Unlock instant, AI-driven research and patent intelligence for your innovation.

Method and device for accessing isolated host in local area network

A technology of isolation zone and local area network, applied in wide area network, data exchange network, data exchange through path configuration, etc., can solve the problems of hosts mapped to the DMZ area, unable to improve the utilization efficiency of IP addresses on the WAN side, and inconvenient DMZ hosts. , to achieve the effect of improving utilization efficiency, convenient access, and improved security

Active Publication Date: 2016-02-10
ZTE CORP
View PDF3 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0002] At present, in some SOHO office broadband access scenarios, in addition to basic Internet access services, multiple devices in the SOHO office area need to be opened for WAN (wide area network, wide area network) access, and the current situation for the IPv4 protocol stack , when dialing through the WAN side, the CPE (Customer Premise Equipment) usually can only obtain an IP address on the WAN side, and when the WAN side accesses the DMZ (demilitarized zone, isolated area) host on the LAN side through the CPE, the IP address obtained by the CPE The IP address can only be mapped to one DMZ host; and, since the CPEWAN side itself will provide some external services, some ports on the CPEWAN side need to be reserved, so all ports on the CPEWAN side cannot be mapped to the DMZ area Therefore, the utilization efficiency of the IP address on the WAN side cannot be improved, and it is inconvenient for the WAN side to access the DMZ host on the LAN side.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method and device for accessing isolated host in local area network
  • Method and device for accessing isolated host in local area network
  • Method and device for accessing isolated host in local area network

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0037] It should be understood that the specific embodiments described here are only used to explain the present invention, not to limit the present invention.

[0038] The present invention provides a method for accessing hosts in isolated areas in LANs. Multiple public network IP addresses are obtained from the WAN side through client terminal equipment CPE, and the mapping between public network IP addresses and private network IP addresses of DMZ hosts on the LAN side is configured. Relationship, when the client on the WAN side accesses the DMZ host on the LAN side through the CPE, the public network IP address is mapped to the corresponding DMZ host to facilitate the access of the client on the WAN side.

[0039] refer to figure 1 , figure 1 It is a schematic flowchart of an embodiment of a method for accessing hosts in a demilitarized area in a local area network according to the present invention.

[0040] The method for accessing hosts in isolated areas in the local ...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a method for accessing a host in an isolated area in a local area network, comprising: configuring a mapping relationship between a public network IP address acquired from the WAN side and a private IP address of an isolated area host on the LAN side; After the access request sent by the client on the LAN side, according to the configured mapping relationship, modify the destination IP address in the access request to the private network IP address of the host in the corresponding isolated area on the LAN side, and send the modified access request to the isolated area. Zone host; receive the reply message returned by the isolated zone host, modify the source IP address contained in it to the public network IP address of the client on the WAN side, and send the modified reply message to the WAN side. The invention also discloses a corresponding device. By adopting the solution disclosed by the invention, while improving the security of the DMZ host, the utilization efficiency of the IP address on the wide area network side is improved, and greater convenience is provided for the access on the wide area network side.

Description

technical field [0001] The invention relates to the technical field of broadband network, in particular to a method and system for accessing hosts in isolated areas in local area networks. Background technique [0002] At present, in some SOHO office broadband access scenarios, in addition to basic Internet access services, multiple devices in the SOHO office area need to be opened for WAN (wide area network, wide area network) access, and the current situation for the IPv4 protocol stack , when dialing through the WAN side, the CPE (Customer Premise Equipment) usually can only obtain an IP address on the WAN side, and when the WAN side accesses the DMZ (demilitarized zone, isolated area) host on the LAN side through the CPE, the IP address obtained by the CPE The IP address can only be mapped to one DMZ host; and, because the CPEWAN side itself will provide some external services, some ports on the CPEWAN side need to be reserved, so it is impossible to map all the ports on...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L29/06H04L29/12H04L12/28H04L45/741
CPCH04L63/0209H04L12/2869H04L61/2514H04L12/2856H04L2101/668
Inventor 毕明达
Owner ZTE CORP