VLAN server
Abstract
This record has no abstract on file.
Term
Term ended
Expired 20 November 2023, 2.8 years ago.
- Priority and filed
- Granted
- Expired
- Today
6 claims: 3 independent, 3 dependent
- 1A server that is connected to multiple VLANs and provides application services for each VLAN, with multiple processes for multiple application services, multiple virtual device drivers provided in association with the processes, and each VLAN. A receiving address change processing unit that changes the destination address based on the VLAN tag and a selection unit that selects a virtual device driver based on the destination address changed by the address change processing unit. When the process on the server receives data from the client, the receiving address change processing unit acquires the internal IP address corresponding to the VLAN tag extracted from the received MAC frame, and obtains the destination IP. The address is rewritten from the external IP address to the internal IP address, the MAC header is deleted to make an IP packet, the IP packet is transferred to the selection unit, and the selection unit corresponds to the destination IP address of the IP packet. A virtual device driver is selected, and the selected virtual device driver forwards the IP packet received from the selection unit to the process. The process that is waiting for data at the destination IP address is a VLAN server that receives the data in the IP packet and executes the process. 複数のVLANと接続され、各VLAN毎のアプリケーションサービスを提供するサーバであって、 複数のアプリケーションサービス用の複数のプロセスと、 前記プロセスと対応づけて設けられた複数の仮想デバイスドライバと、 各VLANから受信したVLANタグが付与されたデータを、VLANタグに基づき宛先アドレスを変更する受信用アドレス変更処理部と、 前記アドレス変更処理部が変更した宛先アドレスに基づいて仮想デバイスドライバを選択する選択部と、を備え、 サーバ上の前記プロセスがクライアントからデータを受信する際、 前記受信用アドレス変更処理部は、受信したMACフレームから取り出したVLANタグに対応する内部向けIPアドレスを取得し、宛先IPアドレスを外部向けIPアドレスから内部向けIPアドレスに書き換え、MACヘッダを削除してIPパケット化し、そのIPパケットを前記選択部へ転送し、 前記選択部は、IPパケットの宛先IPアドレスに対応する前記仮想デバイスドライバを選択し、 選択された前記仮想デバイスドライバは、前記選択部から受信したIPパケットを前記プロセスへ向けて転送し、 宛先IPアドレスでデータ待ちをしている前記プロセスは、IPパケット中のデータを受信し、処理を実行するVLANサーバ。
- 2A server that is connected to a plurality of VLANs and provides an application service for each VLAN, includes a plurality of processes for the plurality of application services, a plurality of virtual device drivers provided in association with the process, and the process. A transmission address change processing unit that receives data from the above via the virtual device driver and changes the source address and assigns a tag based on the source address, and the process on the server is a client. When transmitting data to, the process issues data whose source IP address is an internal IP address, and the transmission address change processing unit is a VLAN corresponding to the source internal IP address. A MAC frame is created by obtaining the tag and the external IP address, rewriting the source IP address in the IP packet to the external IP address, and adding the MAC header including the obtained VLAN tag to the IP packet, and for the transmission. The address change processing unit is a VLAN server that forwards the created MAC frames to the VLAN. 複数のVLANと接続され、各VLAN毎のアプリケーションサービスを提供するサーバであって、 複数のアプリケーションサービス用の複数のプロセスと、 前記プロセスと対応づけて設けられた複数の仮想デバイスドライバと、 前記プロセスからのデータを前記仮想デバイスドライバを介して受信し、送信元アドレスに基づいて、送信元アドレスの変更とタグの付与を行う送信用アドレス変更処理部と、を備え、 サーバ上の前記プロセスがクライアントに対してデータを送信する際、 前記プロセスは、送信元IPアドレスが内部向けIPアドレスであるデータを発行し、 前記送信用アドレス変更処理部は、送信元である内部向けIPアドレスに対応するVLANタグと外部向けIPアドレスとを求め、IPパケットにおける送信元IPアドレスを外部向けIPアドレスに書き換え、求めたVLANタグを含むMACヘッダをIPパケットに付加することによってMACフレームを作成し、 前記送信用アドレス変更処理部は、作成されたMACフレームをVLANへ向けて転送するVLANサーバ。
- 3A server that is connected to multiple VLANs and provides application services for each VLAN, with multiple processes for multiple application services, multiple virtual device drivers provided in association with the processes, and each VLAN. A receiving address change processing unit that changes the destination address based on the VLAN tag and a selection unit that selects a virtual device driver based on the destination address changed by the address change processing unit. And a transmission address change processing unit that receives data from the process via the virtual device driver and changes the source address and assigns a tag based on the source address, and is provided on the server. When the process receives data from the client, the receiving address change processing unit acquires the internal IP address corresponding to the VLAN tag extracted from the received MAC frame, and sets the destination IP address from the external IP address to the internal one. Rewrite to the target IP address, delete the MAC header to make an IP packet, transfer the IP packet to the selection unit, and then The selection unit selects the virtual device driver corresponding to the destination IP address of the IP packet, and the selected virtual device driver forwards the IP packet received from the selection unit to the process and uses the destination IP. The process waiting for data at the address receives the data in the IP packet and performs processing, while when the process on the server sends data to the client, the process is the source. The data whose IP address is the internal IP address is issued, and the transmission address change processing unit obtains the VLAN tag corresponding to the internal IP address which is the source and the external IP address, and the source in the IP packet. A MAC frame is created by rewriting the IP address to an external IP address and adding a MAC header including the obtained VLAN tag to the IP packet, and the transmission address change processing unit directs the created MAC frame to the VLAN. VLAN server to forward. 複数のVLANと接続され、各VLAN毎のアプリケーションサービスを提供するサーバであって、 複数のアプリケーションサービス用の複数のプロセスと、 前記プロセスと対応づけて設けられた複数の仮想デバイスドライバと、 各VLANから受信したVLANタグが付与されたデータを、VLANタグに基づき宛先アドレスを変更する受信用アドレス変更処理部と、 前記アドレス変更処理部が変更した宛先アドレスに基づいて仮想デバイスドライバを選択する選択部と、 前記プロセスからのデータを前記仮想デバイスドライバを介して受信し、送信元アドレスに基づいて、送信元アドレスの変更とタグの付与を行う送信用アドレス変更処理部と、を備え、 サーバ上の前記プロセスがクライアントからデータを受信する際、 前記受信用アドレス変更処理部は、受信したMACフレームから取り出したVLANタグに対応する内部向けIPアドレスを取得し、宛先IPアドレスを外部向けIPアドレスから内部向けIPアドレスに書き換え、MACヘッダを削除してIPパケット化し、そのIPパケットを前記選択部へ転送し、 前記選択部は、IPパケットの宛先IPアドレスに対応する前記仮想デバイスドライバを選択し、 選択された前記仮想デバイスドライバは、前記選択部から受信したIPパケットを前記プロセスへ向けて転送し、 宛先IPアドレスでデータ待ちをしている前記プロセスは、IPパケット中のデータを受信し、処理を実行し、一方、 サーバ上の前記プロセスがクライアントに対してデータを送信する際、 前記プロセスは、送信元IPアドレスが内部向けIPアドレスであるデータを発行し、 前記送信用アドレス変更処理部は、送信元である内部向けIPアドレスに対応するVLANタグと外部向けIPアドレスとを求め、IPパケットにおける送信元IPアドレスを外部向けIPアドレスに書き換え、求めたVLANタグを含むMACヘッダをIPパケットに付加することによってMACフレームを作成し、 前記送信用アドレス変更処理部は、作成されたMACフレームをVLANへ向けて転送するVLANサーバ。
Independent claims3
55 paragraphs, as filed
The present invention relates to a VLAN (Virtual LAN) server, and in particular, enables a physically single server connected to a network using TCP / IP to provide services to a plurality of VLANs. It is about a VLAN server.
In one LAN (Local Area Network) system, the technology to form a virtual group with specific terminals on the LAN without depending on the physical connection is called VLAN (Virtual LAN).
A port is a concentrator installed on a LAN (hereinafter referred to as a switching hub) that sets a port number for each VLAN in advance and forms a virtual group for each port used by each VLAN to perform communication. Called a VLAN. In addition, tag VLANs (IEEE802) are those in which tags (predetermined values) are set in advance for each VLAN in the switching hubs that make up the network, and virtual groups are formed for each tag of the data handled by each VLAN to perform communication. It is called .1Q standard).
Which VLAN each terminal belongs to is identified by the value of the tag attached to the MAC frame. There are merits such as reducing the amount of line traffic by dividing the LAN and reducing costs by sharing physical wiring among multiple VLANs. In addition, VLAN is rapidly becoming widespread in various companies because it is easy to manage the operation of the network.
However, when realizing services such as WEB applications and file transfer functions that should normally be provided by one server in a VLAN, installing one server in each VLAN has drawbacks in terms of cost and operation management.
Therefore, consider a method of physically sharing one server with VLAN. For that purpose, it is appropriate to start as many applications of the same type (WEB, FTP, etc.) processes (hereinafter referred to as server processes) in the server as many as the number of VLANs. As a method for realizing such a server, for example, there is a means provided by Japanese Patent Application Laid-Open No. 2003-167805.
In Japanese Patent Application Laid-Open No. 2003-167805, the server uses a VLAN tag to identify the closed network to which the communication partner client belongs. That is, a VLAN tag is added to the MAC frame from the client, and the server can identify the VLAN to which the source client of the frame belongs by the VLAN tag of the received frame. Further, in Japanese Patent Application Laid-Open No. 2003-167805, TCP / IP is used as a network protocol for transferring received MAC frames to a server process, but TCP / IP stacks and device drivers are provided for the number of closed networks to be accommodated. It is characterized by being. That is, each server process can communicate with a specific closed network by receiving data from the TCP / IP stack corresponding to the closed network.<patcit num="1"><text>Japanese Unexamined Patent Publication No. 2003-167805</text></patcit>
<p> However, in Japanese Patent Application Laid-Open No. 2003-167805, by providing a plurality of TCP / IP stacks and device drivers, for example, a routing table for determining a route to a communication partner and a correspondence between an IP address and a MAC address are managed. Data such as ARP tables must be stored in memory as many as the number of closed networks, and there is a concern that memory usage will increase. Further, in Japanese Patent Application Laid-Open No. 2003-167805, each communication flow for closed networks A to C corresponds to one computer, and it is necessary to have as many computers as there are closed networks, which increases the amount of hardware. There is a concern that may lead to.</p><p> Therefore, in view of the above points, in the present invention, by implementing only one TCP / IP stack and one device driver, the service is provided to a plurality of VLANs while having only one data such as a routing table and an ARP table. The purpose is to realize a VLAN server that can be used. Of course, even if you have only one TCP / IP stack and device driver, if you accommodate multiple VLANs, you need to have as many routing information as that number, but since you do not have multiple routing tables themselves, each table Information common to all can be saved, which contributes to the reduction of memory usage as a whole.</p><p> Another object of the present invention is to provide a VLAN server that solves the following problems in order to consolidate the TCP / IP stack and the device driver into one.</p><p>(1) Identification method of the same type server process Normally, one IP address is assigned to one network interface. Moreover, since the server processes of the same type have the same TCP port number, if there is only one TCP / IP stack, there is a risk that the server processes cannot be distinguished from each other. Therefore, it is necessary to separately propose a method for identifying processes.</p><p>(2) Identification method of communication partner VLAN of server process Since the server process is located above TCP / IP in the network protocol, it does not have a means to recognize VLAN which is a concept lower than TCP / IP. Therefore, the VLAN of the communication partner must be identified by some other method.</p>
<p> The present invention is a server that is connected to a concentrator device accommodating a plurality of VLANs and provides an application service for each VLAN, and the plurality of processes for the plurality of application services and the VLAN via the concentrator device. An address change processing means for changing the destination address based on the tag assigned by the concentrator, and a selection means for selecting a virtual device driver based on the destination address changed by the address change processing means. It is one of the features that the virtual device driver is provided in association with the process and transfers the data received from the NAT processing means to the process via the selection means.</p><p> The present invention is a server that is connected to a concentrator device accommodating a plurality of VLANs and provides an application service for each VLAN, and is provided in association with a plurality of processes for the plurality of application services and the processes. A plurality of virtual device drivers, an address change processing means that receives data from the process via the virtual device driver, changes the source address and assigns a tag based on the source address, and the address change. Another feature is that it is provided with a transfer means for transferring data from the processing means to the line concentrator.</p><p> According to the first solution of the present invention, it is a server that is connected to a plurality of VLANs and provides an application service for each VLAN, and is provided in association with a plurality of processes for the plurality of application services. A receiving address change processing unit that changes the destination address based on the VLAN tag and a destination address changed by the address change processing unit for the plurality of virtual device drivers and the data with the VLAN tag received from each VLAN. A selection unit that selects a virtual device driver based on is provided, and when the process on the server receives data from the client, the reception address change processing unit corresponds to the VLAN tag extracted from the received MAC frame. Acquires the internal IP address, rewrites the destination IP address from the external IP address to the internal IP address, deletes the MAC header to make an IP packet, transfers the IP packet to the selection unit, and the selection unit , Select the virtual device driver corresponding to the destination IP address of the IP packet, The selected virtual device driver forwards the IP packet received from the selection unit to the process, and the process waiting for data at the destination IP address receives and processes the data in the IP packet. A VLAN server is provided to execute.</p><p> According to the second solution of the present invention, it is a server that is connected to a plurality of VLANs and provides an application service for each VLAN, and is provided in association with a plurality of processes for the plurality of application services. A plurality of virtual device drivers, and a transmission address change processing unit that receives data from the process via the virtual device driver and changes the source address and assigns a tag based on the source address. When the process on the server transmits data to the client, the process issues data whose source IP address is an internal IP address, and the transmission address change processing unit transmits. Obtain the VLAN tag corresponding to the original internal IP address and the external IP address, rewrite the source IP address in the IP packet to the external IP address, and add the MAC header including the obtained VLAN tag to the IP packet. As a result, a MAC frame is created, and the transmission address change processing unit is provided with a VLAN server that forwards the created MAC frame toward the VLAN.</p><p> According to the third solution of the present invention, it is a server that is connected to a plurality of VLANs and provides an application service for each VLAN, and is provided in association with a plurality of processes for the plurality of application services. A receiving address change processing unit that changes the destination address based on the VLAN tag and a destination address changed by the address change processing unit for the plurality of virtual device drivers and the data with the VLAN tag received from each VLAN. A selection unit that selects a virtual device driver based on the above, and a transmission address that receives data from the process via the virtual device driver and changes the source address and assigns a tag based on the source address. When the process on the server receives data from the client, the reception address change processing unit acquires an internal IP address corresponding to the VLAN tag fetched from the received MAC frame. , Rewrite the destination IP address from the external IP address to the internal IP address, delete the MAC header to make an IP packet, and transfer the IP packet to the selection unit. The selection unit selects the virtual device driver corresponding to the destination IP address of the IP packet, and the selected virtual device driver forwards the IP packet received from the selection unit to the process and the destination IP. The process waiting for data at the address receives the data in the IP packet and performs processing, while when the process on the server sends data to the client, the process is the source. The data whose IP address is the internal IP address is issued, and the transmission address change processing unit obtains the VLAN tag corresponding to the internal IP address which is the source and the external IP address, and the source in the IP packet. A MAC frame is created by rewriting the IP address to an external IP address and adding a MAC header including the obtained VLAN tag to the IP packet, and the transmission address change processing unit directs the created MAC frame to the VLAN. A VLAN server is provided to forward the data.</p>
<p> In the present invention, although one server has a plurality of server processes to provide services to a plurality of VLANs, only one TCP / IP stack and one device driver are implemented. Therefore, a routing table or an ARP table is used. You only need to have one, and you can reduce the memory usage.</p><p> Further, the present invention has an effect of solving the problems in consolidating the TCP / IP stack and the device driver into one as follows.</p><p>(1) Identification method of the same type server process Normally, only one IP address can be assigned to one network interface in one TCP / IP stack, but is there multiple network interfaces by providing multiple virtual device drivers? It can be made to look like, and it is possible to have multiple IP addresses in the server. Even if each server process has the same port number, it is possible to identify the process by giving it a different internal IP address.</p><p>(2) Identification method of the communication partner VLAN of the server process By associating the VLAN tag with the internal IP address by NAT, the server process can communicate only with the corresponding VLAN. Further, a normal server connected to a conventional LAN has only one TCP / IP stack, but when the usage is changed so that this server is used as a server shared by VLAN, according to the present invention, TCP / IP This is easy to achieve because you only have to change the driver without moving the stack.</p>
We have realized a server that provides services to multiple VLANs by using only one TCP / IP stack.
1. Configuration of VLAN server Figure 1 shows the system configuration diagram in this embodiment. In general, since the number of VLANs accommodated by the server is a plurality, in the present embodiment, the number of VLANs accommodated by the server (100) will be described as 3 as an example.
The server (100) is connected to clients # 1-1 to # 3-2 (121 to 126) via a switching hub (concentrator) (113). Clients (clients # 1-1 (121), # 1-2 (122)) belonging to port 1 (114) and port 2 (115) of the switching hub (113) belong to VLAN # 1 (127) and are ports. Clients (clients # 2-1 (123), # 2-2 (134)) belonging to 3 (116) and port 4 (117) belong to VLAN # 2 (128), and ports 5 (118) and 6 Clients belonging to (119) (clients # 3-1 (125), # 3-2 (126)) belong to VLAN # 3 (129).
The server (100) is connected to port 7 (120). Between ports 1 (114) and port 2 (115), port 3 (116) and port 4 (117), and can be data transmitted and received between the port 5 (118) and port 6 (119), for example port over Data cannot be sent or received across VLANs, such as between port 1 (114) and port 3 (116) (port VLAN). In addition, ports 1 to 6 (114 to 119) can send and receive data to and from port 7 (120), but in that case, a VLAN tag is added to the MAC frame by the switching hub (113), and the VLAN is assigned by the VLAN tag. Identifying (tagged VLAN).
The server (100) starts server processes (server processes # 1 to # 3 (101 to 103)) for the number of VLANs for providing services (for example, Web and FTP) to VLANs (127 to 129). If the server is a web-only server, these multiple server processes are all web server processes, and if the services provided for each VLAN are different, for example, start the web server process for VLAN # 1 and start the web server process. It is also possible to start an FTP server for VLAN # 2. In addition to these server processes, the server also converts data from the server process into IP packets, and the TCP / IP stack (104) for passing IP packets addressed to these server processes to the server process, and the TCP / IP stack on the protocol stack. It is equipped with a device driver (105) for sending IP packets to the outside of the server and receiving data from outside the server and passing it to the TCP / IP stack.
The device driver (105) includes virtual device drivers (virtual device drivers # 1 to # 3 (106 to 108)) and a data link control unit (109) for the number of VLANs.
A virtual device driver is one that makes it appear as if it accommodates multiple network interfaces to the TCP / IP stack by registering multiple identical device drivers with different names. If there are multiple network interfaces, it is possible to give as many IP addresses as there are, so by giving each virtual device driver a different IP address, it is possible to register multiple IP addresses in the server. ..
The data link control unit (109) includes a virtual device driver selection means (selection unit) (110), a transmission VLAN tag-NAT means (transmission address change processing unit) (111), and a reception VLAN tag-NAT means (reception). For address change processing unit) (112), the virtual device driver selection means (110) determines which virtual device driver to distribute the packet received from the TCP / IP stack, and passes the packet to the determined driver. It is a thing.
In addition, the transmission VLAN tag-NAT processing means (111) changes the value of the source IP address of the packet to be transmitted to a predetermined external IP address by NAT, adds a MAC header to form a MAC frame, and configures the MAC header. It writes a VLAN tag inside. The NAT method on the transmitting side will be described with reference to FIGS. 10 to 12 (described later).
In addition, the receiving VLAN tag-NAT processing means (112) changes the destination IP address to an appropriate internal IP address by NAT in the received MAC frame, deletes the MAC frame, and converts it into an IP packet. The NAT method on the receiving side will be described in FIGS. 7 to 9 (described later).
Server processes # 1 to # 3 (101 to 103) have a private internal IP address for the VLAN. For example, server process # 1 is inside 192.168.10.1 (hereinafter referred to as N1), server process # 2 is inside 192.168.20.1 (hereinafter referred to as N2), and server process # 3 is inside 192.168.30.1 (hereinafter referred to as N3). Each has an IP address. N1, N2, and N3 are always different values as in this example.
Virtual device drivers # 1 to # 3 (106 to 108) also have internal IP addresses N1 to N3. In this example, the internal IP addresses N1 to N3 are the same as the internal IP addresses N1 to N3 of the server process, respectively. On the other hand, the device driver (105) has external IP addresses 172.21.10.1 (hereinafter referred to as G1), 158.21.1.10 (hereinafter referred to as G2), and 158.21.1.10 (hereinafter referred to as G3) that are open to the public for VLAN. Therefore, when the client (121,122) of VLAN # 1 (127) communicates with the server, the IP address of the server uses G1, G2 for VLAN # 2 (128), and G3 for VLAN # 3 (129). Is used.
Since direct communication is not possible between VLAN # 1 (127), VLAN # 2 (128), and VLAN # 3 (129), it is possible for each VLAN to have a duplicate IP address. Therefore, the external IP addresses G1, G2, and G3 of the server may have the same value as in this example. The registration of the external IP address and the internal IP address on the server will be described in Fig. 6 (described later).
Clients # 1-1 to # 3-2 (121 to 126) have IP addresses C1 to C6, but if they do not overlap in the same VLAN, the IP address will overlap with clients in other VLANs. It doesn't matter. For example, in this embodiment, the client # 2-1 (123) belonging to VLAN # 2 (128) and the client # 3-1 (125) belonging to VLAN # 3 (129) have the same IP address (158.21.1.20). ing.
FIG. 2 shows a hardware configuration diagram of the server (100). A memory (201), a disk device (202), a network interface device (203), a display device (204), and an input device (205) are connected to the CPU (200) via a local bus (206). ..
The disk device (202) stores application programs, TCP / IP stack programs, device driver programs, etc. for providing to VLANs (127 to 129). The CPU (200) expands these programs stored in the disk device (202) on the memory (201), reads them sequentially, and executes them. Next, the network interface device (203) is connected to the switching hub (110) via the LAN cable (207), and the server (100) is connected to the client (121 to 126) on the VLAN (127 to 129). Send and receive frames for communication.
Figure 3 shows the software configuration diagram of the server. Server process # 1 (101) for servicing VLAN # 1 (127), server process # 2 (102) for servicing VLAN # 2 (128), service for VLAN # 3 (129) There is server process # 3 (103) to provide the same type of service, so the port numbers are the same (P1), but the IP addresses have different values N1, N2, N3, respectively. There is. When providing different types of services, there will be multiple port numbers.
In addition, there are TCP / IP stack (104) and device driver (105) that perform network protocol processing, and the device driver (105) has the same number of virtual device drivers (virtual device drivers # 1 to # 3) as VLANs (127 to 129). (106 to 108)) and a data link control unit (109) are provided. The virtual device driver (106 to 108) includes a transmitting unit (300, 302, 304) and a receiving unit (301, 303, 305).
Further, the data link control unit (109) includes a transmission unit (306), a reception unit (308), a virtual device driver selection table (309), and a VLAN tag-NAT table (address change table) (310). The transmission unit (306) has a transmission packet queue (307) for queuing the transmission packet from the virtual device driver (106 to 108) and a transmission VLAN tag for NATing the source IP address of the transmission packet. It has a NAT processing means (111). The receiving unit (308) has a virtual device driver selection means (110) and a receiving VLAN tag-NAT processing means (112). All of these are expanded on the memory (201) of the server (100).
FIG. 4 illustrates the VLAN tag-NAT table (310). This VLAN tag-NAT table (310) contains a server process column (400), a tag column (401), an external IP address column (402), and an internal IP address column (403). Associate by a typical value.
FIG. 5 illustrates the virtual device driver selection table (309). The virtual device driver selection table (309) includes a server process column (500), an internal IP address column (501), and a virtual device driver column (502), and each row is associated with these by specific values.
FIG. 6 is a diagram of a screen image of the display device (204) of the server (100) for creating the VLAN tag-NAT table (310).
Enter three items for each VLAN: VLAN tag input field (601), external IP address input field (602), and internal IP address input field (603). Here, the server process is uniquely determined by the internal IP address, so there is no need to enter it. The server process may be input. The server (100) uses the input information to put the value of the VLAN tag in the tag field (401) of the same row of the VLAN tag-NAT table (310) and to the external IP address field (402). Write the value of the IP address in the internal IP address field (403).
Regarding the virtual device driver selection table (309), the server (100) generates a virtual device driver based on the input internal IP address according to the VLAN tag-NAT table (310), and generates the virtual device driver. Write the internal IP address in the internal IP address field (501) in the same row of the selection table (310), and write the name of the virtual device driver in the virtual device driver field (502).
2. Operation of VLAN server 2.1 From client to server Figure 7 shows when a client on a VLAN sends data to a server process on the server, such as requesting a server on the server to search using the Web. Shows the flow of data in the server.
Here, the client is client # 1-1 (121) on VLAN # 1 (127), and the server process on server (100) is server process # 1 (101). When the receiving unit (308) of the data link control unit (109) of the device driver (105) of the server (100) receives the MAC frame from the network interface device (203), it becomes the receiving VLAN tag-NAT processing means (112). Based on the VLAN tag V1 extracted from the MAC frame using the VLAN tag-NAT table (310), the internal IP address N1 corresponding to V1 is acquired as shown in Fig. 4, and the destination IP address is directed to the outside. Rewrite the IP address G1 to the internal IP address N1. Also, the MAC header is deleted to make an IP packet, which is transferred to the virtual device driver selection unit (110).
The virtual device driver selection unit (110) uses the virtual device driver selection table (310) and uses the virtual device driver # 1 (106) corresponding to N1 as shown in FIG. 5 based on the destination IP address N1 of the IP packet. ) Is selected.
The receiver (301) of virtual device driver # 1 (106) transfers the IP packet to the TCP / IP protocol stack (104) without any processing. The TCP / IP protocol stack (104) takes data from an IP packet and forwards it to server process # 1 (101) waiting for data reception at IP address N1.
FIG. 8 is a flowchart showing the processing in the receiving VLAN tag-NAT processing means (112).
The receiving VLAN tag-NAT processing means (112) refers to the destination IP address and VLAN tag of the receiving MAC frame (801), and searches the internal IP address in the VLAN tag-NAT table based on these (802). .. Determines if there is a corresponding internal IP address (803), otherwise the frame is discarded (805). If there is a corresponding internal IP address, the destination IP address is rewritten to the internal IP address obtained by the search (804), the MAC header is removed (806), and the IP packet is completed.
FIG. 9 shows the changes in the explanation in FIG. 8 when composing an IP packet from a MAC frame.
First, the MAC frame (900) sent from the client includes the MAC header (901), the IP header (902), and the data (903). This frame is forwarded to the server by inserting the VLAN tag (911) into the MAC header (908) at the switching hub. The destination IP address (912) inside the IP header (909) of the MAC frame (907) received by the server is G1, but it is rewritten to the destination internal IP address N1 (918) when it is converted into an IP packet. Also, the MAC header (908) has been removed. Parameters other than these are not rewritten.
2.2 From server to client Figure 10 shows the flow of data in the server when the server process on the server sends data to the client, such as when the server returns the Web search results requested by the client. ing.
As in FIG. 7, the client is client # 1-1 (121) on VLAN # 1 (127), and the server process on server (100) is server process # 1 (101). The data issued by server process # 1 (101) has a source IP address of internal IP address N1, but the TCP / IP protocol stack converts the data into IP packets and virtual device driver # 1 with the same IP address N1 ( Transfer to the transmitter (300) of 106).
The transmission unit (300) of the virtual device driver # 1 (106) queues the IP packet to the transmission packet queue (307) of the transmission unit (306) of the data link control unit (109) without any processing. The transmission unit (306) of the data link control unit (109) extracts a queue element, that is, an IP packet from the transmission packet queue (307) and sends it to the transmission VLAN tag-NAT processing means (111).
In the transmission VLAN tag-NAT processing means (111), the VLAN corresponding to N1 is used as shown in FIG. 4 based on the source IP address N1 for the inside using the VLAN tag-NAT table (310). The tag V1 and the external IP address G1 are obtained, and the source IP address in the IP packet is rewritten from N1 to the external IP address G1. Also, when creating a MAC frame by adding a MAC header to an IP packet, V1 is written to the VLAN tag in the MAC header.
The transmit VLAN tag-NAT processing means (111) forwards the completed MAC frame to the network interface device (203). As described in FIG. 3, the MAC frame is forwarded from the network interface device (203) to VLAN # 1 (127) via the switching hub (113), and the client # 1-1 (121) with the matching destination IP address. ) Receives this.
FIG. 11 is a flowchart showing the processing in the transmission VLAN tag-NAT processing means (111).
Outgoing VLAN tag-NAT processing means (111) sees if the outbound packet queue (307) is empty (1101), extracts one IP packet from the outbound packet queue (307) (1102), and in the packet. Refer to the source IP address of (1103). The source IP address is used as the internal IP address, and based on this, the external IP address and VLAN tag are searched from the VLAN tag-NAT table (1104). It determines if there is a match (1105), otherwise the packet is dropped (1107). If there is a corresponding one, rewrite the source IP address to the external IP address obtained by the search (1106), add the MAC header, and write the obtained VLAN tag in the header (1108).
FIG. 12 shows the changes in the description in FIG. 11 when a MAC frame is composed of IP packets.
That is, the source IP address (1203) inside the IP header (1201) of the transmission IP packet (1200) is N1, but the source IP address is rewritten to the external IP address G1 (1210) when composing a MAC frame. .. In addition, although the MAC header (1206) is added, V1 is written in the VLAN tag (1209) inside the MAC header (1206). Parameters other than these are not rewritten. The transmission MAC frame is forwarded to the client by removing the VLAN tag like the MAC header (1213) at the switching hub.
According to the present invention, one server can physically provide services to a plurality of VLANs. Further, in the present embodiment, a configuration in which a plurality of VLANs are connected via a concentrator such as a switching hub is adopted, but the present invention is not limited to this, and a plurality of VLANs are directly connected or via another network or device. It is possible to adopt a configuration in which VLANs are connected. Further, the VLAN tag of the switching hub may be deleted or added inside the server.
<figref num="1">The system configuration diagram in this embodiment.</figref><figref num="2">Hardware configuration diagram of server (100).</figref><figref num="3">Software configuration diagram of the server.</figref><figref num="4">VLAN tag-Figure of NAT table (310).</figref><figref num="5">Figure of virtual device driver selection table (309).</figref><figref num="6">Figure of screen image in display device (204) of server (100) for creating VLAN tag-NAT table (310).</figref><figref num="7">Explanatory drawing which shows the flow of data at the time of data reception in a server.</figref><figref num="8">VLAN tag for receiving-Flowchart of processing in NAT processing means (112).</figref><figref num="9">Explanatory drawing which shows the change when constructing an IP packet from a MAC frame.</figref><figref num="10">Explanatory drawing which shows the flow of data at the time of data transmission in a server.</figref><figref num="11">VLAN tag for transmission-Flowchart of processing in NAT processing means (111).</figref><figref num="12">Explanatory drawing which shows the change when constructing a MAC frame from an IP packet.</figref>
Code description
100: VLAN server 101 ~ 103: Server process # 1 ~ # 3104: TCP / IP stack 105: Device driver 106 ~ 108: Virtual device driver # 1 ~ # 3109: Data link control unit 110: Virtual device driver selection means 111: Send VLAN tag-NAT processing means 112: Receive VLAN tag-NAT processing means 113: Switching hub 114 ~ 120: Port 1 ~ Port 7121 ~ 126: Client # 1-1 ~ # 3-2127 ~ 129: VLAN # 1 ~ # 3200: CPU201: Memory 202: Disk device 203: Network interface device 204: Display device 205: Input device 206: Local bus 207: LAN cable 300: Transmitter of virtual device driver # 1 301: Virtual device driver # 1 Receiver 302: Transmitter of virtual device driver # 2 303: Receiver of virtual device driver # 2 304: Transmitter of virtual device driver # 3 305: Receiver of virtual device driver # 3 306: Transmission of data link control Part 307: Outgoing packet queue 308: Receive part of data link control unit 400: VLAN tag-Service process column of NAT table 401: VLAN tag-Tag column of NAT table 402: VLAN tag-External IP address column of NAT table 403 : VLAN tag-Internal IP address column 500 in NAT table: Service process column 501 in virtual device driver selection table: Internal IP address column 502 in virtual device driver selection table 502: Virtual device driver column 600 in virtual device driver selection table: VLAN tag-NAT table creation screen 601: VLAN tag input field 602: External IP address input field 603: Internal IP address input field 800: Reception VLAN tag-Processing flowchart start in NAT processing means 801: Receive MAC frame Destination IP address and VLAN tag reference processing 802: VLAN tag-NAT table search processing 803: Search result judgment 804:Destination IP address change processing 805: Frame discard processing 806: MAC header removal processing 807: Receiving VLAN tag-End of processing flowchart in NAT processing means 900: MAC frame sent from client 901: MAC frame sent from client MAC header 902: IP header of the MAC frame sent from the client 903: Data of the MAC frame sent from the client 904: Source IP address of the MAC frame sent from the client 905: IP address of the destination of the MAC frame sent from the client 906: Received MAC frame in the server 907: MAC header of the received MAC frame in the server 908: IP header of the received MAC frame in the server 909: Data of the received MAC frame in the server 910: VLAN tag of the received MAC frame in the server 911: In the server Source IP address of the received MAC frame 912: Destination of the received MAC frame in the server External IP address 913: Received IP packet in the server 914: IP header of the received IP packet in the server 915: Data of the received IP packet in the server 916: Server Source IP address of the received IP packet in 917: Destination internal IP address of the received IP packet in the server 1100: VLAN tag for transmission-Flower chart of processing in NAT processing means Start 1101: Judgment of transmit packet queue 1102: Extraction of transmit packet queue Process 1103: Packet source IP address reference process 1104: VLAN tag-NAT table search process 1105: Search result judgment 1106: Source IP address change process 1107: Packet discard process 1108: MAC header addition process 1109: For transmission VLAN tag-End of processing flowchart in NAT processing means 1200: IP address sent from server 1201: IP header of IP packet sent from server 1202:Data of outgoing IP packet from server 1203: Source internal IP address of outgoing IP packet from server 1204: Destination IP address of outgoing IP packet from server 1205: Outgoing MAC frame from server 1206: Outgoing MAC frame from server MAC header 1207: IP header of MAC frame transmitted from server 1208: Data of MAC frame transmitted from server 1209: VLAN tag of MAC frame transmitted from server 1210: Source external IP address of MAC frame transmitted from server 1211 : Destination IP address of MAC frame sent from server 1212: MAC frame received by client 1213: MAC header of MAC frame received by client 1214: IP header of MAC frame received by client 1215: MAC frame received by client Data 1216: Source external IP address of the MAC frame received by the client 1217: Destination IP address of the MAC frame received by the client
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2003390337 | Japan | A | |
| JP20030390337 | – | – | – |
19 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Written notification of registration of transferR350 | R350 | |
| Request for change of ownership or part of ownershipS111 | S111 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| First payment of annual fees (during grant procedure)A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Report on retrievalA977 | A977 | |
| Written request for application examinationA621 | A621 |
Numbers
- Publication
- 4053967
- Publication, DOCDB
- 4053967
- Publication, EPODOC
- JP4053967B
- Application
- 390337
- Application, DOCDB
- 2003390337
- Application, EPODOC
- JP20030390337
Titles2
- Japanese
- VLANサーバ
- English
- VLAN server
Classification
- CPC, 1
- H04L12/4645
- IPC, 3
- H04L12 46
- H04L12 00
- H04L12 28