Discovery and visualization of active directory domain controllers in topological network maps
Abstract
Active directory (AD) Domain Controllers (DC) discovery includes determining the topology of the network, such as the nodes and connections in the network. For example, synthetic data may be transferred within the network and traced to determine the presence and relationships of the various network components. Alternatively, other mapping techniques are based upon mapping a known set of nodes to determine the relationship of the nodes. Next, Lightweight Directory Access Protocol (LDAP) commands are forwarded to the various nodes to identify the AD DC within a range of IP addresses discovered during the mapping of to the topology of the network.
Term
2.5 yearsto projected expiry
Projected expiry 3 April 2029, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
24 claims: 3 independent, 21 dependent
- 1REIVINDICAÇÕES 1 - Método para descobrir um controlador de domínio, DC, de diretório ativo, AD, compreendendo:o mapeamento de uma topologia de uma rede;a criação de uma ligação de protocolo simples de acesso a diretórios, LDAP, por vinculação a um nó terminal de LDAP;a utilização de instruções de LDAP para realizar uma pesquisa de LDAP para o DC de AD utilizando a ligação de LDAP criada e a devolução de, pelo menos, um nome de domínio totalmente qualificado, FQDN, de um DC de AD descoberto;e a desvinculação do nó terminal de LDAP, em que o mapeamento da topologia da rede compreende a pesquisa de nós num número predefinido de endereços de protocolo de internet, ip, e a repetição da pesquisa para um número predeterminado de saltos.
- 22 - Método da reivindicação 1, em que o mapeamento de uma topologia de uma rede compreende:a transferência de dados sintéticos no interior da rede;e o seguimento dos dados sintéticos.
- 33 - Método da reivindicação 1, em que o mapeamento da topologia da rede compreende, ainda:a determinação da conectividade de camada 2 e camada 3 a partir de quaisquer nós descobertos;a correlação dos dados de endereço das camada 2 e camada 3;e a determinação da conectividade de rede de endereços de IP descobertos. ΕΡ 2 294 792/ΡΤ 2/6
- 44 - Método da reivindicação 1, em que o mapeamento da topologia da rede compreende a receção e armazenamento das preferências de utilizador, compreendendo o tamanho do bloco de endereços de ip e o número de saltos.
- 55 - Método da reivindicação 1, em que a vinculação do nó terminal de LDAP compreende a criação de uma ligação de LDAP a um nó terminal atual de LDAP.
- 66 - Método da reivindicação 1, em que a vinculação do nó terminal de LDAP compreende a criação de uma vinculação de LDAP a um nó associado com credenciais de dominio especificadas por utilizador.
- 77 - Método da reivindicação 1, em que a utilização das instruções de LDAP para realizar uma pesquisa para o DC de AD compreende:a realização de uma consulta de servidor de nomes de dominio, DNS, inversa para cada DC de AD descoberto de modo a estabelecer um endereço de ip para o DC de AD;a inserção, numa lista, de um DC de AD descoberto que tem um endereço de IP dentro de conjuntos de endereços de rede descobertos no mapeamento.
- 88 - Método da reivindicação 7, em que a devolução de, pelo menos, um FQDN compreende:a pesquisa do FQDN de controladores de dominio numa unidade organizacional;e a pesquisa do FQDN de controladores de dominio numa configuração especifica citada.
- 99 - Aparelho para descobrir um controlador de dominio, DC, de diretório ativo, AD, compreendendo o aparelho:um servidor configurado para o mapeamento de uma topologia de uma rede;ΕΡ 2 294 792/ΡΤ 3/6 a criação de um protocolo simples de acesso a diretórios, LDAP, por vinculação a um nó terminal de LDAP;a utilização de instruções de LDAP para realizar uma pesquisa de LDAP para o DC de AD utilizando a ligação de LDAP criada e para a devolução de, pelo menos, um nome de domínio totalmente qualificado, FQDN, de um DC de AD descoberto;e a desvinculação do nó terminal de LDAP, em que, durante o mapeamento da topologia da rede, o servidor é, ainda, configurado para realizar a pesquisa de nós num número predefinido de endereços de ip e para repetir a pesquisa para um número predeterminado de saltos.
- 1010 - Aparelho da reivindicação 9, em que, durante o mapeamento da topologia da rede, o servidor está configurado para:a transferência de dados sintéticos no interior da rede;e o seguimento dos dados sintéticos.
- 1111 - Aparelho da reivindicação 9, em que, durante o mapeamento da topologia da rede, o servidor está, ainda, configurado para:a determinação da conectividade de camada 2 e camada 3 a partir de quaisquer nós descobertos;a correlação dos dados de endereço das camada 2 e camada 3;e a determinação da conectividade de rede de endereços de IP descobertos.
- 1212 - Aparelho da reivindicação 9, em que, durante o mapeamento da topologia da rede, o servidor está, ainda, configurado para ΕΡ 2 294 792/ΡΤ 4/6 a receção e armazenamento das preferências de utilizador, compreendendo o tamanho do bloco de endereços de ip e o número de saltos.
- 1313 - Aparelho da reivindicação 9, em que, durante a vinculação do nó terminal de LDAP, o servidor está, ainda, configurado para a criação de uma ligação de LDAP a um nó terminal atual de LDAP.
- 1414 - Aparelho da reivindicação 9, em que, durante a vinculação do nó terminal de LDAP, o servidor está, ainda, configurado para a criação de uma vinculação de LDAP a um nó associado com credenciais de domínio especificadas por utilizador.
- 1515 - Aparelho da reivindicação 9, em que, durante a utilização das instruções de LDAP para realizar uma pesquisa para o DC de AD, o servidor está, ainda, configurado para:a realização de uma consulta de servidor de nomes de domínio, DNS, inversa para cada DC de AD descoberto de modo a estabelecer um endereço de ip para o DC de AD;a inserção, numa lista, de um DC de AD descoberto que tem um endereço de IP dentro de conjuntos de endereços de rede descobertos no mapeamento.
- 1616 - Aparelho da reivindicação 15, em que, durante a devolução de, pelo menos, um FQDN, o servidor está, ainda, configurado para:a pesquisa do FQDN de controladores de domínio numa unidade organizacional;e a pesquisa do FQDN de controladores de domínio numa configuração específica citada.
- 1717 - Programa de computador para descobrir um controlador de domínio, DC, de diretório ativo, AD, incorporado num meio ΕΡ 2 294 792/ΡΤ 5/6 legível por computador não transitório, sendo o programa de computador configurado para controlar um processador para este executar operações, compreendendo:o mapeamento de uma topologia de uma rede;a criação de uma ligação de protocolo simples de acesso a diretórios, LDAP, por vinculação a um nó terminal de LDAP;a utilização de instruções de LDAP para realizar uma pesguisa de dados de LDAP para o DC de AD utilizando a ligação de LDAP criada e a devolução de, pelo menos, um nome de domínio totalmente qualificado, FQDN, de um DC de AD descoberto;e a desvinculação do nó terminal de LDAP, em que o mapeamento da topologia da rede compreende a pesquisa de nós num número predefinido de endereços de protocolo de internet, ip, e a repetição da pesquisa para um número predeterminado de saltos.
- 1818 - Programa de computador da reivindicação 17, em que o mapeamento de uma topologia de uma rede compreende:a transferência de dados sintéticos no interior da rede;e o seguimento dos dados sintéticos.
- 1919 - Programa de computador da reivindicação 17, em que o mapeamento da topologia da rede compreende, ainda:a determinação da conectividade de camada 2 e camada 3 a partir de quaisquer nós descobertos;a correlação dos dados de endereço das camada 2 e camada 3;e a determinação da conectividade de rede de endereços de IP descobertos.
- 2020 - Programa de computador da reivindicação 17, em que o mapeamento da topologia da rede compreende a receção e ΕΡ 2 294 792/ΡΤ 6/6 armazenamento das preferências de utilizador, compreendendo o tamanho do bloco de endereços de ip e o número de saltos.
- 2121 - Programa de computador da reivindicação 17, em que a vinculação do nó terminal de LDAP compreende a criação de uma ligação de LDAP a um nó terminal atual de LDAP.
- 2222 - Programa de computador da reivindicação 17, em que a vinculação do nó terminal de LDAP compreende a criação de uma vinculação de LDAP a um nó associado com credenciais de domínio especificadas por utilizador.
- 2323 - Programa de computador da reivindicação 17, em que a utilização das instruções de LDAP para realizar uma pesquisa para o DC de AD compreende:a realização de uma consulta de servidor de nomes de domínio, DNS, inversa para cada DC de AD descoberto de modo a estabelecer um endereço de ip para o DC de AD;a inserção, numa lista, de um DC de AD descoberto que tem um endereço de IP dentro de conjuntos de endereços de rede descobertos no mapeamento.
- 2424 - Programa de computador da reivindicação 23, em que a devolução de, pelo menos, um FQDN compreende:a pesquisa do FQDN de controladores de domínio numa unidade organizacional;e a pesquisa do FQDN de controladores de domínio numa configuração específica citada.
Independent claims24
96 paragraphs in 6 sections, as filed
DESCRIPTION
Discovery and visualization of active directory domain controllers in network topological map maps
FIELD OF INVENTION
The present invention relates to the use of network topology mapping techniques for discovery and integration into network topological structure maps to discover Active Directory Domain (DC) Domain Controllers.
BACKGROUND OF THE INVENTION
XP2556498, US20061056306A1 and XP15053254 are prior art documents related to the invention.
AD DCs, or functionally similar network nodes, perform important administrative functions on the network. For example, AD DCs typically manage the registration and access of users and devices.
Over time, as a network grows, expands, and evolves, AD DC locations can be lost. Known AD DC mapping tools begin with a set of known nodes and observe the characteristics of nodes to identify AD DCs. However, if nodes are no longer known, these nodes cannot be polled to determine if they are AD DCs. In addition, each section of the network typically needs to have a local AD DC and the known application may not correctly identify any AD DC for each localized cluster of nodes. Thus, conventional AD mapping tools visualize the AD infrastructure without a sense of integration into the network infrastructure of the network topology.
Network topology is the study of the arrangement or mapping of the elements (links, nodes, etc.) of a network, in particular the physical (real) and logical (virtual) interconnections between nodes. A local area network (LAN) is an example of a network that has a physical topology and a logical topology. Any particular node in the LAN will have one or more links to one or more nodes in the network and the mapping of those links and nodes in a graph.
ΕΡ 2,294,792 / ΡΤ results in a geometric shape that determines the physical topology of the network. Similarly, data flow mapping between nodes in the network determines the logical topology of the network.
Thus, a network topology describes the specific physical or logical arrangement of the elements of a network. The elements may be physical or logical, the physical elements being real and the logical elements being, for example, virtual elements or an arrangement of the elements of a network. Two networks may share a similar topology if the configuration of the connections is the same, although networks may differ in other aspects such as physical interconnections, domains, node distances, transmission speeds and / or signal types. A network can incorporate multiple smaller networks. By way of example, a private telephone exchange is a network and that network is part of a local telephone exchange. The local exchange is part of a larger network of phones that allow international calling and is networked with mobile phone networks.
Any particular network topology is determined solely by graphically mapping the configuration of physical and / or logical links between nodes. A LAN Network Topology is therefore technically a part of the theory of gratitude. Node distances, physical interconnections, baud rates, and / or signal types may differ across two networks, yet their topologies may be identical. The arrangement or mapping of network elements gives rise to certain basic topologies, which can then be combined to form more complex topologies (hybrid topologies). The most common of these basic types of topologies include bus (such as Linear Bus, Distributed), star, ring, mesh (including a partially bonded or fully bonded mesh), tree, hybrid, which is composed of one or more network topologies, and point to point.
A logical topology corresponds to a mapping of apparent links between nodes in a network, as evidenced by the path that data seems to travel when traveling between nodes. The logical classification of network topologies generally follows the same classifications as the physical classifications of network topologies, and the path that data follows between nodes is used to determine the topology.
ΕΡ 2,294,792 / ΡΤ being the actual physical links used to determine the topology. Logical topologies are often closely associated with media access control (MAC) methods and protocols. Logical topologies are usually determined by network protocols and not determined by the physical arrangement of network cables, wires and devices or the flow of electrical signals, although in many cases the paths that electrical signals follow between us may coincide. closely with the logical flow of data, hence the convention of using the terms 'logical topology' and 'signal topology' as synonyms. Logical topologies are typically able to be dynamically reconfigured by special types of equipment, such as routers and switches.
Summary of the Invention
The invention is defined by the wording of the independent claims. Embodiments of the present patent application, related to the discovery of Active Directory (DC) Domain Controllers (AD) by means of a topography mapping application and method, which form a map of the network topological structure, use query and parsing data returned using Simple Directory Access Protocol (LDAP) to identify AD DCs and then integrate devices running LDAP into the topological map.
Certain embodiments of the present patent application relate to AD DC discovery which includes determining network topology, such as nodes and links in the network. After determining the network topology, nodes and connections on the network are determined. Then LDAP (linked) connections are created (a) to the current user's LDAP endpoint (server) or (b) if the user has specified one or more domain credentials, to the LDAP endpoint associated with those credentials. LDAP connections can be created using conventional techniques and instructions. Then, an LDAP data lookup is performed using the links created to return any known Fully Qualified Domain Names (FQDN) from Domain Controllers. A reverse Domain Name Server (DNS) query is then
29 2,294,792 / ΡΤ performed for each discovered Domain Controller (DC) in order to establish an IP address for the DC. Any DC that has an IP address in the discovered network address sets in the network topology can be inserted into the existing list of discovered nodes, each node being identified as a DC. Finally, LDAP bindings are closed or unlinked.
BRIEF DESCRIPTION OF DRAWINGS
For a good understanding of the invention, reference should be made to the accompanying drawings, in which:
Fig. 1 is a high level schematic diagram of an AD DC mapping system according to embodiments of the present patent application;
Fig. 2 is a flowchart of a network mapping method according to embodiments of the present patent application; and Fig. 3 is a flowchart of an AD DC mapping method according to embodiments of the present patent application.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
Referring to Fig. 1, embodiments of the present patent application relate to an AD DC mapping unit 100 configured to connect to network 10 that includes multiple nodes 1a, 1b. In particular, network 10 includes an AD 1a DC and other nodes 1b, as described in more detail below.
In some networks, AD la DC are servers that respond to security authentication requests (login, permission checking, etc.) within the server domain. Typically, one DC per domain has been configured as the Primary Domain Controller (PDC); all other DCs were Reserve Domain Controllers (BDC). A BDC can authenticate users to a domain, but all updates to the domain (new users, passwords).
ΕΡ 2,294,792 / ΡΤ
The communicating systems with unchanged updates, group membership, etc.) can only be performed through the PDC, which would then propagate these changes to all BDCs in the domain. If the PDC is not available (or unable the user requesting the change), the will be successful. If the PDC is permanently unavailable (eg, if the machine fails), an existing BDC can be promoted to PDC. Due to the critical nature of PDC, best practices dictate that PDC should be dedicated exclusively to domain services and not be used for file / print services / applications that may slow down or send the system down.
In newer networks, AD has largely eliminated the concept of PDC and BDC in favor of multi-master replication technology. However, there are still a number of functions that only a Domain Controller can perform, called Flexible Single Operations Masters functions. Some of these functions have to be performed by one DC per domain, while others require only one DC per AD forest. If the server performing one of these roles is lost, the domain may still function, and if the server is no longer available, an administrator can assign an alternate DC to take over the role, in a process known as role capture.
Typically, AD is managed using a graphical Management Console. AD is an implementation of Simple Directory Access Protocol (LDAP) directory services, described below. The primary purpose of AD is to provide central authentication and authorization services. AD also allows administrators to assign policies, deploy software, and apply critical updates to an organization. 0 FURTHER stores information and settings in a central database. AD networks can range from a small installation with a few hundred objects to a large installation with millions of objects.
AD is a directory service used to store information about network resources spanning a domain. An AD structure is a hierarchical structure of objects. Objects fall into three broad categories: resources (eg, printers), services (eg, email) and users (accounts and user groups). AD provides information about objects, organizes objects, controls access, and defines security.
ΕΡ 2,294,792 / ΡΤ
Each object represents a single entity, be it a user, a computer, a printer, or a group) and its attributes. Some objects may also be containers for other objects. An object is uniquely identified by its name and has a set of attributes, characteristics, and information that the object can contain, defined by a schema, which also determines the type of objects that can be stored in AD.
Each attribute object can be used on several different schema class objects. These schema objects exist to allow the schema to be extended or modified as needed. However, because each schema object is essential for defining AD objects, disabling or altering these objects can have serious consequences because they will fundamentally alter the structure of AD itself. A schema object, when changed, will automatically propagate through AD, and once the object is created, the object can typically only be deactivated but not deleted. Similarly, changing the schema usually requires a reasonable amount of planning.
The structure that contains the objects is seen on several levels. At the top of the structure is the Forest - the set of all objects, their attributes and rules (attribute syntax) in AD. The forest contains one or more trees with transitive trusts. A tree contains one or more Domains and domain trees, whose relationship, once again, obeys a transitive trust hierarchy. Domains are identified by their DNS name structure, the namespace.
Objects contained in a domain can be grouped into containers called Organizational Units (OU). OUs hierarchize a domain, make it easier to administer, and can give an appearance of an organization's structure in organizational or geographical terms. An OU can contain smaller ORs and can contain multiple nested ORs. Typically, it is recommended to have as few domains as possible in AD and rely on OU to produce a framework and improve policy implementation and administration. The OU is the common level at which group policies, which are AD objects, called Group Policy Objects (GPO) apply, although
Policies may also apply to domains or sites. Δ OU is the level at which administrative powers are commonly delegated, but granular delegation can also be performed on individual objects or attributes.
AD also supports the creation of site groupings, which are physical rather than logical, defined by one or more IP subnets. Sites are distinguished between sites linked by low speed (eg wide area network (WAN), virtual private network (VPN)) and high speed (eg local area network (LAN)) links. Sites are independent of OU domain and structure and are common throughout the forest. Sites are used to control replication-generated network traffic and also to route clients to the nearest Domain Controllers. Exchange 2007 also uses the site topology for mail routing. Policies can also be applied at the site level.
Properly dividing the enterprise information infrastructure into a hierarchy of one or more top-level OUs is often a critical decision. Common models are by business unit, by geographic location, by type of service, or by object type. These models are also often used in combination. The OUs should be structured primarily to facilitate administrative delegation and secondarily to facilitate the application of group policies. Although OUs can form an administrative boundary, the only true security boundary is the forest itself, and an administrator of any domain in the forest must be trusted in all domains in the forest.
Physically, AD information is kept in one or more equal DC pairs. Typically, each DC has a copy of AD, and changes on one computer are synchronized, or converged, between all DC computers by multi-master replication. Associated servers, which are not DC, are called Member Servers.
The AD database is typically divided into different storage media or partitions. The 'Schema' partition contains the definition of object classes and attributes within the Forest. The 'Configuration' partition contains information about the
29 2,294,792 / física physical structure and configuration of the forest (such as site topology). The 'Domain' partition holds all objects created in this domain. The first two partitions replicate to all DCs in the Forest. The Domain partition replicates only to the DC within your domain. Subsets of objects in the domain partition are also replicated to DC that are configured as global catalogs.
AD is generally fully integrated with DNS and TCP / IP. AD replication is a push and not pull technology, where data is distributed on demand. The Knowledge Consistency Checker (KCC) creates a site link replication topology using sites that are defined to manage traffic. Intrasite replication is frequent and automatic as a result of a change notification, which causes peers to initiate a pull replication cycle. Intersite replication intervals are less frequent and do not use default change notification, although this is configurable and may be identical to intrasite replication. A different computational cost may be assigned to each link and the site link topology will be changed accordingly by the KCC. DC replication can occur transitively across multiple site links in site link bridges with the same protocol if the cost is low, although KCC automatically costs a site-to-site direct link lower than transitive links. Site-to-site replication can be configured to occur between a head-to-point server at each site, which then replicates changes to another DC within the site.
In a multi-domain forest, the AD database is now partitioned. That is, each domain only keeps a list of the objects that belong to that domain. For example, a user created in Domain A would only be listed on the Domain A DC. Global catalog servers (GC) are used to provide a global listing of all objects in the Forest. The Global catalog is kept in DC and configured as global catalog servers. Global Catalog Servers replicate to themselves all objects from all domains and thus provide a global listing of objects in the forest. However, in order to minimize replication traffic and to keep the GC database small, replicate only
ΕΡ 2,294,792 / selecionados selected attributes of each object. This is called the partial attribute set (PAS). PAS can be modified by modifying the schema and marking attributes for replication to the GC.
Active Directory replication uses remote procedure calls. For example, between sites, a user may choose to use SMTP for replication, but only for Schema or Configuration changes. 0 SMTP cannot be used to replicate the Domain partition. In other words, if a domain exists on both sides of a WAN connection, RPC is used for replication.
Active Directory is a necessary component for many services in an organization, such as an email exchange. Flexible Single Operations Masters (FSMO) roles are also known as operations master roles. Although AD DC works in a multi-master model, ie upgrades can occur in multiple places at once, there are several functions that necessarily occur in one place.
AD typically supports UNC (\), URL (/), and LDAP URL names for object access. AD uses the LDAP version of the X.500 naming structure internally. Each object has a common name (CN) and a Distinguished name (DN). DC is a domain object class and can have many more than four parts. The object may also have a Canonical name, essentially the reverse DN, without identifiers, and using diagonal bars. To identify the object within its container, use the Relative Distinguished Name (RDN): Each object also has a Globally Unique Identifier (GUID), a unique and unchanging 128-bit string that is used by AD to search. and replication. Certain objects also have a User Principal Name (UPN) and an objectname @ domain name form (objectname @ domain name).
To allow users in one domain to access resources in another, AD uses trusts. Trusts within a forest are created automatically when domains are created. The forest sets the default bounds of trusts, not the domain, and a transitive implicit trust is automatic for all
29 2,294,792 / ΡΤ domains within a forest. In addition to a transitive bidirectional trust, AD trust relationships can be shortcut (two-domain union in different trees, transitive, unidirectional, or bidirectional), forest (transitive, unidirectional, or bidirectional), territory (transitive, or intransitive). unidirectional or bi-directional) or external (intransitive, unidirectional or bi-directional) to link to other forests or non-AD domains. In a one-way trust, when one domain allows access to users in another domain, the other domain does not allow access to users in the first domain. In a two-way trust relationship, two domains allow access to users in the other domain. In this context, a trusting domain is the domain that allows users to access a trusted domain, a trusted domain is the trusted domain; whose users have access to the trusting domain.
Software distribution is performed by a separate service that uses additional proprietary schema attributes that work in conjunction with the LDAP protocol. Active Directory does not automate software distribution, but provides a mechanism under which other services may provide software distribution.
AD DC mapping unit 100 includes a mapping module 110. In particular, mapping module 110 is configured to map nodes la, lb in network 10 and optionally also to map links 2 that connect nodes la, lb. Various network topography mapping techniques are known and can be integrated into the embodiments of the present patent application, as described in more detail below.
Mapping module 110 automatically discovers everything on the network, including fixed computers, servers, printers, concentrators, switches, and routers using discovery and discovery methods (ping / ICMP, SNMP, SIP-based VoIP, NetBIOS, and more) to perform a scan IP address sets and find nodes as described below in Fig. 2.
ΕΡ 2,294,792 / ΡΤ
Referring now to Fig. 2, a mapping method 200 is provided according to embodiments of the present patent application. In particular, mapping method 200 includes the mapping data criteria setting step in step 210. For example, a user may define a set of IP addresses, the number of hops (or attached devices of each discovered device) and device types (e.g. g., SNMP devices, or sending clients) to discover during the search.
Continuing with Fig. 2, at step 220, a node search is performed. For example, types of discovery methods such as ICMP Ping, NetBIOS, SIP clients, etc. they involve transmitting small UDP or ICMP packets to each IP address in the defined set, as well as discovering devices within the number of hops since discovered devices. Thus, data is sent and tracked for each IP address defined to determine the device associated with an IP address and the physical and virtual paths used to reach its IP address. Optionally, large sets of IP addresses are subdivided into blocks of 10 addresses, and responses are searched from these 10 addresses. When scanning the network in this way, noticeable effects are minimized on bandwidth or network devices.
Continuing with Fig. 2, the node discovery in step 220 is described in more detail. At step 221, a block node lookup of a preselected N number of IP addresses is performed using user-configured discovery methods. Layer 3 connectivity can then be determined from discovered nodes at step 222. If hop count> 0 is set, repeat step 221 with newly discovered network pools until hop count is reached, step 223. Layer 2 connectivity is then determined from any discovered nodes identified as a switch or concentrator administered at step 224. The Layer 2 and Layer 3 address data from steps 221-224 are then correlated, for example, using address translation tables (ARP) and Spanning Tree tables collected from discovered SNMP prepared nodes at step 225. Then at step 226, the
29 2,294,792 / de network connectivity by examining each discovered node's IP address (es). Layer 2 connectivity is used when available; otherwise, Layer 3 connectivity is used.
The network topology search results are stored in step 230.
For example, mapping module 110 may collect and store all topology information in a database 140, providing a source of topology and asset information for enterprise level configuration management (CMDB) database strategies. The mapping module 110 also automatically maintains this data to update network nodes, thus providing network engineers with a constantly accurate representation of the network to meet visibility and compliance requirements.
Optionally, the network topology search results are stored at step 230. For example, upon discovery of the network nodes, the mapping module 110 can compile the information into a cohesive and easy to interpret network topology map, for example. , with nodes represented by Icons and colored lines representing the speed of network connectivity on a user interface 130. In this way, the mapping module 110 allows network engineers to accurately observe how devices are connected to the network. Mapping module 110 can access managed switches and concentrators to accurately lay out port connectivity for all network devices, resulting in a complete map illustrating all nodes connected directly to a managed switch or concentrator with port information. displayed adjacent to the node.
Turning to Fig. 1, in an implementation of the present patent application, mapping module 110 performs layer 2 mapping. Layer 2, or the data link layer, provides the functional and procedural means for transferring data between entities. detect and possibly correct errors that may occur at the physical layer. Originally, this layer was designed for point-to-point and point-to-multipoint media, characteristic of wide area media in the telephone system.
ΕΡ 2,294,792 / ΡΤ
Δ Local Area Network (LAN) architecture, which included broadcast-capable multiple access media, was developed independently of ISO's work on IEEE Project 802. LAN services typically organize bits from the physical layer into logical sequences called frames.
The highest level sublayer is a Logic Link Control (LLC) sublayer. This sublayer multiplexes protocols running at the top of the data link layer and optionally provides flow control, acknowledgment and error recovery. LLC provides addressing and data link control. Specifies which mechanisms should be used to approach stations along the transmission medium and to control data exchanged between originating and receiving machines.
The sublayer below the LLC is Media Access Control (MAC). Sometimes it refers to the sublayer that determines who is allowed to access the medium at any time (usually CSMA / CD) and at other times this phrase refers to a frame structure with MAC addresses inside it. There are generally two forms of media access control: distributed and centralized. The Media Access Control sublayer also determines where a data frame ends and where the next one begins.
Continuing with FIG. 1, in an implementation of the present patent application, mapping module 110 performs a layer 3 mapping. Layer 3, or the network layer, is the third layer of seven in the OSI model and the third layer of mapping. five in the TCP / IP model. In essence, the network layer is responsible for end-to-end (source-to-destination) packet distribution, while the data-link layer is responsible for node-to-node (hop-to-hop) frame distribution. The network layer provides the functional and procedural means for transferring variable length data streams from one source to one destination across one or more networks while maintaining quality of service and error control functions. The network layer handles the transmission of information from source to destination.
EP 2 294 792 / EN
When performing a multilevel discovery, mapping module 110 uses multiple discovery methods to provide an integrated Layer 2 and Layer 3 topology OSI map that includes:
• IP address • MAC address • Last registered user (requires optional Sending Clients) • DNS name • Node name (determined by SNMP or other client protocol) • Switch port connection
This multilevel discovery of network infrastructure data gives network engineers easy access to significant time-saving features, including automated tiered topology representation, to show additionally managed routers and subnets, switches and concentrators, or, in addition, end nodes that can be filtered by type or group to further refine the settings.
Continuing with Fig. 1, the AD DC mapping unit 100 further includes an AD DC discovery unit 120. In particular, after the mapping module 110 forms a topology map, the AD DC discovery unit 120 can use this mapping data to determine the locations of the AD 1a DC within the module network 10.
AD DC Discovery Unit 120 uses Simple Directory Access Protocol (LDAP) instructions 121 to form interrogations and parsing of returned data to identify the AD DC, and then integrates devices running LDAP for topological map.
LDAP is an application protocol for performing queries and modifying directory services running over TCP / IP. A directory is a set of objects with similar attributes arranged in a logical and hierarchical manner. The most common example is the phone book, which consists of a series of names (of people or organizations)
ΕΡ 2,294,792 / ΡΤ arranged in alphabetical order, each name having an address and telephone number attached. Because of this basic design (among other factors) LDAP is often used by other services for authentication, despite the security issues it causes.
An LDAP directory tree often reflects multiple political, geographic, and / or organizational boundaries, depending on the template you choose. Current LDAP deployments tend to use Domain Name System (DNS) names to structure the highest levels of the hierarchy. Deep inside the directory may appear entries representing people, organizational units, printers, documents, groups of people, or anything else representing a particular tree entry (or multiple entries).
The current version of LDAPv3 is specified in a series of Internet Engineering Working Group (IETF) Standard Request for Comments (RFC), as described in detail in RFC 4510.
A client initiates an LDAP session by connecting to an LDAP server by default on TCP port 389. The client then sends the operation requests to the server and the server in turn sends responses. With some exceptions, the client does not have to wait for a response before sending the next request and the server can send the responses in any order. The customer may request various operations.
LDAP is defined in terms of ASN.l and protocol messages are encoded in BER BER format, and use textual representations for various fields / types of ASN.l.
• The protocol accesses LDAP directories:
• A directory is a tree of directory entries.
• An entry consists of a set of attributes.
• An attribute has a name (an attribute type or attribute description) and one or more values. Attributes are defined in a schema (see below).
• Each entry has a unique identifier: its Distinguished Name (DN). This is your Relative Distinguished Name (RDN) constructed from some input attribute (s), followed by
29 2,294,792 / ΡΤ by the parent entry DN, where DN is a full filename and RDN is a relative filename in a folder.
A DN can change over the life of the input, for example when inputs are shifted within a tree. To safely and unambiguously identify entries, a UUID can be made available in the set of operational attributes of the entry.
A server contains a subtree starting at a specific entry, eg, dc = example, dc = com and their children. Servers can also contain references to other servers, so an access attempt ou = department, dc = example, dc = com could return a referral or continuation reference to a server containing this part of the directory tree. The client may then contact the other server. Some servers also support chaining, which means that the server contacts the other server and returns the results to the client.
LDAP rarely defines any sort: The server can return values in an attribute, attributes in an entry, and entries found by a search operation in any order. This feature results from formal definitions and an entry is defined as a set of attributes, and an attribute is a set of values, and sets need not be sorted.
In an LDAP operation, the client gives each request a positive Message ID and the server response has the same Message ID. The response includes a numeric result code that indicates success, some error condition, or some other special cases. Prior to the reply, the server may send other messages with other result data. For example, each entry found by the Search operation is returned in such a message.
The LDAP Search operation can be used for search and read entries. The server returns the corresponding entries and perhaps continuation references (in any order), followed by the end result with the result code. The Compare operation adopts a DN, a name of
29 2,294,792 / ΡΤ attribute is an attribute value, and checks whether the named entry contains that attribute with that value.
The contents of entries in a subtree are governed by a schema. The schema defines the types of attributes that directory entries can contain. An attribute definition includes a syntax, and most non-binary values in LDAPv3 use a UTF-8 string syntax. The schema defines object classes. Each entry must have an objectClass attribute, containing named classes defined in the schema. The schema definition of the classes of an entry defines the type of object that the entry can represent - eg, a person, organization, or domain. Object class definitions also list which attributes are required and which are optional. For example, an entry representing a person may belong to the top and person classes. Enrolling in the person class would require the entry to contain the sn and cn attributes and would allow the entry to also contain userPassword, telephoneNumber, and other attributes. Since entries can belong to multiple classes, each entry has a complex of optional and required attribute sets formed by the union of the object classes it represents. ObjectClasses can be inherited and a single entry can have multiple objectClasses to define the available and required attributes of the entry itself. A parallel to the schema of an objectClass is a class definition and an instance in object-oriented programming, representing objectClass LDAP and LDAP entry, respectively.
Schema also includes various other information controlling directory entries. Most schema elements have a globally unique name and Object Identifier (OID). Directory servers can publish the directory schema by controlling an entry in a base DN given by the entry's subschema / subentry operational attribute (an operational attribute describes directory operation rather than user information and is only returned from a search , when explicitly requested). Server administrators can set their own schemes beyond the normal ones. One scheme for representing individual people within organizations is called a white page scheme.
ΕΡ 2,294,792 / ΡΤ
Turning to Fig. 1, in one configuration, a user registers with the AD DC discovery unit with administrator access, and then the AD DC discovery module 120 accesses the node database 130 and drives. the synthetic LDAP functions for nodes la, lb identified in network 10 to determine AD la DC in the network.
After this AD 1a DC location information is located by the AD 1a DC discovery module 120, the node database 130 can be updated to reflect this information about the AD 1a DC locations, and the display 140 You can especially display the AD la DC, for example, by indicating the AD la DC with a special symbol, color, or graphic.
Referring now to Fig. 3, the embodiments of the present patent application relate to an AD DC discovery method 300, which includes the network topology determination steps in step 310, such as like nodes and connections on the network. For example, as described above, at step 310, synthetic data may be transferred within the network and followed to determine the presence and relationships of different network components. Alternatively, other mapping techniques rely on mapping a known set of nodes to determine the relationship between nodes.
Then LDAP (linked) connections are created in step 320 (a) to the current user's LDAP terminal node (or a server). Alternatively, if the user has specified one or more domain credentials, a binding to the LDAP endpoint associated with those credentials is created. LDAP bindings can be created using conventional techniques and instructions.
LDAP statements are then used to locate the AD DC in step 330. For example, an LDAP data lookup can be performed using bindings created to return any known Fully Qualified Domain Names (FQDN) of DC in steps 331 and 332. In particular, at step 331, a search of DC FQDNs is performed at the organizational unit. Similarly, at step 332, a search of the DCFDNs in the specific configuration cited is performed. Of this
Thus, an AD DC located outside the LDAP terminal node identified in step 320 can be performed using the mapping data from step 310. In searching for the FQDNs in steps 331 and 332, one can use the ldapsearch API statement (ldap_search_s ()) and then any response (s) can be iterated for reevaluation. These response (s) contain the FQDNs of one or more DCs.
Then, in step 333, an inverse Domain Name Server (DNS) lookup is performed for each Domain Controller (DC) discovered in steps 331 and 332 to establish an IP address for the DC. At step 334, any DC that has an IP address within the network address pool discovered in step 310 is inserted into the existing list of discovered nodes, each identified as a DC. At step 340, each LDAP connection created at step 320 is closed or unlinked to return the node to its original state.
As discussed above, various embodiments of the invention may be configured on numerous physical elements or may be configured on a single network element, or configured on multiple elements having various described functions distributed throughout. Control of the IP SLA or other monitoring configurations and other functions can be performed on various network components, such as user equipment, VoIP server, access port, or other network component associated with the VoIP network, and network access.
One skilled in the art should understand that the above discussed embodiments of the invention are illustrative only and that the invention may be embodied in numerous embodiments as discussed above. Furthermore, the invention may be implemented as a computer program in a computer readable medium, wherein the computer program controls a computer or a processor causing it to perform various functions which are discussed as method steps and also discussed as hardware or hardware / software elements.
Contents6
10 members in 7 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 15327308 | United States of America | A | |
| 15327308 | United States of America | A | |
| 153273 | – | – | – |
| US20080153273 | – | – | – |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| US2009285120A1 | United States of America | A1 | |
| WO2009139810A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2009139810A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP2294792A2 | European Patent Office (EPO) | A2 | |
| US8045486B2 | United States of America | B2 | |
| EP2294792B1 | European Patent Office (EPO) | B1 | |
| ES2562448T3 | Spain | T3 | |
| PT2294792EThis record | Portugal | E | |
| DK2294792T3 | Denmark | T3 | |
| PL2294792T3 | Poland | T3 |
Numbers
- Publication
- 2294792
- Publication, DOCDB
- 2294792
- Publication, EPODOC
- PT2294792E
- Application
- 97469001
- Application, DOCDB
- 09746900
- Application, EPODOC
- PT20090746900T
Titles2
- English
- DISCOVERY AND VISUALIZATION OF ACTIVE DIRECTORY DOMAIN CONTROLLERS IN TOPOLOGICAL NETWORK MAPS
- Portuguese
- DESCOBERTA E VISUALIZAÇÃO DE CONTROLADORES DE DOMÍNIO DE DIRETÓRIO ATIVO EM MAPAS DE ESTRUTURAS TOPOLÓGICAS DE REDES
Classification
- CPC, 3
- H04L41/12
- H04L41/0826
- H04L61/4523
- IPC, 3
- H04L29 08
- H04L12 24
- H04L29 12