Movatterモバイル変換


[0]ホーム

URL:


CN105407082A - Host isolation apparatus in VLAN and method thereof - Google Patents

Host isolation apparatus in VLAN and method thereof
Download PDF

Info

Publication number
CN105407082A
CN105407082ACN201510698285.5ACN201510698285ACN105407082ACN 105407082 ACN105407082 ACN 105407082ACN 201510698285 ACN201510698285 ACN 201510698285ACN 105407082 ACN105407082 ACN 105407082A
Authority
CN
China
Prior art keywords
vlan
isolated
main frame
primary
mutually
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201510698285.5A
Other languages
Chinese (zh)
Inventor
范春燕
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Shanghai Feixun Data Communication Technology Co Ltd
Original Assignee
Shanghai Feixun Data Communication Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Shanghai Feixun Data Communication Technology Co LtdfiledCriticalShanghai Feixun Data Communication Technology Co Ltd
Priority to CN201510698285.5ApriorityCriticalpatent/CN105407082A/en
Publication of CN105407082ApublicationCriticalpatent/CN105407082A/en
Priority to PCT/CN2016/097744prioritypatent/WO2017067328A1/en
Pendinglegal-statusCriticalCurrent

Links

Classifications

Landscapes

Abstract

The invention discloses a host isolation apparatus in a VLAN and a method thereof. The apparatus comprises a receiving module, a configuration module and a deployment module, wherein the receiving module is used for receiving a request of mutually isolating assigned hosts in the VLAN; the configuration module is used for distributing a main VLAN and an auxiliary VLANs associated with the main VLAN in the VLAN, wherein the auxiliary VLAN comprises an isolation VLAN; a host in the main VLAN is allowable to communicate with any other hosts; a host in the isolation VLAN is only allowable to communicate with the host in the main VLAN; the deployment module is used for deploying a server in the VLAN into the main VLAN and deploying the assigned hosts into the isolation VLAN so that the assigned hosts are isolated to each other. By using the apparatus and the method, the assigned hosts in the same VLAN can be isolated so that an information safety requirement can be satisfied through less management cost and resources.

Description

The apparatus and method of main frame isolation in a kind of VLAN
Technical field
The present invention relates to communication technical field, particularly relate to the apparatus and method of main frame isolation in a kind of VLAN.
Background technology
Because present network environment is day by day complicated, information security seems particularly important.And enterprise is for the needs of protection company secret, also in the urgent need in this enterprise network, client host can with server communication, and can not with other client host communications in network.
In prior art, realize mutually not communicating between the main frame in an enterprise network, can only be that each main frame is all assigned to different VLAN (VirtualLocalAreaNetwork, Chinese is " VLAN ") in, when host number is very many time, need to distribute a large amount of VLAN, thus cause the wasting of resources, network management is complicated.
Summary of the invention
The technical problem that the present invention mainly solves is to provide the apparatus and method of main frame isolation in a kind of VLAN, can realize carrying out communication isolating to the given host be deployed in same VLAN, thus reach the requirement of information security with less management cost and resource.
For solving the problems of the technologies described above, the technical scheme that the present invention adopts is: the device providing main frame isolation in a kind of VLAN, and this device comprises: receiver module, for being received in VLAN the request that given host is isolated mutually; Configuration module, for the auxiliary vlan distributing primary vlan and associate with described primary vlan in described VLAN, described auxiliary vlan comprises isolated vlan, main frame in described primary vlan allows and any other main-machine communication, and the main frame in described isolated vlan only allows and the main-machine communication in described primary vlan; Deployment module, for by the server disposition in described VLAN in described primary vlan, and described given host to be deployed in described isolated vlan, to isolate mutually between described given host.For solving the problems of the technologies described above, the technical scheme that the present invention adopts is: the method providing main frame isolation in a kind of VLAN, and the step of the method comprises: receive in VLAN the request that given host is isolated mutually; The auxiliary vlan distributing primary vlan and associate with described primary vlan in described VLAN, described auxiliary vlan comprises isolated vlan, main frame in described primary vlan allows and any other main-machine communication, and the main frame in described isolated vlan only allows and the main-machine communication in described primary vlan; By the server disposition in described VLAN in described primary vlan, and described given host is deployed in described isolated vlan, to isolate mutually between described given host.
Be different from prior art, in VLAN of the present invention, the device of main frame isolation is received in VLAN the request that given host is isolated mutually, the auxiliary vlan distributing primary vlan and associate with primary vlan in VLAN, by server disposition in primary vlan, and the host deployments that will isolate mutually is in isolated vlan, can realize carrying out communication isolating to given host in same VLAN, thus both reach information security, reduce again the wasting of resources, save management cost.
Accompanying drawing explanation
Fig. 1 is the structural representation of the first execution mode of a kind of device provided by the invention;
Fig. 2 is the structural representation of the second execution mode of a kind of device provided by the invention;
Fig. 3 is the schematic flow sheet of the first execution mode of a kind of method provided by the invention.
Embodiment
Below in conjunction with embodiment, more detailed description is further done to technical scheme of the present invention.Obviously, described embodiment is only a part of embodiment of the present invention, instead of whole embodiments.Based on the embodiment in the present invention, the every other embodiment that those of ordinary skill in the art obtain under the prerequisite of not making creative work, all should belong to the scope of protection of the invention.
Consult Fig. 1, Fig. 1 is the structural representation of the first execution mode of the device of main frame isolation in a kind of VLAN provided by the invention.In this VLAN, the device 100 of main frame isolation comprises: receiver module 110, configuration module 120, deployment module 130.
Wherein, receiver module 110, for being received in VLAN the request that given host is isolated mutually.This request can be network manager by configuring in real time thus the request sent switch, or perform the instruction of existing configuration file on switches thus the request triggered.Concrete, the hardware identifier of the main frame needing isolation mutually will be carried in request, be generally MAC Address, employing hexadecimal number represents, totally six bytes (48), show as the form of " * *-* *-* *-* *-* *-* * ", each " * " represents a hexadecimal number, such as, need the host identification of isolating to be " 44-37-E6-0C-45-DE " and " 11-22-E6-0C-45-33 ".
Configuration module 120 connects receiver module 110, trigger according to the request that receiver module 110 receives, the auxiliary vlan distributing primary vlan and associate with described primary vlan in this VLAN, described auxiliary vlan comprises isolated vlan, main frame in described primary vlan allows and any other main-machine communication, and the main frame in described isolated vlan only allows and the main-machine communication in described primary vlan.In network system, the IP address being " * .*.*.* " by form identifies VLAN, each " * " represents a decimal number (length is an octet), such as " 10.10.10.0 ", described VLAN and the primary vlan distributed in this VLAN and auxiliary vlan have identical IP address and different ports, therefore it seems from external system, they belong to identical VLAN.
The result that deployment module 130 configures according to configuration module 120, by the server disposition in VLAN in described primary vlan, and is deployed to described given host in described isolated vlan, to isolate mutually between described given host.
Be different from prior art, the device of main frame isolation in VLAN of the present invention, according in VLAN to the request that given host is isolated mutually, for this VLAN distributes primary vlan and auxiliary vlan, auxiliary vlan comprises isolated vlan, main frame wherein in primary vlan allows and any other main-machine communication, main frame in auxiliary vlan only allows and the host identification in primary vlan, and the host deployments that will isolate mutually is in isolated vlan, thus achieve and just can isolate mutually given host in a VLAN, without the need to by host deployments to different VLAN, thus achieve information security with less management cost and resource.
Consult Fig. 2, Fig. 2 is the structural representation of the second execution mode of the device of main frame isolation in a kind of VLAN provided by the invention.This device 200 comprises: receiver module 210, configuration module 220, deployment module 230.
Wherein, receiver module 210 is for being received in VLAN the request that given host is isolated mutually.Concrete, can be deployed server and main frame in existing VLAN, network manager will carry out communication isolating to given host in this VLAN according to real network deployment requirements; Also can be that network manager needs a newly-built VLAN, and in this VLAN deployment server and mutually isolated main frame.Concrete, this request can be network manager by configuring in real time thus the request sent switch, or perform the instruction of existing configuration file on switches thus the request of triggering.Concrete, by carrying the hardware identifier of the main frame needing isolation mutually in request, be generally MAC Address, such as, need the host identification of isolating to be " 44-37-E6-0C-45-DE " and " 11-22-E6-0C-45-33 ".
Configuration module 220 comprises and comprises dispensing unit 221 and record cell 222.Dispensing unit 221 triggers for the request received according to receiver module 210, the designated port of described VLAN is distributed to primary vlan respectively, and isolated vlan designated port distributed in the auxiliary vlan that associates with described primary vlan, main frame in described primary vlan allows and any other main-machine communication, and the main frame in described isolated vlan only allows and the main-machine communication in described primary vlan.In network system, the IP address being " * .*.*.* " by form identifies VLAN, such as " 10.10.10.0 ", and a VLAN can have multiple port, usual employing integer carrys out identification port, such as 1,2,3 ... such as, port one, 2,3 is distributed to primary vlan, port 7 ~ 20 is distributed to isolated vlan, VLAN and the primary vlan distributed in this VLAN and auxiliary vlan have identical IP address and different ports, and therefore it seems from external system, they belong to identical VLAN.When dispensing unit 221 has carried out described port assignment operation, record cell 222 will record described port assignment information, and namely which port often kind of VLAN comprises.Concrete, described port assignment information can be recorded in the register of switch.Further, " main frame in primary vlan allows and any other main-machine communication, and the main frame in isolated vlan only allows and the main-machine communication in described primary vlan " this policy information will be kept in VLAN, concrete, can be in the preserving existence intersection property register of changing planes.
The result that deployment module 230 configures according to configuration module 220, by the server disposition in VLAN in described primary vlan, and described given host is deployed in described isolated vlan, concrete, deployment module 230 recording configuration module 220 is the port of described primary vlan distribution and the incidence relation of server, and recording configuration module 220 is the port of described isolated vlan distribution and the incidence relation of given host, to isolate mutually between described given host.
Optionally, in another example of the present embodiment, receiver module 210 further receives the request that the main frame that can communicate at least two mutually and described given host are isolated, such as, can communicate mutually between the main frame being designated " 33-33-33-33-33-33 " and " 44-44-44-44-44-44 ", but need to isolate between other main frames.Configuration module 220 distribute auxiliary vlan associate with primary vlan, comprise group VLAN further, the main frame in described group VLAN only allow internal mutual to communicate and with described primary vlan in main-machine communication; Concrete, the designated port of described VLAN is distributed to described group VLAN by dispensing unit 221 respectively; And record cell 222 records described port assignment information; Deployment module 230, further by the host deployments of described at least two communications mutually to described group VLAN, concrete, deployment module 230 is further recorded as the port of described group VLAN distribution and the incidence relation of described at least two main frames communicated mutually.In this example, achieve deployment and other main frames in same VLAN and isolate but the multiple main frames allowing internal mutual to communicate.
Be different from prior art, the device of main frame isolation in VLAN of the present invention, according in VLAN to the request that given host is isolated mutually, for this VLAN distributes primary vlan and auxiliary vlan, auxiliary vlan comprises isolated vlan, main frame wherein in primary vlan allows and any other main-machine communication, main frame in auxiliary vlan only allows and the host identification in primary vlan, and the host deployments that will isolate mutually is in isolated vlan, thus achieve and just can isolate mutually given host in a VLAN, without the need to by host deployments to different VLAN, thus achieve information security with less management cost and resource.
Consult Fig. 3, Fig. 3 is the schematic flow sheet of the first execution mode of main frame partition method in a kind of VLAN provided by the invention.The step of the method comprises:
S301: receive in assigned vlan the request that given host is isolated mutually.
Concrete, can be deployed server and main frame in existing VLAN, network manager will carry out communication isolating to given host in this VLAN according to real network deployment requirements; Also can be that network manager needs a newly-built VLAN, and in this VLAN deployment server and mutually isolated main frame.
Concrete, this request can be network manager by configuring in real time thus the request sent switch, or perform the instruction of existing configuration file on switches thus the request of triggering.Concrete, by carrying the hardware identifier of the main frame needing isolation mutually in request, be generally MAC Address, such as, need the host identification of isolating to be " 44-37-E6-0C-45-DE " and " 11-22-E6-0C-45-33 ".
S302: the auxiliary vlan distributing primary vlan and associate with described primary vlan in described VLAN, described auxiliary vlan comprises isolated vlan, main frame in described primary vlan allows and any other main-machine communication, and the main frame in described isolated vlan only allows and the main-machine communication in described primary vlan.
Concrete, the auxiliary vlan distributing primary vlan and associate with described primary vlan in described VLAN, described auxiliary vlan comprises isolated vlan: the designated port of described VLAN is distributed to primary vlan respectively, and designated port is distributed to the isolated vlan in the auxiliary vlan that associates with described primary vlan; And record described port assignment information, namely which port often kind of VLAN comprises.
In network system, the IP address being " * .*.*.* " by form identifies VLAN, such as " 10.10.10.0 ", and a VLAN can have multiple port, usual employing integer carrys out identification port, such as 1,2,3 ... such as, can be that port one, 2,3 is distributed to primary vlan, port 7 ~ 20 is distributed to isolated vlan, VLAN and the primary vlan distributed in this VLAN and auxiliary vlan have identical IP address and different ports, and therefore it seems from external system, they belong to identical VLAN.Described port assignment information can be recorded in the register of switch.Further, " main frame in primary vlan allows and any other main-machine communication, and the main frame in isolated vlan only allows and the main-machine communication in described primary vlan " this policy information will be kept in VLAN, such as, can be in the preserving existence intersection property register of changing planes.
S303: by the server disposition in described VLAN in described primary vlan, and described given host be deployed in described isolated vlan, to isolate mutually between described given host.
Concrete, changing step can be: be recorded as the port of described primary vlan distribution and the incidence relation of described server, is recorded as the port of described isolated vlan distribution and the incidence relation of described given host.
Optionally, in another example of the present embodiment, step s301 further receives the request that the main frame that can communicate at least two mutually and described given host are isolated, such as, can communicate mutually between the main frame being designated " 33-33-33-33-33-33 " and " 44-44-44-44-44-44 ", but need to isolate between other main frames.The auxiliary vlan associated with primary vlan distributed in step s302, also comprises group VLAN further, the main frame in described group VLAN only allow internal mutual to communicate and and described primary vlan in main-machine communication; Concrete, this step can be that the designated port of described VLAN is distributed to described group VLAN respectively; And record described port assignment information; Step s303, further by the host deployments of described at least two mutual communications to described group VLAN, concrete, this step can for being further recorded as the incidence relation of port that described group VLAN distributes and described at least two mutual main frames communicated.In this example, achieve deployment and other main frames in same VLAN and isolate but the multiple main frames allowing internal mutual to communicate.
Be different from prior art, the method of main frame isolation in VLAN of the present invention, according in VLAN to the request that given host is isolated mutually, for this VLAN distributes primary vlan and auxiliary vlan, auxiliary vlan comprises isolated vlan, main frame wherein in primary vlan allows and any other main-machine communication, main frame in auxiliary vlan only allows and the host identification in primary vlan, and the host deployments that will isolate mutually is in isolated vlan, thus achieve and just can isolate mutually given host in a VLAN, without the need to by host deployments to different VLAN, thus achieve information security with less management cost and resource.
The foregoing is only embodiments of the present invention; not thereby the scope of the claims of the present invention is limited; every utilize specification of the present invention and accompanying drawing content to do equivalent structure or equivalent flow process conversion; or be directly or indirectly used in other relevant technical fields, be all in like manner included in scope of patent protection of the present invention.

Claims (10)

CN201510698285.5A2015-10-232015-10-23Host isolation apparatus in VLAN and method thereofPendingCN105407082A (en)

Priority Applications (2)

Application NumberPriority DateFiling DateTitle
CN201510698285.5ACN105407082A (en)2015-10-232015-10-23Host isolation apparatus in VLAN and method thereof
PCT/CN2016/097744WO2017067328A1 (en)2015-10-232016-08-31Apparatus and method for host isolation in vlan

Applications Claiming Priority (1)

Application NumberPriority DateFiling DateTitle
CN201510698285.5ACN105407082A (en)2015-10-232015-10-23Host isolation apparatus in VLAN and method thereof

Publications (1)

Publication NumberPublication Date
CN105407082Atrue CN105407082A (en)2016-03-16

Family

ID=55472337

Family Applications (1)

Application NumberTitlePriority DateFiling Date
CN201510698285.5APendingCN105407082A (en)2015-10-232015-10-23Host isolation apparatus in VLAN and method thereof

Country Status (2)

CountryLink
CN (1)CN105407082A (en)
WO (1)WO2017067328A1 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
WO2017067328A1 (en)*2015-10-232017-04-27上海斐讯数据通信技术有限公司Apparatus and method for host isolation in vlan

Citations (4)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US20060146835A1 (en)*2004-12-302006-07-06Sanjib HomchaudhuriPlatform independent implementation of private VLANS
CN102780608A (en)*2011-05-132012-11-14国际商业机器公司Efficient software-based private VLAN solution for distributed virtual switches
CN103141059A (en)*2011-06-242013-06-05思科技术公司Private virtual local area network isolation
CN104883325A (en)*2014-02-272015-09-02国际商业机器公司PVLAN switch and method of connecting the PVLAN switch to non-PVLAN apparatus

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN100553220C (en)*2007-08-222009-10-21杭州华三通信技术有限公司 A method and device for realizing downlink user isolation in a VLAN
CN105407082A (en)*2015-10-232016-03-16上海斐讯数据通信技术有限公司Host isolation apparatus in VLAN and method thereof

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US20060146835A1 (en)*2004-12-302006-07-06Sanjib HomchaudhuriPlatform independent implementation of private VLANS
CN102780608A (en)*2011-05-132012-11-14国际商业机器公司Efficient software-based private VLAN solution for distributed virtual switches
CN103141059A (en)*2011-06-242013-06-05思科技术公司Private virtual local area network isolation
CN104883325A (en)*2014-02-272015-09-02国际商业机器公司PVLAN switch and method of connecting the PVLAN switch to non-PVLAN apparatus

Cited By (1)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
WO2017067328A1 (en)*2015-10-232017-04-27上海斐讯数据通信技术有限公司Apparatus and method for host isolation in vlan

Also Published As

Publication numberPublication date
WO2017067328A1 (en)2017-04-27

Similar Documents

PublicationPublication DateTitle
US10848461B2 (en)Unified security policies across virtual private clouds with overlapping IP address blocks
CN106034052B (en)The system and method that two laminar flow amounts are monitored a kind of between of virtual machine
EP2845350B1 (en)Method and apparatus for providing tenant information for network flows
EP2995067B1 (en)A direct connect virtual private interface for a one to many connection with multiple virtual private clouds
CN105284080B (en)The virtual network management method and data center systems of data center
CN105391568B (en)A kind of implementation method, the device and system of software defined network SDN
US9363207B2 (en)Private virtual local area network isolation
CN107977255B (en)Apparatus and method for separating tenant-specific data
EP4040739A1 (en)Optical line terminal olt device virtualization method and related device
CN104253767B (en)A kind of implementation method of virtual burst network and a kind of interchanger
CN105745883B (en) Method, network device and system for synchronization of forwarding tables
US10454880B2 (en)IP packet processing method and apparatus, and network system
CN106936777A (en)Cloud computing distributed network implementation method based on OpenFlow, system
CN107135134A (en)Private network cut-in method and system based on virtual switch and SDN technologies
WO2011162777A1 (en)Tenant isolation in a multi-tenant cloud system
EP2681878B1 (en)Technique for managing an allocation of a vlan
CN105591863A (en)Method and device for realizing interworking between virtual private cloud network and external network
US20200007472A1 (en)Service insertion in basic virtual network environment
CN104012057A (en)Flexible And Scalable Enhanced Transmission Selection Method For Network Fabrics
KR101969396B1 (en)Method, Apparatus and System for Remotely Configuring PTP Service of Optical Network Unit
CN105530200B (en)The VLAN allocation method of different terminals business
US11323287B2 (en)Link layer method of configuring a bare-metal server in a virtual network
EP3618407B1 (en)Method for implementing three-layer communication
CN105812221B (en)The device and method of data transmission in virtual expansible Local Area Network
CN107005479B (en) Method, device and system for data forwarding in software-defined network SDN

Legal Events

DateCodeTitleDescription
C06Publication
PB01Publication
C10Entry into substantive examination
SE01Entry into force of request for substantive examination
RJ01Rejection of invention patent application after publication

Application publication date:20160316

RJ01Rejection of invention patent application after publication

[8]ページ先頭

©2009-2025 Movatter.jp