Summary of the invention
Technical problem to be solved by this invention is, provides a kind of the crucial VPN network equipment is carried out the method for load balancing, also can realize redundancy backup simultaneously, improves the overall usability of VPN network with this.
The technical scheme that the present invention solve the technical problem employing is, a kind of method that realizes the traffic load equilibrium is provided, and may further comprise the steps: a. bottom-end gateway and a plurality of higher level's gateway are set up the tunnel; B. bottom-end gateway is assigned to each tunnel with local traffic equilibrium.
Also comprise: c. upper end gateway is according to the time interval, to bottom-end gateway announcement load state; D. bottom-end gateway is regulated the traffic according to the load state of upper end gateway.The tunnel that described bottom-end gateway has been set up by the keepalive mechanism assurance can be used.Described tunnel is the IPsec tunnel, and described keepalive mechanism is that mechanism (Dead Peer Detection) is surveyed in the dead opposite end of IKE.The upper end gateway is provided with a traffic threshold, when the load of this gateway surpasses this threshold value, each bottom-end gateway is sent the load notice message.In the described steps d, described " the adjusting traffic " is: the newly-increased traffic is distributed to the lighter tunnel of load, existing proper communication connection is not changed.If the upper end gateway that lost efficacy, then each bottom-end gateway will with this lost efficacy between the gateway communication diversion to be connected with normal upper end gateway the tunnel in.
" time interval " among the above-mentioned steps c can be a predetermined constant time interval, also can this be adjusted at interval according to the load state of upper end gateway, as increase the length in this time interval when the traffic is big, to alleviate network burden.
The present invention also provides a kind of center gateway, has the load announcement module, and described load announcement module is announced this center gateway load state to bottom-end gateway.
The present invention also provides a kind of gateway, has the load adjusting module, and to the newly-increased traffic of each tunnel distributing, described center gateway is the center gateway that is connected by the tunnel with this gateway to described load adjusting module according to the load state of each center gateway.Described load adjusting module also is used for the communication diversion by the inefficacy tunnel is arrived normal tunnel, described inefficacy tunnel is the tunnel between the upper end gateway of this gateway and inefficacy, and described normal tunnel is the tunnel between this gateway and the upper end gateway working properly.
The invention has the beneficial effects as follows, solved the problem of load balancing that prior art still can not fine solution IPsec security gateway, avoided complicated, loaded down with trivial details equipment state backup, adopted a kind of simple and practicable strategy, the mechanism of initiatively dividing equally the traffic by each opposite end, realize the load balancing of key safety gateway device, thereby improved the overall performance of VPN network, strengthened the actual operation ability of IPsec VPN.The present invention is applicable to the IPsec VPN of various network topologies, can satisfy the high-availability requirement of the heavy enterprise VPN of traffic carrying capacity.
The present invention is further illustrated below in conjunction with the drawings and specific embodiments.
Embodiment
Referring to Fig. 1." security gateway " as herein described is meant that it has security performance, with regard to the position in the network, also is referred to herein as " upper end gateway " or " center gateway " with regard to it.
" tunnel " as herein described is a kind of communication port.The described tunnel of present embodiment focuses on the communication port that uses IPsec technology encapsulation IP bag, also is a kind of safe communication tunnel.
Consider the particularity of IPsec technology, for the correct IPsec of enforcement encapsulates and decapsulation, the security parameter that need between the tunnel both sides, be consistent, and guarantee the synchronous of correlation behavior, this just makes common load balancing scheme can not satisfy its needs; Many the VPN security gateways of making load balancing are used as a gateway group, bottom-end gateway is all set up the IPsec tunnel with each gateway wherein, the equipment of gateway group is according to the loading condition of certain time interval to bottom-end gateway announcement oneself, perhaps the loading condition of all gateway group equipment is announced to bottom-end gateway by independent flow announcement device unification, bottom-end gateway is then moved towards according to the load of certain strategy decision oneself according to these information, reaches load balancing between the gateway group equipment with this.This scheme is applied in the star VPN network topology more, the traffic of a large amount of bottom-end gateway is all through the security gateway equipment at center, this just makes central apparatus be easy to form performance bottleneck, and central apparatus is carried out the performance that load balancing can significantly improve whole network.
The present invention realizes that the several steps of equally loaded is:
1. at first, bottom-end gateway directly with the security gateway group in each gateway device all set up the IPsec tunnel, and can use by the tunnel that the assurance of IKE DPD (detection of dead opposite end) keepalive mechanism has been built up.
2. then, bottom-end gateway equipment is according to own local policy, balancedly with local traffic distribution to different tunnel that gateway group each equipment in upper end is set up in, the equilibrium distribution is all carried out to the local traffic in each lower end, so just can be so that reach load balancing between each equipment of gateway group of upper end.
3. each gateway device of upper end is according to certain time interval, by the loading condition of IKE message to each lower end announcement oneself, the data traffic size of comprise the number that connects, having born etc.; For the bottom-end gateway number when a lot, for reducing the overhead that the load notice message is brought, can by one independently flow announcement device give bottom-end gateway with the unified announcement of loading condition of each equipment; Also has a kind of method that reduces load notice message number, this is based on a kind of like this understanding, promptly when load that certain gateway device bore during much smaller than maximum load value that it can bear, its loading condition does not need to be concerned about, in other words a threshold value can be set at the load capacity of each gateway device, in case load surpasses this value, promptly need loading condition is announced lower end equipment, thus, can effectively reduce load notice message quantity, thereby reduce the additional networks expense of bringing thus.
4. after bottom-end gateway receives the load notice message, the traffic that then will increase connection newly is distributed in the IPsec tunnel of setting up with the light gateway of load, communication for the connection that has existed is then unaffected, this is can also normally carry out because need only the communication of existing connection, show that corresponding gateway still is available, and there is no need to pursuing absolute load balancing, and go to switch the existing traffic, can cause communication stream between a plurality of gateways, to vibrate because do like this, thus the normal communication of influence; Through above-mentioned processing, can reach gratifying load balancing between each gateway device of security gateway group, thereby can improve the availability of whole VPN network.
Above-mentioned " flow announcement device " function is flow or the load notice message that receives upper end gateway group, and unified each gateway of lower end that is distributed to is to reduce flow or load notice message number in the circuit.
Obviously such scheme also can be realized the redundancy backup function, loses efficacy as long as find one of them gateway, promptly can promptly switch to another available gateway, thereby makes and reduce to minimum to the influence of communication.
The present invention initiatively sets up IPsec by lower end and center gateway and is connected, thereby can realize so-called remote backup function realizing on the redundancy backup function and not requiring that the equipment of security gateway group physically is in same place.
The present invention is by crucial gateway device in the VPN network is carried out load balancing, improves the availability of whole VPN network, therefore is suitable for integrated planning and deployment to the VPN network.Especially in star VPN network topology, non-central end gateway device is implemented identical strategy, can improve the availability of center gateway group better, thereby significantly improve the overall performance of VPN.
" flow announcement device " of the present invention function is flow or the load notice message that receives upper end gateway group, and unified each gateway of lower end that is distributed to is to reduce flow or load notice message number in the circuit.Fairly simple because of its function, to those skilled in the art, there is no the difficulty of enforcement, so no longer its concrete structure is explained in detail.
As embodiment more specifically, referring to Fig. 1.
What Fig. 1 showed is a kind of more typical star network topology.The security gateway GA and the GB that are positioned at the center form a security gateway group GAB, and the lower end is connected with four security boundary gateway G1, G2, G3 and G4; Wherein G1 and G3 communicate by the IPsec tunnel that the GAB with the center sets up, and communicating by letter of G2 and G4 also undertaken by GAB; Under this environment, all communication stream are all through the GAB at center, therefore for preventing that GAB from becoming performance bottleneck, and the overall performance of raising network, need carry out load balancing and redundancy backup between the GA at center and GB.
Concrete steps are as follows.
1.G1, G2, G3 at first set up the IPsec tunnel with GA, GB respectively according to the needs of communicating by letter in this locality with G4, and keep the availability in all tunnels by IKE DPD message mechanism; Originally, G1, G2, G3 and G4 communicate by letter to this locality with algorithm according to identical strategy and shunt, and the traffic that guarantees respectively the tunnel set up with GA, GB separately about equally like this can be so that the load of GA and GB tends to balance on the whole.
2. the maximum load of hypothesis GA, GB is 100, and the measurement of load is determined according to the concrete performance of each equipment; The load threshold of setting GA, GB is respectively 60,55, and whether this value decision needs to send the load notice message to each gateway device of lower end; When the load of GA, GB is 15,14 respectively, show that GA and GB also have enough abilities to handle traffic load, need not the opposite end and be concerned about its loading condition this moment; Afterwards, along with the increase of the traffic, the load of GB surpasses its threshold value 55, and GB begins to send the load notice message to the opposite end, and this can utilize IKE existing information exchange (Informational Exchange) mechanism to realize; The processing of GA also similarly; Timing mechanism is adopted in the transmission of load notice message, the timing size can be used fixed value, also can dynamically adjust according to loading condition, for example when threshold value, adopt long fixed time interval, then reduce timing along with the increase of load, to increase load notice message transmission frequency, when reaching a certain warning value, load (supposes that GA is 90, GB is 88) time, then begin to reduce the transmission of load notice message, send the additional networks pressure that the load notice message is brought, guarantee the carrying out of normal data communication as far as possible to reduce this moment.
3. after G1 or G2 receive the load notice message of GA, GB,, carry out the tunnel at the newly-increased traffic that connects and select, it is distributed to the lighter tunnel of load according to the loading condition of the GA that is obtained, GB; As long as the existing communication that connects can normally be carried out, just should not change its original tunnel approach, can guarantee existing the stable of communication that connect like this; The connection here is at a concrete communication session, promptly come unique definite by source address, destination address, source port, destination interface and agreement, for example 192.168.1.1 promptly is a connection to the FTP of 192.168.2.1 communication, and 192.168.1.1 promptly is another connection to the Web application (http protocol) of 192.168.2.1.
4. the purpose that center gateway GA, GB are carried out load balancing is in order to improve the overall usability of VPN network, if therefore existing connection communication can normally be carried out, just needn't change the existing communication tunnel that connects, unless existing communication occurs unusually according to the load of GA, GB is different; In other words, for G1, G2, G3 or G4, the upper end load notice message that obtains only works to its newly-increased selection strategy that connects communication, its purpose is that one is can guarantee existing communication stable, avoid meaningless communication vibration, the load that second can more promptly obtain center gateway GA, GB is tending towards balanced.
5. if certain center gateway lost efficacy, as GA, G1, G2, G3 and G4 can react more rapidly, and the communication diversion that will carry out with GA guarantees not to be interrupted with communicating by letter of GA with this in the IPsec tunnel of setting up with GB.
Certainly, the front is mentioned, and such scheme is not limited to the star-shaped network structure that Fig. 1 shows, for CFS to CFS (Site-to-Site) network configuration, and the Dial-up Network of remote customer dialing access local security gateway, also be suitable for.
The present invention can significantly improve the load performance of key safety gateway device in the VPN network, thereby improves the overall usability of network.
The regulative mode that above embodiment provides is that the traffic that only will increase connection newly is distributed in the IPsec tunnel of setting up with the light gateway of load, and does not change for the communication of the connection that has existed.
In addition, about two kinds of following situations:
1) original normal connection is done the adjustment of part to realize equilibrium rapidly;
2) all original connections and newly-increased connecting are redistributed;
Even its effect is not ideal,, still belong to interest field of the present invention as embodiment.
The present invention also provides a kind of center gateway, and described " center gateway " is a kind of gateway, and because of its position in network, this paper is called " center gateway " to show difference.Described center gateway also has a load announcement module except that the function with common gateway, described load announcement module function is bottom-end gateway to be announced the load state of this center gateway.Can be regularly announcement, also can dynamically adjust the time limit.When load was excessive, the center gateway increased the time interval of transmit status announcement, to reduce the overhead that produces because of announcement.
The present invention also provides a kind of gateway, and usually, in network environment of the present invention, this gateway is in the lower end usually.This gateway has the load adjusting module, and to the newly-increased traffic of each tunnel distributing, described center gateway is the center gateway that is connected by the tunnel with this gateway to described load adjusting module according to the load state of each center gateway.Described load adjusting module also is used for the communication diversion by the inefficacy tunnel is arrived normal tunnel, described inefficacy tunnel is the tunnel between the upper end gateway of this gateway and inefficacy, and described normal tunnel is the tunnel between this gateway and the upper end gateway working properly.