A kind of SDP terminal traffic agent method, device, equipment and storage medium
A terminal and traffic technology, applied in the computer field, can solve problems such as knocking on the door amplification and the inability to manage and control the four-layer traffic, and achieve the effect of improving network security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Publication Date
- 2022-03-25
Smart Images

Figure 1 
Figure 2 
Figure 3
Abstract
Description
technical field
[0001] The present invention relates to the field of computer technology, in particular to an SDP terminal traffic proxy method, device, equipment and storage medium. Background technique
[0002] At present, SDP (Software Defined Perimeter, software-defined boundary) is one of the important technical directions of zero trust. Its main purpose is to reduce the exposure of application gateway ports. The main logic is to gradually release the client IP to the application gateway by knocking on the door. The access policy of the TCP (Transmission Control Protocol, Transmission Control Protocol) port (generally controlled by iptables), but in reality, the egress IP of the traffic of multiple terminals may be the same, which will cause the problem of port policy amplification. Moreover, for the zero-trust application gateway, it can only obtain the IP address of the last network node through which the traffic passes. For multiple terminals using the same egress IP...
Examples
Embodiment Construction
[0038] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments It is only some embodiments of the present invention, but not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without making creative efforts belong to the protection scope of the present invention.
[0039]In the existing technology, SDP gradually releases the access policy from the client IP to the TCP port of the application gateway by knocking on the door. However, in reality, the egress IP of the traffic of multiple terminals may be the same, which will cause the problem of port policy amplification. , and authentication control canno...