EP1317112B1

Handling connections moving between firewalls

Abstract

This record has no abstract on file.

EP1317112B1, drawing sheet 1
Sheet 1 of 5

Term

Term ended

Expired 26 November 2022, 3.8 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

16 claims: 9 independent, 7 dependent

  1. 1
    A method of handling mobile entities for use in a firewall, characterized in maintaining (400) a first mobile entity table comprising identifiers of mobile entities (201,234,300) which are active in the firewall (204, 205, 236, 239, 240, 305, 321), maintaining (402) a second mobile entity table comprising identifiers of mobile entities (201,234,300) which are active in a predefined set of other firewalls and identifiers of corresponding other firewalls (204, 205, 238, 239, 240, 305, 321), detecting (404) a new mobile entity, which is not currently active in the firewall (204, 205, 236, 239, 240, 305, 321), finding (406) on the basis of the second mobile entity table, if the new mobile entity (201,234,300) is currently active in another firewall (204, 205, 236, 239, 240, 305, 321), and if the mobile entity is currently active in another firewall, querying (408), from the another firewall, state information related to the new mobile entity (201,234,300), and storing (410) the state information in the firewall to be used for processing data packets from/to the new mobile entity.
  2. 3
    A method according to any one of preceding claims, further characterized in sending (502) the first mobile entity table to a predefined set of other firewalls as a response to a predefined action.
  3. 7
    A method according to any one of preceding claims, further characterized in receiving (600) from at least one other firewall a mobile entity table comprising identifiers of mobile entities which are active in the at least one other firewall, updating (602) the second mobile entity table on the basis of the received mobile entity table, and deleting (606) an entry in the first mobile entity table, if a corre-sponding entry is contained in the received mobile entity table.
  4. 8
    A method according to any one of preceding claims, characterized in that detecting a new mobile entity comprises detecting (414) a data packet in which the source is the new mobile entity (201,234,300).
  5. 10
    A method according to any one of preceding claims, charac- terized in that the identifier is an IP address or a subscriber number.
  6. 11
    A method according to any one of preceding claims, characterized in that the state information related to the new mobile entity (201,234,300) comprises state of the ongoing connections of the new mobile entity.
  7. 13
    A firewall (204, 205, 236, 239, 240, 305, 321) characterized in comprising memory and mechanism for maintaining (400) a first mobile entity table comprising identifiers of mobile entities which are active in the firewall (204, 205, 236, 239, 240, 305, 321), memory and mechanism maintaining (402) a second mobile entity table comprising identifiers of mobile entities (201,234,300) which are active in a predefined set of other firewalls and identifiers of corresponding other firewalls (204, 205, 236, 239, 240, 305, 321), mechanism for detecting (404) a new mobile entity, which is not currently active in the firewall (204, 205, 236, 239, 240, 305, 321). mechanism for finding (408) on the basis of the second mobile entity table, if the new mobile entity (201,234,300) is currently active in another firewall (204, 205, 236, 239, 240, 305, 321), and mechanism for querying (408), from the another firewall, state information related to the new mobile entity, and mechanism and memory for storing (410) the state information in the firewall (204, 205, 236, 239, 240, 305, 321) to be used for processing data packets from/to the new mobile entity (201,234,300), if the mobile entity is currently active in another firewall.
  8. 15
    A computer-readable medium storing instructions that when executed by a computer cause the computer to perform each of the method steps of any of claims 1 to 12.
  9. 16
    A computer program comprising program code means for performing all the steps of any of claims 1 to 12 when the program is run on a computer.