System and method of obtaining data from private cloud behind enterprise firewall
A public cloud includes a processor. The processor obtains, from a client via a first network connection, a data access request that specifies data stored in a private cloud separated from the public cloud server by a firewall; sends the data access request to the private cloud through the firewall via a second network connection; receives the data stored in the private cloud via the second network connection; and forwards the received data stored in the private cloud to the client.
1. A public cloud server in a public cloud, comprising:
a processor programmed to:
obtain, from a first client via a first network connection, a data access request that specifies data stored in a private cloud separated from the public cloud server by a firewall,
authenticate access to the data, for the first client, using credential data stored in the public cloud server,
send the data access request to the private cloud through the firewall via a second network connection,
receive the data stored in the private cloud via the second network connection, and
forward, using a virtual private network (VPN) interface table, the received data stored in the private cloud to the first client,
wherein the public cloud server comprises the VPN interface table, and
wherein the VPN interface table specifies logical network connections between the first client, the public cloud server, and the private cloud.
2. The public cloud server of claim 1 , wherein the second network connection is a secure socket layer connection.
3. The public cloud server of claim 1 , wherein the data access request is sent to the private cloud using the VPN interface table.
4. The public cloud server of claim 1 , wherein the logical network connections route IP traffic through a secure socket layer (SSL) connection.
5. The public cloud server of claim 4 , wherein the second network connection is a SSL connection, and wherein the first network connection is not a SSL connection.
6. The public cloud server of claim 1 , wherein the first network connection is a connection through the Internet.
7. The public cloud server of claim 1 , wherein the data access request comprises:
a first credential associated with the public cloud server; and
a second credential associated with the private cloud.
8. The public cloud server of claim 1 , wherein the processor is further programmed to:
obtain, from a second client, a second data access request that specifies second data stored in the private cloud;
in response to obtaining the second data access request, establish a third network connection, wherein the third network connection is a secure socket layer link connection between the public cloud server and the private cloud;
send the second data access request to a private cloud server via the third network connection;
receive the second data stored in the private cloud via the third network connection; and
forward the second data to the second client.
9. The public cloud server of claim 8 , wherein the processor is further programmed to:
after establishing the third network connection, establish a virtual private network (VPN),
wherein the VPN specifies logical connections between the second client, the public cloud, and the private cloud.
10. The public cloud server of claim 9 , wherein the second data access request is sent to the private cloud server using the VPN.
11. The public cloud server of claim 9 , wherein the second data is forwarded to the second client using the VPN.
12. The public cloud server of claim 1 , wherein the processor is further programmed to:
before sending the data access request to the private cloud, establish a virtual private network (VPN),
wherein the VPN specifies logical connections between the first client, the public cloud, and the private cloud.
13. The public cloud server of claim 12 , wherein the data access request is sent to the private cloud using the VPN.
14. The public cloud server of claim 12 , wherein the data is forwarded to the first client using the VPN.
15. A method of operating a public cloud server in a public cloud, comprising:
obtaining, by the public cloud server from a first client via a first network connection, a data access request that specifies data stored in a private cloud separated from the public cloud server by a firewall,
authenticating access to the data, for the first client, using credential data stored in the public cloud server,
sending, by the public cloud server, the data access request to the private cloud through the firewall via a second network connection,
receiving, by the public cloud server, the data stored in the private cloud via the second network connection, and
forwarding, by the public cloud server using a virtual private network (VPN) interface table, the received data stored in the private cloud to the first client,
wherein the VPN interface table specifies logical network connections between the first client, the public cloud server, and the private cloud.
16. The method of claim 15 , further comprising:
before sending the data access request to the private cloud, establishing a virtual private network (VPN),
wherein the VPN specifies logical connections between the first client, the public cloud, and the private cloud.
17. A non-transitory computer readable medium comprising computer readable program code, which when executed by a computer processor enables the computer processor to perform a method for operating a public cloud server in a public cloud, the method comprising:
obtaining, by the public cloud server from a first client via a first network connection, a data access request that specifies data stored in a private cloud separated from the public cloud server by a firewall,
authenticating access to the data, for the first client, using credential data stored in the public cloud server,
sending, by the public cloud server, the data access request to the private cloud through the firewall via a second network connection,
receiving, by the public cloud server, the data stored in the private cloud via the second network connection, and
forwarding, by the public cloud server using a virtual private network (VPN) interface table, the received data stored in the private cloud to the first client,
wherein the VPN interface table specifies logical network connections between the first client, the public cloud server, and the private cloud.
18. The non-transitory computer readable medium of claim 17 , wherein the method further comprises:
before sending the data access request to the private cloud, establishing a virtual private network (VPN),
wherein the VPN specifies logical connections between the first client, the public cloud, and the private cloud.