Movatterモバイル変換


[0]ホーム

URL:


CN108600170A - A kind of method and system of control multisegment environment lower network equipment internet behavior - Google Patents

A kind of method and system of control multisegment environment lower network equipment internet behavior
Download PDF

Info

Publication number
CN108600170A
CN108600170ACN201810230500.2ACN201810230500ACN108600170ACN 108600170 ACN108600170 ACN 108600170ACN 201810230500 ACN201810230500 ACN 201810230500ACN 108600170 ACN108600170 ACN 108600170A
Authority
CN
China
Prior art keywords
control device
tier switch
gateway
address
network equipment
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201810230500.2A
Other languages
Chinese (zh)
Inventor
陈世杰
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
DASHIZHI (BEIJING) SOFTWARE ENGINEERING Co Ltd
Original Assignee
DASHIZHI (BEIJING) SOFTWARE ENGINEERING Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by DASHIZHI (BEIJING) SOFTWARE ENGINEERING Co LtdfiledCriticalDASHIZHI (BEIJING) SOFTWARE ENGINEERING Co Ltd
Priority to CN201810230500.2ApriorityCriticalpatent/CN108600170A/en
Publication of CN108600170ApublicationCriticalpatent/CN108600170A/en
Pendinglegal-statusCriticalCurrent

Links

Classifications

Landscapes

Abstract

The present invention provides a kind of method and system of control multisegment environment lower network equipment internet behavior, wherein method includes the following steps:S1:Packet filtering driving is installed on the gateway of net control device;S2:The network segment VLAN1 net control device being connected to where three-tier switch first line of a couplet egress gateways;The IP address of the net control device is configured to the IP address of VLAN1, the gateway ip address of net control device is configured to the IP address of egress gateways;S3:The port that three-tier switch is connected to three-tier switch egress gateways sends ARP deception messages, and the gateway MAC address that this port stores is made to become the MAC Address of net control device;S4:The packet filtering driving installed on gateway by the net control device controls network equipment online.This programme can avoid the case where leading to not cause network log-in management to fail due to carrying out ARP deceptions after carrying out ARP static bindings by control computer installation ARP fire walls or to gateway.

Description

A kind of method and system of control multisegment environment lower network equipment internet behavior
Technical field
The present invention relates to network control technology field more particularly to a kind of control multisegment environment lower network equipment online rowsFor method and system.
Background technology
Following technology is based primarily upon for deployment network log-in management system under multisegment environment at present to realize:
For the network environment of common gateway (network equipments such as router, fire wall) plus non-three-tier switch, useThe network log-in management software of ARP Cheating Technologies, typically in one computer installation and deployment of LAN, then to entire LANIt sends ARP and cheats message so that the computer for installing network log-in management software is considered as gateway by other computers of LAN, and by netNetwork message is sent to this computer, and such network log-in management software where network interface card installs network message filtering by driving, justThe network message that all computers of LAN can be captured is forwarded to real gateway after processing, is played a game with this to realizeThe management and control of domain net online computing behavior.
But the network environment of non-three-tier switch is added for the network environment of non-three-tier switch, that is, gateway, thoughThe management of local area network online computing behavior so may be implemented by the network log-in management software of ARP Cheating Technologies, but ifIn the case that the computer controlled is mounted with ARP fire walls or has carried out ARP static bindings to gateway, since ARP can not be carried outIt cheats and leads to network log-in management disabler.
Invention content
In view of this, the technical problem to be solved in the present invention is to provide a kind of online of control multisegment environment lower network equipmentThe method and system of behavior can be avoided because installing ARP fire walls by control computer or to being led after gateway progress ARP static bindingsThe case where cause can not carry out ARP deceptions and network log-in management is caused to fail.
The technical proposal of the invention is realized in this way:
A method of control multisegment environment lower network equipment internet behavior includes the following steps:
S1:Packet filtering driving is installed on the gateway of net control device;
S2:The network segment VLAN1 net control device being connected to where three-tier switch first line of a couplet egress gateways;By instituteThe IP address for stating net control device is configured to the IP address of VLAN1, and the gateway ip address of net control device is configured to exportThe IP address of gateway;
S3:The port that three-tier switch is connected to three-tier switch egress gateways sends ARP deception messages, this port is made to depositThe gateway MAC address of storage becomes the MAC Address of net control device;
S4:Network equipment online is controlled in the packet filtering driving installed on gateway by the net control deviceSystem.
Preferably, further include:
Configuration refers to route on the three-tier switch first line of a couplet egress gateways in advance.
Preferably, after the S4, further include:
The port that three-tier switch is connected to three-tier switch egress gateways sends the correct message of gateway A RP.
Preferably, further include:
Network message in operational process is intercepted into daily record and database is written in internet behavior management and control situation.
Preferably, further include:
SNMP access rights are opened for net control device on the three-tier switch, net control device passes through SNMPNetwork management protocol reads the correspondence of the IP address and MAC Address for each network segment network equipment that three-tier switch is stored, andListed Host List.
Preferably, further include:
The establishment monitoring network segment, the IP address for the three-tier switch port that three-tier switch egress gateways are connected and MACLocation is inserted in the monitoring network segment.
The invention also provides a kind of systems of multisegment environment lower network equipment online processed, including:
Module is installed, for installing packet filtering driving on the gateway of net control device;
Configuration module, the network segment for being connected to the net control device where three-tier switch first line of a couplet egress gatewaysVLAN1;The IP address of the net control device is configured to the IP address of VLAN1, the gateway ip address of net control deviceIt is configured to the IP address of egress gateways;
Sending module, the port for connecting three-tier switch to three-tier switch egress gateways send ARP and cheat message,The gateway MAC address that this port stores is set to become the MAC Address of net control device;
Control module, the packet filtering installed on the gateway by the net control device drive to the network equipmentOnline is controlled.
Preferably, further include:
Routing module is referred to, for configuration to refer to route on the three-tier switch first line of a couplet egress gateways in advance.
Preferably, further include:
Recovery module, the port for connecting three-tier switch to three-tier switch egress gateways are sending gateway A RP justTrue message.
Preferably, further include:
Journal module, for network message in operational process to be intercepted daily record and internet behavior management and control situation write-in dataLibrary.
The method and system of control multisegment environment lower network equipment internet behavior proposed by the present invention, for L3 SwitchingThe three-tier switch port that machine egress gateways are connected carries out ARP deceptions, rather than directly local area network computer carries out gatewayARP is cheated, so as to avoid because installing ARP fire walls by control computer or to leading to nothing after gateway progress ARP static bindingsThe case where method carries out ARP deceptions, and thus network log-in management fails.
Description of the drawings
Fig. 1 is the method flow diagram for the control multisegment environment lower network equipment internet behavior that the embodiment of the present invention proposes;
Fig. 2 is the method flow for the control multisegment environment lower network equipment internet behavior that further embodiment of this invention proposesFigure;
Fig. 3 is the system for the control multisegment environment lower network equipment internet behavior that invention embodiment proposesStructure diagram.
Specific implementation mode
Following will be combined with the drawings in the embodiments of the present invention, and technical solution in the embodiment of the present invention carries out clear, completeSite preparation describes, it is clear that described embodiments are only a part of the embodiments of the present invention, instead of all the embodiments.It is based onEmbodiment in the present invention, it is obtained by those of ordinary skill in the art without making creative efforts every otherEmbodiment shall fall within the protection scope of the present invention.
As shown in Figure 1, the embodiment of the present invention proposes a kind of side of control multisegment environment lower network equipment internet behaviorMethod includes the following steps:
S101:Packet filtering driving is installed on the gateway of net control device;
S102:The network segment VLAN1 net control device being connected to where three-tier switch first line of a couplet egress gateways;It willThe IP address of the net control device is configured to the IP address of VLAN1, and the gateway ip address of net control device is configured to outThe IP address of mouth gateway;
S103:The port that three-tier switch is connected to three-tier switch egress gateways sends ARP deception messages, makes this portThe gateway MAC address of storage becomes the MAC Address of net control device;
S104:The packet filtering driving installed on gateway by the net control device, which surfs the Internet to the network equipment, to be carried outControl.
As it can be seen that the method and system for the control multisegment environment lower network equipment internet behavior that the embodiment of the present invention proposes,ARP deceptions are carried out for the three-tier switch port that three-tier switch egress gateways are connected, rather than directly local area network is electricBrain carries out the ARP deceptions of gateway, so as to avoid static because carrying out ARP by control computer installation ARP fire walls or to gatewayLead to not carry out ARP deceptions after binding, thus the case where network log-in management failure.
In a preferred embodiment of the invention, the method further includes:
Configuration refers to route on the three-tier switch first line of a couplet egress gateways in advance.
In a preferred embodiment of the invention, the method further includes:
The port that three-tier switch is connected to three-tier switch egress gateways sends the correct message of gateway A RP.
In a preferred embodiment of the invention, the method further includes:
Network message in operational process is intercepted into daily record and database is written in internet behavior management and control situation.
In a preferred embodiment of the invention, the method further includes:
SNMP access rights are opened for net control device on the three-tier switch, net control device passes through SNMPNetwork management protocol reads the correspondence of the IP address and MAC Address for each network segment network equipment that three-tier switch is stored, andListed Host List.
In a preferred embodiment of the invention, the method further includes:
The establishment monitoring network segment, the IP address for the three-tier switch port that three-tier switch egress gateways are connected and MACLocation is inserted in the monitoring network segment.
As shown in Fig. 2, further embodiment of this invention proposes a kind of control multisegment environment lower network equipment internet behaviorMethod, include the following steps:
S201:Packet filtering driving is installed on the gateway of net control device.
In the present embodiment, installation personnel can pre-set network behavior filtering rule to carry out crawl and mistake to messageFilter.
S202::The network segment VLAN1 net control device being connected to where three-tier switch first line of a couplet egress gateways;The IP address of the net control device is configured to the IP address of VLAN1, the gateway ip address of net control device is configured toThe IP address of egress gateways.
In the present embodiment, it is also necessary to which configuration refers to route on the three-tier switch first line of a couplet egress gateways in advance.
The network message of passback will be transmitted directly to the computer of each network segment by this egress gateways in this way, without passing through againCross the computer or device forwards of installation this system.
Since the public network downlink message without being returned to three-tier switch egress gateways is captured and is filtered, but by going outMouth gateway is transmitted directly to the computer of each network segment by way of referring to routing, so as to avoid because being grabbed to downlink messageTake, filter and forward and caused by network message delay, speed loss risk so that downlink message can directly with linear speed intoRow forwarding, to significantly reduce because network speed is slack-off caused by deployment network log-in management system, network performance declinesIt happens.
S203:SNMP access rights are opened for net control device on the three-tier switch, net control device is logicalIt crosses SNMP network management protocols and reads the IP address for each network segment network equipment that three-tier switch is stored and the corresponding pass of MAC AddressSystem, and listed Host List.
In order to accurately identify the computer of each network segment of three-tier switch, need on three-tier switch for installation this systemComputer or opening of device SNMP access rights, this sample system can read three layers in real time by SNMP Simple Network Management ProtocolsThe correspondence of the IP address and MAC Address of each network segment computer that interchanger is stored, and listed the master of this systemMachine list, consequently facilitating administrator can accurately identify this computer and configure internet policy for it.
S204:Create monitoring the network segment, the IP address for the three-tier switch port that three-tier switch egress gateways are connected andMAC Address is inserted in the monitoring network segment.
S205:The port that three-tier switch is connected to three-tier switch egress gateways sends ARP deception messages, makes this portThe gateway MAC address of storage becomes the MAC Address of net control device.
In the present embodiment, the port that three-tier switch is connected to three-tier switch egress gateways sends the ARP deceptions of gatewayThe IP address of the MAC Address of message namely net control device+three-tier switch egress gateways so that the net of this port storageClosing MAC Address becomes the MAC Address of net control device, then when this port receives each network segment computer uplink of three-tier switchIt will be sent directly on net control device, be driven by the network message filtering of net control device network interface card to grab after messageNetwork message is taken, and the network behavior filtering rule that administrator is previously set is installed to capture and filter to message, is metThe internet behavior control rule of administrator's setting is just directly let pass and is forwarded, and otherwise directly abandons message, is realized to three with thisThe management of each network segment online computing behavior of layer switch.
S206:The packet filtering driving installed on gateway by the net control device, which surfs the Internet to the network equipment, to be carried outControl.
S207:The port that three-tier switch is connected to three-tier switch egress gateways sends the correct message of gateway A RP.
When needing to stop controlling, the port that three-tier switch can be connected to three-tier switch egress gateways sends gatewayThe MAC Address of the correct message of ARP namely IP address+gateway of gateway, in this way this port can be by each network segments of three-tier switchThe uplink message that computer sends over is sent directly to the egress gateways of three-tier switch, to restore normal network messageCommunication.
S208:Network message in operational process is intercepted into daily record and database is written in internet behavior management and control situation.
In the present embodiment, write-in database can be in order to subsequent for future reference and audit.
As shown in figure 3, the invention also provides a kind of systems of multisegment environment lower network equipment online processed, including:
Module 301 is installed, for installing packet filtering driving on the gateway of net control device;
Configuration module 302, for the net control device to be connected to where three-tier switch first line of a couplet egress gatewaysNetwork segment VLAN1;The IP address of the net control device is configured to the IP address of VLAN1, the gateway IP of net control deviceAddress configuration is the IP address of egress gateways;
Sending module 303, the port for connecting three-tier switch to three-tier switch egress gateways send ARP deception reportsText makes the gateway MAC address that this port stores become the MAC Address of net control device;
Control module 304, the packet filtering installed on the gateway by the net control device drive to networkEquipment online is controlled.
In a preferred embodiment of the invention, this system further includes referring to routing module, in advance described threeConfiguration refers to route on layer switch first line of a couplet egress gateways.
In a preferred embodiment of the invention, this system further includes recovery module, for being exported to three-tier switchGateway connects the correct message of the port transmission gateway A RP of three-tier switch.
In a preferred embodiment of the invention, this system further includes journal module, is used for network in operational processMessage intercepts daily record and database is written in internet behavior management and control situation.
The method and system of control multisegment environment lower network equipment internet behavior proposed by the present invention, for L3 SwitchingThe three-tier switch port that machine egress gateways are connected carries out ARP deceptions, rather than directly local area network computer carries out gatewayARP is cheated, so as to avoid because installing ARP fire walls by control computer or to leading to nothing after gateway progress ARP static bindingsThe case where method carries out ARP deceptions, and thus network log-in management fails.
In conclusion following effect at least may be implemented in the embodiment of the present invention:
1, this system is due to being the network segment where being directly connected to three-tier switch upper outlet gateway, rather than passes through concatenationOr the mode of bridge joint is disposed, and the Single Point of Faliure for being easy to occur is disposed so as to avoid passing through concatenation or bridge mode, toAvoid the risk of network interruption.
2, this system carries out ARP deceptions for the three-tier switch port that three-tier switch egress gateways are connected, withoutIt is the ARP deceptions that direct local area network computer carries out gateway, so as to avoid because installing ARP fire walls or right by control computerThe case where gateway leads to not carry out ARP deceptions after carrying out ARP static bindings, and thus network log-in management fails.
3, this system is only captured, filtered and is controlled to the uplink message of each network segment computer of three-tier switch, is accorded withClosing the message of administrator's default access allows to pass through, and the message for violating administrator's default access rule directly abandons, just with thisThe management to online computing behavior may be implemented.Simultaneously as without the public network downlink returned to three-tier switch egress gatewaysMessage is captured and is filtered, but is transmitted directly to the computer of each network segment by way of referring to routing by egress gateways,So as to avoid because to the crawl of downlink message, filtering and forwarding and caused by network message delay, speed loss risk,Downlink message is directly forwarded with linear speed, is led because of deployment network log-in management system to significantly reduceThe case where network speed of cause is slack-off, network performance declines.
4, when where this system computer or the network equipment break down when, on the one hand can pass through the subsidiary network of systemRecovery tool sends the three-tier switch port that the correct IP of gateway and mac address information are connected to egress gateways in real time, fromAnd it can be with real-time recovery network communication.In addition, the egress gateways of three-tier switch can also be sent out to the port of connection three-tier switchThe IP and mac address information for giving itself update the IP and mac address information of the gateway cached in this port ARP entry, toRealize it is unattended in the case of the automatic function of restoring network communication, to realize safer internet behavior pipeReason.
5, in addition, the deployment of this system need not adjust existing network structure, it is only necessary to export net in three-tier switchThe network segment where closing need not adjust the other configurations of egress gateways and three-tier switch there are one port more than needed, fromAnd the workload and complexity of deployment this system are reduced, it is easy to implement more quick and efficient network management.
Finally, it should be noted that:The foregoing is merely presently preferred embodiments of the present invention, is merely to illustrate the skill of the present inventionArt scheme, is not intended to limit the scope of the present invention.Any modification for being made all within the spirits and principles of the present invention,Equivalent replacement, improvement etc., are included within the scope of protection of the present invention.

Claims (10)

CN201810230500.2A2018-03-202018-03-20A kind of method and system of control multisegment environment lower network equipment internet behaviorPendingCN108600170A (en)

Priority Applications (1)

Application NumberPriority DateFiling DateTitle
CN201810230500.2ACN108600170A (en)2018-03-202018-03-20A kind of method and system of control multisegment environment lower network equipment internet behavior

Applications Claiming Priority (1)

Application NumberPriority DateFiling DateTitle
CN201810230500.2ACN108600170A (en)2018-03-202018-03-20A kind of method and system of control multisegment environment lower network equipment internet behavior

Publications (1)

Publication NumberPublication Date
CN108600170Atrue CN108600170A (en)2018-09-28

Family

ID=63626914

Family Applications (1)

Application NumberTitlePriority DateFiling Date
CN201810230500.2APendingCN108600170A (en)2018-03-202018-03-20A kind of method and system of control multisegment environment lower network equipment internet behavior

Country Status (1)

CountryLink
CN (1)CN108600170A (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN110650093A (en)*2019-08-292020-01-03苏州浪潮智能科技有限公司Multi-network-segment access method and system for single operating system
CN110912928A (en)*2019-12-112020-03-24百度在线网络技术(北京)有限公司Firewall implementation method and device and electronic equipment
CN114363007A (en)*2021-12-102022-04-15包头海平面高分子工业有限公司九原分公司Internet surfing behavior control system and method based on single internet surfing behavior management device

Citations (5)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN102739433A (en)*2011-03-302012-10-17大势至(北京)软件工程有限公司Control method of local area network computer through network management software allocation based on multi-net environment of three-layer switch
CN102739512A (en)*2011-03-302012-10-17大势至(北京)软件工程有限公司Method for centrally filtering network data packet based on three-layer switchboard under multi virtual local area network (VLAN) environment
CN106453087A (en)*2016-08-112017-02-22宁波亦道信息科技有限公司Control method of local area network computer through network management software allocation based on multi-net-segment environment of three-layer switch
US20170302554A1 (en)*2016-04-182017-10-19Nyansa, Inc.System and method for using real-time packet data to detect and manage network issues
CN107332812A (en)*2016-04-292017-11-07新华三技术有限公司The implementation method and device of NS software

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN102739433A (en)*2011-03-302012-10-17大势至(北京)软件工程有限公司Control method of local area network computer through network management software allocation based on multi-net environment of three-layer switch
CN102739512A (en)*2011-03-302012-10-17大势至(北京)软件工程有限公司Method for centrally filtering network data packet based on three-layer switchboard under multi virtual local area network (VLAN) environment
US20170302554A1 (en)*2016-04-182017-10-19Nyansa, Inc.System and method for using real-time packet data to detect and manage network issues
CN107332812A (en)*2016-04-292017-11-07新华三技术有限公司The implementation method and device of NS software
CN106453087A (en)*2016-08-112017-02-22宁波亦道信息科技有限公司Control method of local area network computer through network management software allocation based on multi-net-segment environment of three-layer switch

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
CRAIG HUNT: "《TCP/IP网络管理》", 31 December 2000*
刘静: "《防火墙技术项目化教程》", 31 December 2015*

Cited By (5)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN110650093A (en)*2019-08-292020-01-03苏州浪潮智能科技有限公司Multi-network-segment access method and system for single operating system
CN110912928A (en)*2019-12-112020-03-24百度在线网络技术(北京)有限公司Firewall implementation method and device and electronic equipment
CN110912928B (en)*2019-12-112022-01-28百度在线网络技术(北京)有限公司Firewall implementation method and device and electronic equipment
CN114363007A (en)*2021-12-102022-04-15包头海平面高分子工业有限公司九原分公司Internet surfing behavior control system and method based on single internet surfing behavior management device
CN114363007B (en)*2021-12-102024-01-09包头海平面高分子工业有限公司九原分公司Internet surfing behavior management and control system and method based on single Internet surfing behavior management device

Similar Documents

PublicationPublication DateTitle
US11329913B2 (en)Avoiding asymetric routing in an SDWAN by dynamically setting BGP attributes within routing information advertised by an SDWAN appliance
US7224668B1 (en)Control plane security and traffic flow management
KR100653634B1 (en) Network traffic control system and method
US10530641B2 (en)Uninterrupted flow processing by a software defined network (SDN) appliance despite a lost or disrupted connection with an SDN controller
US7480707B2 (en)Network communications management system and method
CN1761240B (en) Smart Integrated Cyber Security Appliances for Highly Realizable Applications
JP2007531397A (en) Information transmission method in tree and ring topology of network system
CN108600170A (en)A kind of method and system of control multisegment environment lower network equipment internet behavior
CN107743109A (en) Protection method, control device, processing device and system for traffic attack
Tiso et al.Designing Cisco network service architectures (ARCH): Foundation learning guide
CN106612225A (en)Openstack based agent deployment system and method
CN101355464A (en)Electric control method and apparatus for monitoring network wire break and automatically restarting network equipment
CN111953661A (en) A SDN-based east-west traffic security protection method and system
US8526437B2 (en)Communication system and communication control device
CN108881127A (en)A kind of method and system of control remote access permission
CN106411863A (en)Virtualization platform for processing network traffic of virtual switches in real time
WO2024016642A1 (en)Sdn-based intelligent ship network system
CN112422348B (en) A power information data collection communication system and method
ByresDesigning secure networks for process control
JP2005244602A (en)Subscriber unit redundant system and subscriber unit redundant method
CN107682342B (en)Method and system for DDoS (distributed denial of service) flow traction based on openflow
CN114338422A (en)MPLS-based medium and large enterprise network and implementation method thereof
CN103534995A (en) A kind of inter-board communication method of router cluster, router and router cluster
CN112202756A (en)Method and system for realizing network boundary access control based on SDN technology
CN102055599A (en)Network management equipment for network management of computer

Legal Events

DateCodeTitleDescription
PB01Publication
PB01Publication
SE01Entry into force of request for substantive examination
SE01Entry into force of request for substantive examination
RJ01Rejection of invention patent application after publication

Application publication date:20180928

RJ01Rejection of invention patent application after publication

[8]ページ先頭

©2009-2025 Movatter.jp