Vyacheslav Aleksandrovich
  • Poluyan Andrej Mikhajlovich
  • Nikolaev Valerij Viktorovich
RU2718608C1
DIRECT INTERCONNECTION GATEWAY 2018
  • Williams, Matthew Robert
RU2740035C1
NETWORK SYSTEM, METHOD, DEVICE AND PROGRAM 2013
  • Midzukosi Yasukhiro
  • Fudzinami Makoto
  • Yamada Josiyuki
RU2616169C2

RU 2 757 297 C1

Authors

Guzev Oleg Yurevich

Tychina Leonid Anatolevich

Dates

2021-10-13Published

2021-04-19Filed