Claims
- 1. In a computer networking environment having a plurality of firewall nodes on a path between a first terminal and a host terminal, where the firewall nodes delineate one network segment from another network segment, a method of establishing a communication link comprising the steps of:
- providing a plurality of virtual hosts on each of the plurality of firewall nodes;
- forming forward and reverse DNS tables for each of said plurality of firewall nodes wherein the DNS entries correspond to addresses of the virtual hosts on a given network segment and the virtual hosts correspond to actual hosts;
- in response to the first terminal's DNS query to determine the address of the host, providing the address of the virtual host assigned to handle requests for the host terminal;
- transmitting a connection request using the address of the virtual host;
- at the virtual host assigned to handle requests for the host, and subsequently, at each successive virtual host located on firewall nodes on the path:
- receiving a connection request;
- obtaining a host name using reverse DNS, the host name corresponding to the requested address;
- obtaining an address for use on the next network segment using DNS corresponding to the host name;
- requesting a connection using the address for the next network segment;
- receiving a connection request at the host and responding to the request; and,
- transmitting the response in the reverse direction traversing the same path from virtual host to virtual host until the response reaches the first terminal.
- 2. The method of claim 1 wherein the virtual hosts of a given firewall node resides on more than one physical machine.
- 3. The method of claim 2 wherein the DNS service is dynamically updated depending upon the load associated with the physical machines.
- 4. The method of claim 1 wherein the virtual hosts perform channel processing.
- 5. The method of claim 1 wherein each virtual host has a set of configuration parameters.
- 6. The method of claim 1 wherein one of the virtual hosts on each firewall node is a configuration host allowing for the configuration of the firewall node.
Parent Case Info
This is a continuation of patent application Ser. No. 08/733,361, filed Oct. 17, 1996, now U.S. Pat. No. 5,898,830, issued on Apr. 27, 1999, entitled, "Firewall Providing Enhanced Network Security And User Transparency", invented by Wesinger, Jr. et al.
US Referenced Citations (10)
Continuations (1)
|
Number |
Date |
Country |
Parent |
733361 |
Oct 1996 |
|