A kind of based on network management interactive system and the exchange method of sharing NAT
Technical field
The present invention relates to the network device management technology, relate in particular to a kind of based on network management interactive system and the exchange method of sharing NAT.
Background technology
Along with the develop rapidly of computer networking technology, various types of communication equipment is widely used, and network size is also increasing.Stably move in order to ensure network-efficient, just need effectively manage the network equipment.
Because IPv4 (procotol the 4th edition) number of addresses is limited; Generally only limit to network management system and have public ip address; And its network equipment of managing (being managed devices) has been assigned with private network IP address, and the network management system that therefore has public ip address can't be managed the network equipment that has distributed private network IP address.
For the problems referred to above; Solution commonly used is that the equipment through network enabled address transition (NAT) connects between the network equipment of network management system and its management, carries out alternately through setting up certain protocol between the network equipment of network management system and its management then.But present network management becomes increasingly complex; Need the object of management also more and more; Therefore in carrying out the network management process, often have a plurality of network management systems, a plurality of network management protocols are like Simple Network Management Protocol (SNMP), Simple Object Access Protocol (SOAP) etc.At present for the good solution of neither one also of the mutual aspect between multiple network management system, multiple network management agreement and the managed devices.
Summary of the invention
Technical problem to be solved by this invention is: propose a kind ofly based on network management interactive system and the exchange method of sharing NAT, be implemented in when having a plurality of network management systems and a plurality of network management protocol in the network management process the effective management to managed devices.
The present invention solves the problems of the technologies described above the scheme that is adopted: a kind of based on the network management interactive system of sharing NAT, comprising: at least one network management system, at least one managed devices also comprise: share NAT ride through system and at least one NAT gateway;
Said shared NAT ride through system is used for receiving through the NAT gateway logon message of managed devices, and preserves the MAC Address of the managed devices that carries in public network address information and the logon message of managed devices, the mapping table of private net address information; And be used to receive the registration of network management system and preserve the IP address and the port of network management system, and the mapping table of managed devices is notified to the network management system that succeeds in registration;
Said network management system is used for obtaining the mapping table of managed devices through in shared NAT ride through system registration; According to the public network address information of the managed devices in the mapping table, send the NMP message to managed devices through the NAT gateway;
Said NAT gateway; Be used for and carry out from the NMP message of network management system sending to managed devices after the intranet and extranet address transition, and will carry out from the NMP response message of managed devices sending to shared NAT ride through system after the intranet and extranet conversion;
Said managed devices is used to receive and resolve that network management system sends carries out the NMP request message of address transition through the NAT gateway, sends the NMP response message to the NAT gateway after carrying out the order in the message.
Further, the public network address information of said managed devices information comprises the public network IP address and the port of managed devices, and the private net address information of carrying in the said logon message comprises the private network IP address and the port of managed devices.
Further, include multiple network management agreement processing module in said network management system and the managed devices, to realize processing to heterogeneous networks management agreement message.
Further, said network management system is registered through sending the register requirement message to shared NAT ride through system.
Concrete, said register requirement message content comprises: the message serial number, need carry out NMP, agreement that NAT passes through and receive and handle port, network management system IP address.
Further; IP address and port when said shared NAT ride through system also is used to preserve the network management system registration; Behind the network management response message that receives the managed devices transmission; Through the log-on message of the corresponding network management system of analytic message content search, thereby message is transmitted to the respective wire guard system.
A kind of based on the network management exchange method of sharing NAT, may further comprise the steps:
A. managed devices regularly sends logon message to shared NAT ride through system through the NAT gateway, in logon message, carries managed devices private net address information and MAC Address;
B. network management system is sent the register requirement message to shared NAT ride through system and is registered the log-on message of shared NAT ride through system preservation network management system;
The MAC Address that carries in the public network address information of c. shared NAT ride through system preservation managed devices and the logon message, the mapping table of private net address information; The mapping table of managed devices is notified to the network management system through registration;
D. network management system generates the NMP request message, according to the public network address information of managed devices, sends to the NAT gateway then;
E. managed devices is received in the NAT gateway through the procotol request message after the network address translation; And call corresponding NMP processing module and carry out dissection process.
Further, said method is further comprising the steps of:
F. after managed devices is handled the procotol request message that receives; Send the NMP response message to the NAT gateway; The NAT gateway encapsulates the address of purpose network management system and the NMP response message is carried out sending to shared NAT ride through system after the address transition in the NMP response message, share IP address and the port transmission NMP response message of NAT ride through system according to the network management system of preserving.
Further, among the step a, said managed devices sends the address aging cycle of the timing cycle of logon message less than the NAT gateway.
Further, among the step c, the public network address information of said managed devices information comprises the public network IP address and the port of managed devices, and the private net address information of carrying in the said logon message comprises the private network IP address and the port of managed devices.
The invention has the beneficial effects as follows: a plurality of NMSs unify a plurality of NMPs can multiplexing NAT ride through system and managed devices between the NAT passage; Thereby make network management system only need pay close attention to own service; And need not to be concerned about the position at managed devices place, reduced the complexity of network management; Have only a NAT passage lanes can effectively reduce network message between managed devices and each NMS simultaneously, improve the network bandwidth.
Description of drawings
Fig. 1 is of the present invention based on the network management interactive system structured flowchart of sharing NAT;
Fig. 2 is of the present invention based on the network management interactive system workflow sketch map of sharing NAT;
Fig. 3 is of the present invention based on the network management exchange method flow chart of sharing NAT.
Embodiment
Referring to Fig. 1, the network management interactive system based on sharing NAT among the present invention comprises:
Managed devices: need the registration at shared NAT ride through system place earlier, the private net address information of in logon message, carrying the MAC Address and the managed devices of managed devices, said private net address information comprises private network IP address and port;
Network management system: also need to register at shared NAT ride through system place earlier; Through sharing the essential information that the NAT ride through system can obtain managed devices; Comprise public network IP and port, MAC Address, private network IP address and port send the procotol message to managed devices then; The NAT passage lanes that utilizes shared NAT ride through system to provide simultaneously receives the procotol message of managed devices;
Share the NAT ride through system: accept the registration of managed devices and network management system; Preserve the IP address and the port of network management system respectively; And the public network IP of managed devices and port, MAC Address; The mapping table of private network IP address and port, thereby the NAT passage lanes between the network management system of foundation and the managed devices are according to NMP message transfer message between managed devices and network management system;
Network address translation (nat) gateway: be used for managed devices is carried out the intranet and extranet address transition;
Managed devices: receive and resolve network management system and send the procotol message, send the NMP response message to shared NAT ride through system after the order in the execution message.
Fig. 2 has shown the workflow of this system clearly: at first regularly registered to shared NAT ride through system through the NAT gateway by managed devices; The private net address information and the MAC Address of this managed devices have been carried in this logon message; Said managed devices sends the address aging cycle of the timing cycle of logon message less than the NAT gateway, shares the address transition mapping table that the NAT ride through system is preserved managed devices: comprise the public network IP address of managed devices and the MAC Address of port, private network IP address and port and managed devices; Network management system is also sent the register requirement message to shared NAT ride through system; Share the NAT ride through system register requirement message is handled (promptly whether allowing this network management system registration); And return registering result information to network management system, if allow the network management system registration to share IP address and the port that the NAT ride through system is preserved network management system; After network management system is successfully registered,, obtain the address transition mapping table of managed devices through to the information of sharing NAT ride through system inquiry managed devices; When needs carried out network management, network management system generated the NMP request message, and the row format encapsulation of going forward side by side is sent to the NAT gateway then; The NAT gateway is preserved the address of network management system and the NMP request message is carried out being sent to corresponding managed devices after the address transition; By managed devices the format message is resolved, and call corresponding NMP processing module and handle; Generate the NMP response message by managed devices subsequently, the row format encapsulation of going forward side by side is sent to the NAT gateway then.The NAT gateway encapsulates the address of network management system in the NMP response message, be sent to after the row address of the going forward side by side conversion and share the NAT ride through system; Share the NAT ride through system obtains the purpose network management system after resolving the format message IP address and port, will format message according to purpose IP address and port again and be sent to corresponding network management system; Corresponding network management system is called corresponding NMP processing module and is handled.
Referring to Fig. 3, the network management exchange method based on shared NAT among the present invention may further comprise the steps:
1. managed devices is registered to shared NAT ride through system; Carry the MAC Address of managed devices and the private network IP address and the port of managed devices in the logon message; Logon message arrives through the NAT gateway shares the NAT ride through system; Sharing the NAT ride through system preserves managed devices and comprises public network IP and port, MAC Address, the address transition mapping table of private network IP address and port;
2. network management system is registered to shared NAT ride through system: network management system is carried out NAT to certain NMP (like SNMP, SOAP etc.) if desired and is passed through; Then generate the register requirement message; The register requirement message information comprises: message serial number, the NMP, the agreement that need NAT to pass through receive and handle port, network management system server IP address etc., and network management system sends to logon message and shares the NAT ride through system then; Share the decision of NAT ride through system and whether allow registration: share the NAT ride through system and receive and also resolve the register requirement message, and take and whether the system processing power decision allows the register requirement of network management system according to its other resources; If allow, then preserve log-on message, and preserve the IP address and the port of network management system, if do not allow, registration failure then;
3. after network management system succeeds in registration,, obtain the address transition mapping table of managed devices to the information of sharing NAT ride through system inquiry managed devices; Generate the NMP request message according to the management service needs; Then the NMP message is encapsulated in the protocol data zone of XML (extend markup language) document, the XML document that will be packaged with the NMP request message again sends to through SOCKET (socket) shares the NAT ride through system; Wherein, the form of XML document is as shown in the table:
4. share the NAT ride through system and receive and resolve the XML document that is packaged with the NMP request; Obtain purpose IP address (being managed devices IP address) and destination interface, and transmit XML document to corresponding managed devices according to above-mentioned purpose IP address and destination interface;
5. after carrying out address transition and write down network management system IP address through the NAT gateway, the XML document that is packaged with the NMP request reaches corresponding managed devices;
6. corresponding managed devices receives and resolves the XML document that is packaged with the NMP request; And, call the corresponding protocol processing module and carry out protocol analysis and processing (promptly carrying out the management request of network management system) according to the NMP type that parses;
7. managed devices generates the NMP response message, then this NMP response message is encapsulated in the XML document, sends to share the NAT ride through system;
8. reach after after the XML document that is packaged with the NMP response message carries out address transition through the NAT gateway and encapsulates purpose network management system IP address and share the NAT ride through system;
9. share the NAT ride through system and receive and resolve the XML document that is packaged with the NMP response message; Obtain purpose IP address (being network management system IP address); Then according to the log-on message of the network management system of preserving; Find corresponding network management system port, the XML document that at last will be packaged with the NMP response message according to purpose IP address and port is transmitted to corresponding network management system;
10. network management system receives and resolves and is packaged with the XML document of NMP response message, and according to the NMP type, calls corresponding NMP processing module and carry out protocol analysis and processing.