The invention determines if a security association (SA) extends end-to-end between a source node originating a connection and a destination node. In such a case, there will be no ambiguities in routing due to network address translation, and the SA is allowed. In the preferred embodiment, both end nodes of a security connection test themselves and the remote node for gateway status to determine if any ambiguities might exist in network routing due to the presence of a network address translator.
Internet Protocol Security (Ipsec) Packet Processing For Multiple Clients Sharing A Single Network Address
Joyce A. Porter - Apex NC, US David J. Wierbowski - Owego NY, US
Assignee:
International Business Machines Corporation - Armonk NY
International Classification:
G06F 15/16
US Classification:
709232, 709225
Abstract:
Embodiments of the present invention address deficiencies of the art in respect to secure communications for multiple hosts in an address translation environment and provide a method, system and computer program product for IPsec SA management for multiple clients sharing a single network address. In one embodiment, a computer implemented method for IPsec SA management for multiple hosts sharing a single network address can include receiving a packet for IPsec processing for a specified client among the multiple clients sharing the single network address. A dynamic SA can be located among multiple dynamic SAs for the specified client using client identifying information exclusive of a 5-tuple produced for the dynamic SA. Finally, IPsec processing can be performed for the packet.
Preventing Duplicate Sources From Clients Served By A Network Address Port Translator
Patricia Jakubik - Raleigh NC, US Linwood Overby - Raleigh NC, US Joyce Porter - Apex NC, US David Wierbowski - Owego NY, US
Assignee:
INTERNATIONAL BUSINESS MACHINES CORPORATION - Armonk NY
International Classification:
H04L 12/56 H04L 12/28
US Classification:
370389000, 370431000
Abstract:
Preventing duplicate sources on a protocol connection that uses network addresses, protocols and port numbers to identify connections that include port number translation. In response to an inbound IPsec packet from a remote source client, a determination is made as to whether or not a port number is available within a range of port numbers that comply with a security association governing the connection. If so, an available port number is assigned to the connection, thereby avoiding a possibility of a duplicate source. If a port number is not available, the packet is rejected.
Preventing Duplicate Sources From Clients Served By A Network Address Port Translator
Patricia Jakubik - Raleigh NC, US Linwood Overby Jr. - Raleigh NC, US Joyce Porter - Apex NC, US David Wierbowski - Owego NY, US
Assignee:
INTERNATIONAL BUSINESS MACHINES CORPORATION - Armonk NY
International Classification:
H04J 3/22 H04L 12/56 H04J 3/16 H04L 12/28
US Classification:
370466000
Abstract:
Preventing duplicate sources on a protocol connection that uses network addresses, protocols and port numbers to identify source applications that are served by a NAPT. If an arriving packet encapsulates an encrypted packet and has passed through an NAPT en route to the destination host, the encapsulated packet is decrypted to obtain an original source port number and original packet protocol from the decrypted packet. A source port mapping table (SPMT) is searched for an association between the NAPT source address, the original source port, and the original packet protocol associated with the NAPT source address and port number. If an incorrect association is found, the packet is rejected as representing an illegal duplicate source; that is, a second packet from a different host served by a NAPT that is USING the same SOURCE port and protocol.
Internet Protocol Security (Ipsec) Packet Processing For Multiple Clients Sharing A Single Network Address
Joyce A. Porter - Apex NC, US David J. Wierbowski - Owego NY, US
Assignee:
International Business Machines Corporation - Armonk NY
International Classification:
H04L 29/06
US Classification:
713154
Abstract:
Embodiments of the present invention address deficiencies of the art in respect to secure communications for multiple hosts in an address translation environment and provide a method, system and computer program product for IPsec SA management for multiple clients sharing a single network address. In one embodiment, a computer implemented method for IPsec SA management for multiple hosts sharing a single network address can include receiving a packet for IPsec processing for a specified client among the multiple clients sharing the single network address. A dynamic SA can be located among multiple dynamic SAs for the specified client using client identifying information exclusive of a 5-tuple produced for the dynamic SA. Finally, IPsec processing can be performed for the packet.
- Armonk NY, US Christopher Meyer - Cary NC, US John R. Moore - Raleigh NC, US Joyce A. Porter - Apex NC, US
International Classification:
H04L 12/911 G06F 17/30 H04L 29/08
Abstract:
Aspects of the present invention disclose a method, computer program product, and system for determining a number of allowed lists and initiating a change in a number of lists. The method includes receiving a defined list count of a plurality of lists of a coupling facility structure, monitoring list usage by the coupling facility structure, determining that additional lists are required by the coupling facility structure above the defined list count, based on the monitored list usage. The method includes, in response to determining that additional lists are required by the coupling facility structure, determining a new number of lists, where the new number of lists are based on an availability of space for the new number of lists on the coupling facility structure and the new number of lists exceeds the defined list count. The method includes rebuilding coupling facility structure based upon the determined new number of lists.
Preventing Duplicate Sources From Clients Served By A Network Address Port Translator
- Armonk NY, US Joyce Anne Porter - Apex NC, US David John Wierbowski - Owego NY, US
Assignee:
International Business Machines Corporation - Armonk NY
International Classification:
H04L 29/12
US Classification:
709245
Abstract:
Preventing duplicate sources on a protocol connection that uses network addresses, protocols and port numbers to identify connections that include port number translation. In response to an inbound IPsec packet from a remote source client, a determination is made as to whether or not a port number is available within a range of port numbers that comply with a security association governing the connection. If so, an available port number is assigned to the connection, thereby avoiding a possibility of a duplicate source. If a port number is not available, the packet is rejected.
Kansas City MOPast: Work Form Home at Ameriplans IBO Business Owners Hello Friends & Family
My Name is Joyce Porter
Independent Business Marketing
Thank you for your visit...
Welcome Joyce
Thanks for your interest in A... Hello Friends & Family
My Name is Joyce Porter
Independent Business Marketing
Thank you for your visit...
Welcome Joyce
Thanks for your interest in A PERFECT SCENARIO.
PLEASE CLICK ON THIS LINK TO VERIFY YOUR EMAIL ADDRESS AND
RECEIVE YOUR COMPLETELY NO COST AUTO-RESPONDER!
Joyce Porter...
Kansas City, MOSkinny Body Care (via http://marketingstraus.biz)
Thank You
I Like This how Cool
Invite: You can invite any prospects to a Webinar or Conference call so they... Skinny Body Care (via http://marketingstraus.biz)
Thank You
I Like This how Cool
Invite: You can invite any prospects to a Webinar or Conference call so they know we are a real team and are working together to help everyone achieve their "3 to be Free" goal. This is The Conference call Daily...
Oak Park, ILBoard of Directors at Oak Park Festival Theatre I am an actress based in Chicago but also working in L.A. and Florida.
I am a Professor Emeritus of film and a lectureer on the arts.
Youtube
Mastering Senior Life: Thriving and Surviving...
Here's a description of a new book that will give practical advice to ...
Duration:
4m 50s
Joyce Porter Commercial Reel 2021
Scenes from several commercials I've been in, both comic and dramatic.
Duration:
1m 10s
S5#451 Actress Joyce Porter Better Call Saul ...
(KeithAndrewNetW... Today on the (KeithAndrewNetW... We have gotten ...
Duration:
24m 36s
Joyce Porter in My Haunted House
My scene from The Lifetime Movie Channel's series "My Haunted House". ...
Duration:
1m 11s
Joyce Porter Better Call Saul
I had a co-star role in Episode 503 of Better Call Saul.
Duration:
1m 44s
Joyce Porter 2020 Dramatic Reel
Scenes from TV and movies, including Better Call Saul. Characters incl...