CN100563255C - The partition method of Internet protocol storage area network and spacer assembly - Google Patents

The partition method of Internet protocol storage area network and spacer assembly Download PDF

Info

Publication number
CN100563255C
CN100563255C CNB2006100869065A CN200610086906A CN100563255C CN 100563255 C CN100563255 C CN 100563255C CN B2006100869065 A CNB2006100869065 A CN B2006100869065A CN 200610086906 A CN200610086906 A CN 200610086906A CN 100563255 C CN100563255 C CN 100563255C
Authority
CN
China
Prior art keywords
san
target side
iscsi
initiator
external network
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Expired - Fee Related
Application number
CNB2006100869065A
Other languages
Chinese (zh)
Other versions
CN1866966A (en
Inventor
李晓
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
New H3C Technologies Co Ltd
Original Assignee
Hangzhou H3C Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hangzhou H3C Technologies Co Ltd filed Critical Hangzhou H3C Technologies Co Ltd
Priority to CNB2006100869065A priority Critical patent/CN100563255C/en
Publication of CN1866966A publication Critical patent/CN1866966A/en
Application granted granted Critical
Publication of CN100563255C publication Critical patent/CN100563255C/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention discloses the partition method of a kind of IP SAN that is communicated with external network by fringe node, comprising: on fringe node, set up with external network in being connected of initiator; On fringe node, set up with IP SAN that the initiator is visited in being connected of target side; With the initiator be connected and with being connected of target side between transmit the iSCSI load of being carried.After using the present invention, external network can't be known situations such as internal structure among the IP SAN, route, can not directly visit storage system, has improved security of storage data; Because SAN and external network are isolated, SAN inside can be planned the IP address arbitrarily separately, has increased the independence of SAN.

Description

The partition method of Internet protocol storage area network and spacer assembly
Technical field
The present invention relates to SAN (Storage Area Network, storage area network) technology, relate in particular to the partition method and the spacer assembly of a kind of IP (Internet Protocol, Internet protocol) SAN network.
Background technology
After traditional storage system has experienced SCSI (Small Computer System Interface, attached small computer system interface) the direct-connected mode of cable, be to be main flow with FC (Fibre Channel, optical-fibre channel) always.The appearance of iSCSI (Internet Small Computer System Interface, internet attached small computer system interface) provides the means of another kind of transmission scsi command, and it can be shared storage resources in the IP scope.
ISCSI is IETF (Internet Engineering Task Force, the Internet engineering duty group) standard of Zhi Dinging, be used for the scsi data piece is mapped to the Ethernet data bag, the SCSI agreement that is about to the data storage device use is carried on the TCP/IP to be transmitted.Its supports the physical layer protocol of Ethernet, and allows to support the equipment of this agreement to be directly connected on the Ethernet switch of standard or the router to form IP SAN network.
The structure of classical ip SAN network and applied environment are as shown in Figure 1 in the prior art, in the SAN network, a plurality of IP storage systems insert IP network by IP Switch, and the main frame that is connected on the IP network can adopt the iSCSI agreement that these IP storage systems are conducted interviews.IP Switch in the SAN network carries out two layers or three layers of forwarding between external IP network and the SAN network, does not resolve the iSCSI agreement that is carried on TCP (Transmission Control Protocol, the transmission control protocol) agreement in the repeating process.
Make the main frame in the external network carry out visit to storage system in the IP SAN network by the iSCSI agreement, being used for that the IP storage system is carried out IP address, the tcp port number of the storage system of addressing just must be open to IP network.And the IP SAN information stores nucleus of user network often, its fail safe is very crucial for the user, the access mode of this opening makes that IP SAN is difficult to external network is carried out effective security protection, is subjected to virus, attack or information from external network threat such as to steal easily.
Simultaneously, when the IP address of storage system in the IP SAN network or routing iinformation change, all need to notify external network, increased network load.
Summary of the invention
The present invention will solve is that the safety measure that the open visit mode of SAN network in the prior art causes is difficult to carry out the problem bigger with network load.
The partition method of the IP SAN that is communicated with external network by fringe node of the present invention may further comprise the steps:
On fringe node, set up with external network in being connected of initiator;
On fringe node, set up with IP SAN that the initiator is visited in being connected of target side;
With the initiator be connected and with being connected of target side between transmit the internet attached small computer system interface iSCSI load of being carried.
Preferably, described method also comprises:
Preserve target side and inner inlet information thereof among the IP SAN on fringe node, wherein inner inlet is the inlet of target side;
The outside inlet information of target side is set on fringe node, wherein outside inlet for fringe node with being connected of initiator in the inlet that has, this outside inlet information is corresponding to target side that this initiator visited.
Preferably, described method also comprises after the outside inlet information of target side is set: fringe node is redirected to initiator's access request the outside inlet of target side.
Alternatively, target side and inner inlet information thereof regularly initiate to find that to target side session Discovery Session carries out by fringe node among the described preservation IP SAN in IPSAN.
Alternatively, target side and inner inlet information thereof are undertaken by operation the Internet store name service iSNS agreement in IP SAN among the described preservation IP SAN.
Preferably, described and initiator be connected with the connection that comprises carrying iSCSI standard session Normal Session being connected of target side.
The invention provides the spacer assembly of a kind of IP SAN and external network, comprise extranet access unit and SAN addressed location, wherein:
The extranet access unit be used for by with external network in being connected of initiator carrying out iSCSI and communicate by letter, will export memory access units to from the iSCSI load that this connection receives, and will connect by this from the iSCSI load of memory access units input and send;
Memory access units be used for by with IP SAN that the initiator is visited in being connected of target side send the iSCSI load that receives from the extranet access unit, and will export the extranet access unit to from the iSCSI load that target side receives.
Preferably, described device also includes message interest statement unit, is used for preserving the inside inlet and the outside inlet information of target side among the IP SAN;
Initiator's the outside inlet that is connected by this initiator access destination side carries out in described extranet access unit and the external network;
Described memory access units is carried out with the inside inlet that is connected by this target side of target side.
Preferably, described device also comprises the outer net request unit, is used for notifying the initiator with the outside inlet information of the target side that the initiator visited in the external network.
Preferably, described device also comprises the maintenance of information unit, is used for according to target side among the current IP SAN and inner inlet information updating inlet information unit thereof.
The invention provides another kind ofly, may further comprise the steps by isolating the partition method of the IP SAN that node is communicated with external network:
By isolating node and carrying out IP SAN being connected of external network and communicate by letter with the iSCSI of external network;
By isolating required iSCSI load in being connected acquisition and the iSCSI of external network communicates by letter of target side among node and the IP SAN.
Preferably, described method also comprises: safeguard target side and inlet information thereof among the current IP SAN on isolating node;
Described inlet information comprises inner inlet and corresponding outside inlet information, and inner inlet is the inlet of target side;
Described communication with the iSCSI of external network comprises that iSCSI finds the Discovery process, wherein is redirected the current outside inlet information of returning to external network initiator request target side in Discovery message in the Redirection message at iSCSI.
Preferably, described communication with the iSCSI of external network comprises iSCSI Normal Session, carries out with being connected of external network initiator by the outside inlet of isolation node with accessed target side;
The required iSCSI load of described acquisition and external network communication is specially in iSCSI Normal Session: to isolate node is the identical iSCSI NormalSession that carries out of initiator and accessed target side, obtain target side with the iSCSI load that sends that is connected of isolation node.
Preferably, describedly safeguard that on isolating node target side and inlet information thereof among the current IP SAN undertaken by regular transmissions Discovery message or application iSNS agreement.
Preferably, described isolation node surpasses 1, forms barrier point cluster;
Described method also comprises: isolate target side and inner inlet and outside inlet information on other isolation nodes in the node backup set group.
The present invention is by being connected the agency being communicated with on the fringe node of IP SAN and external network, make external network directly not visit the target side among the IP SAN, target side among the IP SAN and external network are kept apart, be convenient to the IP SAN application sets safety prevention measure efficiently that neutralizes; And the address of IP SAN network internal and routing iinformation variation can not impact the visit of external network, have reduced network load.
Description of drawings
Fig. 1 is the network structure of a kind of IP SAN in the prior art;
Fig. 2 is the network structure of IP SAN among the present invention;
Fig. 3 is the flow chart of IP SAN partition method embodiment one of the present invention;
Fig. 4 is the interaction diagrams between initiator, fringe node and the target side among the IP SAN partition method embodiment two of the present invention;
Fig. 5 is the structural representation of IP SAN spacer assembly of the present invention.
Fig. 6 uses the network structure of example for the present invention.
Embodiment
Main frame has been continued to use the customer end/server mode of SCSI to storage system based on the visit of iSCSI, and client is main frame normally, initiates read-write operation request to server; Server is storage system normally, the request of customer in response end.In field of storage, client is initiatively sent the storage operation instruction as initiator (Initiator), and server is as the storage operation instruction of target side (Target) passive response and execution client.
In order to satisfy the requirement of SCSI blocks of data (block data) inputoutput pair transmission reliability, in the iSCSI standard, adopt and carry the iSCSI agreement based on the Transmission Control Protocol that connects.Therefore, the target side in location needs the IP address and the tcp port number of its place network node on network, is called the inlet (Portal) of target side.The initiator connects according to the inlet and the target side of target side, finishes iSCSI memory access process by the iSCSI load that connects carrying.
IP SAN usually is connected with external network by one or more fringe node, its structure as shown in Figure 2, target side is connected at least one fringe node, with being communicated with of realization and external network initiator.For avoiding open access to target side among the IP SAN, can IP SAN and external network be kept apart by fringe node among the present invention, external network all by in fringe node, is proceeded to the iSCSI visit of objectives side to the iSCSI of IP SAN visit by fringe node.Like this, to the initiator in the external network, fringe node carries out iSCSI as the agency of each target side among the IP SAN with it and communicates by letter; To the target side among the IPSAN, fringe node carries out iSCSI as the agency of initiator in the external network with it and communicates by letter.When fringe node surpassed 1, the target side that each fringe node is acted on behalf of was different with other fringe nodes.
The flow process of IP SAN partition method embodiment one of the present invention as shown in Figure 3, at step S310, target side and the inner inlet information thereof among the IP SAN is collected and preserved to fringe node by iSCSI Discovery Session (discovery session).Inner inlet is the inlet of target side.
In the iSCSI standard, the initiator obtains the current configuration information of target side by Discovery Session, comprises the suction parameter of target side.In IP SAN inside, after fringe node and each target side are carried out Discovery Session, on fringe node, will preserve the inside inlet information of all target side among the IP SAN.
In some applications, target side and inner inlet information thereof may change because of the iSCSI storage operation.In order to guarantee the accuracy of target side in the fringe node and inner inlet information thereof, can make fringe node regularly initiate Discovery Session and obtain current target side's information.
At step S320, the outside inlet information of target side is set on fringe node.Outside inlet is the virtual inlet that is provided with on fringe node for each target side among the IP SAN, for the initiator in the external network target side conducted interviews, thereby to the information of outside net mask IP SAN inside.
Outside inlet information comprises the IP address and/or the tcp port number of target side.After the outside inlet information of target side is set, can on fringe node, preserve the inside inlet and the outside inlet information of target side by mapping table.Below be a kind of possibility form of this mapping table:
Inner inlet information Outside inlet information
Storage system IP address, the port numbers of this storage system in IP SAN Fringe node is to the IP address of external network, corresponding to the port numbers of this storage system
At step S330, the initiator of external network initiates Discovery Session to IP SAN.Undertaken communicating by letter by fringe node among the IP SAN with the iSCSI of external network, the inlet that carries out iSCSIDiscovery Session for the external network initiator is configured on the fringe node, this inlet has the effective address of external network, be used for each target side among the IP SAN is conducted interviews, can be regarded as the inlet of entire I P SAN.When externally the network initiator initiates Discovery Session, adopt inlet and the fringe node of IP SAN to connect.
At step S340, fringe node is redirected to the initiator of external network the outside inlet of this initiator access destination side.
In Discovery Session, the initiator informs the target side of its desire visit of fringe node by Discovery Message (discovery message); Fringe node finds the outside inlet of local target side of preserving, and informs that in Redirection Message (redirect message) initiator is redirected to another inlet with real request of data, and promptly the outside of initiator access destination side enters the mouth.
At step S350, the initiator of external network initiates iSCSI NormalSession (standard session) to the inlet that is redirected, and fringe node is set up iSCSI with the inlet that is redirected with the initiator and is connected.At this moment, fringe node is as the agency of target side real accessed among the IP SAN, response external network initiator's Normal Session.
At step S360, fringe node is searched the local inside corresponding with this outside inlet that preserve and is entered the mouth, and acts on behalf of the external network initiator and sets up iSCSI with target side be connected in IP SAN, is used for carrying out NormalSession.
At step S370, among the Normal Session, fringe node will from the iSCSI load that receives being connected of external network initiator by with IP SAN being connected of target side be sent to target side, and will from IP SAN target side be connected the iSCSI load that receives by being sent to the initiator with being connected of external network initiator.In other words, fringe node with external network be connected and with being connected of target side between transmit the iSCSI load of being carried.
Among the iSCSI Normal Session, the initiator is sent to target side with storage operation instruction and/or data encapsulation in iSCSI load, and target side returns to the initiator with instruction execution result and/or data encapsulation in iSCSI load.Fringe node sends to target side real among the IP SAN with it as the iSCSI load of acting on behalf of the target side reception, its iSCSI load as the execution result that comprises real target side among the IP SAN of acting on behalf of initiator's reception is sent to the initiator of external network, thereby finish the storage operation of external network initiator target side among the IP SAN.
In actual applications, according to concrete networking structure and demands of applications, some steps in the above-mentioned flow process can be omitted.For example, consider a kind of the simplest situation, in IP SAN, has only a target side, and during the configuration information of known this target side of initiator in the external network, fringe node the inlet of IPSAN can be omitted as the outside inlet of this target side outside inlet setting and with external network initiator's Discovery Session, execution in step S350 to S370 can realize the visit of initiator to target side.
The difference of IP SAN partition method embodiment of the present invention two and embodiment one is to adopt the iSNS agreement to carry out the collection process of target side among the IP SAN and inner inlet information thereof, with among the step S310 of alternate embodiment one by the Discovery Session between fringe node and the target side.Identical among other steps and the embodiment one.Equally, also can omit the some of them step according to practical situations.
The iSNS agreement is generally used for fairly large SAN, the storage system of operation iSNS agreement after the startup initiatively to target side and the configuration information such as inlet thereof of its iSNS server registration on it, and when above-mentioned information change notice iSNS server.The initiator can be to the configuration information of iSNS server lookup target side, and the information that obtains according to inquiry is initiated the storage operation to target side.
Need to prove that the iSNS server can be a fringe node among the embodiment two, also can be communication node in the external network.When the iSNS server is node in the external network, fringe node carries out the TCP agency equally between IP SAN internal node and iSNS server, parsing obtains IP SAN internal object side and configuration information thereof from the message of IP SAN, after wherein inside inlet information is revised as the outside inlet information of this target side, send to the iSNS server.At this moment, the external network initiator no longer carries out Discovery Session with fringe node, and the outside inlet information of target side that directly obtains with the iSNS server from external network is initiated Normal Session to fringe node.
When fringe node during as the iSNS server, the information interaction flow process among the embodiment two between initiator, fringe node and the target side as shown in Figure 4.Fringe node by and target side between iSNSDiscovery Process (discovery procedure) collect and preserve target side and configuration information thereof among the IP SAN; Among the Discovery Session between initiator and fringe node, to initiator's the target side information that DiscoveryMessage asked, fringe node is given the initiator with the outside inlet information-reply of target side in Redirection Message.The initiator initiates NormalSession according to the outside inlet information of target side, set up TCP with the fringe node of acting on behalf of as target side and be connected, fringe node initiates Normal Session and sets up TCP to connect as initiator agency accessed target side in IP SAN; Carry out in the process at Normal Session, fringe node copies as the Normal Session that target side is carried out with outside initiator to its NormalSession that carries out, promptly with the external network initiator be connected and with being connected of target side between transmit iSCSI load, the external network initiator is carried out storage operation to it is carrying out with being connected equally of target side; Normal Session finishes, and fringe node disconnects its TCP with the initiator respectively with target side and is connected.
As seen, external network is divided into two sections to the visit of IP SAN to carry out, connect between external network initiator and the fringe node and carry out external network and communicate by letter with the iSCSI of IP SAN, fringe node by with IPSAN in obtain and required information during the iSCSI of external network communicates by letter being connected of target side.For example, target side that iSCSI load comprises among the Discovery Session of fringe node and external network and configuration information thereof come from fringe node and IP SAN inside based among iSNS Discovery Process that is connected or the embodiment one and the Discovery Session between the target side; ISCSI load among fringe node and external network initiator's the Normal Session comes from the iSCSI load of being carried target side being connected in NormalSession among fringe node and the IP SAN.
Fig. 5 is the structural representation of IP SAN spacer assembly among the present invention, inlet information unit 530 is connected with extranet access unit 510, memory access units 520, outer net request unit 540 and maintenance of information unit 550 respectively, and extranet access unit 510 is connected with memory access units 520.Spacer assembly connects external network and IP SAN.
Target side in the inlet information unit 530 among the in store IP SAN and inner inlet information thereof and corresponding outside inlet information.The inside inlet information of target side among the current IP SAN and target side is collected in maintenance of information unit 550, is updated into the content of preserving in the message interest statement unit 530 when target side or its inner inlet information change.
Outer net request unit 540 response external network initiators' Discovery Session.Discovery request to the external network initiator, outer net request unit 540 inquiry inlet information units 530 obtain the outside inlet information of the target side of its request, in Redirection message, notify the initiator, carry out concrete storage access operations by Normal Session for it with the outside inlet information of target side.
Extranet access unit 510 response external network initiators' Normal Session.The external network initiator is to the Normal Session of the outside inlet of target side, and being connected of spacer assembly and external network initiator set up with the outside inlet of target side in extranet access unit 510, and notifies memory access units 520 with the outside inlet of target side.Memory access units 520 finds the inside inlet of the target side with this outside inlet from inlet information unit 530, connect to this inside inlet initiation Normal Session and with target side.
Extranet access unit 510 will be from exporting memory access units 520 to iSCSI load that being connected of external network initiator receives, and the iSCSI load-bearings that memory access units 520 will 510 inputs from the extranet access unit be sent to target side with being connected of target side.Treat to return the iSCSI load that target side is replied with being connected of target side, memory access units 520 exports this iSCSI load to extranet access unit 510.Extranet access unit 510 will be from the iSCSI load-bearing of memory access units input sending with being connected of external network initiator, as replying the external network initiator.
Like this, spacer assembly provides the normal visit of external network to target side when isolating IP SAN and external network.Be understood that spacer assembly can be applied on the fringe node among Fig. 2.
In the IP SAN network configuration in Fig. 6, isolate node and be communicated with the external IP network by access node or isolated controlling node.The present invention can be applied on the isolation node among Fig. 6, is that fringe node is used the partition method of IP SAN of the present invention or made spacer assembly of the present invention be operated in and isolates on the node to isolate node promptly.
Access node is not handled the iSCSI agreement, transmits and only carry out the IP message, and may be equipment such as three-layer network appliance or fire compartment wall in the prior art.Isolate node and can isolate the different target side of node with other by single agency, also can act on behalf of with other as a barrier point cluster and isolate node and the different target side of other barrier point clusters by a plurality of isolation nodes.
Can provide bigger bandwidth and better availability by a plurality of isolation nodes for its target side of acting on behalf of as a barrier point cluster.Barrier point cluster can have multiple implementation, for example both can comprise more than two and two and isolate node, by one of them as host node; Also can comprise and isolate node and isolated controlling node more than two and two.Usually cluster is responsible for synchronously or is backed up cluster information, received access request and determine and isolate the access request that the node response is received by that by host node or isolated controlling node.
Barrier point cluster needs information synchronous or backup to comprise this cluster agency's all target side and inner inlet and corresponding outside inlet information among the present invention.For example, when in the cluster each isolated target side that node is responsible for acting on behalf of when different with other isolation nodes in the cluster, can isolate node at each and back up other isolation target side that node is acted on behalf of and inside and outside inlet information thereof, so that other isolation nodes can be taken over its work when certain isolation node breaks down.About synchronously or back up the concrete mode of above-mentioned information, and the host node in the cluster or isolated controlling node receive the concrete mode of request and distribution load, and multiple realization has been arranged in existing Clustering, repeats no more herein.
Barrier point cluster can be communicated with external network by access node, also can directly connect external network.Especially in the cluster with isolated controlling node, the isolated controlling node can integrated cluster control and the function of access node, and barrier point cluster directly connects external network at this moment.
After using the present invention, external network can't be known situations such as internal structure among the IP SAN, route, can not directly visit storage system, has improved security of storage data; Because SAN and external network are isolated, SAN inside can be planned the IP address arbitrarily separately, has increased the independence of SAN.
The present invention can be used as software function module and is applied in the fire compartment wall, is deployed in the junction of SAN and external network, and the safeguard procedures that provide in conjunction with fire compartment wall provide better security performance for SAN.Also can in NAT (Network Address Translation, network address translation) equipment, use the present invention, realize the support that iSCSI is penetrated in the mode of ALG (Application Layer Gateway, ALG).
Above-described embodiment of the present invention does not constitute the qualification to protection range of the present invention.Any modification of being done within the spirit and principles in the present invention, be equal to and replace and improvement etc., all should be included within the claim protection range of the present invention.

Claims (12)

1. the partition method of an Internet protocol storage area network IP SAN, described IP SAN is communicated with external network by fringe node, it is characterized in that, said method comprising the steps of:
Preserve target side and inner inlet information thereof among the IP SAN on fringe node, wherein inner inlet is the inlet of target side; The outside inlet information of target side is set on fringe node, wherein outside inlet for fringe node with being connected of initiator in the inlet that has, this outside inlet information is corresponding to target side that this initiator visited;
On fringe node by described outside inlet information set up with external network in being connected of initiator;
Being connected on fringe node by target side among the IP SAN that described inner inlet information is set up with the initiator is visited;
With the initiator be connected and with being connected of target side between transmit the internet attached small computer system interface iSCSI load of being carried.
2. the partition method of IP SAN according to claim 1 is characterized in that, described method also comprises after the outside inlet information of target side is set: fringe node enters the mouth the outside that initiator's access request is redirected to target side.
3. the partition method of IP SAN as claimed in claim 1 or 2, it is characterized in that: target side and inner inlet information thereof regularly initiate to find that to target side session Discovery Session carries out by fringe node among the described preservation IP SAN in IP SAN.
4. the partition method of IP SAN as claimed in claim 1 or 2, it is characterized in that: target side and inner inlet information thereof are undertaken by operation the Internet store name service iSNS agreement in IP SAN among the described preservation IP SAN.
5. as the partition method of IP SAN as described in any one of the claim 1 to 2, it is characterized in that: described and initiator be connected with the connection that comprises carrying iSCSI standard session NormalSession being connected of target side.
6. the spacer assembly of IP SAN and external network is characterized in that, comprises extranet access unit and memory access units, wherein:
The extranet access unit be used for by with external network in being connected of initiator carrying out iSCSI and communicate by letter, will export memory access units to from the iSCSI load that this connection receives, and will connect by this from the iSCSI load of memory access units input and send;
Memory access units be used for by with IP SAN that the initiator is visited in being connected of target side send the iSCSI load that receives from the extranet access unit, and will export the extranet access unit to from the iSCSI load that target side receives;
Described device also includes message interest statement unit, is used for preserving the inside inlet and the outside inlet information of target side among the IP SAN; Initiator's the outside inlet that is connected by this initiator access destination side carries out in described extranet access unit and the external network; Described memory access units is carried out with the inside inlet that is connected by this target side of target side.
7. as the spacer assembly of IP SAN as described in the claim 6 and external network, it is characterized in that: described device also comprises the outer net request unit, is used for notifying the initiator with the outside inlet information of the target side that the initiator visited in the external network.
8. as the spacer assembly of IP SAN as described in claim 6 or 7 and external network, it is characterized in that: described device also comprises the maintenance of information unit, is used for according to target side among the current IP SAN and inner inlet information updating inlet information unit thereof.
9. the partition method of an IP SAN, described IP SAN is communicated with external network by isolating node, it is characterized in that, said method comprising the steps of:
On isolating node, safeguard target side and inlet information thereof among the current IP SAN; Described inlet information comprises inner inlet and corresponding outside inlet information, and inner inlet is the inlet of target side;
By isolating node and carrying out IP SAN being connected of external network and communicate by letter with the iSCSI of external network; Described communication with the iSCSI of external network comprises that iSCSI finds the Discovery process, wherein is redirected the current outside inlet information of returning to external network initiator request target side in discovery Discovery message in the Redirection message at iSCSI;
By isolating required iSCSI load in being connected acquisition and the iSCSI of external network communicates by letter of target side among node and the IP SAN.
10. as the partition method of IP SAN as described in the claim 9, it is characterized in that: described communication with the iSCSI of external network comprises iSCSI standard session Normal Session, carries out with being connected of external network initiator by the outside inlet of isolation node with accessed target side;
The required iSCSI load of described acquisition and external network communication is specially in iSCSI standard session NormalSession: to isolate node is that initiator and accessed target side are carried out identical iSCSI standard session Normal Session, obtain target side with the iSCSI load that sends that is connected of isolation node.
11. the partition method as IP SAN as described in claim 9 or 10 is characterized in that: described target side among the current IP SAN and the inlet information thereof safeguarded on isolating node is found Discovery message by regular transmission or is used the iSNS agreement and carry out.
12. the partition method as claim 9 or 10 IP SAN as described in any is characterized in that: described isolation node surpasses 1, forms barrier point cluster;
Described method also comprises: isolate target side and inner inlet and outside inlet information on other isolation nodes in the node backup set group.
CNB2006100869065A 2006-06-14 2006-06-14 The partition method of Internet protocol storage area network and spacer assembly Expired - Fee Related CN100563255C (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CNB2006100869065A CN100563255C (en) 2006-06-14 2006-06-14 The partition method of Internet protocol storage area network and spacer assembly

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CNB2006100869065A CN100563255C (en) 2006-06-14 2006-06-14 The partition method of Internet protocol storage area network and spacer assembly

Publications (2)

Publication Number Publication Date
CN1866966A CN1866966A (en) 2006-11-22
CN100563255C true CN100563255C (en) 2009-11-25

Family

ID=37425849

Family Applications (1)

Application Number Title Priority Date Filing Date
CNB2006100869065A Expired - Fee Related CN100563255C (en) 2006-06-14 2006-06-14 The partition method of Internet protocol storage area network and spacer assembly

Country Status (1)

Country Link
CN (1) CN100563255C (en)

Families Citing this family (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101115009B (en) * 2007-08-31 2010-06-02 杭州华三通信技术有限公司 Storage resource access control method, storage control system and applied host machine
CN101136929B (en) * 2007-10-19 2010-08-25 杭州华三通信技术有限公司 Internet small computer system interface data transmission method and apparatus
US8725875B2 (en) * 2011-06-21 2014-05-13 Intel Corporation Native cloud computing via network segmentation
WO2016106661A1 (en) * 2014-12-31 2016-07-07 华为技术有限公司 Access control method for storage device, storage device, and control system
CN106789952B (en) * 2016-11-30 2020-05-15 用友优普信息技术有限公司 Method and system for serving local area network into internet
CN108696395B (en) * 2018-05-23 2021-06-25 湖南麒麟信安科技股份有限公司 Network switching device under multi-network isolation environment and application method thereof

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
NAT技术及应用. 彭湘凯.计算机应用与软件,第2003年02期. 2003
NAT技术及应用. 彭湘凯.计算机应用与软件,第2003年02期. 2003 *

Also Published As

Publication number Publication date
CN1866966A (en) 2006-11-22

Similar Documents

Publication Publication Date Title
CN100563255C (en) The partition method of Internet protocol storage area network and spacer assembly
CN101557417B (en) Method and apparatus for HBA migration
JPH1127320A (en) Packet relay control method, packet repeater and program storage medium
CN101572643B (en) Method and system for realizing data transmission among private networks
JPH06243103A (en) Parallel computer system
CN101257523A (en) Method for supporting IP network interconnectivity between partitions in a virtualized environment
CN103973424B (en) Failure in caching system solves method and apparatus
CN101827039B (en) Method and equipment for load sharing
CN104168257A (en) Data isolation device based on non-network mode, and method and system thereof
CN104202420B (en) A kind of method and apparatus for supporting Internet of things middleware cluster expansion
CN102811219A (en) Method for remotely accessing desktop of computer in intranet across network segments in cluster system
US6965934B1 (en) Encapsulation protocol for linking storage area networks over a packet-based network
CN1905495B (en) Network monitoring device, network monitoring method, network system and network communication method
CA2391353A1 (en) Encapsulation protocol for linking storage area networks over a packet-based network
CN100490393C (en) Method for accessing user network management platform
CN102882733B (en) A kind of cross-over NAT equipment realizes WEB network management method
CN105592050B (en) It is a kind of prevent attack method and firewall
JP4619943B2 (en) Packet communication method and packet communication system
US10924397B2 (en) Multi-VRF and multi-service insertion on edge gateway virtual machines
CN101201723A (en) Virtual disc router system, virtual disc accesses system and method
CN100469054C (en) Method and equipment in use for communication connection of redirecting network
US20210352004A1 (en) Multi-vrf and multi-service insertion on edge gateway virtual machines
CN109981437B (en) Multi-data center intercommunication method based on VPC and related equipment
CN101170544A (en) A communication method in high-availability cluster system based on single practical IP address
CN114422301B (en) Gateway for traversing NAT based on P2P-VPN technology

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CP03 Change of name, title or address
CP03 Change of name, title or address

Address after: 310052 Binjiang District Changhe Road, Zhejiang, China, No. 466, No.

Patentee after: Xinhua three Technology Co., Ltd.

Address before: 310053 Hangzhou hi tech Industrial Development Zone, Zhejiang province science and Technology Industrial Park, No. 310 and No. six road, HUAWEI, Hangzhou production base

Patentee before: Huasan Communication Technology Co., Ltd.

CF01 Termination of patent right due to non-payment of annual fee
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20091125

Termination date: 20200614