IP Library Granted Patent US 7,631,349
Granted Patent B2
US 7,631,349 · App. 09/759,728 · Granted Dec 8, 2009

Method and apparatus for firewall traversal

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,631,349
App. No.
09/759,728
Granted
Dec 8, 2009
Kind
B2
Abstract

A method and apparatus for traversing a firewall are described.

Claims (44)

1. A method for traversing a firewall, comprising:

initiating a first connection to go through said firewall;

evaluating the first connection for a response from a remote system indicating a successful first connection;

initiating a second connection to go through said firewall if a successful first connection is not established, wherein said second connection is different then said first connection;

evaluating the second connection for a response from a remote system indicating a successful second connection;

initiating a third connection to go through said firewall if a successful second connection is not established, wherein said third connection is different than said second connection and said first connection; and

evaluating the third connection for a response from a remote system indicating a successful third connection.

2. The method of claim 1 wherein the first connection, the second connection, and the third connection is selected from the group consisting of Transmission Control Protocol (TOP) connection, User Datagram Protocol (UDP) connection, hypertext transfer protocol (HTTP) connection, hypertext transfer protocol (HTTP) connection via a proxy connection, and Internet Control Message Protocol (IOMP) connection.

3. The method according to claim 2 , wherein initiating a TOP connection comprises initiating a TOP connection to a predefined address and port.

4. The method according to claim 2 , wherein initiating a HTTP connection comprises initiating a HTTP connection to a predefined address using port 80 .

5. The method according to claim 2 , wherein Initiating a HTTP connection via a proxy connection further comprises determining a likely proxy address and port.

6. The method according to claim 5 , wherein determining a likely proxy address and port further comprises packs sniffing.

7. The method according to claim 6 , wherein packet sniffing further comprises:

sampling packets;

extracting information from the sampled packets; and

building a database of likely proxy addresses and ports.

8. The method according to claim 7 , wherein extracting information from the sampled packets comprises extracting TCP port information.

9. The method according to claim 7 , wherein extracting information from the sampled packs comprises examining TCP packets for HTTP data.

10. The method of claim 2 further comprising using Internet Protocol (IP).

11. The method according to claim 10 , wherein initiating a HTTP connection via a proxy connection further comprises determining a likely proxy address by sampling packets and extracting IP addresses.

12. The method of claim 2 further comprising using Ethernet with the Transmission Control Protocol (TCP).

13. The method according to claim 12 , wherein initiating a HTTP connection via a proxy connection further comprises determining a likely proxy address by sampling packets and extracting Ethernet addresses.

14. A machine-readable medium having stored thereon instructions, which when executed by a processor, causes saw processor to perform the following:

initiate a first connection to go through a firewall;

evaluate the first connection for a response from a remote system indicating a successful first connection;

initiate a second connection to go through said firewall if a successful first connection is not established, wherein said second connection is different than said first connection;

evaluate the second connection for a response from a remote system indicating a successful second connection;

initiate a third connection to go through said firewall if a successful second connection is not established, wherein said third connection is different than said second connection and said first connection; and

evaluate the third connection for a response from a remote system indicating a successful third connection.

15. The machine-readable medium according to claim 14 , further configuring said processor to perform the following:

implement the first connection, the second connection, and the third connection selected from the group consisting of Transmission Control Protocol (TCP) connection. User Datagram Protocol (UDP) connection, hypertext transfer protocol (HTTP) connection, hypertext transfer protocol (HTTP) proxy connection, and Internet Control Message Protocol (ICMP) connection.

16. The machine-readable medium according to claim 15 , further configuring said processor to perform the following:

examine network traffic; and

build a database of parameters likely to allow establishment of a HTTP connection via a proxy connection.

17. A method for traversing a firewall comprising:

means for initiating a first connection to go through said firewall;

means for evaluating the first connection for a response from a remote system indicating a successful first connection;

means for initiating a second connection to go through said firewall if a successful first connection is not established, wherein said second connection is different than said first connection;

means for evaluating the second connection for a response from a remote system indicating a successful second connection;

means for initiating a third connection to go through said firewall if a successful second connection is not established, wherein said third connection is different than said second connection and said first connection; and means for evaluating the third connection for a response from a remote system indicating a successful third connection.

18. The apparatus of claim 17 , wherein means for initiating the first connection, means for initiating the second connection, and mans for initiating the third connection further comprises means for initiating a connection selected from the group consisting of Transmission Control Protocol (TCP) connection, User Datagram Protocol (UDP) connection, hypertext transfer protocol (HTTP) connection, hypertext transfer protocol (HTTP) proxy connection, and Internet Control Message Protocol (IOMP) connection.

19. The apparatus of claim 18 , wherein means for initiating a HTTP connection via a proxy connection further comprises determining a likely proxy address by sniffing packets and extracting information from the packets.

20. The apparatus of claim 18 , wherein means for initiating a HTTP connection via a proxy connection further comprises determining a likely proxy address by receiving information from a computer connected to the firewall.

21. The apparatus of claim 17 , further comprising means for updating firewall traversal strategies.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Dec 8, 2023
From: BMO BANK N.A., AS ADMINISTRATIVE AGENT
To: DIGI INTERNATIONAL INC.
Reel/Frame 065835/0205 →
SECURITY INTEREST Recorded Dec 8, 2023
From: DIGI INTERNATIONAL INC.
To: BMO BANK N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 065836/0981 →
SECURITY INTEREST Recorded Dec 19, 2019
From: DIGI INTERNATIONAL INC.
To: BMO HARRIS BANK N.A.
Reel/Frame 051370/0023 →
RELEASE OF SECURITY INTEREST Recorded Mar 30, 2011
From: SILICON VALLEY BANK
To: DIGI INTERNATIONAL INC.
Reel/Frame 026049/0467 →