Proxy Server Traversal Through NAT and Firewall
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current NGN systems face challenges in traversing audio and video services through Network Address Translation (NAT) and Firewall (FW) devices due to address and port mapping issues, which hinder the integration of voice, data, and video services, especially in enterprise networks, and require modifications or updates to existing NAT/FW devices.
Innovation Solution
A method and system utilizing a proxy server to analyze and modify signaling and media stream addresses and ports in real-time, allowing traversal through NAT/FWs without reconstructing existing devices, supporting multi-layer and symmetric NATs, and providing QoS control and encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional NAT/FW devices are used for address translation and security filtering, then network security and IP address conservation are improved, but multimedia service traversal capability deteriorates
Solution Approach 1:
The patent introduces a proxy server as an intermediary component between the NAT/FW device and the multimedia service. The proxy server intercepts signaling messages, analyzes their content, and modifies address information in the message load to match the address translation performed by NAT/FW. This intermediary approach allows traditional NAT/FW devices to maintain their security functions while enabling multimedia services to traverse successfully through coordinated address modification.
2Reliability
If firewall filtering principles are strictly enforced for security, then network security is improved, but dynamic port assignment for multimedia communications is blocked
Solution Approach 1:
The patent implements preliminary action by having the proxy server pre-analyze signaling messages and pre-modify address information in the message load before the actual multimedia communication occurs. The proxy server extracts address information from signaling protocols like H.323, SIP, or MGCP, and proactively updates the message load with correct translated addresses, ensuring that when multimedia data flows through the firewall, the addresses already match the filtered ranges, thus avoiding security conflicts.
3Quantity of substance
If NAT translates internal IP addresses to public IP addresses, then IP address conservation is improved, but multimedia stream transmission fails due to address mismatch
Solution Approach 1:
The patent uses the proxy server as an intermediary that coordinates between NAT address translation and multimedia stream transmission. When NAT translates internal IP addresses to public IP addresses, the proxy server intercepts signaling messages, extracts the translated address information, and modifies the message load to contain matching addresses. This ensures that multimedia streams use consistent address information throughout the translation process, maintaining transmission reliability while preserving IP address conservation benefits.
4Adaptability or versatility
If existing NAT/FW devices are modified to support multimedia traversal, then service traversal capability is improved, but device complexity and update requirements increase
Solution Approach 1:
The patent extracts the complex multimedia traversal functionality from the existing NAT/FW devices and places it in a separate proxy server component. Instead of modifying and complicating the NAT/FW device firmware or software, the solution removes the traversal logic into an independent proxy server that handles signaling message analysis and address modification. This keeps the original NAT/FW devices simple and unchanged while adding traversal capability through the external proxy server.
Data Source
AI summary
The present invention discloses a method for implementing traversal through network address translation. The method adopts a FULL PROXY mode for implementing traversal through Network Address Translation (NAT) server or Firewall (FW) by simultaneously relaying call signalings and media streams from a user terminal in a private network. Meanwhile, a system for implementing traversal through network address translation is disclosed. In accordance with this invention, no reconstruction of existing NAT/FWs and user terminals are needed for implementing traversal in any networking architecture while issues of Quality of Service (QoS), security, and aged mapping list of NAT can be solved.


