VPN Gateway Packet Filtering for Secure Data Center Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In communication systems, when a wide area network is interposed between a data center and a wireless LAN, existing technologies face challenges in providing secure connections and controlling access, especially for terminals connecting to the Internet, as they may not be able to sufficiently enforce parental controls or restrict access to harmful content.
Innovation Solution
A communication system is implemented with a first gateway connecting to the terminal via a VPN through the wide area network and wireless LAN, a second gateway connected to another wide area network, and a virtual network between the gateways, including a function block for filtering packets from both wide area networks, ensuring secure communication and content control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a terminal connects to a data center via a wireless LAN and wide area network without a VPN, then network access is simple and direct, but security is compromised and parental control cannot be enforced
Solution Approach 1:
A VPN gateway is introduced as an intermediary between the terminal and the data center. The gateway establishes a VPN tunnel that routes all traffic through a controlled path, enabling security policies and parental controls to be enforced without requiring changes to the terminal or data center infrastructure. This mediator approach resolves the contradiction by adding security functionality without fundamentally redesigning the entire network architecture.
Solution Approach 2:
The network connection is segmented into distinct functional components: the wireless LAN access, the wide area network transport, and the VPN gateway layer. This segmentation allows security controls to be applied at the VPN gateway layer independently, without affecting the simplicity of wireless LAN access or requiring modifications to the core data center infrastructure.
2Ease of operation
If parental control and access restriction are implemented without a VPN gateway, then the network structure remains simple, but control over incoming calls and data is insufficient
Solution Approach 1:
Security policies, parental controls, and access restrictions are configured in advance at the VPN gateway before any traffic flows through the network. The gateway pre-establishes filtering rules for incoming calls and data based on user profiles and parental settings, automatically enforcing these controls without requiring real-time intervention or complex runtime decision-making in the network path.
3Object-affected harmful factors
If no filtering function is provided in the data center, then network configuration is simple, but harmful content and unauthorized access cannot be blocked
Solution Approach 1:
The VPN gateway serves as a mediator that implements filtering functionality between the terminal and the data center. It inspects and filters incoming calls and data packets based on pre-configured security policies, blocking harmful content and unauthorized access without requiring the data center itself to implement complex filtering infrastructure.
Solution Approach 2:
The VPN gateway automatically enforces security policies and parental controls based on pre-configured rules, making filtering decisions autonomously without requiring manual intervention or complex configuration at each network node. The system self-manages the filtering function through automated policy application.
Data Source
AI summary
A data center comprises a first gateway that connects with a terminal using a VPN (Virtual Private Network) through a wireless LAN and a first wide area network, a second gateway that connects to a second wide area network (WAN2), a virtual network connected to the first gateway and the second gateway; and a function block that is provided between the first gateway and the second gateway and that performs filtering of at least one of a packet input from the first wide area network side and a packet input from the second wide area network.


