A method for realizing the establishment of multiple ipsec tunnels between network devices

A technology for tunnel establishment and network equipment, applied in the field of Internet communication, can solve problems such as high resource consumption and difficult maintenance, and achieve the effect of reducing CPU resource consumption and realizing dynamic connection and dynamic maintenance.

Inactive Publication Date: 2015-12-02
OPZOON TECH
View PDF3 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0004] The purpose of the present invention is to provide a method for establishing multiple IPsec tunnels between network devices, which solves the problem of large resource consumption and difficult maintenance when establishing multiple IPsec tunnel connections between network devices

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • A method for realizing the establishment of multiple ipsec tunnels between network devices

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0014] The present invention will be described in further detail below in conjunction with the accompanying drawings and specific embodiments.

[0015] The present invention provides a method for establishing connections between multiple IPsec tunnels between network devices, such as figure 1 As shown, the method includes:

[0016] S1. The server side performs static configuration, the configuration includes configuring the local IP address of the server side to establish an IPsec tunnel, and configuring a two-dimensional correspondence table, the two-dimensional correspondence table including IP addresses of all clients and corresponding protection subnets;

[0017] The server side is static and must be configured, and the necessary information for tunnel establishment has been configured, and the client side has also been configured, including the IP address and the corresponding protection subnet, and the two-dimensional correspondence table is configured according to these...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention provides a method for achieving establishment of multiple internet protocol security (IPsec) tunnels among network devices. The method for achieving the establishment of the multiple IPsec tunnels among the network devices includes the following steps that static allocation is conducted on a server side, wherein the allocation comprises a local internet protocol (IP) address of the establishment of the IP sec tunnels of the server side, a two-dimension corresponding table is allocated, and the two-dimension corresponding table comprises IP addresses of all client sides and protection subnets corresponding to the IP addresses; the server side scans the two-dimension corresponding table and judges whether information of source protection subnet and information of objective protection subnets are matched according to a received tunnel establishment request sent by a client side communication initiator, one IPsec tunnel is established between the initiator and the server side when the information of source protection subnet and the information of the objective protection subnets are matched, the server side and a client side responder conduct inverse negotiation, the client side responder judges whether the protection subnet of the client side is matched with the information of the objective protection subnets according to the establishment request information sent by the server side, when the protection subnet of the client side is matched with the information of the objective protection subnets, tunnel connection is established, and when the protection subnet of the client side is not matched with the information of the objective protection subnets, tunnel connection between the initiator and the server side is broken. Through the method for achieving the establishment of the multiple IPsec tunnels among the network devices, dynamic connection and dynamic maintenance of the multiple IPsec tunnels among the network devices are achieved.

Description

technical field [0001] The invention relates to the technical field of Internet communication, in particular to a method for realizing the establishment of multiple IPsec tunnels between network devices. Background technique [0002] n IPsec (Internet Protocol Security, Internet Security Protocol) client network devices are connected to the same IPsec server network device, so that each IPsec client network device establishes an IPsec tunnel with the IPsec server network device, and requires every two IPsec client network devices The devices can communicate, and the existing method is to configure each IPsec client network device into n-1 protection subnets, respectively corresponding to the subnets of other n-1 IPsec client network devices. However, when the number of IPsec client network devices is large, for example, there are 100 clients, you need to configure 99 protection subnets for each client network device, and configure each IPsec client network device on the IPse...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Patents(China)
IPC IPC(8): H04L12/46
Inventor 陈海滨
Owner OPZOON TECH
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products