Proxy Server Remote Management Without Agents
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for managing computer systems from a remote location are inefficient due to the need for agent installation and firewall reconfiguration, which incur significant costs and labor, and compromise security by allowing inbound connections.
Innovation Solution
A method utilizing a Proxy Server outside the private network to initiate remote management sessions without agent installation or firewall reconfiguration, using an Onsite Manager to prompt the Proxy Server for connections, allowing only outbound connections through the firewall, and bridging the session between the computer system and remote computer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If agent-based methods are used for remote management, then remote access capability is achieved, but deployment cost and complexity increase due to agent installation on all computer systems
Solution Approach 1:
The patent extracts the remote management functionality from the individual computer systems (agents) and consolidates it into a centralized management station. The management station communicates directly with the target computer system without requiring agents to be installed on intermediate devices, thereby eliminating deployment complexity while maintaining remote access capability.
Solution Approach 2:
The patent introduces a management station as an intermediary component that facilitates remote management. This station handles all communication and control operations between the remote administrator and the computer system, eliminating the need for agents to be installed on every computer system while maintaining full remote access functionality.
2Ease of operation
If firewalls are reconfigured to allow inbound connections for remote management, then remote access is enabled, but security is compromised by allowing external connections into the private network
Solution Approach 1:
Instead of configuring the firewall to allow inbound connections from external networks (traditional approach), the patent inverts the approach by having the management station initiate outbound connections to the computer system through the firewall. This reverses the connection direction, allowing remote management while maintaining firewall security rules that only permit outbound traffic.
Solution Approach 2:
The patent converts the firewall's restrictive security policy (which blocks inbound connections) into a benefit by using it to control the direction of communication. The firewall's default deny policy is leveraged to ensure that only authorized outbound connections from the management station are permitted, thereby maintaining security while enabling remote management functionality.
3Productivity
If traditional remote management methods are used, then management functionality is achieved, but time consumption increases due to agent installation and firewall reconfiguration requirements
Solution Approach 1:
The management station is pre-configured with the necessary communication protocols and firewall penetration capabilities before deployment. This preliminary preparation eliminates the need for time-consuming on-site agent installation and firewall reconfiguration during the actual deployment, significantly reducing the overall deployment time while maintaining full management functionality.
Data Source
AI summary
A method for managing the computer systems of a private network from a remote physical location in a manner that does not require the installation of agents on the computer systems of the private network, or the reconfiguration of the firewall of the private network to permit access into the private network.


