IP Library Granted Patent US 7,406,709
Granted Patent B2
US 7,406,709 · App. 10/657,813 · Granted Jul 29, 2008

Apparatus and method for allowing peer-to-peer network traffic across enterprise firewalls

Assignee: Audiocodes, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,406,709
App. No.
10/657,813
Granted
Jul 29, 2008
Kind
B2
Abstract

A system and method for allowing bidirectional network traffic to pass through a network address translation (“NAT”)/firewall device thereby allowing bidirectional traffic to flow between the private side of the NAT/firewall device and the public side of the NAT/firewall device while maintaining security between the public side and the private side is described. A network processing system on the public side of the NAT/firewall device anchors network traffic to and from the private side of the NAT/firewall device. A traversal client resides on the private side of the NAT/firewall device and has a secure connection with the network processing system. The traversal client is operable to pass signaling packets bound for a terminal on the private side of the NAT/firewall from the network processing system. The traversal client is also operable to send test packets through the NAT/firewall to create the allocations in the NAT/firewall to allow the bidirectional traffic to pass from the public side to the private side.

Claims (20)

1. A system for traversing a network address translation/firewall device, having a public side and a private side, with network traffic, the network traffic passing between a device on the private side and a device on the public side; the system comprising:

a network processing system on the public side of the network address translation/firewall device, the network processing system operable to anchor network traffic to and from the private side of the network address translation/firewall device; and

a traversal client on the private side of the network address translation/firewall device having a secure connection with the network processing system, wherein the traversal client is operable to pass packets through the network address translation/firewall device in order to create allocations in the network address translation/firewall device to allow the network traffic to pass between the private side device and the public side device, and wherein the traversal client does not reside in the path of the traffic between the private side device and the public side device.

2. The system of claim 1 wherein the anchoring by the network processing system is accomplished by substituting the address associated with the private side device with an address assigned to the network processing system.

3. The system of claim 1 wherein the packets sent by the traversal client through the network address translation/firewall to create allocations in the network address translation/firewall device are formed in the network processing system and sent to the traversal client over the secure connection.

4. The system of claim 1 wherein the network traffic is a voice-over-Internet Protocol session.

5. The system of claim 4 wherein the voice-over-Internet Protocol session uses SIP messaging.

6. The system of claim 4 wherein the voice-over-Internet-Protocol session includes signaling traffic separate from the bearer traffic, and wherein the signaling traffic from the public side device is transmitted to the private side device using the traversal client and the secure connection.

7. The system of claim 4 wherein the private side device must register with a registrar on the public side of the network address translation/firewall device in order to receive voice-over-Internet-Protocol calls.

8. A method for traversing a network address translation/firewall device, having a public side and a private side, with bidirectional network traffic, the bidirectional network traffic passing between a device on the private side and a device on the public side; the system comprising:

receiving packets at a network processing system, the network processing system on the public side of the network address translation/firewall device;

passing control information bound for the private side device through a traversal client, the traversal client having a secure connection with the network processing system;

creating allocations in the network address translation/firewall device to allow the bidirectional network traffic through the network address translation/firewall device, the allocations created by sending a test packet from the traversal client to the network processing system through the network address translation/firewall device, wherein the traversal client does not reside in the path of the traffic between the private side device and the public side device.

9. The method of claim 8 further comprising the step of anchoring the network traffic to and from the private side of the network address translation/firewall device using the network processing system.

10. The method of claim 9 wherein the step of anchoring is accomplished by substituting the address associated with the private side device with an address assigned to the network processing system.

11. The method of claim 8 wherein the test packet sent by the traversal client through the network address translation/firewall to create allocations in the network address translation/firewall device are formed in the network processing system and sent to the traversal client over the secure connection.

12. The method of claim 8 wherein the traffic is a voice-over-Internet Protocol session.

13. The method of claim 12 wherein the voice-over-Internet Protocol session uses SIP messaging.

14. The method of claim 13 wherein the voice-over-Internet-Protocol session includes signaling traffic separate from the bearer traffic, and wherein the signaling traffic from the public side device is transmitted to the private side device using the traversal client and the secure connection.

15. The method of claim 12 wherein the private side device must register with a registrar on the public side of the network address translation/firewall device in order to receive voice-over-Internet-Protocol calls.

Assignments (3)
MERGER Recorded Jun 25, 2008
From: AUDIOCODES TEXAS, INC.
To: AUDIOCODES, INC.
Reel/Frame 021150/0154 →
CHANGE OF NAME Recorded Apr 19, 2007
From: NETRAKE CORPORATION
To: AUDIOCODES TEXAS, INC.
Reel/Frame 019182/0120 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2003
From: MAHER III., ROBERT DANIEL; RANA, ASWINKUMAR VISHANJI; LIE, MILTON ANDRE; DEERMAN, JAMES ROBERT
To: NETRAKE CORPORATION
Reel/Frame 014479/0409 →
Continuity (2)
Provisional Application 6040939100 · Sep 9, 2002
Related Publication 20040128554A1 · Jul 1, 2004