Discovery and visualization of active directory domain controllers in topological network maps
Abstract
This record has no abstract on file.
Term
2.5 yearsto projected expiry
Projected expiry 3 April 2029, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
1 claim: 1 independent, 0 dependent
- 1Zastrzeżenia patentowe 1. Sposób wykrywania kontrolera domeny, DC, usługi katalogowej active directory, AD, obejmujący:odwzorowywanie topologii sieci;tworzenie połączenia prostego protokołu dostępu do katalogów (lightweight directory access protocol), LDAP, przez powiązywanie z punktem końcowym protokołu LDAP;wykorzystywanie poleceń protokołu LDAP do przeprowadzenia wyszukiwania LDAP kontrolera DC usługi AD z wykorzystaniem utworzonego połączenia protokołu LDAP, oraz zwracanie co najmniej jednej pełnej, jednoznacznej nazwy domenowej, FQDN, wykrytego kontrolera DC usługi AD;oraz usuwanie powiązania z punktem końcowym protokołu LDAP, przy czym odwzorowywanie topologii sieci obejmuje wyszukiwanie węzłów w z góry określonej liczbie adresów protokołu internetowego, ip, i powtarzanie wyszukiwania dla z góry określonej liczby przeskoków. korelowanie danych adresowych warstwy 2 i warstwy 3;oraz określanie łączności sieciowej wykrytych adresów ip. 53/59P37532PL00 EP 2 294 792 B1 4. Sposób według zastrzeżenia 1, w którym odwzorowywanie topologii sieci obejmuje odbieranie i zapisywanie preferencji użytkownika zawierających rozmiar bloku adresów ip i liczbę przeskoków. 5. Sposób według zastrzeżenia 1, w którym powiązywanie z punktem końcowym protokołu LDAP obejmuje tworzenie połączenia protokołu LDAP z bieżącym punktem końcowym protokołu LDAP. 6. Sposób według zastrzeżenia 1, w którym powiązywanie z punktem końcowym protokołu LDAP obejmuje tworzenie powiązania protokołu LDAP z węzłem związanym z danymi uwierzytelniającymi domeny określonymi przez użytkownika. 7. Sposób według zastrzeżenia 1, w którym wykorzystywanie poleceń protokołu LDAP do przeprowadzenia wyszukiwania kontrolera DC usługi AD obejmuje: przeprowadzanie odwrotnego odpytywania serwera nazw domenowych, DNS, dla każdego wykrytego kontrolera DC usługi AD w celu ustanowienia adresu ip dla kontrolera DC usługi AD;umieszczanie, w wykazie, wykrytego kontrolera DC usługi AD, który posiada adres ip w zakresach adresów sieciowych wykrytych w odwzorowaniu. 8. Sposób według zastrzeżenia 1, w którym zwracanie co najmniej jednej nazwy FQDN obejmuje: wyszukiwanie nazwy FQDN kontrolerów domeny w jednostce organizacyjnej;oraz wyszukiwanie nazwy FQDN kontrolerów domeny we wskazanej specjalnej konfiguracji. 53/59P37532PL00 EP 2 294 792 B1 9. Urządzenie do wykrywania kontrolera domeny, DC, usługi katalogowej active directory, AD, przy czym urządzenie to zawiera: serwer skonfigurowany do odwzorowywania topologii sieci;tworzenia prostego protokołu dostępu do katalogów (lightweight directory access protocol), LDAP, przez powiązywanie z punktem końcowym protokołu LDAP;wykorzystywanie poleceń protokołu LDAP do przeprowadzenia wyszukiwania LDAP kontrolera DC usługi AD z wykorzystaniem utworzonego połączenia protokołu LDAP, oraz do zwracania co najmniej jednej pełnej, jednoznacznej nazwy domenowej, FQDN, wykrytego kontrolera DC usługi AD;oraz usuwania powiązania z punktem końcowym protokołu LDAP, przy czym, podczas odwzorowywania topologii sieci, serwer jest ponadto skonfigurowany do wyszukiwania węzłów w z góry określonej liczbie adresów ip i powtarzania wyszukiwania dla z góry określonej liczby przeskoków. 10. Urządzenie według zastrzeżenia 9, w którym, podczas odwzorowywania topologii sieci, serwer jest skonfigurowany do przesyłania danych syntetycznych w sieci, oraz śledzenia danych syntetycznych. 11. Urządzenie według zastrzeżenia 9, w którym, podczas odwzorowywania topologii sieci, serwer jest ponadto skonfigurowany do: określania łączności warstwy 2 i warstwy 3 na podstawie wykrytych węzłów;korelowania danych adresowych warstwy 2 i warstwy 3;oraz określania łączności sieciowej wykrytych adresów ip. 53/59P37532PL00 EP 2 294 792 B1 przeskoków. 13. Urządzenie według zastrzeżenia 9, w którym, podczas powiązywania z punktem końcowym protokołu LDAP, serwer jest ponadto skonfigurowany do tworzenia połączenia protokołu LDAP z bieżącym punktem końcowym protokołu LDAP. 14. Urządzenie według zastrzeżenia 9, w którym, podczas powiązywania z punktem końcowym protokołu LDAP, serwer jest ponadto skonfigurowany do tworzenia powiązania protokołu LDAP z węzłem związanym z danymi uwierzytelniającymi domeny określonymi przez użytkownika. 15. Urządzenie według zastrzeżenia 9, w którym, podczas wykorzystywania poleceń protokołu LDAP do przeprowadzenia wyszukiwania kontrolera DC usługi AD, serwer jest ponadto skonfigurowany do: przeprowadzania odwrotnego odpytywania serwera nazw domenowych, DNS, dla każdego wykrytego kontrolera DC usługi AD w celu ustanowienia adresu ip dla kontrolera DC usługi AD;umieszczania, w wykazie, wykrytego kontrolera DC usługi AD, który posiada adres ip w zakresach adresów sieciowych wykrytych w odwzorowaniu. 53/59P37532PL00 EP 2 294 792 B1 16. Urządzenie według zastrzeżenia 15, w którym, podczas zwracania co najmniej jednej nazwy FQDN, serwer jest ponadto skonfigurowany do: wyszukiwania nazwy FQDN kontrolerów domeny w jednostce organizacyjnej;oraz wyszukiwania nazwy FQDN kontrolerów domeny we wskazanej specjalnej konfiguracji. 17. Program komputerowy do wykrywania kontrolera domeny, DC, usługi katalogowej active directory, AD, zawarty na nieprzechodnim odczytywalnym komputerowo nośniku, przy czym program komputerowy jest skonfigurowany do sterowania procesorem, aby wykonywał operacje obejmujące: odwzorowywanie topologii sieci;tworzenie połączenia prostego protokołu dostępu do katalogów (lightweight directory access protocol), LDAP, przez powiązywanie z punktem końcowym protokołu LDAP;wykorzystywanie poleceń protokołu LDAP do przeprowadzenia wyszukiwania danych LDAP dla kontrolera DC usługi AD z wykorzystaniem utworzonego połączenia protokołu LDAP, oraz zwracanie co najmniej jednej pełnej, jednoznacznej nazwy domenowej, FQDN, wykrytego kontrolera DC usługi AD;oraz usuwanie powiązania z punktem końcowym protokołu LDAP, którym odwzorowywanie topologii sieci obejmuje wyszukiwanie węzłów w z góry określonej liczbie adresów ip i powtarzanie wyszukiwania dla liczby przeskoków. góry określonej 18. Program komputerowy według zastrzeżenia 17, w którym odwzorowywanie topologii sieci obejmuje: przesyłanie danych syntetycznych w sieci;oraz śledzenie danych syntetycznych. 53/59P37532PL00 EP 2 294 792 B1 19. Program komputerowy według zastrzeżenia 17, w którym odwzorowywanie topologii sieci obejmuje ponadto: określanie łączności warstwy 2 i warstwy 3 na podstawie jakichkolwiek wykrytych węzłów;korelowanie danych adresowych warstwy 2 i warstwy 3;oraz określanie łączności sieciowej wykrytych adresów ip. 20. Program komputerowy według zastrzeżenia 17, w którym odwzorowywanie topologii sieci obejmuje odbieranie i zapisywanie preferencji użytkownika zawierających rozmiar bloku adresów ip i liczbę przeskoków. 21. Program komputerowy według zastrzeżenia 17, w którym powiązywanie z punktem końcowym protokołu LDAP obejmuje tworzenie połączenia protokołu LDAP z bieżącym punktem końcowym protokołu LDAP. 22. Program komputerowy według zastrzeżenia 17, w którym powiązywanie z punktem końcowym protokołu LDAP obejmuje tworzenie powiązania protokołu LDAP z węzłem związanym z danymi uwierzytelniającymi domeny określonymi przez użytkownika. 23. Program komputerowy według zastrzeżenia 17, w którym wykorzystywanie poleceń protokołu LDAP do wyszukiwania kontrolera DC usługi AD obejmuje: przeprowadzanie odwrotnego odpytywania serwera nazw domenowych, DNS, dla każdego wykrytego kontrolera DC usługi AD w celu ustanowienia adresu ip dla kontrolera DC usługi AD;umieszczanie, w wykazie, wykrytego kontrolera DC usługi AD, który posiada adres ip w zakresach adresów sieciowych wykrytych w odwzorowaniu. 53/59P37532PL00 EP 2 294 792 B1 24. Program komputerowy według zastrzeżenia 23, zwracanie co najmniej jednej nazwy FQDN obejmuje: wyszukiwanie nazwy FQDN kontrolerów domeny w organizacyjnej;oraz wyszukiwanie nazwy FQDN kontrolerów domeny we specjalnej konfiguracji. Solarwinds Worldwide, Pełnomocnik: w którym jednostce wskazanej LLC 53/59P37532PL00 EP 2 294 792 B1 Figura 1 Kontroler D( usługi AD Połączenia Sieć 10 Jednostka odwzorowania kontrolera DC usługi AD 100 Moduł Baza danych odwzorowania sieci DB węzłów Moduł wykrywania Interfejs użytkownika kontrolera DC usługi AD Polecenia LDAP 121 53/59P37532PL00 EP 2 294 792 B1 53/59P37532PL00 EP 2 294 792 B1
105 paragraphs in 30 sections, as filed
The present invention relates to the use of network topology mapping techniques for detecting and integrating with topological network mapping to detect domain controllers (DC) of the Active Directory (AD) directory service.
BACKGROUND OF THE INVENTION [0002] Documents XP2556498, US 2006/056306 A1 and XP15053254 constitute the known state of the art relating to the invention. The AD DC controller or functionally similar network nodes perform important administrative functions in the network. For example, the AD DC controller usually manages user and device registration and access.
[0003] Over time, as the network grows, expands, and expands, the AC controller DC service locations may be lost. Known AD DC controller mapping tools start with a set of known nodes and check the characteristics of the nodes to identify the AD DC controller. However, if the nodes are no longer known, these nodes cannot be checked to determine if they are an AD DC controller. In addition, each network section must usually have a local AD DC controller, and a known application may incorrectly identify any AD DC controller for each located node group. Thus, AD mapping AD service without infrastructure tools network infrastructure topology traditional visualization integrate integration with
53 / 59P37532PL00
EP 2 294 792 B1 [0004]
Network topology is a mapping of especially (virtual) physical elements of system connections or etc.) of networks, and logical ones. The local network (links, nodes, (real)) between computer nodes (LAN) is one example of a network that shows both physical and topology logical topology. Any given node in the LAN will have one or more links to one or more other nodes in the network, and mapping these links and nodes to a graph results in a geometric shape that determines the physical topology of the network. Similarly, mapping data flow between nodes in a network determines the logical topology of the network.
[0005] Network topology thus describes a specific physical or logical arrangement of network elements. The elements can be physical or logical so that the physical elements are real, and the logical elements can be, for example, virtual elements or the arrangement of network elements. The two networks can share a similar topology if the connection configuration is the same, although the networks may differ in other aspects such as physical interconnections, domains, node distances, transmission rates and / or signal types. A network can contain many smaller networks. As an example, a private telephone exchange is a network and this network forms part of the local telephone exchange. The local exchange is part of a larger telephone network that allows international calls, and is network-connected to the mobile telephone network.
[0006] Any given network topology is only determined by graphical mapping of physical configuration and / or logical connections between nodes. The topology of the LAN is technically part of graph theory. Node distances, physical interconnections, transmission rates and / or signal types may differ in two networks, and their topologies may still be identical. Layout or
53 / 59P37532PL00
The mapping of network elements creates specific basic topologies that can then be combined to create more complex topologies (hybrid topologies). The most common of these basic types of topology are: bus (such as linear, distributed bus), star, ring, mesh (including partially connected or fully connected mesh), tree, hybrid topology, which consists of one or more topologies networks, and point-to-point.
[0007] The logical topology corresponds to the mapping of visible connections between network nodes, as follows from the path that data apparently takes when passing between nodes. The logical classification of network topology basically corresponds the same classifications as for physical classifications of network topologies, where the path followed by data between nodes is used to determine the topology as opposed to the actual physical connections used to determine the topology. Logical topologies are often closely related to media access control (MAC) methods and protocols. Logical topologies are generally defined by network protocols as opposed to determined by the physical arrangement of cables, wires and network devices, or by the flow of electrical signals, although, in many cases, the paths that electrical signals follow between nodes may closely match the logical data flow, hence the convention the interchangeable use of the terms 'logical topology' and 'signal topology'. Logical topologies are usually capable of dynamic reconfiguration using special types of equipment such as routers and switches.
The essence of the invention
53 / 59P37532PL00
EP 2 294 792 B1)
DC [0008] The invention is defined by the content of the independent. Examples of this embodiment for the detection of active directory (AD) directory domain controllers through a topography mapping method and application that create a topological network mapping, use lightweight directory access protocol (LDAP) queries, and return data analysis to identify the controller DC of AD service and then integrating devices supporting LDAP with topological mapping.
[0009] Some embodiments of the present application relate to the detection of an AD DC controller that includes determining network topology, such as nodes and connections in the network. Once determined, the network topology, such as nodes and connections in the network, is determined. Then, LDAP connections are created (associated) either (a) with the user's current LDAP endpoint ("server") or (b) if the user has specified one or more domain credentials, with the LDAP endpoint associated with those credentials . LDAP connections can be created using traditional techniques and commands. Then, LDAP data searches are performed using the connections created to return any known full unambiguous domain names (FQDNs) of the domain controllers. Reverse polling of the domain name server (DNS) is then performed for each detected domain controller (DC) to establish the IP address for the DC controller. Any DC controller that turns out to have an IP address in the ranges of network addresses detected in the network topology can be placed in an existing list of discovered nodes, each identified as a DC controller. Finally, LDAP connections are closed or their binding is removed.
53 / 59P37532PL00
EP 2 294 792 B1
BRIEF DESCRIPTION OF THE DRAWINGS [0010] For a proper understanding of the invention, refer to the attached drawings, in which:
FIG. 1 is a high level diagram of a AD controller DC mapping system in accordance with embodiments of the present application;
FIG. 2 is a flowchart of a method of mapping the network in accordance with the embodiments of the present application; and
FIG. 3 is a flowchart of a method for mapping the AD DC controller in accordance with the embodiments of the present application.
DETAILED DESCRIPTION OF PREFERRED EMBODIMENTS [0011] With reference to FIG. 1, embodiments of the present application relate to an AD mapping DC controller 100 configured to connect to a network 10 that includes a plurality of nodes 1a, 1b. In particular, the network 10 includes an AD DC controller 1a and other nodes 1b as detailed below.
[0012] In some networks, the AD 1a DC controller are servers that respond to security authentication requests (login, permission checks, etc.) in the server domain. Typically, one of the DC controllers per domain has been configured as the primary domain controller (PDC); all other DC controllers have become redundant domain controllers (BDCs). The BDC controller could authenticate users in the domain, but all domain updates (new users, changed passwords, group memberships, etc.) could only be made through the PDC controller, which would then send these changes to all BDC controllers in the domain.
53 / 59P37532PL00
EP 2 294 792 B1
If the PDC became unreachable (or unable to communicate with the user requesting the change), the update would fail. If the PDC has become permanently unreachable (e.g. if the device has failed), the existing BDC could be promoted to the PDC. Due to the decisive nature of the PDC controller, the best practical actions indicated that the PDC controller should be dedicated only to domain services, and not be subject to use for file / print / application services that could slow down or cause a system crash.
[0013] In newer networks, AD has largely eliminated the idea of PDC and BDC controllers in favor of multi-master replication.
However, there are still many roles that only one domain controller can play, called Flexible Single Master Operation roles. Some of these roles must be performed by one DC controller per domain, while others require only one DC controller per AD forest. If a server with one of these roles is lost, the domain can still function, and if the server is unreachable again, the administrator can designate an alternate DC controller to take over its role, in a process known as role takeover.
[0014] AD is usually managed using a graphical management console (Management Console). The AD service implements the directory services for the lightweight directory access protocol (LDAP), described below. The main purpose of AD is to provide central authentication and authorization services. The AD service also allows administrators to assign policies, apply software, and apply critical updates to organizations. The AD service stores information and settings in a central database. AD networks
53 / 59P37532PL00
EP 2 294 792 B1 can be different from small installations with several hundred facilities to large installations with millions of facilities.
[0015] The AD service is a directory service used to store information about network resources within a domain. The AD structure is a hierarchical structure of objects. Objects fall into three broad categories: resources (e.g. printers), services (e.g. email), and users (accounts and user groups). The AD service provides information about objects, organizes objects, controls access and sets security.
[0016] Each object represents a single unit (be it a user, computer, printer or group) and its attributes. Some objects can also be containers of other objects. The object is uniquely identified by its name and has a set of attributes, characteristics and information that the object can contain, defined by a schema, which also defines the type of objects that can be stored in AD.
[0017] Each attribute object may be used in several different schema class objects. These schema objects exist to allow you to extend or modify the schema when you need it. However, because each schema object is an integral part of the AD object definition, deactivating or changing these objects can have serious consequences because it will fundamentally change the structure of AD itself. The schema object that has changed will automatically propagate within AD, and once the object is created, the object can usually only be deactivated, but not deleted. Similarly, changing the schema usually requires a significant amount of planning.
[0018] The structure that maintains the objects is seen at many levels. At the top of the structure is a forest (Forest) set of each object, its attributes, and rules (attribute syntax) in AD. The forest maintains one or more
53 / 59P37532PL00
EP 2 294 792 B1 transitive trees in a trust relationship. The tree maintains one or more domains and domain trees that are re-associated in the transitive trust hierarchy. Domains are identified by their DNS name structure, namespace.
[0019] Objects maintained in the domain can be grouped into containers called organizational units (OU). OUs give a domain a hierarchy, facilitate its administration, and can provide an organizational or geographical impression of organization structure. An OU may contain smaller OUs and can maintain multiple nested OUs. Usually, it is recommended that there be as few domains as possible in AD and to rely on OUs to structure and streamline policy implementation and administration. The OU is the common level at which group policies that are AD objects, called Group Policy Objects (GPOs), apply, although policies can also be applied to domains or sites. The OU is the level at which administrative authorities are usually appointed, but detailed designation for individual objects or attributes can also be carried out.
[0020] AD also supports the creation of sites that are physical rather than logical groupings defined by one or more IP subnets. Sites distinguish between locations connected using low speed connections (e.g. wide area network (WAN), virtual private networks (VPN)) and using high speed connections (e.g. local area networks (LAN)). Sites are independent of the domain and OU structure, and are shared throughout the forest. Sites are used to control network traffic generated by replication, and to direct clients to the nearest domain controllers. Exchange 2007 also uses the site topology for
53 / 59P37532PL00
Mail routing. Policies can also be applied at the site level.
[0021] The actual division of an enterprise information infrastructure into a hierarchy of one or more top-level domains and OUs is often a key decision. Typical models are by business unit, by geographic location, by type of service, or by type of facility. These models are also usually used in combination. OUs should first be structured to facilitate administrative designation and secondly to facilitate the application of group policies. Although OUs can create an administrative boundary, the only really secure border is the forest itself, and the administrator of any domain in the forest must be trusted across all domains in the forest.
[0022] Physically, the AD information is maintained in one or more peer DC controllers. Typically, each DC controller has a copy of AD, and changes on one computer are synchronized, or strive for convergence, among all DC controller computers as a result of multi-master replication. Connected servers that are not DC controllers are called Member Servers.
[0023] The AD service database is usually divided into different warehouses or parts. The "Schema" section defines the object classes and attributes in the forest. The "Configuration" section contains information about the physical structure and configuration of the forest (such as site topology). The "Domain" part maintains all objects created in this domain. The first two parts are replicated to all DC controllers in the forest. The domain part is replicated only to DC controllers in your domain. Subsets of objects in the domain section are also replicated to DC controllers that are configured as global directories.
53 / 59P37532PL00
[0024] The AD service is essentially fully integrated with DNS and the TCP / IP protocol. AD replication is a demand-based technology (pull technology), not an automatic technology (push technology) in which the data is a consistency check tool
Consistency Checker) (KCC) creates a site link using distributed information topology on demand (Knowledge of replication of defined sites to manage traffic. Inside the site is
Replication as a result of replication) are less frequent and automatic change notifications, which means that peer nodes start the replication cycle according to their demand (pull Replication intervals occur between sites and do not use the change notification by default, although they can be configured and they can be identical to replication inside the site. A different calculation cost can be assigned to each link and the site link topology will be changed accordingly by the KCC tool. Replication between DC controllers can be transitive through several site links on site link bridges of the same protocol if the "cost" is low, although the KCC automatically determines the cost of a direct link between two sites as lower than for transitive connections. Replication between two sites configured to occur (bridgehead server) in each replicates changes to other DC controllers in the site.
[0025] In a multi-domain forest, the AD database is divided. This means that each domain maintains a list of only those objects that belong to that domain. For example, a user created in Domain A would only be in the Domain A DC controller list. Global catalog server (GC) servers are used to provide a global listing of all objects in the forest. The global catalog is maintained in DC controllers configured as it can be front-end then between the site server that
53 / 59P37532PL00
Global catalog servers. Global catalog servers replicate all objects from all domains with each other, and thus provide a global list of objects in the forest. However, in order to minimize replication traffic and keep the GC catalog database small, only the selected attributes of each object are replicated. This is referred to as the partial attribute set (PAS). The PAS set can be modified by modifying the schema and marking attributes for replication to the GC catalog.
[0026] Active Directory directory service replication uses remote procedure calls. For example, between sites, the user can choose to use SMTP for replication, but only for schema or configuration changes. SMTP cannot be used to replicate parts of a domain. In other words, if there is a domain on both sides of the WAN connection, RPC is used for replication.
[0027] The Active Directory directory service is a necessary component for many services in an organization, such as email exchange. Flexible Single Master Operation (FSMO) roles are also known as role operations master. Although AD DC controllers work in a multi-parent model, i.e. updates can occur in many places at once, there are several roles that are necessarily a single instance:
[0028] AD usually supports UNC (\), URL (/) and
LDAP URL for access to objects. The AD service internally uses the version of LDAP with the X.500 naming structure. Each object has a common name (CN) and a distinguished name (DN). The DC controller is a domain object class and can have many more than four parts. The object can also have a canonical name, essentially an inverted DN, without identifiers, and using diagonal lines. To identify an object in its container, the distinguished name (RDN) is used. Each object has
53 / 59P37532PL00
Also a globally unique identifier (GUID), a unique and immutable 128-bit string that is used by AD for search and replication. Some objects also have a user principal name (UPN), in the form of object name @ domain.
[0029] In order to allow users in one domain to access resources in another domain, AD uses trusts. In-forest trusts are automatically created when domains are created. The forest sets the default trust limits, not the domain, and implicitly, transitive trust is automatic for all domains in the forest. Just like two-way transitive trust, AD trust can be a shortcut (connects two domains of different trees, transitive, one-way or two-way), forest (transitive, one-way or two-way), sphere (transitive or intransitive, one-way or two-way), or external (non-transition, one-way or two-way) to connect to other forests or domains other than AD domains. For one-way trust, when one domain allows users to access the second domain, but the other domain does not allow users to access the first domain. For two-way trust, two domains allow users to access the other domain. In this context, the trusting domain is a domain that allows users to access from a trusted domain, wherein the trusted domain is a domain that is trusted; whose users have access to the trusting domain.
[0030] Software distribution is performed by a separate service that uses additional proprietary schema attributes that work in conjunction with the LDAP protocol. The Active Directory directory service does not automate software distribution, but provides a mechanism by which other services can provide software distribution.
53 / 59P37532PL00
[0031] The AD controller mapping unit 100 includes mapping module 110. In particular, the mapping module 110 is configured to map the nodes 1a, 1b in the network 10 and optionally also to map the connections 2 that connect the nodes 1a, 1b. Various network topography mapping techniques are known and may be integrated in embodiments of the present application as detailed below.
[0032] Mapping module 110 automatically detects everything on the network, including desktops, servers, printers, hubs, switches and routers using identification and detection methods (ping / ICMP, SNMP, SIP-based VoIP, NetBIOS and others) for scanning IP ranges and discovery nodes, as described below in FIG. 2.
[0033] Referring now to FIG. 2, the way is presented
200 mapping according to embodiments of the present application. In particular, the mapping method 200 includes the step of defining data mapping criteria in step 210. For example, the user may define the range of IP addresses, the number of hops (or connected devices with each detected device), and types of devices (e.g. SNMP devices or response clients) to be detected during search.
[0034] Continuing reference to FIG. 2, in step 220, a node search is performed. For example, types of detection methods such as ICMP Ping, NetBIOS, SIP clients, etc. require the transmission of small UDP or ICMP packets to each IP address within a defined range, as well as device detection in terms of hop counts from the detected device. Thus, data is sent and tracked for each defined IP address to determine the device associated with the IP address and the physical and virtual paths used to reach the corresponding IP address.
53 / 59P37532PL00
EP 2 294 792 B1
Optionally, large ranges of IP addresses are further divided into blocks of 10 addresses, with the answers being searched for from these 10 addresses. By searching the network in this way, the perceptible effects on the bandwidth of the network or device are minimized.
[0035] Continuing reference to FIG. 2, node detection in step 220 is described in more detail. Searching for nodes in blocks with a previously selected number of N IP addresses using user-configured discovery methods, step 221. Then, layer 3 connectivity can be determined based on any detected nodes in step 222. If a hop count> 0 is specified, then step 221 is repeated with the newly detected network ranges until hop count is reached, step 223. Then, layer 2 connectivity is determined based on any detected nodes identified as the managed switch or hub in step 224. Layer 2 and Layer 3 address data from steps 221-224 are then correlated, for example, by using an address translation table (ARP) and a Spanning Tree table collected from detected nodes with the SNMP function in step 225. Then , network connectivity is determined in step 226 by examining each IP address (s) of the discovered nodes. Layer 2 connectivity is used when available; otherwise, layer 3 connectivity is used.
[0036] The results of the network topology search are recorded in step 230. For example, mapping module 110 may collect and save all topology information in database 140, providing topology source and asset information for the enterprise configuration management database (CMDB) strategy . The mapping module 110 also automatically maintains this data to update network nodes, thus providing network engineers constantly
53 / 59P37532PL00
Accurate representation of the network for visibility and compliance requirements.
[0037] Optionally, the results of the network topology search are recorded in step 230. For example, when network nodes are detected, the mapping module 110 can compile information into a coherent, readable mapping of the network topology, for example, using node icons and colored lines representing speed network connectivity on user interface 130. In this way, mapping module 110 allows network engineers to see exactly how devices on the network are connected. The mapping module 110 can access managed switches and hubs to create an accurate port connectivity scheme for all network devices, resulting in a complete mapping that illustrates all nodes connected directly to the managed switch or hub, with port information displayed next to node.
Returning to FIG 1, in one implementation of the present application, the mapping module 110 implements mapping of layer 2. Layer 2, or the data link layer, provides functional and procedural means for transferring data between network units and for detecting and possibly correcting errors that may occur in the physical layer. Originally, this layer was intended for point-to-point or point-to-point carriers characteristic of wide area network carriers in the telephone system. The local area network (LAN) architecture, which contained multi-available media with the ability to broadcast, was developed independent of ISO operations in the IEEE 802 Project. LAN services usually organize bits, from the physical layer, into logical sequences called frames. Logical Link Control Sublayer
53 / 59P37532PL00
[0039] The highest sublayer is Logical Link Control (LLC). This sublayer multiplexes protocols operating at the top of the data link layer, optionally providing flow control,
Layer LLC provides data. It defines confirmation and deleting addressing and error control link mechanisms to be used to address the station in the transmission medium and to control data exchanged between source and destination devices.
[0040] The sublayer below the LLC layer is Media Access Control (MAC). Sometimes this applies to the sublayer that determines who is allowed to access the media at any given time (usually CSMA / CD), and at other times it refers to the frame structure with MAC addresses inside. There are basically two forms of media access control: distributed and centralized. The media access control sublayer also determines where one data frame ends and the next begins.
[0041] Continuing reference to FIG 1, in one implementation of the present application, mapping module 110 implements mapping of layer 3. Layer 3, or the network layer, is the third layer among seven in the OSI model and the third layer of five in the TCP / IP model. In fact, the network layer is responsible for delivering packets from one end to the other (from source to destination), while the data link layer is responsible for delivering frames from node to node (from one hop to another). The network layer provides functional and procedural means for transmitting variable length data sequences from the source to the destination via one or more networks, while maintaining service quality and error control functions. The network layer deals with
53 / 59P37532PL00
By transmitting information all the way from their source to their destination.
[0042] By implementing multi-level discovery, the mapping module 110 uses a variety of detection methods to provide integrated mapping of the layer 2 and layer 3 topology of the OSI model comprising
- IP address - MAC address
- Last logged in user (requires optional response clients)
- DNS name
- The node name (specified by SNMP or other client protocol)
- Switch port connection [0043] This multi-level network infrastructure data detection allows network engineers to easily access important time-saving features, including automated topology representation at levels, to show routers and subnets, additionally managed switches and hubs, or in addition, end nodes , which can be filtered by type or group to further refine layouts.
[0044] Continuing reference to FIG. 1, the AD DC controller mapping unit 100 further includes the AD DC controller discovery unit 120. In particular, when the mapping module 110 has created the topology mapping, the AD DC controller detection unit 120 may use this mapping data to determine the location of the AC DC controller 1a in the module network 10.
[0045] The AD DC Controller Discovery Unit 120 uses lightweight directory access protocol (LDAP) commands 121 to create queries and parse returned data to
53 / 59P37532PL00
Then
LDAP to identify the AD DC controller and integrate devices that support the topological mapping protocol.
[0046] LDAP is an application protocol for polling and modifying directory services based on the TCP / IP protocol. A catalog is a collection of objects with similar attributes organized in a logical and hierarchical manner. The most common example is the telephone directory, which consists of a series of names (either persons or organizations) organized alphabetically, with each name accompanied by an address and telephone number. Because of this basic construction (among other factors), LDAP is often used by other services for authentication, despite the security problems it causes.
[0047] The LDAP directory tree often reflects different political, geographical and / or organizational boundaries, depending on the model chosen. The current use of LDAP seeks to use domain name system (DNS) names to structure the highest levels of hierarchy. Deeper inside the directory, there may be entries representing individuals, organizational units, printers, documents, groups of people, and anything else that represents a given entry (or multiple entries) of the tree.
[0048] The current version of LDAPv3 is defined in a series of comments Requests for comments (RFC) of the Internet Engineering Task Force (IETF) in the Standard Track category, described in detail in RFC 4510.
[0049] The client starts an LDAP session by connecting to the LDAP server, by default on TCP port 389. The client then sends requests for operations to the server, while the server sends replies. With a few exceptions, the client does not need to wait for a response before sending the next request, and the server can send responses in any order. The client may request several different operations.
53 / 59P37532PL00
[0050] LDAP is defined within the scope of the standard
ASN.1, while protocol messages are encoded in binary BER format, and uses text representations for many ASN.1 fields / types.
- The protocol accesses the LDAP directories:
- The directory is a directory entry tree.
- The entry consists of a set of attributes.
- The attribute has a name (attribute type or attribute description) and one or more values. The attributes are defined in the schema (see below).
- Each entry has a unique identifier: its distinguished name (DN). It consists of a distinguished name (RDN) formed from a certain attribute (s) in the entry followed by the DN of the parent entry, where DN is the full file name and RDN as the relative file name in the folder.
[0051] The DN may change during the lifetime of the entry, for example when entries are moved within a tree. In order to reliably and uniquely identify entries, a UUID could be provided in a set of working attributes of an entry.
[0052] The server maintains a subtree starting from a specific entry, e.g. "dc = example, dc = com" and its children. Servers can also maintain references to other servers, so an attempt to access "ou = department, dc = example, dc = com" could return a referral or continuation reference to the server that maintains that part of the directory tree. The client can then connect to another server. Some servers also support chaining, which means that the server connects to another server and returns the results to the client.
[0053] LDAP rarely specifies any order: The server can return values in the attribute,
53 / 59P37532PL00
Attributes in the entry, and entries found by the search operation in any order. This feature results from formal definitions, and the entry is defined as a set of attributes, while the attribute is a set of values, and the sets do not need to be ordered.
[0054] In LDAP operations, the client assigns a positive Message ID to each request, and the server response has the same Message ID. The response contains a numeric result code that indicates success, some error condition, or some other special case. Before responding, the server may send other messages with different result data. For example, any entry found by a search operation is returned in such a message.
[0055] The LDAP search operation can be used for both searching and reading entries. The server returns matching entries and perhaps references to continue (in any order), followed by the final result with the result code. The comparison operation retrieves the DN, attribute name and attribute value, and checks whether the named entry contains this attribute with that value.
[0056] The contents of subtree entries are managed by the schema. The schema defines the types of attributes that directory entries may contain. The attribute definition includes syntax, and most non-binary values in LDAPv3 use UTF-8 string syntax. The schema defines object classes. Each entry must have an object class attribute (objectClass) containing named classes defined in the schema. The schema definition for entry classes defines what type of object the entry can represent - e.g. a person, organization or domain. Object class definitions also indicate which attributes are mandatory and which are optional. For example, an entry representing a person could belong to the classes "top" and "person". Belonging to the "person" class would require that this entry contain the attributes "sn" and "cn", and allow the entry
53 / 59P37532PL00
EP 2 294 792 B1 also contained the attribute "user password" ("userPassword"), "telephone number" ("telephoneNumber"), and other attributes. Because entries can belong to many classes, each entry has a set of optional and mandatory sets of attributes created it represents.
inherited from a combination of object classes that it has
Object classes (ObjectClasses) can be a single entry can have multiple object classes to define the available and required attributes of the entry itself. Parallel to the object class schema is the class definition and the instance in object-oriented programming, representing the LDAP object class and the LDAP entry, respectively.
[0057] The schema also contains various other information controlling directory entries. Most schema elements have a name and globally unique object identifier (OID). Directory servers can publish the directory schema that controls the entry in the base DN given by the work attribute of the sub-schema / child entry for the entry (the work attribute describes the directory operation, not user information, and is returned from the search only when explicitly requested). Server administrators can define their own schemes as additional to standard schemes. The scheme to represent individuals in an organization is referred to as the white pages schema.
[0058] Referring back to FIG. 1, in one configuration, the user logs in to the AD DC controller discovery unit with administrator access, and then the AD DC controller discovery module 120 accesses the 130 node database and directs synthetic LDAP functions to the identified nodes 1a, 1b in the network 10 to specify DC 1 controller and AD on the network.
[0059] When this AD DC controller location 1a information is located by the detection module 120
53 / 59P37532PL00
In the AD DC controller, the database of 130 nodes may be updated to reflect this information about the locations of the AD DC controller 1a, and the display 140 may specifically display the AD DC controller 1a, e.g. by indicating the DC controller 1a of the service AD by means of a special symbol, color or graphic.
[0060] Referring now to FIG. 3, embodiments of the present application relate to a method 300 of detecting an AD DC controller, which includes the steps of: determining the network topology at step 310, such as nodes and connections in the network. For example, as described above, in step 310, synthetic data may be transmitted over the network and tracked to determine the presence and relationship between the various network components. Alternatively, other mapping techniques rely on mapping a known set of nodes to determine the relationship between nodes.
[0061] Then, LDAP connections are created (associated) in step 320 or (a) with the user's current LDAP endpoint (or "server"). Alternatively, if the user has specified one or more domain credentials, an association with the LDAP endpoint associated with the credentials is created. LDAP connections can be created using traditional techniques and commands.
[0062] Then, LPAD commands are used to locate the AD DC controller in step 330. For example, LDAP data searches can be performed using created connections to return any known full unambiguous domain names (FQDNs) of the DC domain controller in in steps 331 and 332. In particular, in step 331, the DC controller FQDN is searched for in the organizational unit. Similarly, at step 332, a DC controller FQDN name lookup is performed in the indicated special configuration. In this way, the controller
53 / 59P37532PL00
EP 2 294 792 B1
The AD DC located outside the LDAP endpoint identified in step 320 can be implemented using the mapping data from step 310. In the FQDN name search in steps 331 and 332, the ldapsearch API command (ldap_search_s ()) can be used, followed by any the answer (s) can be iterated for re-evaluation. This response (s) contains the FQDN of one or more DC controllers. [0063] Then, in step 333, reverse polling of the domain name server (DNS) of the domain controller (DC) detected in steps 331 of establishing the IP address for the DC controller is performed. In any DC controller that appears to have an IP address in the network address ranges detected in step 310, it is placed in an existing list of discovered nodes, each identified as a DC controller. At step 340, each LDAP connection created at step 320 is closed or its binding removed to return the node to its original state.
above, various embodiments configured in multiple elements may be configured in a single network element or configured in multiple elements having various distributed functions illustrated in their scope. IP SLA control or other monitoring configurations and other functions can be implemented in various network components, such as user equipment, in the VOIP server, in the access gateway or in another network component associated with the VOIP network and network access.
[0065] One of ordinary skill in the art will understand that the above-discussed embodiments of the invention have only an illustrative purpose, and that the invention may be practiced in many for everyone and 332 in order to step 334, [0064] As discussed, the invention may be physical, or may configurations as discussed above. In addition, the invention can be implemented as a computer program on a carrier
53 / 59P37532PL00
Computer readable, the computer program controlling a computer or processor to perform various functions that are discussed as method steps and also discussed as hardware or hardware / software components.
Solarwinds Worldwide, LLC Representative:
53 / 59P37532PL00
EP 2 294 792 B1
Contents30
10 members in 7 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 15327308 | United States of America | A | |
| 15327308 | United States of America | A | |
| 09746900 | European Patent Office (EPO) | A | |
| 2009002119 | United States of America | W | |
| 2009002119 | United States of America | W | |
| EP20090746900 | – | – | – |
| US20080153273 | – | – | – |
| WO2009US02119 | – | – | – |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| US2009285120A1 | United States of America | A1 | |
| WO2009139810A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2009139810A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP2294792A2 | European Patent Office (EPO) | A2 | |
| US8045486B2 | United States of America | B2 | |
| EP2294792B1 | European Patent Office (EPO) | B1 | |
| ES2562448T3 | Spain | T3 | |
| PT2294792E | Portugal | E | |
| DK2294792T3 | Denmark | T3 | |
| PL2294792T3This record | Poland | T3 |
Numbers
- Publication, DOCDB
- 2294792
- Publication, EPODOC
- PL2294792T
- Application
- 746900
- Application, DOCDB
- 09746900
- Application, EPODOC
- PL20090746900T
Titles2
- English
- DISCOVERY AND VISUALIZATION OF ACTIVE DIRECTORY DOMAIN CONTROLLERS IN TOPOLOGICAL NETWORK MAPS
- Polish
- Wykrywanie i wizualizacja kontrolerów domeny usługi katalogowej active directory w topologicznych odwzorowaniach sieci
Classification
- CPC, 3
- H04L41/12
- H04L41/0826
- H04L61/4523
- IPC, 3
- H04L12 24
- H04L29 08
- H04L29 12