IP Library › Granted Patent US 7,890,995
Granted Patent B2
US 7,890,995 · App. 10/721,753 · Granted Feb 15, 2011

System and method for remote management of communications networks

Assignee: Cisco Technology, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,890,995
App. No.
10/721,753
Granted
Feb 15, 2011
Kind
B2
Abstract

The invention provides a system and method for that facilitating the remote management of one or more networks. In enabling the remote management of a network, embodiments of the invention provide limited access to service providers through a firewall, without the need to modify the configuration of the firewall. Advantageously, the cost of providing such access may be reduced compared to conventional approaches. In addition, such access may be limited to data inquiries or other commands, which can reduce the risk that the security of the network is compromised.

Claims (58)

1. A method for controlling a network remotely, the method comprising:

configuring a first control unit, inside a first firewall, the first control unit separate from the first firewall and used to control the network, configuring of the first control unit including:

querying a proxy server outside the first firewall from the first control unit to obtain a proxy server IP address,

receiving proxy server identification information with respect to the proxy server outside the first firewall, the proxy server identification information including the proxy server IP address,

generating an access key in the first control unit, and

sending the access key and first control unit identification information to the proxy server;

configuring the proxy server outside the first firewall, the proxy server being implemented within a De-Militarized Zone (DMZ) between the network and an unprotected public network, configuring of the proxy server including:

receiving the first control unit identification information,

storing the first control unit identification information in the proxy server,

adding the first control unit as a first remote device, and

exchanging a validation message between the first control unit and the proxy server,

establishing a session between the first control unit and the proxy server, by use of the access key; and

establishing a connection between the proxy server and a console which resides within the unprotected public network, to permit remote user management of the network by communication between the first control unit and the console via the proxy server.

2. The method of claim 1 , further comprising configuring a second control unit inside a second firewall, the proxy server being outside the second firewall.

3. The method of claim 1 , wherein receiving the proxy server identification information includes receiving a proxy server host name, a proxy server IP address, and a proxy server port number.

4. The method of claim 1 , wherein establishing a session between the first control unit and the proxy server includes coupling through a second firewall, the proxy server being inside the second firewall.

5. The method of claim 4 , further comprising connecting between the proxy server and a console, the console being inside the second firewall, the connecting using an IP address facing inside the second firewall.

6. A communications system, comprising:

a first enterprise network;

a first firewall;

a first control unit communicatively coupled to the first enterprise network to manage the first enterprise network, the first control unit being separate from the first firewall:

a public network; and

a proxy server located outside the first fire wall and implemented within a De-Militarized Zone (DMZ) between the first enterprise network and the public network, the first control unit being configured to:

querying the proxy server to obtain a proxy server IP address;

receive proxy server identification information with respect to the proxy server, the proxy server identification information including the proxy server IP address;

generate an access key; and

send the access key and first control unit identification information to the proxy server,

the proxy server being configured to:

receive the first control unit identification information;

store the first control unit identification information;

add the first control unit as a first remote device; and

exchange a validation message between the first control unit and the proxy server, the first control unit and the proxy server configured to establish a communication session based on the first access key, the proxy server to aggregate and store performance data provided by the first control unit.

7. The communications system of claim 6 , wherein receiving the proxy server information includes a proxy server host name and a proxy server port number.

8. The communication system of claim 6 , further comprising:

a second firewall communicatively coupled to the public network;

a second control unit communicatively coupled to the second firewall; and

a second enterprise network communicatively coupled to the second control unit, the second control unit being configured with proxy server information, the proxy server being configured with second control unit information, the second control unit being further configured to send a second access key to the proxy server, the second control unit and the proxy server configured to establish a communication session based on the second access key.

9. A communications system, comprising:

a first console residing within an unprotected public network and configured to generate at least one console request message, the console request message including at least one of a request for network management data, a request for Internet Protocol (IP)-Private Branch Exchange (PBX), or a request for status information;

a first firewall communicatively coupled to the proxy server;

a first control unit to control a protected network, the first control unit residing within the protected network and being communicatively coupled to the first firewall; and

a proxy server communicatively coupled to the first console, the proxy server configured to establish a connection with the first control unit by sending proxy server identification information including a proxy server IP address to the first control unit, receive from the first control unit control unit identification information and an access key generated by the first control unit, adding the first control unit as a first remote device, and exchange a validation message with the first control unit, the proxy server further being configured to pool the at least one console request message, to provide access from the first console to the first control unit and to aggregate and store performance data provided by the first control unit, the proxy server being implemented within a De-Militarized Zone (DMZ) between a protected network and the unprotected public network

the first control unit configured to receive the at least one request from the proxy server, and to output at least one response corresponding to the at least one request to the proxy server, the proxy server configured to output the at least one response to the first console.

10. The system of claim 9 , further comprising a second console communicatively coupled to the proxy server, the second console configured to generate at least one other request, the proxy server configured to pool the at least one other request.

11. The system of claim 9 , further comprising:

a second firewall communicatively coupled to the proxy server; and

a second control unit, the second control unit communicatively coupled to the second firewall, the second control unit configured to receive the at least one request from the proxy server, the second control unit further configured to output at least one response corresponding to the at least one request to the proxy server, the proxy server configured to output the at least one response to the first console.

12. The system of claim 9 , wherein the proxy server includes:

a client request handler for receiving a client request from the first console;

a shared request object pool communicatively coupled to the client request handler, the shared request object pool configured to store the at least one request; and

a server request handler communicatively coupled to the shared request object pool, the server request handler configured to read the at least one request from the shared request object pool, the server request handler configured to send the at least one request to the first control unit, the server request handler configured to receive the at least one response, the server request handler configured to output the at least one response to the first console.

13. The system of claim 9 , wherein the proxy server includes processor-executable code, the code performing the steps of:

receiving a client request from the first console;

writing the at least one request;

reading the at least one request;

sending the at least one request to the first control unit;

receiving the at least one response; and

outputting the at least one response to the first console.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2008
From: CISCO SYSTEMS, INC.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 020860/0257 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2007
From: QOVIA, INC.
To: CISCO SYSTEMS, INC.
Reel/Frame 020208/0156 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2004
From: SHIM, CHOON B.; TWOREK, RICHARD M.
To: QOVIA, INC.
Reel/Frame 015268/0621 →
Continuity (1)
Related Publication 20050114665A1 · May 26, 2005