A kind of network management interactive system and exchange method based on sharing NAT
Technical field
The present invention relates to the network device management technology, relate in particular to a kind of network management interactive system and exchange method based on sharing NAT.
Background technology
Along with the develop rapidly of computer networking technology, various types of communication equipment is widely used, and network size is also increasing.Stably move in order to ensure network-efficient, just need to effectively manage the network equipment.
Due to IPv4(procotol the 4th edition) number of addresses is limited, generally only limit to network management system and have public ip address, and the network equipment that it is managed (being managed devices) has been assigned with private network IP address, the network management system that therefore has public ip address can't be managed the network equipment that has distributed private network IP address.
For the problems referred to above, solution commonly used is that the equipment by network enabled address transition (NAT) is connected between the network equipment of network management system and its management, then between the network equipment of network management system and its management, by setting up certain protocol, is undertaken alternately.But present network management becomes increasingly complex, need the object of management also more and more, therefore often have a plurality of network management systems in carrying out network management procedure, a plurality of network management protocols, as Simple Network Management Protocol (SNMP), Simple Object Access Protocol (SOAP) etc.At present for the good solution of neither one also of the mutual aspect between multiple network management system, multiple network management agreement and managed devices.
Summary of the invention
Technical problem to be solved by this invention is: a kind of network management interactive system and exchange method based on sharing NAT proposed, while realizing having a plurality of network management systems and a plurality of network management protocol in network management procedure to effective management of managed devices.
The present invention solves the problems of the technologies described above adopted scheme: a kind of network management interactive system based on sharing NAT, and comprising: at least one network management system, at least one managed devices also comprise: share NAT ride through system and at least one NAT gateway;
Described shared NAT ride through system, for receive the logon message of managed devices by the NAT gateway, and preserve the MAC Address of the managed devices carried in the public network address information of managed devices and logon message, the mapping table of private net address information; And for the registration that receives network management system IP address and the port of preserving network management system, and the mapping table of managed devices is notified to the network management system succeeded in registration; And, for receiving and resolve the XML document that is packaged with the NMP request, obtain purpose IP address and destination interface, and forward XML document to corresponding managed devices according to above-mentioned purpose IP address and destination interface; The XML document that is packaged with the NMP request reaches corresponding managed devices after carrying out address transition and record network management system IP address by the NAT gateway;
Described network management system, for by shared NAT ride through system registration, after succeeding in registration, to the information of sharing NAT ride through system inquiry managed devices, obtain the address transition mapping table of managed devices; Need generating network management agreement request message according to management service, then the NMP message is encapsulated in the protocol data zone of XML document, then the XML document that will be packaged with the NMP request message sends to and shares the NAT ride through system by SOCKET;
Described NAT gateway, for carrying out from the NMP message of network management system sending to managed devices after the intranet and extranet address transition, and will carry out from the NMP response message of managed devices sending to shared NAT ride through system after the intranet and extranet conversion;
Described managed devices, for receiving and resolving, network management system sends through the NAT gateway, carries out the NMP request message of address transition, sends the NMP response message to the NAT gateway after carrying out the order in message.
Further, the public network address information of described managed devices information comprises public network IP address and the port of managed devices, and the private net address information of carrying in described logon message comprises private network IP address and the port of managed devices.
Further, include multiple network management agreement processing module in described network management system and managed devices, to realize the processing to heterogeneous networks management agreement message.
Further, described network management system is registered by shared NAT ride through system, sending the registration request message.
Concrete, described registration request message content comprises: the message serial number, need to carry out NMP, agreement reception & disposal port, network management system IP address that NAT passes through.
Further, described shared NAT ride through system is also for preserving network management system IP address and the port in when registration, after the network management response message that receives the managed devices transmission, the log-on message of corresponding network management system by the analytic message content search, thus forward the packet to the respective wire guard system.
A kind of network management exchange method based on sharing NAT comprises the following steps:
A. managed devices regularly sends logon message to shared NAT ride through system by the NAT gateway, carries managed devices private net address information and MAC Address in logon message;
B. network management system is registered to shared NAT ride through system transmission registration request message, shares the log-on message that the NAT ride through system is preserved network management system;
The MAC Address of c. carrying in the public network address information of shared NAT ride through system preservation managed devices and logon message, the mapping table of private net address information; The mapping table of managed devices is notified to the network management system through registration;
D. network management system generating network management agreement request message, then be encapsulated into the NMP message in the protocol data zone of XML document, then the XML document that will be packaged with the NMP request message sends to and shares the NAT ride through system by SOCKET; Share the NAT ride through system and receive and resolve the XML document that is packaged with the NMP request, obtain purpose IP address and destination interface, and forward XML document to corresponding managed devices according to above-mentioned purpose IP address and destination interface; The XML document that is packaged with the NMP request reaches corresponding managed devices after carrying out address transition and record network management system IP address by the NAT gateway;
E. managed devices is received in the procotol request message of NAT gateway after network address translation; And call corresponding NMP processing module and carry out dissection process.
Further, described method is further comprising the steps of:
F. after managed devices is processed the procotol request message received, send the NMP response message to the NAT gateway, the NAT gateway encapsulates the address of purpose network management system and the NMP response message is carried out sending to shared NAT ride through system after address transition in the NMP response message, shares the NAT ride through system and sends the NMP response message according to IP address and the port of the network management system of preserving.
Further, in step a, the timing cycle of described managed devices transmission logon message is less than the address aging cycle of NAT gateway.
Further, in step c, the public network address information of described managed devices information comprises public network IP address and the port of managed devices, and the private net address information of carrying in described logon message comprises private network IP address and the port of managed devices.
The invention has the beneficial effects as follows: a plurality of NMSs unify a plurality of NMPs can multiplexing NAT ride through system and managed devices between the NAT passage, thereby make network management system only need to pay close attention to own service, and, without the position of being concerned about the managed devices place, reduced the complexity of network management; Between managed devices and each network management system, only have a NAT passage lanes can effectively reduce network message simultaneously, improve the network bandwidth.
The accompanying drawing explanation
Fig. 1 is the network management interactive system structured flowchart based on sharing NAT of the present invention;
Fig. 2 is the network management interactive system workflow schematic diagram based on sharing NAT of the present invention;
Fig. 3 is the network management exchange method flow chart based on sharing NAT of the present invention.
Embodiment
Referring to Fig. 1, the network management interactive system based on sharing NAT in the present invention comprises:
Managed devices: need first to register at shared NAT ride through system place, carry the MAC Address of managed devices and the private net address information of managed devices in logon message, described private net address information comprises private network IP address and port;
Network management system: also need first to register at shared NAT ride through system place, can obtain the essential information of managed devices by sharing the NAT ride through system, comprise public network IP and port, MAC Address, private network IP address and port, then send the procotol message to managed devices; The NAT passage lanes that simultaneously utilizes shared NAT ride through system to provide receives the procotol message of managed devices;
Share the NAT ride through system: accept the registration of managed devices and network management system, preserve respectively IP address and the port of network management system, and the public network IP of managed devices and port, MAC Address, the mapping table of private network IP address and port, thereby the NAT passage lanes between the network management system of foundation and managed devices, according to NMP message transfer message between managed devices and network management system;
Network address translation (nat) gateway: for managed devices is carried out to the intranet and extranet address transition;
Managed devices: receive and resolve network management system and send the procotol message, after the order in the execution message, to shared NAT ride through system, send the NMP response message.
Fig. 2 has expressed the workflow of this system: at first by managed devices, regularly by the NAT gateway, to shared NAT ride through system, registered, private net address information and the MAC Address of this managed devices have been carried in this logon message, the timing cycle of described managed devices transmission logon message is less than the address aging cycle of NAT gateway, shares the address transition mapping table that the NAT ride through system is preserved managed devices: the MAC Address that comprises public network IP address and port, private network IP address and port and the managed devices of managed devices; Network management system also sends the registration request message to shared NAT ride through system, share the NAT ride through system registration request message is processed to (whether allowing this network management system registration), and return to registering result information to network management system, if allow the network management system registration to share IP address and the port that the NAT ride through system is preserved network management system; After network management system is successfully registered, by the information to sharing NAT ride through system inquiry managed devices, obtain the address transition mapping table of managed devices; When needs carry out network management, network management system generating network management agreement request message, the row format encapsulation of going forward side by side, then be sent to the NAT gateway; The NAT gateway is preserved the address of network management system and the NMP request message is carried out being sent to corresponding managed devices after address transition; By managed devices, the format message is resolved, and call corresponding NMP processing module and processed; By managed devices generating network management agreement response message, the row format encapsulation of going forward side by side, then be sent to the NAT gateway subsequently.The NAT gateway encapsulates the address of network management system in the NMP response message, after the row address of going forward side by side conversion, is sent to and shares the NAT ride through system; Share the NAT ride through system and obtain IP address and the port of purpose network management system after resolving the format message, then will format message according to purpose IP address and port and be sent to corresponding network management system; Corresponding network management system is called corresponding NMP processing module and is processed.
Referring to Fig. 3, the network management exchange method based on sharing NAT in the present invention comprises the following steps:
1. managed devices is registered to shared NAT ride through system, carry the MAC Address of managed devices and private network IP address and the port of managed devices in logon message, logon message arrives and shares the NAT ride through system through the NAT gateway, sharing the NAT ride through system preserves managed devices and comprises public network IP and port, MAC Address, the address transition mapping table of private network IP address and port;
2. network management system is registered to shared NAT ride through system: if network management system need to be carried out NAT to certain NMP (as SNMP, SOAP etc.), pass through, generate the registration request message, the registration request message information comprises: message serial number, the NMP that needs NAT to pass through, agreement reception & disposal port, network management system server IP address etc., and then network management system sends to logon message to share the NAT ride through system; Share the NAT ride through system and determine whether allow registration: share the NAT ride through system and receives and resolve the registration request message, and according to self resource occupation and the system processing power decision registration request that whether allows network management system; If allow, preserve log-on message, and preserve IP address and the port of network management system, if do not allow, registration failure;
3., after network management system succeeds in registration, to the information of sharing NAT ride through system inquiry managed devices, obtain the address transition mapping table of managed devices; Need generating network management agreement request message according to management service, then the NMP message is encapsulated into to the XML(extend markup language) in the protocol data zone of document, then the XML document that will be packaged with the NMP request message is by the SOCKET(socket) send to and share the NAT ride through system; Wherein, the form of XML document is as shown in the table:
4. share the NAT ride through system and receive and resolve the XML document that is packaged with the NMP request, obtain purpose IP address (being managed devices IP address) and destination interface, and forward XML document to corresponding managed devices according to above-mentioned purpose IP address and destination interface;
5. the XML document that is packaged with the NMP request reaches corresponding managed devices after carrying out address transition and record network management system IP address by the NAT gateway;
6. corresponding managed devices receives and resolves the XML document that is packaged with the NMP request, and, according to the NMP type parsed, call corresponding protocol process module and carry out protocol analysis and processing (carrying out the management request of network management system);
7. managed devices generating network management agreement response message, then be encapsulated into this NMP response message in XML document, sends to and share the NAT ride through system;
8. the XML document that is packaged with the NMP response message carry out address transition by the NAT gateway and encapsulate purpose network management system IP address after after reach and share the NAT ride through system;
9. share the NAT ride through system and receive and resolve the XML document that is packaged with the NMP response message, obtain purpose IP address (being network management system IP address), then according to the log-on message of the network management system of preserving, find corresponding network management system port, the XML document that finally according to purpose IP address and port, will be packaged with the NMP response message is transmitted to corresponding network management system;
10. network management system receives and resolves the XML document that is packaged with the NMP response message, and, according to the NMP type, calls corresponding NMP processing module and carry out protocol analysis and processing.