Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

13 results about "Virtual firewall" patented technology

A virtual firewall (VF) is a network firewall service or appliance running entirely within a virtualized environment and which provides the usual packet filtering and monitoring provided via a physical network firewall. The VF can be realized as a traditional software firewall on a guest virtual machine already running, a purpose-built virtual security appliance designed with virtual network security in mind, a virtual switch with additional security capabilities, or a managed kernel process running within the host hypervisor.

Method and apparatus for implementing service chain pseudo-proxy

ActiveCN120263464BIntelligent NetworkVirtual firewall
The application provides a method and device for implementing a service chain pseudo-proxy. The method comprises providing a corresponding relationship between a pseudo-proxy segment identifier (SID) and a virtual firewall IP address on an intelligent network card, the intelligent network card being located on a server carrying a virtual firewall; receiving an SRv6 packet from a service chain interface; identifying that the SID list of the received SRv6 packet contains a pseudo-proxy SID to generate a flow table item; wherein the matching item is the packet characteristic information of the outer MAC header of the SRv6 packet; the action item is the SRH header of the cached SRv6 packet; based on the SID list of the SRv6 packet containing the pseudo-proxy SID, the IP address of the virtual firewall is found; the SRH header of the SRv6 packet is stripped and cached, and the SRv6 packet is sent to the virtual firewall.
Owner:NEW H3C TECH CO LTD

A network deployment method, device, server and medium

ActiveCN119052091BSecuring communicationNetwork deploymentVirtual firewall
The application provides a network deployment method, device, server and medium, and relates to the field of communication.The network deployment method comprises the following steps: obtaining a first service and a second service; calling a virtual infrastructure manager (VIM) and a software defined network (SDN) controller to create a first virtual router and a second virtual router; calling a security controller to create a virtual firewall in the case that the first service and the second service have security interaction requirements; calling the VIM, the SDN controller and the security controller to establish a first logical link and a second logical link; the first logical link is a logical link interconnecting the first virtual router and the virtual firewall, and the second logical link is a logical link interconnecting the second virtual router and the virtual firewall.In the embodiment of the application, the virtual routers of different services share the virtual firewall, so that the vFW resource occupation can be effectively reduced, and the network deployment cost is reduced.
Owner:CHINA MOBILE COMM LTD RES INST +1

Route selection method and system under VPC network model based on Openstack and SDN technology

The invention discloses a route selection method and system under a VPC network model based on Openstack and SDN technologies, and the method comprises the steps: creating a plurality of line public networks, and inputting an external access line of a corresponding external network by an SDN controller; creating a VPC network and a subnet of the VPC network, and issuing VPC network configuration by the SDN controller; a VPC network is used to create a virtual machine, and the SDN controller issues a virtual port configuration of the virtual machine to the serverleaf switch; creating a virtual firewall and binding a VPC network, and issuing firewall configuration to the virtual firewall by the SDN controller; a public network exit is added in a virtual router under a VPC network, a default gateway is set, and an SDN controller issues virtual port configuration of multiple exits of the router to a virtual firewall; and the virtual machine dynamically selects to access the extranet in an extranet direct connection mode or a firewall passing mode. According to the invention, the routing path can be dynamically adjusted according to the network condition, the service requirement and the security policy, the network performance is optimized, and the network security is ensured.
Owner:CHINA TELECOM DIGITAL INTELLIGENCE TECH CO LTD

Virtual firewall for use in a private mobile core

Aspects of the subject disclosure may include, for example, a method that includes deploying a first virtual machine configured to implement a plurality of control plane network functions in a wireless network, deploying a second virtual machine configured to implement a user plane function in the wireless network, deploying a third virtual machine configured to implement firewall functions, and deploying the first virtual machine, the second virtual machine and the third virtual machine on an on-premises host server. Other embodiments are disclosed.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Method and system for multi-AZ management of multiple public network exit default gateways based on OpenStack and SDN technology

PendingCN120567669ATransmissionVirtual firewallInternet traffic
The invention discloses a multi-AZ management multi-public network exit default gateway method and system based on OpenStack and SDN technology, and the method comprises the steps: creating a plurality of line public networks in each available region, and inputting an external access line of a corresponding external network in the corresponding available region by an SDN controller; creating a VPC network and creating a sub-network with multiple available areas; creating a virtual machine with multiple available areas by using a VPC network; creating a virtual firewall and binding a VPC network; a public network gateway with multiple available areas is started in a router under the VPC network, and a default gateway is selected for each available area; and the virtual machine accesses the external networks of all the public network gateways opened in the available area. According to the invention, continuity and high availability of the network flow can be provided, and the problem of network interruption caused by a single-point fault is avoided.
Owner:CHINA TELECOM DIGITAL INTELLIGENCE TECH CO LTD

Dynamic routing interface configuration method and device, and electronic equipment

The application provides a dynamic routing docking configuration method and device and electronic equipment, the method is applied to a cloud management platform, the method comprises the following steps: creating a virtual router (vRouter) by calling a virtual infrastructure manager (VIM) and a software defined network (SDN) controller, and creating a virtual firewall (vFW) by calling a security controller; creating an interconnection logical link and a dynamic routing neighbor between the vRouter and the vFW by calling the VIM, the SDN controller and the security controller, realizing the configuration of dynamic routing docking between the vRouter and the vFW, so that the vRouter and the vFW can be dynamically routed and docked, the demand for dynamic routing docking between the vRouter and the vFW can be met, the method can be applied to a scene requiring dynamic routing docking, the applicable range is expanded, and the scene applicability is improved.
Owner:CHINA MOBILE COMM LTD RES INST +1

Virtual firewall for use in a private mobile core

ActiveUS12487847B2Dot-and-dash transmission apparatusConnection managementVirtual firewallEngineering
Aspects of the subject disclosure may include, for example, a method that includes deploying a first virtual machine configured to implement a plurality of control plane network functions in a wireless network, deploying a second virtual machine configured to implement a user plane function in the wireless network, deploying a third virtual machine configured to implement firewall functions, and deploying the first virtual machine, the second virtual machine and the third virtual machine on an on-premises host server. Other embodiments are disclosed.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Security protection method and cloud platform

The application provides a security protection method and a cloud platform, the method is applied to the cloud platform, the cloud platform comprises a spine switch, a first leaf switch and a second leaf switch; the first leaf switch is connected with a plurality of virtual switches, the virtual switches are connected with a plurality of tenant virtual machines, and the second leaf switch is connected with a plurality of hardware firewalls; the method comprises the following steps: when the virtual switch receives network traffic, a target second leaf switch is determined, the network traffic is sent to the hardware firewall through the first leaf switch connected with the virtual switch, the spine switch and the target second leaf switch, the network traffic is subjected to security detection through the hardware firewall, and if the traffic is abnormal traffic, the traffic is intercepted. According to the method of the application, the traffic can be guided to the hardware firewall for security detection, each tenant can share the hardware firewall to realize security protection, a virtual firewall does not need to be deployed by the tenant, the security protection cost can be reduced, and the resource utilization rate is improved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Method and equipment for realizing service chain pseudo proxy

ActiveCN120263464ASecuring communicationIntelligent NetworkVirtual firewall
The invention provides a method and equipment for realizing a service chain pseudo agent. The method comprises the following steps: setting a corresponding relationship between a pseudo agent segment identifier SID and a virtual firewall IP address on an intelligent network card, wherein the virtual network card is located in a server bearing the virtual firewall; receiving the SRv6 message from the service link interface; identifying that the SID list of the received SRv6 message contains a pseudo agent SID to generate a flow table item; wherein the matching item is message feature information of an outer MAC head of the SRv6 message; the action item is an SRH head of the encapsulated and cached SRv6 message; the IP address of the virtual firewall is searched based on the fact that the SID list of the SRv6 message contains a pseudo agent SID; and the SRH head of the SRv6 message is stripped and cached, and the SRv6 message is sent to the virtual firewall.
Owner:NEW H3C TECH CO LTD

Industrial control network architecture and control method

PendingCN121842220ASecuring communicationVirtual firewallNetwork control
The invention relates to an industrial control network architecture, and belongs to the technical field of vehicle manufacturing. Comprising a foreground network, a background network, a physical firewall and an SDN controller. Wherein the foreground network comprises an access layer and a convergence layer, and the access layer is connected with the service terminal through a port and is connected with the convergence layer through a TRUNK link; the convergence layer is provided with a distributed gateway and is used for receiving the service data of the TRUNK link from the access layer, performing packaging processing according to a VLAN identifier, mapping the VLAN identifier of the service data into a VXLAN identifier and forwarding the service data to a background network; and the SDN controller is in communication connection with a convergence layer of the background network and the foreground network, and is used for generating a virtual firewall based on the physical firewall, and performing access limitation and flow filtering on service data between the foreground network and the background network through the virtual firewall so as to perform isolation protection on the service data. According to the invention, the security, flexibility and expandability of the industrial control network can be improved.
Owner:SAIC GM WULING AUTOMOBILE CO LTD

Virtual firewall construction method based on openstack framework

ActiveUS12432179B2Securing communicationData packVirtual firewall
A virtual firewall construction method based on an OpenStack framework, and a storage medium. The method includes: modifying a firewall rule of a target data packet service according to a preset rule, and obtaining a modified target data packet service, the modified target data packet service utilizes the modified firewall rule to perform data packet control, and a forwarding stack is provided in the modified target data packet service, a forwarding performance of the forwarding stack is higher than the forwarding performance of a routing service of the OpenStack framework; a firewall configuration interface is provided in the firewall rule of the modified target data packet service, and the firewall configuration interface is configured to, according to different users under different virtual networks, set a data packet processing rule meeting requirements of the users; and replacing the routing service of the OpenStack framework according to the modified target packet service.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Electromagnetic shielding device based on physical isolation

ActiveCN223978964UMagnetic/electric field screeningMicrocontrollerVirtual firewall
The utility model provides an electromagnetic shielding device based on physical isolation, which comprises a shielding box, a first shielding net is arranged on the outer side surface of the shielding box, a plurality of supporting legs are arranged at the bottom of the shielding box, a lifting platform is arranged in the shielding box, and the lifting platform comprises transmission assemblies symmetrically arranged on the front side and the rear side of the inner side wall of the shielding box. A placing table is movably arranged between the two transmission assemblies, an opening part communicated with the lifting platform is formed in the top of the shielding box, a movable groove is formed in the side wall of the opening part from the rear side to the front side, a winding assembly is arranged on the side, close to the opening part, of the rear side of the shielding box, and the winding assembly moves in the movable groove. A microcontroller is arranged on the inner side wall of the shielding box, the microcontroller is electrically connected with the transmission assembly and the winding assembly, the microcontroller is connected with the upper control unit through a wire, and the problem that existing network security depends on a virtual firewall and cannot cope with the continuously iterative hacker technology is solved.
Owner:WUHAN LUOLUN ELECTRONIC TECHNOLOGY CO LTD

NAT (Network Address Translation) mapping-based NB (Node B) gateway non-inductive migration method and device

The invention belongs to the field of network security, and provides an NAT (Network Address Translation) mapping-based NB gateway non-inductive migration method and an NAT mapping-based NB gateway non-inductive migration device. The method comprises the following steps of: starting an updated charging attribute CC value on a PGW side, and performing mapping processing on a special APN (Access Point Name) for NB (Narrow Band) service to obtain a virtual APN and a VPN (Virtual Private Network) instance; the method comprises the following steps: creating a private network address pool VPN channel on a CE side, deploying a virtual firewall corresponding to the private network address pool VPN channel on an NAT side, and performing destination address translation on an NB gateway solidified address through the virtual firewall to obtain an NAT mapping relation; an updated IPv4 address pool is started on the PGW side and is allocated to the virtual APN, and private network deployment is performed by adopting a public network address field to obtain a global unique terminal address resource; a backhaul route is configured on the CE side, and a reverse control message issued by the platform is guided to the corresponding virtual firewall; and deploying a static reverse mapping rule in the virtual firewall based on the NAT mapping relationship to obtain a bidirectional conversion channel. The migration stability can be ensured on the premise that the terminal does not need to be transformed.
Owner:E SURFING IOT CO LTD