Communication systems and methods
By using seed network devices and LLDP information in the network management system, network devices behind NAT are automatically discovered and configured, solving the problem of time-consuming manual addition and improving management efficiency.
Patent Information
- Application Number
- CN202310834129.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-10-31
- Filing Date
- 2020-01-14
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2040-01-14
AI Technical Summary
The network management system cannot automatically discover and configure network devices behind a Network Address Translation (NAT) device, making the manual addition process time-consuming and tedious.
The first connection is established through a seed network device, neighboring network devices are discovered using Link Layer Data Protocol (LLDP) information, and a unique activation configuration is submitted through a tunneled connection. Subsequently, a non-tunneled connection is established to automatically configure all neighboring network devices.
It enables automatic discovery and configuration of network devices behind NAT devices, reducing the time and resource requirements of manual operations and improving management efficiency.
Smart Images

Figure CN116781660B_ABST
Abstract
Description
[0001] This application is a divisional application of Chinese Patent Application No. 202010037016.5, the entire contents of which are incorporated herein by reference. Technical Field
[0002] This disclosure relates to computer networks, and more specifically, to the discovery and configuration of network devices. Background Technology
[0003] A computer network is a collective term for interconnected computing devices that can exchange data and share resources. The operation of various devices enables communication between computing devices. For example, a computer network can include routers, switches, gateways, firewalls, and various other devices that provide and facilitate network communication.
[0004] These network devices typically include mechanisms such as management interfaces for configuring the devices locally or remotely. By interacting with the management interface, administrators can perform configuration tasks and execute operational commands to collect and view operational data from the managed devices. For example, administrators can configure the device's interface cards, adjust parameters for supported network protocols, specify physical components within the device, modify routing information maintained by the router, access software modules and other resources residing on the device, and perform other configuration tasks. Furthermore, administrators can allow users to view current operating parameters, system logs, network connectivity information, network activity or other status information from the device, and view and respond to event information received from the device.
[0005] Network configuration services can be performed using a variety of distinct devices, such as routers with service cards and / or dedicated service devices. These services include connectivity services such as Layer 3 Virtual Private Network (L3VPN), Virtual Private Local Area Network (VPLS), and peer-to-peer (P2P) services. Other services include network configuration services such as Dot1q VLANs. Network management systems can support these services, allowing administrators to easily create and manage these advanced network configuration services. In customer deployments, there may be thousands to millions of connectivity services. When services change, network management systems typically deploy configuration services across the network via transactions. In some cases, concurrent changes may occur between devices because multiple administrators can modify services in parallel.
[0006] For example, network management systems typically have the ability to discover devices within their network and automatically add them as device objects for further management (such as push configuration). For instance, a user can specify a range of IP addresses or subnets and specify credentials such as via Simple Network Management Protocol (SNMP). The network management system can then scan the list of IP addresses and add all reachable devices for further management. Summary of the Invention
[0007] This disclosure typically describes techniques for managing network devices. A network management system can discover network devices behind network address translation (NAT) devices such as firewalls and configure the discovered network devices.
[0008] In one embodiment, the method includes: at a network management system, connecting to a seed network device via a first connection; the network management system discovering multiple neighboring network devices near the seed network device via the first connection; the network management system initiating a second tunneled connection to the multiple neighboring network devices via the seed device; the network management system submitting an activation configuration for each of the multiple neighboring network devices via the second connection, each activation configuration being unique for one of the multiple neighboring network devices; and establishing a non-tunneled SSH connection to each of the multiple neighboring network devices via the network management system and in response to submitting the activation configuration.
[0009] In another embodiment, the system includes a memory and one or more processors coupled to the memory, the one or more processors being configured to: connect to a seed network device via a first connection; discover a plurality of neighboring network devices adjacent to the seed network device via the first connection; initiate a tunneled second connection to the plurality of neighboring network devices via the seed device; submit an activation configuration for each of the plurality of neighboring network devices via the tunneled second connection, each activation configuration being unique to one of the plurality of neighboring network devices; and, in response to submitting the activation configuration, establish a non-tunneled SSH connection to each of the plurality of neighboring network devices.
[0010] In another embodiment, the non-volatile computer-readable medium includes instructions that, when executed by one or more processors, cause the one or more processors to: connect to a seed network device via a first connection; discover a plurality of neighboring network devices adjacent to the seed network device via the first connection; initiate a tunneled second connection to the plurality of neighboring network devices via the seed device; submit an activation configuration for each of the plurality of neighboring network devices via the tunneled second connection, each activation configuration being unique for one of the plurality of neighboring network devices; and, in response to submitting the activation configuration, establish a non-tunneled SSH connection to each of the plurality of neighboring network devices.
[0011] Details of one or more embodiments are set forth in the accompanying drawings and the following description. Other features, objectives, and advantages will become apparent from the description and drawings, as well as from the claims. Attached Figure Description
[0012] Figure 1 This is a block diagram illustrating an embodiment of an apparatus comprising an enterprise network that can be managed using a network management system, according to the technology of this disclosure.
[0013] Figure 2 It is shown Figure 1 A block diagram of an exemplary set of components of a network management system.
[0014] Figure 3 This is a flowchart illustrating further techniques of this disclosure. Detailed Implementation
[0015] When an administrator might want to add devices behind a NAT device (such as a firewall) to a network management system, the network management system may be unable to scan for IP address ranges or subnets because it cannot access the private IP addresses of the network devices behind the firewall and therefore cannot add these IP addresses for further management. In this embodiment, the administrator may have to manually add each network device behind the firewall to the network management system. For example, the administrator can model the network devices on the network management system. The network management system can generate an activation configuration for the network devices. The network management system can submit the activation configuration of the network devices. The network management system can then wait for outbound SSH connections from the network devices. This process can be repeated to add each network device behind the NAT device. If the number of network devices behind the firewall is large, manually adding each network device can be a time-consuming and tedious task. The technology disclosed herein enables a network management system to add network devices behind NAT devices without requiring the administrator to manually add all network devices behind the NAT device to the network management system.
[0016] Figure 1 This is a block diagram illustrating an embodiment of an enterprise network 6 that can be managed using a network management system 10. The managed enterprise network 6 devices 14A to 14G (collectively referred to as "network devices 14") include network devices interconnected via communication links to form a communication topology for exchanging resources and information. For example, network devices 14 may include routers, switches, gateways, bridges, hubs, servers, firewalls, or other intrusion detection systems (IDS) or intrusion prevention systems (IDP), computing devices, computing terminals, printers, other network devices, or combinations of such devices. Although described herein as supporting packet transmission, delivery, or otherwise, enterprise network 6 may also transmit data according to any other discrete data units defined by any other protocol, such as cells defined by the Asynchronous Transfer Mode (ATM) protocol or datagrams defined by the User Datagram Protocol (UDP). The communication links interconnecting network devices 14, network management system 10, and NAT devices 16 may be physical links (e.g., fiber optic, copper wire, etc.), wireless, or any combination thereof.
[0017] Enterprise network 6 is shown as being coupled to public network 18 (e.g., the Internet) via a communication link. For example, public network 18 may include one or more administrator computing devices. Public network 18 can provide access to web servers, application servers, public databases, media servers, end-user devices, and other types of network resource devices and content.
[0018] The network management system 10 is communicatively coupled to the network device 14 via the enterprise network 6 through a NAT device 16. In some embodiments, the NAT device 16 may be a firewall device. In some embodiments, the network management system 10 forms part of a device management system, although... Figure 1 For illustrative purposes, only one device from the device management system is shown. Figure 1 In this embodiment, the network management system 10 is not directly connected to any network device 14.
[0019] Once network device 14 is deployed and activated, administrator 12 can use network management system 10 (or multiple such network management systems) to manage network devices using the device management protocol, provided that administrator 12 has added network device 14 to network management system 10. As mentioned above, network management system 10 may not be able to access the private IP address of network device 14.
[0020] An exemplary device protocol is the Simple Network Management Protocol (SNMP), which allows the network management system 10 to traverse and modify the Management Information Base (MIB) that stores configuration data within each managed network device 14. Further details of the SNMP protocol can be found in Harrington et al., RFC 3411, “An Architecture for Describing Simple Network Management Protocol (SNMP) Management Frameworks,” Network Working Group, the Internet Engineering Task Force draft, December 2002, accessible at http: / / tools.ietf.org / html / rfc3411, the entire contents of which are incorporated herein by reference.
[0021] In typical practice, the network management system 10 and network devices 14 are centrally maintained by the enterprise's IT team. An administrator 12 interacts with the network management system 10 to remotely monitor and configure network devices 14. For example, the administrator 12 can receive alerts about any network device 14 from the network management system 10, view the configuration data of network device 14, modify the configuration data of network device 14, add new network devices to the enterprise network 6, remove existing network devices from the enterprise network 6, or otherwise manipulate the enterprise network 6 and the network devices therein. Although described with respect to an enterprise network, the techniques disclosed herein are applicable to other public and private network types, including LANs, VLANs, VPNs, etc.
[0022] In some embodiments, the administrator 12 interacts with network device 14 using network management system 10 or a local workstation via, for example, remote login, Secure Shell (SSH), or other such communication sessions. That is, network device 14 typically provides an interface for interaction, such as a command-line interface (CLI), a web-based interface, a graphical user interface (GUI), etc., through which the user can interact with the device to issue text-based commands. For example, these interfaces typically allow users to interact with the device via, for example, remote login, SSH, Hypertext Transfer Protocol (HTTP), or other network sessions, typing text according to a defined syntax to submit commands to the management device. In some embodiments, the user uses network management system 10 to initiate an SSH session with one of network devices 14 (e.g., device 14F) via link 15 to configure device 14F. In this way, the user can provide network device 14 with commands in a format for execution.
[0023] Furthermore, the administrator 12 can also create scripts submitted by the network management system 10 to any or all network devices 14. For example, in addition to the CLI interface, the network device 14 provides an interface for receiving scripts that specify commands according to a scripting language. In a sense, scripts can be output by the network management system 10 to automatically initiate corresponding remote procedure calls (RPCs) on the managed network devices 14. For example, the scripts can follow Extensible Markup Language (XML) or another data description language.
[0024] Administrator 12 uses network management system 10 to configure network device 14 to specify specific operational characteristics that facilitate administrator 12's objectives. For example, administrator 12 can specify specific operational policies, or other policies, for a device (e.g., device 14C) regarding security, device accessibility, communication service engineering, Quality of Service (QoS), Network Address Translation (NAT), packet filtering, packet forwarding, rate limiting, etc. Network management system 10 performs configuration using one or more network management protocols (such as SNMP or the Network Configuration Protocol (NETCONF) or its derivatives) designed to manage configuration data within network device 14. Typically, NETCONF provides a mechanism for configuring network devices and uses Extensible Markup Language (XML)-based data encoding for configuration data (which may include policy data). NETCONF is described in Enns, “NETCONF Configuration Protocol,” Network Working Group, RFC 4741, Dec. 2006, available at tools.ietf.org / html / rfc4741. Network management system 10 can establish NETCONF sessions with one or more network devices 14.
[0025] Typically, before committing configuration changes to network device 14, for example in a private data store, network management system 10 maintains a working draft of an alternative configuration to be applied to network device 14. The network management system device supporting the private data store maintains a private copy of the data separately in the private data store until the private copy is committed to the database. A data change request in a draft needs to be checked for conflicts with other drafts, and the changes are retained. This occurs at the business layer, and conflict detection does not happen in real time. Embodiments of techniques for detecting conflicts between multiple proposed changes to configuration data are discussed in more detail in Chandrasekhar et al., “PROCESSING MULTIPLE PARALLEL HIGH LEVEL CONFIGURATIONCHANGES FOR MANAGED NETWORK DEVICES”, filed August 6, 2019, the entire contents of which are incorporated herein by reference.
[0026] exist Figure 1 In this embodiment, network devices 14A to 14G are behind NAT device 16 relative to network management system 10. In this embodiment, network management system 10 can also manage other network devices (not shown) that are not behind NAT device relative to network management system 10. For example, network management system 10 can manage network devices in network 8. Utilizing... Figure 1 The configuration of the embodiments described above typically requires manually adding network devices 14A to 14G to the network management system 10.
[0027] Although network management system 10 can access the IP addresses of network devices not behind NAT devices (e.g., devices in network 8), network management system 10 may not be able to access the private IP address of network device 14. Therefore, it is desirable to enable network management system 10 to add and configure network devices 14 without requiring administrator 12 to manually add each network device 14 to network management system 10. For example, the administrator can model a single network device among network devices 14 and submit the activation configuration for that device. Then, for example, network management system 10 can discover other network devices 14 through Link Layer Data Protocol (LLDP) information about that single network device. The network management system can also add newly discovered network devices 14 and also submit the activation configuration for the newly discovered network devices 14.
[0028] According to the technology disclosed herein, network management system 10 can discover, add, and configure network devices 14 behind NAT device 16. For example, administrator 12 can model one of network devices 14A to 14G (e.g., network device 14A) on network management system 10 as a seed network device. In other words, network management system 10 can receive a model of seed network device 14A from administrator 12. The model of seed network device 14A may contain information about how seed network device 14A is configured, the capabilities of seed network device 14A, etc. In response to receiving the model of seed network device 14A, network management system 10 can generate a first activation configuration. For example, administrator 12 can manually submit the first activation configuration on seed network device 14A via links 11 and 17. Alternatively, for example, network management system 10 can submit the first activation configuration for the seed network device using a script. In response to the submitted first activation configuration of the seed network device 14A, the seed network device 14A can request a first connection to the network management system 10 via an outbound secure shell (SSH) connection through links 17 and 11, and a first connection can be established between the network management system 10 and the seed network device 14A. Although the path through links 17 and 11 is not shown, the first connection is also represented by connection 1. In some embodiments, the network management system 10 can establish the first connection. In other embodiments, the seed network device 14A can establish the first connection. In some embodiments, the first connection between the network management system 10 and the seed network device 14A can be an SSH connection.
[0029] Then, the network management system 10 can utilize the first connection between the network management system 10 and the seed network device 14A to discover other network devices, such as network devices 14B to 14G. In one embodiment, the network management system 10 can use the Link Layer Data Protocol (LLDP) information of the seed network device 14A to discover neighboring network devices such as 14B to 14G. LLDP is a link layer protocol used by network devices to advertise their identity, capabilities, and neighbors. In some embodiments, the network management system 10 utilizes the connection between the network management system 10 and other network devices 14B to 14G to recursively scan the LLDP information on newly discovered network devices to discover all discoverable network devices behind the NAT device 16. To the extent that some network devices behind the NAT device 16 are not discovered, the administrator 12 can provide the network management system 10 with their private IP addresses in the enterprise network 6, such as by providing a range of IP addresses or subnets.
[0030] In some embodiments, the network management system 10 can discover multiple network devices through the LLDP information of the seed network device 14A. For ease of illustration, the embodiments discussed herein focus on a single network device (network device 14B). For example, by connecting to the seed network device 14A via a first connection tunnel, the network management system 10 can attempt to create a second connection to a neighboring network device (e.g., network device 14B) adjacent to the seed network device 14A. For example, the network management system 10 can attempt to establish SSH connections on links 11, 17, and 19. Although the paths via links 11, 17, and 19 are not shown, the second connection is also represented by links. With the tunneled SSH connection, network device 14A will not be able to read message traffic for network device 14B. If the second connection is successfully established, the network management system 10 can automatically model the neighboring network device (e.g., network device 14B) onto the network management system 10, generate a second activation configuration, and submit the second activation configuration for the neighboring network device 14B. Neighboring network device 14B can request a third connection with network management system 10, for example, an outbound SSH connection via links 13 and 11. This third connection will not pass through seed network device 14A. In other words, the third connection will be a non-tunneled connection relative to seed network device 14A because it does not traverse seed network device 14A. Although the path via links 13 and 11 is not shown, the third connection is also represented by connection 3. A third connection can be established between network management system 10 and neighboring network device 14B. In some embodiments, network management system 10 can establish the third connection. In other embodiments, neighboring network device 14B can establish the third connection. Network management system 10 can then utilize the third connection between network management system 10 and neighboring network device 14B to discover other network devices behind NAT device 16 using the LLDP information of neighboring network device 14B. Similar to the network devices in enterprise network 6 (e.g., network devices 14C-14G), network management system 10 can continue until network management system 10 discovers all discoverable network devices in enterprise network 6. In some embodiments, similar to network devices (e.g., network devices 14C-14G) in enterprise network 6, network management system 10 may continue until network management system 10 discovers and configures all discoverable network devices in enterprise network 6.
[0031] In some embodiments, the network management system 10 can discover multiple neighboring network devices through the seed network device 14A. The network management system 10 can initiate tunneled second connections to the multiple neighboring network devices through the seed network device 14A. The network management system 10 can automatically model the multiple neighboring network devices and can automatically submit a unique activation configuration for each neighboring network device. In other words, each neighboring network device will have an activation configuration different from every other neighboring network device.
[0032] In this way, the techniques of this disclosure can discover devices behind NAT devices, such as NAT device 16, in bulk without the time-consuming and tedious manual configuration of individual devices behind the NAT device. As mentioned above, the network management system 10 may not be able to access the private IP addresses of network devices behind the NAT device and therefore cannot discover network devices behind the NAT device by scanning the IP address list. These techniques of this disclosure can enable network operators to save costs and potentially require less administrator resources.
[0033] Figure 2 It is shown that it is used for Figure 1 A block diagram of an exemplary set of components of a network management system 10. In this embodiment, the network management system 10 includes a control unit 22, a network interface 34, and a user interface 36. The network interface 34 may represent a network device (not shown) communicatively coupled to an external device (e.g., Figure 1 An exemplary interface (one of the network devices 14A-14G in the example). Network interface 34 may represent a wireless and / or wired interface, such as an Ethernet interface or a wireless radio device configured to communicate according to a wireless standard, such as one or more IEEE 802.11 wireless network protocols (such as 802.11a / b / g / n or other such wireless protocols). Although only one network interface is shown for illustrative purposes, in various embodiments, the network management system 10 may include multiple network interfaces.
[0034] Control unit 22 represents any combination of hardware, software, and / or firmware for implementing the functions of control unit 22 and its constituent modules and devices. When control unit 22 includes software or firmware, control unit 22 further includes any necessary hardware for storing and executing the software or firmware, such as one or more processors or processing units. Typically, processing units may include one or more microprocessors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or any other equivalent integrated or discrete logic circuits, and any combination of such components. Furthermore, processing units are typically implemented using fixed and / or programmable logic circuits.
[0035] User interface 36 represents one or more interfaces, such as administrator 12 ( Figure 1 Users interact with the network management system 10 through a user interface 36, for example, by providing input and receiving output. For example, the user interface 36 may represent one or more of a monitor, keyboard, mouse, touchscreen, touchpad, trackpad, speaker, camera, microphone, etc. Furthermore, in this embodiment, although the network management system 10 includes a user interface, the administrator 12 does not need to interact directly with the network management system 10, but can remotely access the network management system 10 via, for example, a network interface 34.
[0036] In this embodiment, the control unit 22 includes a user interface module 38, a network interface module 32, and a management module 24. The control unit 22 executes the user interface module 38 to receive input from and / or provide output to the user interface 36. The control unit 22 also executes the network interface module 32 to send and receive data (e.g., packets) via the network interface 34. The user interface module 38, the network interface module 32, and the management module 24 may again be implemented as corresponding hardware units, or software or firmware, or a combination thereof.
[0037] The control unit 22 can be implemented as one or more processing units in a fixed or programmable digital logic circuit. Such digital logic circuitry may include one or more microprocessors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or any other equivalent integrated or discrete logic circuitry, and any combination of such components. When implemented as a programmable logic circuit, the control unit 22 may further include one or more computer-readable storage media storing hardware or firmware instructions executable by the processing units of the control unit 22.
[0038] Control unit 22 executes management module 24 to manage various network devices, such as, Figure 1 The network device 14A-14G in the example. For example, management includes: based on the user (e.g., Figure 1 The administrator 12) receives instructions to configure the network device; and provides the user with the ability to submit instructions to configure the network device via the user interface 36. In some embodiments, the management module 24 is a software process such as a management background program or a management application. In this embodiment, the management module 24 further includes a configuration module 26.
[0039] Management module 24 is configured to receive configuration instructions for a set of managed network devices from a user, such as administrator 12, via user interface 36. One embodiment is the first active configuration described above with respect to network management system 10. For example, the user can update the configuration instructions over time to add new services, remove existing services, or modify existing services performed by the managed devices.
[0040] The network management system 10 also includes a configuration database 40. The configuration database 40 typically includes information describing the managed network devices (e.g., network device 14). For example, the configuration database 40 may include information indicating device identifiers (such as MAC and / or IP addresses), device type, device manufacturer, and device category (e.g., router, switch, bridge, hub, etc.). The configuration database 40 also stores current configuration information for the managed devices (e.g., network device 14).
[0041] Although user interface 36 is described as allowing administrator 12 ( Figure 1 The network device 14 interacts with the network management system 10; however, in other embodiments, other interfaces may be used. For example, the network management system 10 may include a representative state transition (REST) administrator (not shown) that can be used as an interface to another device, through which the administrator 12 can configure the network management system 10. Similarly, the administrator 12 can configure the network device 14 by interacting with the network management system 10 through the REST administrator.
[0042] Figure 3 This is a flowchart illustrating further techniques of this disclosure. The network management system 10 can receive a model (42) of a seed network device (e.g., seed network device 14A). For example, the network management system 10 can receive the model of seed network device 14A from the administrator 12 via user interface 36. The network management system 10 can generate a first activation configuration (44) based on the received model of seed network device 14A. The network management system 10 can submit the first activation configuration of seed network device 14A (46). For example, the network management system 10 can connect to and push the first activation configuration of seed network device 14A via network interface 34, link 11, and link 17.
[0043] The network management system 10 can receive a request for a first connection (48) from the seed network device 14A. The request for the first connection can be made via links 17 and 11 through the outbound SSH connection. A first connection (50) can be established between the network management system 10 and the seed network device 14A via network interface 34, link 11, and link 17. In some embodiments, the first connection can be established via the network management device 10. In other embodiments, the seed network device 14A can establish the first connection using outbound SSH.
[0044] During the first connection, network management device 10 can access LLDP information stored in the memory of seed network device 14A. In this way, network management device 10 can discover neighboring devices (52) adjacent to seed network device 14A. In some embodiments, network management device 10 can discover multiple neighboring network devices. For ease of illustration, the embodiments herein focus on network device 14B. For example, network management device 10 can identify neighboring network device 14B by, for example, a private IP address, using the LLDP information stored in the memory of seed network device 14A.
[0045] Then, the network management system 10 can connect to the neighboring network device 14B via a second connection (54) through network interface 34, link 11, link 17, and link 19, based on identification information from LLDP information stored in the memory of the seed network device 14A. In some embodiments, the second connection can be an SSH connection tunneled through the first connection to the seed network device 14A (via link 11 and link 17). For example, the network management system 10 can automatically model the neighboring network device 14B using a script (56). The network management system 10 can generate a new activation configuration, in this case a second activation configuration (58). This second activation configuration can be unique to the neighboring network device 14B. The network management system 10 can then submit the second activation configuration for the neighboring network device 14B via the tunneled SSH connection through network interface 34, link 11, link 17, and link 19 (60).
[0046] A third connection (62) can be established between the network management system 10 and the neighboring network device 14B. This third connection may not be a connection via the seed network device 14A. In other words, the third connection can be a non-tunneled connection relative to the seed network device 14A. For example, the third connection can be via links 11 and 13 and can be an SSH connection. The third connection is used to manage the neighboring network device 14B via the network management system 10. In some embodiments, the network management system 10 establishes the third connection. In other embodiments, the neighboring network device 14B establishes the third connection using outbound SSH. The network management device 10 can then discover other network devices in the enterprise network 6 (52) from LLDP information stored in the memory of the neighboring network device 14B. The network management system 10 can continue this process between modules (52) and (62) until all discoverable network devices 14A-14G are discovered. In some embodiments, the network management system 10 can continue this process between modules (52) and (62) until all discoverable network devices 14A-14G are discovered.
[0047] In this way, network management system 10 can discover all discoverable network devices behind NAT device 16 using only a single manually modeled seed network device. Network management system 10 can use tunneled SSH connections to connect to other network devices and automatically submit the active configurations already created for those network devices. Then, as described above, these other devices can request non-tunneled connections to network management system 10.
[0048] although Figure 3 The steps are shown to occur sequentially; however, these steps can be executed in parallel. For example, if the network management system 10 discovers information on multiple neighboring network devices of the seed network device 14A, the network management system 10 can initiate tunneled second connections to the multiple neighboring network devices through the seed network device 14A. The network management system 10 can automatically model the multiple neighboring network devices and can automatically submit a unique activation configuration for each neighboring network device. In other words, each neighboring network device will have an activation configuration different from every other neighboring network device.
[0049] The techniques described in this disclosure may be implemented at least partially in hardware, software, firmware, or any combination thereof. For example, various aspects of the described techniques may be implemented within one or more processors, including one or more microprocessors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or any other equivalent integrated or discrete logic circuits, and any combination of such components. Generally, the terms "processor" or "processing circuitry" may refer to any of the aforementioned logic circuits, alone or in combination with other logic circuits, or any other equivalent circuitry. A control unit, including hardware, may also execute one or more of the techniques of this disclosure.
[0050] Such hardware, software, and firmware can be implemented within the same device or in separate devices to support the various operations and functions described in this disclosure. Furthermore, any of the described units, modules, or components can be implemented together or separately as discrete but interoperable logical devices. Describing different features as modules or units is intended to highlight different functional aspects and does not necessarily imply that such modules or units are implemented through separate hardware or software components. Specifically, the functions associated with one or more modules can be performed through separate hardware or software components, or integrated within common or separate hardware or software components.
[0051] The techniques described in this disclosure can also be embodied or encoded in a computer-readable medium containing instructions, such as a computer-readable storage medium. For example, when the instructions are executed, the instructions embodied or encoded in the computer-readable medium can cause a programmable processor or other processor to perform the method. Computer-readable media can include non-transitory computer-readable storage media and transient communication media. Computer-readable storage media (tangible and non-transitory) can include random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, hard disk, CD-ROM, floppy disk, magnetic tape cassette, magnetic media, optical media, or other computer-readable storage media. It should be understood that the term "computer-readable storage medium" refers to a physical storage medium, and not a signal, carrier, or other transient medium.
[0052] Various embodiments have been described. These and other embodiments are within the scope of the appended claims.
[0053] In addition, this technology can be configured as follows.
[0054] (1) A communication system, comprising:
[0055] Memory; and
[0056] One or more processors are coupled to the memory, the one or more processors being configured to:
[0057] Connected to the seed network device via a first connection;
[0058] The first connection discovers multiple neighboring network devices adjacent to the seed network device;
[0059] A tunneled second connection is initiated from the seed network device to the plurality of neighboring network devices;
[0060] The activation configuration of each of the plurality of neighboring network devices is submitted through the tunneled second connection, and each activation configuration is unique to one of the plurality of neighboring network devices; and
[0061] In response to submitting the activation configuration, a non-tunneled secure shell connection is established to each of the plurality of neighboring network devices.
[0062] (2) The system according to (1), wherein the one or more processors are configured to discover the plurality of neighboring network devices by using link layer discovery protocol information of the seed network device.
[0063] (3) The system according to (1) or (2), wherein the one or more processors are configured to discover neighboring network devices by receiving the private IP address of at least one of the plurality of neighboring network devices.
[0064] (4) The system according to (1) or (2), wherein the first connection includes a containment connection.
[0065] (5) The system according to (1) or (2), wherein the tunnel-type second connection includes a containment connection.
[0066] (6) The system according to (1) or (2), wherein the one or more processors are further configured to submit the activation configuration of the seed network device.
[0067] (7) The system according to (1) or (2), wherein the one or more processors are further configured to automatically model the plurality of neighbor network devices.
[0068] (8) The system according to (1) or (2), wherein the one or more processors are further configured to automatically generate activation configurations for the plurality of neighboring network devices.
[0069] (9) A communication method, comprising:
[0070] The network management system connects to the seed network device via a first connection.
[0071] The network management system discovers multiple neighboring network devices near the seed network device through the first connection;
[0072] The network management system initiates a tunneled second connection to the plurality of neighboring network devices through the seed network device;
[0073] The network management system submits the activation configuration of each of the plurality of neighboring network devices through the tunneled second connection, and each activation configuration is unique for one of the plurality of neighboring network devices;
[0074] Established by the network management system and in response to submitting the activation configuration to the
[0075] The non-tunneling containment connection of each of the plurality of neighboring network devices. (10) The method according to (9), wherein finding the plurality of neighboring network devices includes making
[0076] The link layer discovery protocol information of the seed network device.
[0077] (11) The method according to (9) or (10), wherein discovering the plurality of neighboring network devices includes receiving the private IP address of at least one of the plurality of neighboring network devices.
[0078] (12) The method according to (9) or (10), wherein the first connection includes a containment connection.
[0079] (13) The method according to (9) or (10), wherein the tunnel-type second connection includes a containment connection.
[0080] (14) The method according to (9) or (10) further includes submitting the activation configuration of the seed network device by the network management system.
[0081] (15) The method according to (9) or (10) further includes automatically modeling the plurality of neighboring network devices by the network management system.
[0082] (16) The method according to (9) or (10) further includes automatically generating an activation configuration for the plurality of neighboring network devices by the network management system.
[0083] (17) A non-transitory computer-readable medium, comprising instructions that, when executed by one or more processors, cause the one or more processors to:
[0084] Connected to the seed network device via a first connection;
[0085] The first connection discovers multiple neighboring network devices adjacent to the seed network device;
[0086] A tunneled second connection is initiated from the seed network device to the plurality of neighboring network devices;
[0087] The activation configuration of each of the plurality of neighboring network devices is submitted through the tunneled second connection, and each activation configuration is unique to one of the plurality of neighboring network devices; and
[0088] In response to submitting the activation configuration, a non-tunneled secure shell connection is established to each of the plurality of neighboring network devices.
[0089] (18) The non-transitory computer-readable medium according to (17), wherein the instructions cause the one or more processors to discover the plurality of neighboring network devices by using the link layer discovery protocol information of the seed network device.
Claims
1. A communication system, comprising: one or more processors; as well as A memory, coupled to the one or more processors, stores instructions that, when executed, cause the one or more processors to: Connected from the system to a first network device via a first connection, the first network device being behind a network address translation device or firewall relative to the system; One or more second network devices are discovered through the first connection, the one or more second network devices being behind the network address translation device or the firewall relative to the system; One or more tunneled second connections are initiated from the system to the one or more second network devices via the first network device; An activation configuration is sent to each of the one or more second network devices via the one or more tunneled second connections, and each activation configuration is unique to one of the one or more second network devices; and Establish a non-tunneling connection to each of the one or more second network devices.
2. The system according to claim 1, wherein, The instructions cause the one or more processors to discover the one or more second network devices by using the link layer discovery protocol information of the first network device.
3. The system according to claim 1 or 2, wherein, The instructions cause the one or more processors to discover at least one of the one or more second network devices by receiving the private IP address of at least one of the one or more second network devices.
4. The system according to claim 1 or 2, wherein, The first connection includes a containment connection.
5. The system according to claim 1 or 2, wherein, The one or more tunnel-type second connections include one or more containment connections.
6. The system according to claim 1 or 2, wherein, The instruction also causes the one or more processors to send a first activation configuration to the first network device via the first connection.
7. The system according to claim 1 or 2, wherein, The instructions also cause the one or more processors to automatically model the one or more second network devices.
8. The system according to claim 1 or 2, wherein, The instructions also cause the one or more processors to automatically generate each activation configuration for each of the one or more second network devices that are sent to the one or more second network devices.
9. The system according to claim 1 or 2, wherein, The instructions also cause the one or more processors to discover one or more third network devices by using the link layer discovery protocol information of the one or more second network devices.
10. A communication method, comprising: A first network device is connected from a network management system via a first connection, wherein the first network device is behind a network address translation device or a firewall relative to the network management system. The network management system discovers one or more second network devices through the first connection, and the one or more second network devices are behind the network address translation device or the firewall relative to the network management system; One or more tunneled second connections are initiated by the network management system through the first network device from the network management system to the one or more second network devices; The network management system sends an activation configuration to each of the one or more second network devices through the one or more tunneled second connections, and each activation configuration is unique to one of the one or more second network devices; and A non-tunneling connection is established by the network management system to each of the one or more second network devices.
11. The method according to claim 10, wherein, Discovering the one or more second network devices includes using the link layer discovery protocol information of the first network device.
12. The method according to claim 10 or claim 11, wherein, Discovering the one or more second network devices includes receiving the private IP address of at least one of the one or more second network devices.
13. The method according to claim 10 or 11, wherein, The first connection includes a containment connection.
14. The method according to claim 10 or claim 11, wherein, The one or more tunnel-type second connections include one or more containment connections.
15. The method according to claim 10 or claim 11, further comprising: The network management system sends a first activation configuration to the first network device through the first connection.
16. The method of claim 10 or claim 11, further comprising automatically modeling the one or more second network devices through the network management system.
17. The method of claim 10 or claim 11, further comprising automatically generating each activation configuration of each of the one or more second network devices sent to each of the first or second network devices.
18. The method of claim 10 or claim 11, further comprising the network management system discovering one or more third network devices by using link layer discovery protocol information of the one or more second network devices.
19. A non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to: A first network device is connected from a network management system via a first connection, wherein the first network device is behind a network address translation device or a firewall relative to the network management system. One or more second network devices are discovered through the first connection, the one or more second network devices being behind the network address translation device or the firewall relative to the network management system; One or more tunneled second connections are initiated from the network management system to the one or more second network devices through the first network device; An activation configuration is sent to each of the one or more second network devices via the one or more tunneled second connections, and each activation configuration is unique to one of the one or more second network devices; and Establish a non-tunneling connection to each of the one or more second network devices.
20. The non-transitory computer-readable medium according to claim 19, wherein, The instructions cause the one or more processors to discover the one or more second network devices by using the link layer discovery protocol information of the first network device.
Citation Information
Patent Citations
Processing multiple parallel high level configuration changes for managed network devices
US10374886B1
Topology discovery of a private network
US20070189190A1
Various methods and apparatuses for accessing networked devices without accessible addresses via virtual IP addresses
US20100235481A1