Intermediary Device Network Profile IP Address Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data communication networks lack a systematic method to dynamically specify and manage internet protocol addresses for intermediary devices when establishing connections with servers, which can lead to security issues and inefficient traffic management.
Innovation Solution
The implementation of network profiles that allow intermediary devices to select and use specific internet protocol addresses from a pool of subnet IP addresses and mapped IP addresses for connections, enabling dynamic IP address selection based on network profiles bound to load balancing, content switching, or monitoring services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the intermediary device uses its own IP address as the source IP for backend connections, then the device can establish connections with servers, but the server cannot distinguish between regular traffic and monitor probes, reducing security and traffic management efficiency
Solution Approach 1:
The patent segments the IP address pool into different categories (SNIPs and MIPs) and further divides them into multiple IP sets. Each IP set is assigned for specific purposes (e.g., one set for regular traffic, another for monitor probes). This segmentation allows the server to distinguish between different types of traffic based on the source IP address, resolving the contradiction between establishing connections and maintaining security/traffic management efficiency.
Solution Approach 2:
The patent assigns different qualities or characteristics to different IP addresses within the pool. Specifically, certain IP addresses are designated with the quality of being suitable for monitor probes, while others are designated for regular client traffic. This local quality differentiation enables the server to identify and handle monitor probes separately from regular traffic, improving both security and traffic management without compromising connection establishment.
2Ease of operation
If the intermediary device uses a single IP address for all backend connections, then the configuration is simple, but the device cannot efficiently manage internal connections or distribute traffic to specific services
Solution Approach 1:
The patent implements a dynamic IP address selection mechanism where the intermediary device automatically selects the appropriate IP address from the pool based on the specific service and connection requirements. Instead of using a static single IP address, the system dynamically chooses from multiple IP sets, allowing efficient internal connection management and service-specific traffic distribution while maintaining ease of operation through automated selection.
Solution Approach 2:
The IP address pool serves multiple functions simultaneously: it provides source IP addresses for regular client traffic, for monitor probes, and for different services. By making the IP address pool universal and multi-functional, the system can efficiently manage diverse internal connections without requiring separate configurations for each function, thus maintaining ease of operation while improving productivity.
3Reliability
If the intermediary device dynamically selects IP addresses from a pool, then the device can improve traffic management and security, but the device complexity increases due to the need to manage IP pools and profiles
Solution Approach 1:
The patent employs preliminary action by pre-configuring the IP address pool and organizing IP addresses into named sets with specific purposes defined in advance. Network profiles are created beforehand that associate specific IP sets with particular services or functions. This preliminary organization reduces the complexity of dynamic selection during operation, as the device only needs to retrieve and use pre-defined configurations rather than making complex decisions in real-time, thus maintaining security and traffic management capabilities while reducing operational complexity.
4Reliability
If the server is configured to respond only to requests from specific IP addresses, then server security is improved, but the intermediary device needs a systematic method to manage and specify which IP addresses to use
Solution Approach 1:
The system performs preliminary action by pre-defining network profiles that specify which IP sets should be used for different services and scenarios. These profiles are configured in advance and associate specific IP address sets with particular services, monitors, or traffic types. This preliminary specification eliminates the need for complex real-time decision-making about IP address selection, allowing the intermediary device to simply retrieve the appropriate pre-configured IP set from the profile, thus maintaining server security while simplifying IP address management.
Solution Approach 2:
The network profile acts as an intermediary between the server's security requirements and the IP address pool. The profile translates the security requirement (server responds only to specific IPs) into a manageable configuration that the intermediary device can easily implement. By introducing this intermediary layer of abstraction, the system maintains strict security controls while reducing the complexity of IP address specification management.
Data Source
AI summary
The present solution is directed to a system for specifying a source internet protocol (IP) address used by an intermediary device for a connection to a server. The system includes a device intermediary to a plurality of clients and a server. The device may have a net profile for sending traffic to servers. The net profile specifies one or more internet protocol (IP) addresses to use as a source IP address for a connection between the device and the server. The device receives a request from a client of the plurality of clients via a first transport layer connection between the client and the device, identifies the net profile for the request, and establishes, responsive to the request, a second transport layer connection between the device and the server using an IP address.


