Background technology
In the communications field, the equipment redundancy backup is meant by certain technology, two physical equipments can be used as an equipment in logic.With the router as access controller (AC) is example, present Virtual Router Redundancy Protocol (Virtual Router Redundancy Protocol, VRRP) (Hot Standby Router Protocol, HSRP) (with reference to RFC2281) can support the routing forwarding redundancy for (with reference to RFC3768), Hot Standy Router Protocol.Router provides heterogeneous network interconnected mechanism, realizes an output packet is sent to another network.And route is exactly the routing information that instructs the IP packet to send.Routing Protocol is exactly regulation and the standard of appointing in advance in instructing IP packet process of transmitting.Routing iinformation transmits between neighboring router, guarantees that all-router knows the path of other router.In Routing Protocol, network topology structure is described by creating routing table.Route Selection and packet forwarding capability are carried out in Routing Protocol and route collaborative work.
Fig. 1 is the schematic diagram that is used to illustrate the notion of dynamic routing protocol.As shown in Figure 1, router-A is only known and the own direct-connected 192.168.1.0/24 network segment and the existence of the 192.168.2.0/24 network segment, does not know the existence of the 192.168.3.0/24 network segment.And router B only knows and the own direct-connected 192.168.2.0/24 network segment and the existence of the 192.168.3.0/24 network segment, does not know the existence of the 192.168.1.0/24 network segment.Pass through Routing Protocol, router-A is issued the routing iinformation of 192.168.1.0/24 on interface B, router B issues the routing iinformation of 192.168.3.0/24 on interface A, thereby makes router B know that routing iinformation, the router-A of the 192.168.1.0/24 network segment know the routing iinformation of the 192.168.3.0/24 network segment.In Fig. 1, also show the dynamic routing table of each router and have PC (Personal Computer, PC) terminal that data send demand.
Fig. 2 illustrates the mechanism that realizes redundancy backup in the prior art by the VRRP agreement.As shown in Figure 2, main with access controller (AC) and backup AC formation redundancy backup group.In Fig. 2, a master works simultaneously with AC and a backup AC.Backup AC only uses as backup under the normal condition.Main network side and user side interface person with AC enables a VRRP example, backs up simultaneously and enables on the AC and the main corresponding VRRP example of VRRP example with AC.At user side, the master uses down link (Downlink) VRRP virtual address and access point (AP) to set up the tunnel with AC; At network side, the master uses up link (Uplink) VRRP virtual address and Radius server to carry out authentication and accounting with AC.
Main as follows with the back-up job flow process of carrying out between AC and the backup AC:
1, at first, create high available network on AC and backup AC and insert example (High Available Network Access Instance HANASI), adds and enables the AC interface IP address of identical HANASI and the virtual ip address of VRRP thereof main.Generally need main two virtual ip address of Uplink, Downlink of configuration with AC and backup AC.
2, main AC of using and backup AC back up the two-layer protocol based on VRRP.For these two virtual addresses can correctly be worked, main with AC and fully Uplink, the Downlink heartbeat line between the AC must belong to a double layer network respectively separately together.
The Uplink virtual address is mainly used in network equipments such as Radius server, Portal server and communicates, thereby guaranteeing that authentication and accounting is smooth and easy carries out.The Downlink virtual address is mainly used in AC and sets up the tunnel connection with user side equipments such as AP, guarantees management and the control of AC to AP and user.In addition, if the gateway of wireless terminal is arranged on the AC, also need be on AC the virtual address gateway of configure user.
3, determine main and standby relation by the VRRP agreement between the AC.Simultaneously, main with setting up privately owned synchronous tunnel by the heartbeat line between AC and the backup AC, main synchronously with the user profile on AC and the backup AC.
4, behind the AP access network, AP at first sends the DISCOVER broadcasting packet and seeks AC.If AC and AP coexist in the double layer network, then mainly return virtual IP address and the virtual MAC address thereof of Downlink to AP with AC, AP sets up CAPWAP tunnel with AC by the virtual MAC address with leading, thereby obtains required configuration and upgrade file.
If AP is connected by three-layer network with AC, then AP searches the IP address of AC by DHCP option43 message or DNS message, perhaps obtain the IP address of AC by the address of static configuration among the AP, this IP address is the Downlink virtual address that disposes among the HANASI.AP sets up CAPWAP tunnel with main with AC by this address, thereby obtains required configuration and upgrade file.
Meanwhile, mainly communicate based on network equipments such as Uplink virtual address and Radius server, Portal server with AC.
5, main multidate information (managed AP and enter stable operation or offline information, authentification of user by reaching the standard grade or offline information) after will stablizing by privately owned synchronous tunnel with AC and backup AC etc. is synchronized to and backs up on the AC.
6, backup AC continues to accept the main hello packet that AC sent out of using by the heartbeat line, and the main state with AC of detecting.In case in official hour, do not receive main hello packet with AC, then backing up AC thinks main and breaks down with AC that (reason of the generation of fault may be the complete machine fault, or certain enables the AC interface fault of HANASI, also can be based on the switching condition of customizations such as packet loss, time delay, QOS), backup AC is automatically upgraded to main with AC and external issue gratuitous ARP packet, broadcasts the main AC identity of using of oneself.
7, after backup AC enables, all AP all set up the tunnel with backup AC and are connected, and AC authenticates accordingly and manages by backup, and carries out corresponding business.
8, main recover with AC after, backup AC abandons main with the AC identity and be reduced into and back up AC.Original fault AC switches to new master and uses AC.The CAPWAP tunnel of AP automatically switches to new master with on the AC, and network equipments such as Radius server automatically switch and to communicate by letter with AC with new master.
9, after the master reactivated with AC, all new AP all set up the tunnel with the master with AC and are connected, and authenticated accordingly and managed with AC by main, and carry out corresponding business.
The shortcoming of prior art scheme
In the scheme of prior art, all be based on the active and standby switching that the VRRP agreement realizes, and the subject matter of VRRP is: main AC and the backup AC of using can only be in same double layer network, the switching of link can only change the ARP cache of self by the notice uplink downlink that sends of gratuitous ARP, thereby realizes the switching of link.If active and standby AC is not in same double layer network, then link can't switch, and causes network to interrupt, and can't guarantee the reliability of network, also just can't realize the strange land redundancy backup of equipment.
Summary of the invention
The invention provides a kind of method of utilizing dynamic routing protocol to realize the strange land redundancy backup of router, can come the scope of expansion equipment redundancy, realize the function of heat backup at different sites part by utilizing proprietary protocol and dynamic routing protocol.
To achieve these goals, according to an aspect of the present invention, the strange land redundancy backup method of a kind of access controller system, described access controller system comprises two access controllers, described two access controllers are arranged in different double layer networks, and described method comprises: the interface IP address of each access controller of configuration access control system and the proprietary protocol and the dynamic routing protocol that will use in the access controller system; Described two access controllers are consulted main and standby relation by proprietary protocol, determine a main access controller and the backup access controller used from described two access controllers; The master issues the uplink interface of access controller system and the virtual host address of downlink interface with access controller by dynamic routing protocol; The master is undertaken synchronously by privately owned synchronous tunnel with access controller and backup access controller; Take place when unusual with access controller when main, the backup access controller switches to the main access controller of using, by the main access controller identity of using of proprietary protocol broadcasting oneself, and by the uplink interface of dynamic routing protocol issue access controller system and the virtual host address of downlink interface.
According to an aspect of the present invention, the strange land redundancy backup method also comprises: when former master recovers just often to operate as the backup access controller with access controller.
According to an aspect of the present invention, the strange land redundancy backup method also comprises: when former master recovers just often with access controller, describedly formerly main consult main and standby relation again with access controller and become again to lead to use access controller with current master with access controller, current master switches to the backup access controller with access controller and carries out work.
According to an aspect of the present invention, described dynamic routing protocol is any one in routing information protocol RIP, ospf ospf protocol, Intermediate System-to-Intermediate System Intermediate System to Intermediate System and the Border Gateway Protocol (BGP).
According to an aspect of the present invention, the master sets up privately owned synchronous tunnel with access controller and backup access controller by the heartbeat line.
According to an aspect of the present invention, in the switch step of strange land redundancy backup method, if the master does not receive from the affirmation message that backs up access controller in the given time with access controller, then the master carries out switch step with access controller notice backup access controller.
According to an aspect of the present invention, the backup access controller receives the main predetermined message that sends with access controller by synchronous tunnel, if in official hour, receive main described predetermined message, then back up access controller and determine mainly to break down and begin switch step with access controller with access controller.
According to an aspect of the present invention, the backup access controller determines whether to carry out switch step based at least one condition in packet loss, time delay, the service quality QoS.
Embodiment
Below, describe embodiments of the present invention in detail with reference to accompanying drawing.
Fig. 3 is the schematic diagram that illustrates according to the configuration of the access control system that can realize the strange land redundancy backup of the embodiment of the invention.
As shown in Figure 3, the access control system that can realize the strange land redundancy backup according to the embodiment of the invention comprises a main access controller (AC) and the backup AC of using.The master can reach by network with AC and backup AC, by the privately owned connection of heartbeat link establishment tunnel.
The access control system of the strange land redundancy backup of Fig. 3 is different with the system with the layer network redundancy backup of the prior art, and its master can be not limited in the same double layer network with AC and backup AC.Main with AC and backup AC formation redundancy backup group.
In access control system according to mobile redundancy backup of the present invention, the main AC of using and the backup AC that are in the different double layer networks upward create high available network access example (High Available NetworkAccess Instance, HANASI), and use proprietary protocol to specify the IP address of the HANASI of opposite end, connect thereby set up synchronously, consult main and standby relation.Main with setting up privately owned synchronous tunnel between AC and the backup AC, carry out the synchronous of user profile.Here, can between the master is with AC and backup AC, set up privately owned synchronous tunnel by the heartbeat line.At user side, AC uses Downlink virtual interface and AP to set up the tunnel, AP is connected by three-layer network with AC, AP searches the IP address of AC by option43 message or DNS message, perhaps obtain the IP address of AC by the address of static configuration among the AP, this IP address is the Downlink virtual interface address that disposes among the HANASI.AP sets up CAPWAP tunnel with main with AC by this address, thereby obtains required configuration and upgrade file.At network side, AC uses Uplink virtual interface and Radius server to carry out authentication and accounting.The Uplink virtual interface is mainly used in network equipments such as Radius server, Portal server and communicates, thereby guaranteeing that authentication and accounting is smooth and easy carries out.The Downlink virtual interface is mainly used in AC and sets up the tunnel connection with user side equipments such as AP, guarantees management and the control of AC to AP and user.For two virtual interfaces of Uplink and Downlink can correctly be routed to by other equipment in the network, the master releases the virtual address by dynamic routing protocol with AC as the main frame route.Here, dynamic routing protocol for example can be any one in routing information protocol (rip), ospf (OSPF) agreement, Intermediate System-to-Intermediate System (IS-IS) agreement, the Border Gateway Protocol (BGP).In addition, if the gateway of terminal is arranged on the AC, also need be on AC the virtual address gateway of configure user, and release by the route of dynamic routing protocol with terminal.Take place when unusual with AC when main, backup AC switches to the main AC that use, and the master own by proprietary protocol broadcasting uses the AC identity, and issues the Uplink interface of access controller system and the virtual host address of Downlink interface by dynamic routing protocol.
Describe redundancy backup method in detail with reference to Fig. 3 and Fig. 4 below according to the access control system of the embodiment of the invention.
In the present invention, be that the master has defined following state machine with AC and backup AC:
Readiness before Init:HANASI starts;
Master: finish the example major function, for example transmit the message of this AC group, send hello packet for backup AC;
Back:, monitor the main AC that uses that is in the Master state with backup AC role;
Learning:Master elects state;
Transfer: the process status that refers in active and standby switching, need back up some wireless-control or easy-access-gateway data;
Disable: refer to that main is the disabled state of state machine behind the link down with the Uplink on the AC, Downlink or heartbeat Link State.
When starting working according to the access control system of the redundancy backup of the embodiment of the invention, at first, in step 410, the interface IP address of each AC of configuration access control system and the proprietary protocol and the dynamic routing protocol that will use.Particularly, on each AC of access control system, create the HANASI example, specify to add and enable the AC interface of identical HANASI and the virtual ip address of proprietary protocol thereof, and dispose the Routing Protocol that will in route is synchronous, use.Here, need up link (Uplink) virtual interface and down link (Downlink) virtual interface of each AC of configuration access control system usually, configuration virtual IP address (this IP address is the loop-back address of 32 bitmasks).This moment, the state of each AC was Init.
As shown in Figure 3, in this example, main Uplink real address with AC is 192.168.1.1/24 before active and standby switching, the Uplink virtual address is 192.168.10.1/32, the Downlink real address is 172.16.1.1/24, and the Downlink virtual address is 192.16.20.1/32, and the Uplink real address of the backup AC before switching is 192.168.2.1/24, the Downlink real address is 172.16.2.1/24, and Uplink virtual address and Downlink virtual address do not exist.As can be seen, the master is in the different double layer networks with backup AC with AC.By specifying opposite end heartbeat (heartbeat) interface IP address, the heartbeat of setting up logic between the master is with AC and backup AC connects, thereby can use the dynamic routing protocol negotiation and switch main and standby relation.
Next, in step 420, each AC election of access control system is main with AC and backup AC.Particularly, after the configuration of step 410 was finished, each AC enabled the HANASI example, and this moment, each AC was in the Learning state, and sent the clean culture hello packet to opposite end AC, announced the correlation attribute information such as HANASI instance number, priority of oneself.The example of hello packet is shown in Figure 5, will be described after a while.After opposite end AC receives this hello packet, extract attribute information, according to self attributes information, select active and standby AC, and selection result is notified the other side's self attribute information and active and standby election results by hello packet, after the other side receives this hello packet, elect main and standby relation, if the main and standby relation unanimity then finishes the Learning state, according to selection result, enter Master or Back state separately.The AC (that is, the main AC that uses) that enters the Master state periodically sends hello packet, and the AC of notice Back state (that is backup AC) safeguards state separately.
Subsequently, in step 430, the master carries out backed up in synchronization with AC and backup AC by privately owned synchronous tunnel.Main multidate information (managed AP and enter stable operation or offline information, authentification of user by reaching the standard grade or offline information) after will stablizing by privately owned synchronous tunnel with AC and backup AC etc. is synchronized to and backs up on the AC.When the master changed with the last multidate information of AC, the multidate information of change was synchronized on the backup AC.
Then, in step 440, main with the virtual host address of AC by dynamic routing protocol issue Uplink interface and Downlink interface.Particularly, in the present embodiment, the master who is in the Master state joins its interface Uplink and Downlink in the protocol domain of Routing Protocol with AC, and the virtual host address of interface Uplink and Downlink is released by dynamic routing protocol; Be in the AC of other states outside the Master state, its interface Uplink and Downlink are cancelled from the protocol domain of Routing Protocol, outwards do not issue the fictitious host computer route.
In step 450, when main going up with AC takes place will back up AC and switch to the main AC that uses when unusual.Particularly, according to one embodiment of the invention, if lead the affirmation message that does not receive the backup AC of Back state with AC in the given time, then main state exchange with AC is the Transfer state, and notice backup AC carries out active and standby switching.After giving notice, former master is the Disable state with the AC state exchange, and no longer the main of broadcasting oneself used the AC identity, and interface Uplink and Downlink are cancelled from the protocol domain of Routing Protocol, stops outwards to issue the fictitious host computer route.The backup AC that is in the Back state begins to be transformed into the Transfer state after receiving main active and standby switching message with AC.
Alternatively, main with the active and standby switching message of AC except receiving, backup AC also can receive main with the hello packet that AC sent out by the heartbeat line at any time, and the main state with AC of detecting.If in official hour, do not receive main hello packet with AC, then backing up AC thinks main and breaks down with AC that (generation of fault may be the complete machine fault, or certain enables the AC interface fault of HANASI), then back up AC and be transformed into the Transfer state and carry out data sync.The condition that backup AC also can be based on packet loss, time delay, service quality customizations such as (QoS) determines whether to switch.Backup AC enters the Master state from the Transfer state subsequently, and beginning periodically sends hello packet with the Master state of notifying the other side oneself and the main AC identity of using of broadcasting oneself.Simultaneously, former backup AC releases the virtual host address of interface Uplink and Downlink by Routing Protocol, will point to former main route with AC by Routing Protocol and point to oneself in network.So just realize the route switching in the active and standby handoff procedure, kept the unimpeded of network.After switching, all AP all set up the tunnel with the AC of new Master state and are connected, and authenticate accordingly and manage by the backup AC that is in the Back state, and carry out corresponding business.As shown in Figure 3, after active and standby switching was finished, 192.168.10.1/32 was changed in the Uplink virtual address of former backup AC, and Downlink changes into 172.16.2.1/24 in the virtual address, and is identical with the Downlink virtual address with former main Uplink with AC.
By above step, former backup AC has finished handover operation.After this, if former master recovers normal with AC, then former master will that is to say that with AC former main state with AC becomes the Back state from the Disable state as backup AC work, and carry out backed up in synchronization with new master with AC and operate.
Selectively, in according to another embodiment of the present invention, after the master recovered normally with AC, each AC of access control system carried out active and standby election again and uses AC with the master that election makes new advances.Particularly, after former master recovered operate as normal with AC, each AC of access control system received from former main hello packet with AC, and each AC of access control system carries out above-mentioned step 420 and re-elects the main AC that uses.New master releases the fictitious host computer routing iinformation of its interface Uplink and Downlink with AC by dynamic routing protocol, broadcast the main AC identity of using of oneself.The CAPWAP tunnel of AP automatically switches to new master with on the AC, and network equipments such as Radius server automatically switch and to communicate by letter with AC with new master.After new master enabled with AC, all new AP all set up the tunnel with new master with AC and are connected, and authenticate accordingly and manage with AC by new master, and carry out corresponding business.
Fig. 5 shows the form according to the hello packet that sends of the embodiment of the invention between the master is with AC and backup AC.
As shown in Figure 5, this message comprises following field:
Version: version, length are 4, are defined as 2 in the present embodiment;
Type: type, length are 4, have only defined a kind type in the present embodiment: the announcement data, and value is 1;
Virtual AC ID: the ID of virtual A C, length is 8;
Priority: priority, length is 8, the priority that possesses the equipment of redundant IP address is 255;
IP number of addresses in the Count IP Addrs:hello message, length is 8, comprises the ip address number that Uplink or Downlink interface have;
Command: command field is used for carrying out the mandatory order conversion between the master is with AC and backup AC;
Adver Int: main with the time delay of AC process by heartbeat line transmission advertisement message, in the present embodiment, be defaulted as 2;
Checksum: verification and, length is 16, the checking data scope is this hello packet data, promptly the data that begin from version field do not comprise the IP head;
IP Address (es): the IP address relevant with virtual A C, quantity is determined by Count IP Addrs;
Reserve: reserved field;
Old master IP: former main IP with the AC process, when backup AC process receives that a certain master with behind the hello packet of AC, deposits the other side's source IP in the Old_master_ip of oneself.Upgrade to main when using AC when cause backing up AC owing to a certain reason (for example packet receiving is overtime), the AC that be about to upgrade to main usefulness this moment inserts Old_master_ip in the hello packet of its transmission, thereby makes the judgement of leaving Master state and definite next state after making that in the current example other are main and receiving message with the AC process;
Uplink ip/Downlink IP: the virtual ip address of the Uplink/Downlink of this HANASI example;
Updown flag: indicate current message to belong to Uplink or Downlink in logic;
Querry flag: main clock synchronization mark with AC and backup AC;
IPAddress (n):, the IP address of n Up/Downlink of current process is write n field successively according to the value of Count IPAddrs and Updown flag.
Should be understood that above only is an example of hello packet.Those skilled in the art can define the form of hello packet as required voluntarily.
By adopting the strange land redundancy backup method of access controller of the present invention, realize active and standby negotiation and switching by proprietary protocol between master/slave device.In addition, according to the present invention, main equipment elect successfully or active and standby handover success after, main equipment is not issued the gratuitous ARP (being the mode of VRRP) of redundant address, but the notice dynamic routing protocol (OSPF, RIP, IS-IS, BGP etc.) issue redundant address route.Perhaps directly use the address of loopback interface as redundant address; Active and standby equipment disposes identical loop-back address (32 bitmask) on virtual interface, at interfaces enabled dynamic routing protocol (OSPF, RIP, IS-IS, BGP etc.), the virtual interface acquiescence does not enable or does not activate (being the route that routing module can not issued this loop-back address), when the equipment election is Master equipment, enable or activate or add in the Routing Protocol territory, the address of virtual interface is released.Like this, the VRRP agreement can be do not relied on and the not remote backup in same double layer network of active and standby equipment can be realized.
Though illustrate and described the present invention with reference to some exemplary embodiments of the present invention, but it should be appreciated by those skilled in the art that, under the situation of the spirit and scope of the present invention that do not break away from the qualification of claim and equivalent thereof, can make various changes in form and details.