Network Manager for NAT Device Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network managers face challenges in managing network devices behind Network Address Translation (NAT) devices due to the lack of effective methods that do not compromise security functions, particularly in industrial environments where multiple machines use the same IP address range.

Innovation Solution

A centralized network management system is implemented using a network switch's MAC address table, ARP table, and a unique switch identifier to manage devices behind the NAT device, enabling secure communication through encrypted XMPP to maintain control and monitoring without requiring port address translation, allowing for real-time management and discovery of devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If Network Address Translation (NAT) is used to conserve global address space, then IP address exhaustion is mitigated, but network management of devices behind NAT becomes difficult

Engineering Contradiction:
Improveglobal address spaceVSAvoidnetwork management
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The patent introduces a network manager as an intermediary system that operates within the private network behind the NAT device. This network manager maintains a mapping table that correlates private IP addresses with their corresponding public IP addresses and port numbers, enabling centralized management of devices behind NAT without requiring changes to the NAT infrastructure or compromising security functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If Port Address Translation (PAT) is implemented to enable network management behind NAT, then device accessibility is improved, but security functions are compromised

Engineering Contradiction:
Improvedevice accessibilityVSAvoidsecurity functions
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the network management function from the NAT device itself by deploying a dedicated network manager within the private network. This segmentation allows management operations to be performed on devices behind NAT through the network manager's knowledge of address mappings, eliminating the need for PAT security holes while maintaining both security and accessibility.

Inventive Principle:
Principle #1Segmentation

3Quantity of substance

If multiple machines use the same IP address range behind different NAT devices, then address space utilization is optimized, but device identification and management becomes complex

Engineering Contradiction:
Improveaddress space utilizationVSAvoiddevice identification
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The network manager acts as an intermediary that maintains a comprehensive mapping table storing the relationship between private IP addresses, public IP addresses, and port numbers for each device behind NAT. This centralized mapping information allows the network manager to uniquely identify and manage devices even when multiple private networks use the same IP address ranges, eliminating the complexity of device identification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9692723B2Network management of devices residing behind a network device
Publication Date: 2017.06.27 CISCO TECHNOLOGY INC
  • US9692723B2 patent drawing
  • US9692723B2 patent drawing
  • US9692723B2 patent drawing

AI summary

Network device management may be provided. By utilizing a network ID tag (i.e., a switch identifier) corresponding to a network switch, a network management platform on a server may access network devices that exist behind the network switch. The network switch may comprise a network address translation (NAT) device. The network devices may comprise an industrial network comprising groups of machines that exist as islands behind their own respective network switches where each group of machines may utilize the same internet protocol (IP) addresses as other group of machines in the industrial network.