IP Library Granted Patent US 9,350,699
Granted Patent B2
US 9,350,699 · App. 14/339,598 · Granted May 24, 2016

Scalable NAT traversal

Inventors: Sébastien Boire-Lavigne (Montréal, CA); Richard Collette (Laval, CA); Sébastien Lalonde (St-Lazare, CA); Éric Malenfant (Montréal, CA)
Assignee: XMedius Solutions Inc.
H04L61/2567H04L29/125H04L29/12528H04L45/72H04L61/2564H04L61/2575H04L63/029H04L65/1006H04L65/1069H04L61/2589
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,350,699
App. No.
14/339,598
Granted
May 24, 2016
Kind
B2
Abstract

A system and method for traversing a firewall for a voice-over-IP session or other communication session uses four main components: a relay agent, and NAT 30 Agent, a SIP proxy and a application server. The SIP proxy is located in the public network and SIP signaling messages are routed through the SIP proxy. The sever opens ports in the firewall for signaling between the SIP proxy and the relay agent behind the firewall. The application server also opens ports in the firewall for media traffic. The NAT 30 Agent disposed in the path from the firewall to the Internet filters media packets and changes the public source address of the media packets to a predetermined address associated with the open media port.

Claims (16)

1. A method of opening a port in a firewall, the method comprising:

intercepting a firewall punching packet transmitted over a firewall port to a target address in a public network, the firewall punching packet including a public source address indicating the firewall port over which the packet was transmitted;

sending, in response to the firewall punching packet, a reply message to the public source address specified in the firewall punching packet, the reply message comprising a payload that contains the public source address of the firewall punching packet;

if the target address of the firewall punching packet contains a predetermined port number, creating an entry in a mapping table associating a target IP address of the firewall punching packet with the public source address of the firewall punching packet;

intercepting a packet sent to the firewall;

if the source IP address and destination address of the intercepted packet matches an entry in the mapping table, modifying the source address of the intercepted packet to match the target address of the firewall punching packet; and

forwarding the modified packet to the firewall.

2. A device for opening a port in a firewall, the device comprising:

a network interface for connecting said device with a private network protected by said firewall; and

a processor connected to said network interface and configured to:

intercept a firewall punching packet transmitted over a firewall port to a target address in a public network, the firewall punching packet including a public source address indicating the firewall port over which the packet was transmitted;

send, in response to the firewall punching packet, a reply message to the public source address specified in the firewall punching packet, the reply message comprising a payload that contains the public source address of the firewall punching packet;

if the target address of the firewall punching packet contains a predetermined port number, create an entry in a mapping table associating a target IP address of the firewall punching packet with the public source address of the firewall punching packet;

intercept a packet sent to the firewall;

if the source IP address and destination address of the intercepted packet matches an entry in the mapping table, modify the source address of the intercepted packet to match the target address of the firewall punching packet; and

forward the modified packet to the firewall.

Assignments (5)
PATENT RELEASE AND REASSIGNMENT Recorded Mar 11, 2020
From: GLADSTONE BUSINESS LOAN, LLC, AS SUCCESSOR-IN-INTEREST TO GLADSTONE CAPITAL CORPORATION
To: XMEDIUS SOLUTIONS, INC.
Reel/Frame 052150/0200 →
SECURITY INTEREST Recorded Jan 22, 2018
From: XMEDIUS SOLUTIONS INC.
To: GLADSTONE CAPITAL CORPORATION
Reel/Frame 044686/0754 →
CHANGE OF NAME Recorded Apr 21, 2016
From: SAGEM-INTERSTAR INC.
To: SAGEMCOM CANADA INC.
Reel/Frame 038490/0367 →
CHANGE OF NAME Recorded Apr 21, 2016
From: SAGEMCOM CANADA INC.
To: XMEDIUS SOLUTIONS INC.
Reel/Frame 038490/0486 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 2, 2014
From: BOIRE-LAVIGNE, SÉBASTIEN; COLLETTE, RICHARD; LALONDE, SÉBASTIEN; MALENFANT, ÉRIC
To: SAGEM-INTERSTAR, INC.
Reel/Frame 034299/0562 →
Continuity (3)
Continuation 12701147 · Feb 5, 2010
Provisional Application 61150378 · Feb 6, 2009
Related Publication 20140334481A1 · Nov 13, 2014