Unlock instant, AI-driven research and patent intelligence for your innovation.

Implementation method and equipment of one-way access control

A technology of access control and implementation method, applied in the field of network management, can solve the problems of complex configuration, unable to adapt to network development well, unable to actively initiate external access, etc., to achieve the effect of simplifying deployment and configuration

Inactive Publication Date: 2013-04-03
NEW H3C TECH CO LTD
View PDF3 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

It can be seen that the existing one-way access control method mainly solves the above-mentioned security risks by controlling the server in the shared VPN to only provide external services and cannot actively initiate external access.
[0006] However, the one-way access control method in the prior art needs to manually configure the prefix information corresponding to the shared VPN on the PE connected to the departmental VPN, such as all network segment addresses contained in the shared VPN. Obviously, there are a large number of network segment addresses in the shared VPN The configuration will be very complicated in the case of
Moreover, when the network address of the shared VPN changes, it needs to be reconfigured or modified on the PE, which cannot well adapt to the development of the network.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Implementation method and equipment of one-way access control
  • Implementation method and equipment of one-way access control
  • Implementation method and equipment of one-way access control

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0022] In order to make the object, technical solution and advantages of the present invention clearer, the present invention will be described in detail below in conjunction with the accompanying drawings and specific embodiments.

[0023] In practical applications, the security level of departmental VPNs is generally required to be relatively high, while the security level of shared VPNs is slightly lower than that of departmental VPNs. A firewall will be bypassed on the PE side on the MPLS backbone network connected to a VPN with a relatively high security level, which obviously increases maintenance costs. The embodiment of the present invention creatively analyzes the PE structure and VPN characteristics on the MPLS backbone network, and proposes the following: image 3 In the process shown, the central idea is to enable the PE connected to the VPN with a relatively high security level to have the function of one-way access control. For details, see image 3 shown.

[0...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The embodiment of the invention provides implementation method and equipment of one-way access control. The method is used for a network comprising a first VPN (virtual private network) and a second VPN, wherein the safety level of the first VPN is greater than that of the second VPN; an ASPF (application specific packet filter) function is configured on a PE (provider edge) connected with the first VPN in advance, and at least one group attribute value for identifying the second VPN route as the group attribute value of the controlled route is designated. The method comprises the following steps: A, the PE learns the route information, and when the learnt route information contains the designated group attribute value, automatically stores the prefix information contained by the route information; and B, when the PE receives a data message, and if the ASPF function is enabled currently, the PE performs forwarding control on the data message according to the information carried by thereceived data message and the stored prefix information. By adopting the invention, the configuration can be simplified when solving the information security risk and the network development can be adapted.

Description

technical field [0001] The invention relates to network management technology, in particular to a method and equipment for realizing one-way access control. Background technique [0002] In order to solve the needs of isolation between different departments in a large cross-regional enterprise and the need for some terminals or servers to communicate with each other, the existing technology proposes a multi-protocol label switching (MPLS: Multi-Protocol Label Switching) virtual private network (VPN: Virtual Private Network) Network) technology, that is, different departments are planned in different VPNs, which can realize mutual isolation between departments; and a shared VPN is independently planned, and the servers used for collaborative business in each department are placed in the shared VPN, and then , so that the routes of the shared VPN and the departmental VPN can be introduced into each other, and the mutual visits between the departments can be realized through th...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L12/46H04L12/715
Inventor 宋渊
Owner NEW H3C TECH CO LTD