NAT Traversal Tunnel Establishment for Private Network Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the next-generation network (NGN), network terminal devices from private networks face challenges in establishing communication and data access through firewalls installed in NAT routers, particularly for protocols like H.323, SIP, and RTP, due to private IP addresses and dynamic port allocation, which hinder media connections and data transmission.
Innovation Solution
A method is developed to detect firewall policies and establish a tunnel between network terminal devices using techniques such as p2p, local or remote relays, UPnP, STUN, and TCP tunnels, allowing devices to connect through the Internet and bypass firewalls, enabling communication and data access across private networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If NAT devices are installed at the border of private networks to translate IP addresses, then multiple network terminal devices can share one IP address and access the public network, but private IP addresses cannot be recognized on the public network and media connections fail
Solution Approach 1:
The patent introduces an intermediary mechanism (NAT traversal technology) that mediates between private IP addresses and public network requirements. This intermediary translates or relays media packets between NAT-protected devices and external networks, enabling both IP address sharing and reliable media connections to coexist.
2Object-affected harmful factors
If firewalls are deployed to control packet flow into internal networks for security, then network security is improved, but dynamic port allocation for RTP/RTCP protocols is blocked and communication tunnels cannot be established
Solution Approach 1:
The patent applies preliminary action by pre-configuring firewall rules and port forwarding policies before communication needs arise. The system proactively opens necessary ports and establishes permitted traffic patterns in advance, allowing seamless tunnel establishment while maintaining security constraints.
Solution Approach 2:
The patent implements feedback mechanisms where the system monitors communication requirements and dynamically adjusts firewall policies. When tunnel establishment is attempted, the system receives feedback about blocked connections and automatically modifies firewall rules to permit necessary traffic while maintaining security.
3Adaptability or versatility
If end devices constantly listen to external calls and transfer external calls to internal end devices, then incoming call capability is improved, but uninvited external packets are passed through firewall ports and internal device security is compromised
Solution Approach 1:
The patent applies dynamics by making firewall port states dynamic rather than static. Ports are opened temporarily only when needed for specific communication sessions, then closed afterward. This dynamic port management allows incoming calls to be received while preventing unauthorized persistent access to internal devices.
Data Source
AI summary
A method of establishing a tunnel between network terminal devices passing through firewall is applied to a network system which comprises at least two private networks and Internet wherein each of said private networks comprises at least a NAT router and at least a network terminal device (such as a computer, web camera, IP phone, network disk or network printer with network interface etc.), and each of said network terminal devices connects to the Internet through corresponding NAT router respectively. The method enables each of said network terminal devices of said private networks to detect the firewall policy of corresponding NAT router so as to pass through the firewall installed in corresponding NAT router according to its setting and establish a tunnel between said network terminal devices over the Internet for communication and data access by using p2p, a local relay or a remote relay.


