Traditional firewalls apply the combination of source/destination IP addresses, port numbers, and protocols (UDP, TCP, or ICMP) to form access control lists (ACLs) which can effectively allow/deny traffic. However, with the rise of Cloud Data Centers like AWS and Akamai, ACLs face limitations in network management, especially with content delivery network (CDN) security challenges. This paper addresses the issues encountered by a powerful artificial intelligence assisted Juniper Mist Cloud management service. Mist Cloud requires the accessibility to AWS, which is usually prohibited by enterprise firewalls because of numerous unknown services on AWS. This paper proposes a solution with trusted third-party relay hosts for private enterprise networks. It details configurations for VPN Tunnel and firewall settings. Experimental results show minimal delay (only two milliseconds longer) when routing management traffic through a relay. This demonstrates that it provides a secure mechanism without sacrificing operations.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Solution for Public Cloud Accessibility from Private Networks

  • Louise Jia-Lu Chen,
  • Quincy Wu,
  • Jimmy Wang

摘要

Traditional firewalls apply the combination of source/destination IP addresses, port numbers, and protocols (UDP, TCP, or ICMP) to form access control lists (ACLs) which can effectively allow/deny traffic. However, with the rise of Cloud Data Centers like AWS and Akamai, ACLs face limitations in network management, especially with content delivery network (CDN) security challenges. This paper addresses the issues encountered by a powerful artificial intelligence assisted Juniper Mist Cloud management service. Mist Cloud requires the accessibility to AWS, which is usually prohibited by enterprise firewalls because of numerous unknown services on AWS. This paper proposes a solution with trusted third-party relay hosts for private enterprise networks. It details configurations for VPN Tunnel and firewall settings. Experimental results show minimal delay (only two milliseconds longer) when routing management traffic through a relay. This demonstrates that it provides a secure mechanism without sacrificing operations.