A virtual networking method and computer topology network
By using virtual networking methods, port isolation mode, and virtual network center management of switches and member machines, the shortcomings of traditional networking methods in terms of flexibility and security are solved. This enables flexible access, secure isolation, and resource sharing of local area networks, while reducing management complexity and operating costs.
Patent Information
- Application Number
- CN202411325991.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-23
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2044-09-23
AI Technical Summary
Traditional networking methods lack flexibility when facing complex network requirements, making it difficult to quickly adapt to new device access and network topology changes. Furthermore, security cannot be effectively guaranteed, making them vulnerable to unauthorized access and attacks.
By adopting a virtual networking method, the switches are configured in port isolation mode, and the virtual network center manages the switches and member machines to realize the division and access control of local area networks. Combined with DHCP server and virtual address allocation, secure isolation and resource sharing between different local area networks are ensured.
It improves the flexibility and scalability of local area networks, enhances security, reduces management complexity, enables resource sharing and interoperability between different local area networks, and reduces operating costs.
Smart Images

Figure CN119182625B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer network, in particular to a virtual networking method and a computer topology network. BACKGROUND
[0002] With the continuous development of information technology, schools, government agencies, institutions, enterprises and organizations have higher and higher requirements for networks, requiring networks to group different member machines according to actual needs, to achieve rational allocation of resources and access control. For example, computers in the same department of the same enterprise need to be able to access each other, but computers in different departments are required not to be able to access each other. At the same time, when a project team is formed across departments, while meeting the requirements of the same project team in terms of permissions, functions, and use of programs, it also needs to meet the requirements that computers in the same department can access each other, but computers in different departments cannot access each other. This brings great difficulties to the management of computer networks in enterprises. With the deepening of the complexity of the organizational structure of schools, governments, agencies, enterprises and institutions, the demand for network administrators is increasingly high, which has increased the cost of enterprise operation. In addition to this, Internet cafes, network cafes and other business network places also involve situations where different prices of machines provide different permissions, functions and use of programs, which also puts higher requirements on network administrators and increases the operating cost. In addition, enterprises, business network places and other scenarios have increasingly high requirements for security mechanisms. In the case of cross-department and cross-permission, the permission cannot be broken through. This requires enterprises, business network places and other operators to additionally set up related software or mechanisms to ensure security.
[0003] Traditional networking methods often seem inadequate when faced with complex network requirements. For example, traditional networking methods may lack flexibility and be difficult to quickly adapt to the access of new devices and changes in network topology; in terms of scalability, when the network scale needs to be expanded, many challenges may be encountered; in addition, in terms of security, traditional methods may not be able to effectively protect the security of the network and may be vulnerable to unauthorized access and attacks. SUMMARY
[0004] The present application aims to solve one of the problems in the related art to some extent. To this end, the present application provides a virtual networking method, which has the advantages of convenient networking, high scalability and high security.
[0005] In order to achieve the above-mentioned purpose, the present application adopts the following technical solutions:
[0006] A virtual networking method for managing a switch, a center switch, other switches connected to the center switch, and member machines connected to the other switches to build one or more local area networks, comprising the following steps:
[0007] The management switch, the center switch and other switches are set to port isolation mode, wherein, the No. 1 port of the other switch is a management port, the No. 2 port is an uplink port, and the other ports are isolation ports;
[0008] The management port of the other switch is connected with the other ports except the No. 1 port of the management switch, the uplink port of the other switch is connected with the other ports except the No. 2 port of the center switch, and the isolation port of the other switch is connected with the member machine;
[0009] The No. 1 port of the management switch and the No. 2 port of the center switch are connected with the virtual network center, the virtual network center sets IP address for the center switch according to the hardware address of the center switch, and the center switch sets IP address for the other switches connected therewith;
[0010] The model, default address, IP address, port number, default account, default password and isolation instruction of the other switch are formed into an initialization script and imported into the database of the virtual network center;
[0011] The virtual network card set in the member machine is started, the member machine logs in the virtual network center, the member machines needing to form a local area network are divided into the same group, and the virtual network center allocates a network segment for the divided group;
[0012] A virtual DHCP server is added into the divided group, the virtual DHCP server allocates a virtual address for the member machines in the group, and then the divided group forms a local area network, the member machines in the local area network can access each other through the virtual network center, and the member machines in different local area networks cannot access each other without verification.
[0013] Optionally, when the center switch connects with a new other switch, the No. 1 port of the newly connected other switch is a management port, the No. 2 port is an uplink port, the management port of the newly connected other switch is connected with the other ports except the No. 1 port of the management switch, the uplink port of the newly connected other switch is connected with the other ports except the No. 2 port of the center switch, and the other ports of the newly connected other switch are connected with the member machines;
[0014] The database of the virtual network center is traversed, if there is an initialization script with the same model as the newly connected other switch, the virtual network center directly uses the initialization script with the same model to initialize the newly connected other switch, after the initialization, the newly connected other switch is configured to the port isolation mode, and if there is no initialization script with the same model as the newly connected other switch, the model, default address, IP address, port number, default account, default password and isolation instruction of the newly connected other switch are formed into an initialization script and imported into the database of the virtual network center.
[0015] Optionally, the model, default address, IP address, port number, default account, default password, and isolation instruction of the newly connected other switch are imported into the database of the virtual network center to form an initialization script, and the virtual network center uses the newly imported initialization script to initialize the newly connected other switch. If the initialization is successful, the newly connected other switch is successfully connected to the central switch.
[0016] Optionally, when the local area network formed by the divided groups needs to access an external network, the IP address of the external network to be accessed is added to the local area network.
[0017] Optionally, different virtual network centers are connected through a dedicated line or a VPN, and after the connection is established, the member machines under different virtual network centers can be divided into the same group.
[0018] Optionally, the verification between the member machines that need to access each other in different local area networks includes:
[0019] Verification of the account of the member machine registered in the virtual network center and verification of the virtual address of the member machine.
[0020] Optionally, the virtual networking method further includes a program grouping step, and the program grouping step includes the following sub-steps:
[0021] The member machines that need to use the same program are further divided into the same program group;
[0022] The program that needs to be used is added to the program group, and the added program is distributed to the member machines in the program group by the virtual network center;
[0023] After the member machines in different local area networks are divided into the same program group, they can access each other.
[0024] Optionally, the virtual networking method further includes a permission grouping step, and the permission grouping step includes the following sub-steps:
[0025] The member machines that need to set the same permission are further divided into the same permission group;
[0026] The required permission is set for the permission group, and the set permission is set for the member machines in the permission group by the virtual network center;
[0027] After the member machines in different local area networks are divided into the same permission group, they can access each other.
[0028] Optionally, the virtual networking method further includes a function grouping step, and the function grouping step includes the following sub-steps:
[0029] Member machines that need to use the same function are further divided into the same function group; the functions that need to be used are added to the function group, and the added functions are configured by the virtual network center to the member machines in the group;
[0030] Member machines in different local area networks can access each other after being assigned to the same functional group.
[0031] Optionally, the virtual networking method further includes an access packet step, which includes the following sub-steps:
[0032] Member machines that need to perform the same access are further divided into the same access group. The same access means accessing the same member machine, the same network segment, or the same server.
[0033] Add the IP addresses that need to be accessed to the access group;
[0034] Member machines on different local area networks can access each other after being assigned to the same access group.
[0035] Optionally, the other switches also include redundant interfaces and backup interfaces, which are among the other ports of the other switches. The backup interface is connected to a backup member machine to back up data in the local area network, and the redundant interface is connected to a member machine to start when the link of the member machine in the local area network is lost.
[0036] The present invention has the following beneficial effects:
[0037] This invention improves the flexibility and scalability of local area network (LAN) construction, allowing for easy access to new switches and member machines, as well as their initialization and configuration. Simultaneously, it enhances security within and between LANs, effectively preventing unauthorized access through port isolation and verification between member machines. This invention enables resource sharing and interoperability between different LANs. Through the connection and grouping functions of the virtual network center, member machines in different LANs can be partitioned and accessed as needed. Furthermore, this invention improves network management efficiency, reducing management complexity and workload through centralized management and configuration of switches and member machines via the virtual network center.
[0038] In addition, the present invention also provides a computer topology network, including a management switch, a central switch, other switches connected to the central switch, and member machines connected to the other switches;
[0039] The management switch, the center switch and other switches are set in port isolation mode, wherein, a first port of the other switch is a management port, a second port is an uplink port, and other ports are isolation ports; the management port of the other switch is connected with other ports except the first port of the management switch; the uplink port of the other switch is connected with other ports except the second port of the center switch; and the isolation port of the other switch is connected with the member machine; the first port of the management switch and the second port of the center switch access the virtual network center.
[0040] The member machine in the computer topology network is constructed into one or more local area networks by the virtual networking method in any one of the preceding embodiments.
[0041] The computer topology network provided by the present application has the similar beneficial effects to the reasoning process of the beneficial effects of the virtual networking method, which will not be repeated here.
[0042] The features and advantages of the present application will be described in detail in the following specific embodiments and drawings. The best mode or means of the present application will be fully illustrated in combination with the drawings, but it is not a limitation on the technical solutions of the present application. In addition, the features, elements and components appearing in each of the following text and drawings are multiple, and different symbols or numbers are marked for the convenience of representation, but all represent the same or similar structure or function parts. BRIEF DESCRIPTION OF DRAWINGS
[0043] The present application will be further described in combination with the drawings as follows:
[0044] Figure 1 The network topology diagram of a single virtual network center in the embodiment of the present application;
[0045] Figure 2 The network topology diagram of multiple virtual network centers connected through a dedicated line or VPN in the embodiment of the present application;
[0046] Figure 3 The network topology diagram of program grouping in the embodiment of the present application;
[0047] Figure 4 The network topology diagram of authority grouping in the embodiment of the present application;
[0048] Figure 5 The network topology diagram of function grouping in the embodiment of the present application;
[0049] Figure 6 The network topology diagram of access grouping in the embodiment of the present application.
[0050] Wherein, 1 - virtual network center, 2 - center switch, 3 - management switch, 41 to 43 - other switches, 501 to 512 - member machines, 6 - local area network, 7 - virtual DHCP server, 8 - program group, 9 - authority group, 10 - function group, 11 - access group. DETAILED DESCRIPTION
[0051] Embodiments of the present application are described in detail below with reference to the attached drawings, wherein like or similar elements are denoted by the same or similar reference numerals throughout the drawings. The embodiments described in the embodiments are intended to explain the present application, and are not to be understood as limiting the present application.
[0052] In this specification, "one embodiment" or "an embodiment" or "example" means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the application. The appearances of the phrase "in one embodiment" in various places in the specification are not necessarily all referring to the same embodiment.
[0053] As a first aspect of the present application, the present application provides a virtual networking method for a management switch, a center switch, other switches connected to the center switch, and a group of member machines connected to the other switches to build one or more local area networks. More specifically, the use scenario of the virtual networking method involved in the present embodiment is a non-profit organization such as a school, a government agency, an institution, and an enterprise, a business network site such as an Internet bar, and a cybercafe. In these use scenarios, the management switch, the center switch, and the other switches are only distinguished by the logical positions of the switches in the physical network and the functions provided by the switches, and a person skilled in the art can flexibly select the switches according to the actual use scenario. Meanwhile, in the present embodiment, since the management switch, the center switch, and the other switches are only distinguished by the logical positions and the functions, a person skilled in the art can redefine the management switch, the center switch, and the other switches according to the networking requirements, for example, the management switch before the re-networking is defined as the center switch. The member machines involved in the present embodiment can be diskless terminal computers or ordinary computers with disks, which are not limited here. As a preferred embodiment, the member machines involved in the present embodiment are diskless terminal computers. The virtual networking method provided by the present embodiment, that is, building one or more local area networks for a plurality of terminal diskless computers in an enterprise or a business network site, is shown in FIG. 1. The virtual networking method provided by the present embodiment includes the following steps: Figure 1
[0054] Configuration steps: Configure management switch 3, central switch 2, and the other switches to port isolation mode. After being configured in port isolation mode, devices connected to the same switch cannot communicate with each other through that switch. Specifically, in this embodiment, there is one management switch 3 and one central switch 2, and three other switches. Figure 1 The order from left to right in the diagram is: other switches 41, other switches 42, and other switches 43. In other embodiments, the number of other switches can be flexibly selected by those skilled in the art according to actual needs, and is not limited here. In the prior art, switches have multiple ports, and most are in interconnection mode. Therefore, it is necessary to first set all switches to port isolation mode. Among them, the three other switches are configured such that port 1 is the management port, port 2 is the uplink port, and the other ports are isolation ports. Those skilled in the art should know that the port numbers mentioned here are figurative and are distinguished by function or connection for ease of understanding.
[0055] Hardware connection steps: Connect the management ports of other switches to ports other than port 1 of management switch 3; connect the uplink ports of other switches to ports other than port 2 of central switch 2; and connect the isolation ports of other switches to member machines. In this embodiment, each switch connects to four member machines. Figure 1 The order from left to right is as follows:
[0056] Other switches 41 are connected to member machines 501, 502, 503, and 504;
[0057] Other switches 42 are connected to member machines 505, 506, 507, and 508;
[0058] Other switches 43 are connected to member machines 509, 510, 511, and 512;
[0059] In other embodiments, the number of member machines connected to other switches can also be flexibly selected by those skilled in the art according to actual needs, and is not limited here.
[0060] Software connection steps: Port 1 of management switch 3 and Port 2 of central switch 2 are connected to virtual network center 1. In this embodiment, virtual network center 1 is the control center or operating platform for managing and monitoring the virtual network. It is used to configure, monitor, and maintain virtual network resources. Furthermore, in this embodiment, virtual network center 1 can provide a visual interface. Through the visual interface provided by virtual network center 1, network administrators can easily manage and adjust the topology, groups, access permissions, program usage permissions, and function usage permissions of the virtual network. Configuration commands for the switches are issued by virtual network center 1 through port 1 of management switch 3 to the management ports of other switches, thereby configuring the other switches. Uplink and downlink data from other switches are forwarded to virtual network center 1 through the uplink port, via port 2 of central switch 2. Simultaneously, the uplink port can also be used for cascading, stacking, and other expansion operations of switching devices. Virtual network center 1 sets an IP address for central switch 2 based on the hardware address of the connected central switch 2, and central switch 2 sets IP addresses for the other connected switches.
[0061] The process of importing data into the database involves creating an initialization script by combining the model number, default address, IP address, port number, default username, default password, and isolation instructions of other switches. This script will then be imported into the database of Virtual Network Center 1 to enable all switches to be formatted into a unified logical interface supported by the platform, and to automatically generate the location layout and physical connection information of network devices.
[0062] Partitioning steps: Start the virtual network adapter on the member machine, log in to virtual network center 1 on the member machine, and group the member machines that need to form LAN 6 into the same group. For example... Figure 1 As shown, in this embodiment, member machines 501 (connected to other switch 41), 506 (connected to other switch 42), and 511 (connected to other switch 43) are grouped into the same group; member machines 502 (connected to other switch 41), 507 (connected to other switch 42), and 512 (connected to other switch 43) are grouped into the same group. Virtual network center 1 allocates network segments to the two groups. By allocating network segments to different groups, IP conflicts between member machines within each group are avoided.
[0063] Network formation steps: A virtual DHCP server 7 is added to the divided groups. The virtual DHCP server 7 assigns virtual addresses to the member machines within the group, and then the divided groups form a local area network 6. In this embodiment, the virtual DHCP server is provided by a virtual network center, which allocates, manages, or reclaims IP addresses and resources according to business processes or scenarios. The network topology diagram forming local area network 6 is as follows. Figure 1As shown, the member machine 501, the member machine 506 and the member machine 511 form one local area network 6, and the member machine 502, the member machine 507 and the member machine 512 form another local area network 6. Within the local area network 6 formed by the member machine 501, the member machine 506 and the member machine 511, the three member machines can access each other through the virtual network center 1; within the local area network 6 formed by the member machine 502, the member machine 507 and the member machine 512, the three member machines can access each other through the virtual network center 1. However, the member machine 501, the member machine 506 and the member machine 511 belong to one local area network 6, and the member machine 502, the member machine 507 and the member machine 512 belong to another local area network 6, so the member machine 501, the member machine 506 or the member machine 511 cannot access any of the member machine 502, the member machine 507 and the member machine 512 without verification.
[0064] In other embodiments, the network administrator can also form a local area network by any number and any location of member machines according to actual needs. The physical network environment of the servers in the same server room is fixed. Whether the network is allowed to access between multiple servers is determined at the beginning of server deployment, and if it needs to be changed, it needs to be maintained or redeployed VPN, which is not flexible and time-consuming and labor-intensive. The virtual networking method provided in the embodiment does not require complex hardware devices and high cost investment, nor does it require a high-skilled network administrator. Through the virtual network center 1, the administrator can freely network, thereby realizing flexible and efficient network deployment, high visualization, and high intelligence. Moreover, the ports of the switches are all set to isolation mode, and the member machines between different local area networks 6 cannot access each other without verification, which greatly improves the security and convenience of the network management, effectively avoids unauthorized access and interference, and ensures the stable operation of the network. It is especially suitable for use in non-profit organizations such as schools, government agencies and institutions, which have high requirements for permission security. It can not only achieve full authorization of various permissions, but also achieve strict isolation measures between different permissions, thereby meeting the security requirements of non-profit organizations such as schools, government agencies and institutions.
[0065] In the present disclosure, how to perform the configuration step, the hardware connection step and the warehousing step are not specially limited. As an optional implementation manner, when the center switch 2 accesses a new other switch, the No. 1 port of the newly accessed other switch is a management port, and the No. 2 port is an uplink port. The management port of the newly accessed other switch is connected with other ports outside the No. 1 port of the management switch 3, the uplink port of the newly accessed other switch is connected with other ports outside the No. 2 port of the center switch 2, and the other ports of the newly accessed other switch are connected with the member machines.
[0066] If the initialization script of the same type exists in the database of the virtual network center 1, the virtual network center 1 directly uses the initialization script of the same type to initialize the newly accessed other switch. Since the newly accessed switch is mostly in the interconnection mode of each port, the virtual network center 1 configures the newly accessed other switch in the port isolation mode through the management port of the newly accessed other switch via the No. 1 port of the management switch 3, so as to ensure that the newly accessed other switch meets the isolation security requirements. Meanwhile, the efficiency and automation degree of networking are greatly improved, the manual intervention is reduced, the errors and cost increase caused by manual configuration are avoided, and the labor cost is reduced.
[0067] If the initialization script of the same type does not exist, the type, default address, IP address, port number, default account, default password, and isolation instruction of the newly accessed other switch are formed into an initialization script and imported into the database of the virtual network center 1, which provides convenience for subsequent switch management and configuration, enables the network to quickly adapt to the access of new equipment, and has strong scalability.
[0068] In the present disclosure, how to perform the warehousing step is not specially limited. As an optional implementation manner, after the type, default address, IP address, port number, default account, default password, and isolation instruction of the newly accessed other switch are formed into an initialization script and imported into the database of the virtual network center 1, the virtual network center 1 uses the newly imported initialization script to initialize the newly accessed other switch. Similarly, the virtual network center 1 issues an initialization command through the management port of the newly accessed other switch via the No. 1 port of the management switch 3. If the initialization is successful, the newly accessed other switch is successfully accessed to the center switch 2, and the normal communication and cooperation between network devices are ensured. If the initialization is not successful, it indicates that an error occurs in warehousing, and manual checking is required.
[0069] In the present disclosure, how to perform the division step is not specially limited. As an optional implementation manner, when the local area network 6 formed by the divided groups needs to access an external network, the IP address of the external network that needs to be accessed is added to the local area network 6.
[0070] As Figure 1As shown, when the local area network 6 composed of the member machine 501, the member machine 506 and the member machine 511 needs to access a certain external network address, the address of the external network that needs to be accessed is added to the local area network 6 through the virtual network center 1, so that the seamless connection between the local area network 6 and the external network is realized. This enables the member machines in the local area network 6 to conveniently access the resources of the external network, meets the user's demand for external information and services, and expands the function and application range of the network. In terms of cost, this mode is simple to operate, does not need to additionally purchase complex equipment or pay high fees, and only needs to perform a simple IP address adding operation to realize external network access, which has the advantages of low cost and convenient implementation.
[0071] In the present disclosure, how to perform the division step and the networking step is not specially limited. As an optional implementation manner, different virtual network centers 1 are connected through a dedicated line or a VPN, and after the connection is established, the member machines mounted under different virtual network centers 1 can be divided into the same group. For example, Figure 2 As shown, two virtual network centers 1 are connected through a dedicated line or a VPN, and the member machine 504, the member machine 508 and the member machine 509 mounted under the virtual network center 1 on the left side of Figure 2 may be divided into the same group with the member machine 503, the member machine 507 and the member machine 511 mounted under the virtual network center 1 on the right side of Figure 2 . Then, any one of the two virtual network centers 1 can allocate a network segment to the divided group to avoid IP conflict. Meanwhile, a virtual DHCP server 7 is added to the divided group, the virtual DHCP server 7 allocates a virtual address to the member machines in the group, and then the divided group forms a local area network 6 across the virtual network centers 1.
[0072] The connection of different virtual network centers 1 through a dedicated line or a VPN further expands the scenario in which the virtual networking method provided by the present application is used, that is, not only can free networking be realized in the same physical network, but also can free networking be realized in different physical networks, resource integration and sharing across the virtual network centers 1 are realized, the member machines in different regions or organizations can work cooperatively, and the resource utilization rate and work efficiency are improved. When a certain enterprise has branch offices in multiple places, and the member machines under different branch offices need to be grouped to form a local area network 6 across regions, the network management personnel of the enterprise can still use the same way to freely network, without the need for additional adjustment and deployment in the software and hardware aspects. From the cost point of view, the connection of different virtual network centers 1 through a dedicated line or a VPN makes full use of the existing network infrastructure, without the need for large-scale hardware upgrade or modification, which reduces the cost and difficulty of networking. In addition, resource integration and sharing can also avoid repeated investment, further reducing the cost.
[0073] In the present disclosure, no special limitation is made on how to perform the network grouping step. As an optional implementation, the verification between the member machines under different local area networks 6 that need to visit each other includes:
[0074] Verification of the account of the member machine registered in the virtual network center 1, and verification of the virtual address of the member machine.
[0075] Through these strict verification measures, it can be ensured that only the member machines meeting the requirements can visit each other, effectively preventing illegal access and malicious attacks, and ensuring the security of the network and the confidentiality of the data. In terms of cost, this verification method is mainly realized through software and system, without additional hardware cost investment. At the same time, effective security measures can reduce potential losses such as data leakage and system damage caused by security problems, and reduce the subsequent repair and recovery costs.
[0076] In the present disclosure, no special limitation is made on how to perform the division step and the network grouping step. As an optional implementation, the virtual network grouping method provided in the present embodiment further includes a program grouping step, including the following sub-steps:
[0077] The member machines that need to use the same program are further divided into the same program group 8. As shown in the present embodiment, the member machine 501, the member machine 506, and the member machine 507 that complete the local area network are divided into the same program group 8. Figure 3
[0078] The program needed to be used is added to the program group 8, and the added program is distributed to the member machines in the program group 8 by the virtual network center 1, which makes the distribution of the program more efficient and accurate, avoids unnecessary program installation and configuration, and improves the convenience and consistency of the member machines using the program. In terms of cost, centralized distribution of the program can reduce the repeated purchase and installation of the software, and reduce the cost of software license and deployment. In addition, accurate distribution can also avoid waste of resources, and improve the utilization rate of software resources.
[0079] After the program group 8 is divided, the member machines in different local area networks can access each other after being divided into the same program group 8. In the embodiment, although the member machine 501 and the member machine 507 belong to different local area networks, and the member machine 506 and the member machine 507 belong to different local area networks, the three member machines can access each other because they belong to the same program group 8. This makes the network administrator still convenient and fast to configure the project team members when the project team is formed across departments, and promotes the sharing and cooperation of program resources. The member machines can more conveniently communicate and cooperate, and use the same program to complete related tasks, which improves the work efficiency and team cooperation ability. From the cost point of view, the utilization rate of the program can be improved, and the cost of purchasing and installing the program for each member machine is reduced. At the same time, the work efficiency can be improved by cooperation, and the project cycle is shortened, thereby reducing the overall operating cost.
[0080] In the present disclosure, how to perform the division step and the networking step is not specially limited. As an optional implementation manner, the virtual networking method provided in the embodiment further includes a permission grouping step, including the following sub-steps:
[0081] The member machines that need to set the same permission are divided again and divided into the same permission group 9. As shown in FIG. 5, the member machine 511, the member machine 502 and the member machine 512 that complete the local area network are divided into the same permission group 9 in the embodiment. Figure 4
[0082] The required permission is set for the permission group 9, and the set permission is set by the virtual network center 1 to the member machines in the permission group 9, which realizes the centralized management and unified setting of the permission, ensures that the operation of the member machines in the network conforms to the corresponding permission regulations, prevents the overreach operation and data leakage, and enhances the security and management standardization of the network. In terms of cost, the centralized management of the permission can reduce the complexity of the permission setting and management, and reduces the management cost. At the same time, the standardized permission management can reduce the work accidents caused by the permission problems, and reduces the potential security risk cost.
[0083] After the division of the authority group 9, the member machines in different local area networks can access each other after being divided into the same authority group 9. In the embodiment, although the member machine 511 and the member machine 502 belong to different local area networks, and the member machine 511 and the member machine 512 belong to different local area networks, the three member machines can access each other because they belong to the same authority group 9. This makes the network administrator still convenient and fast to configure the project team members when the project team is formed across departments, and facilitates the collaboration and data sharing between the member machines according to the authority. Under the premise of ensuring safety, the member machines can more smoothly exchange information and share resources, and improve the collaboration and efficiency of work. From the cost point of view, effective authority management and collaboration can improve work efficiency, reduce work delay and cost increase caused by authority problems, avoid work repetition or stagnation caused by insufficient authority, and improve the utilization efficiency of human resources.
[0084] In the present disclosure, how to perform the division step and the networking step is not specially limited. As an optional implementation manner, the virtual networking method provided in the embodiment further includes a function grouping step, including the following sub-steps:
[0085] The member machines that need to use the same function are divided again and divided into the same function group 10. As shown in Figure 5 , the member machine 506, the member machine 511 and the member machine 502 that complete the local area network formation are divided into the same function group 10.
[0086] The functions that need to be used are added to the function group 10, and the added functions are set to the member machines in the group by the virtual network center 1, so that the allocation and use of the functions are more reasonable and efficient, and the member machines can quickly obtain and use the corresponding functions according to the requirements, which improves the user experience and work efficiency. In terms of cost, function grouping and centralized setting can avoid repeated development and configuration of functions, and reduce the cost of function implementation. At the same time, reasonable allocation of functions can improve the use efficiency of functions, and reduce unnecessary function idling and waste.
[0087] After the functional group 10 is divided, member machines in different local area networks can access each other once they are assigned to the same functional group 10. In this embodiment, although member machines 506 and 502 belong to different local area networks, and member machines 511 and 502 belong to different local area networks, they can access each other because they belong to the same functional group 10. This allows network administrators to easily and quickly configure project team members when forming cross-departmental project teams, which is conducive to function sharing and collaborative use. Member machines can better collaborate to complete tasks with the same functional requirements, fully utilize the functions, and improve the quality and effectiveness of work. From a cost perspective, function sharing can improve the utilization rate of functions and reduce the cost of configuring functions individually for each member machine. In addition, collaborative use of functions can improve work efficiency and reduce project costs and time investment.
[0088] In this disclosure, no special limitations are made on how to perform the partitioning and networking steps. As an optional implementation, the virtual networking method provided in this embodiment further includes an access packet step, comprising the following sub-steps:
[0089] Member machines requiring the same access are further subdivided into the same access group (11). "Same access" refers to accessing the same member machine, the same network segment, or the same server. For example... Figure 6 As shown in the example, in this embodiment, member machines 511, 507, and 512, which have completed the formation of the local area network, are assigned to the same access group 11.
[0090] Adding the required IP addresses to access group 11 enables fine-grained management of access permissions, ensuring that member machines can only access their authorized resources, thus improving network security and controllability. In terms of cost, fine-grained access management reduces unnecessary network traffic and resource consumption, lowering network operating costs. For example, it avoids network congestion and resource waste caused by unauthorized or accidental access, improving network stability and performance.
[0091] After the division of the access group 11 is completed, the member computers in different local area networks can access each other after being divided into the same access group 11. In the embodiment, although the member computer 511 and the member computer 512 belong to different local area networks, and the member computer 507 and the member computer 512 belong to different local area networks, the three member computers can access each other because they belong to the same access group 11. This makes the network administrator still convenient and fast to configure the project team when the project team is formed across departments, and meets the collaborative work requirements of the member computers on specific access resources. The member computers can effectively communicate and cooperate within the same access group 11, and jointly complete tasks involving specific access resources, thereby improving the collaboration and efficiency of work. From the cost point of view, collaborative work can improve work efficiency, reduce the increase in cost caused by poor communication and cooperation, avoid work duplication or errors caused by poor communication, and improve the accuracy and efficiency of work.
[0092] It should be noted that the local area network, the program group, the permission group, the function group, and the access group can overlap. For example, the member computers under several local area networks form a program group, and the member computers in the program group and other member computers not divided into the program group can form a permission group, a function group, or an access group.
[0093] In the disclosure, how to perform the division step and the networking step is not specially limited. As an optional implementation manner, the other switches in the embodiment further include a redundant interface and a backup interface, the redundant interface and the backup interface are one of the other ports of the other switches, and thus are isolated from the other ports, the first port, and the second port. The backup interface is connected with a backup member computer, and is used to backup data in the local area network to ensure data security. Meanwhile, the interfaces are isolated from each other, thereby ensuring the security of the backup data and avoiding that the backup data is read by other member computers. The redundant interface is connected with a member computer, and is used to start when a link of the member computer in the local area network is disconnected. When the main link fails, the standby link can automatically switch to undertake a data transmission task, thereby ensuring that network connection is not interrupted. The network traffic is shared, and the transmission efficiency of the network is improved.
[0094] Meanwhile, the embodiment further provides a computer topology network, which is suitable for use scenes such as enterprises, Internet cafes, and Internet bars, and includes a management switch, a center switch, other switches connected to the center switch, and member computers connected to the other switches. In these use scenes, the management switch, the center switch, and the other switches are only distinguished according to logical positions of the switches in the physical network, and a person skilled in the art can flexibly select the switches according to actual use scenes. The member computers involved in the embodiment can be diskless terminal computers or ordinary computers with disks, which are not limited here.
[0095] The management switch, the center switch and other switches are set to port isolation mode, wherein, the first port of the other switch is a management port, the second port is an uplink port, and other ports are isolation ports; the management port of the other switch is connected with other ports except the first port of the management switch; the uplink port of the other switch is connected with other ports except the second port of the center switch; and the isolation port of the other switch is connected with member machines; the first port of the management switch and the second port of the center switch access a virtual network center.
[0096] The member machines in the computer topology network provided by the embodiment are set up one or more local area networks by the virtual networking method of any one of the preceding embodiments.
[0097] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited to this. Those skilled in the art should understand that the present application includes but is not limited to the contents described in the drawings and the above specific embodiment. Any modification without deviating from the functional and structural principles of the present application will be included in the scope of the claims.
Claims
1. A virtual networking method, characterized in that, The virtual networking method is used to manage switches, a central switch, other switches connected to the central switch, and member machines connected to the other switches to form one or more local area networks, including the following steps: Configure the management switch, central switch, and other switches to port isolation mode. On the other switches, port 1 is the management port, port 2 is the uplink port, and the other ports are isolation ports. Connect the management ports of other switches to ports other than port 1 of the management switch; connect the uplink ports of other switches to ports other than port 2 of the central switch; and connect the isolation ports of other switches to member machines. The management switch's port 1 and the central switch's port 2 are connected to the virtual network center. The virtual network center sets IP addresses for the central switch based on the hardware address of the connected central switch, and the central switch sets IP addresses for other connected switches. Import the initialization script, which contains the model number, default address, IP address, port number, default username, default password, and isolation commands of other switches, into the database of the virtual network center. The virtual network card set on the member machine is started. The member machine logs into the virtual network center and divides the member machines that need to form a local area network into the same group. The virtual network center allocates network segments to the divided groups. A virtual DHCP server is added to the divided groups. The virtual DHCP server assigns virtual addresses to the member machines in the group. The divided groups then form a local area network. Member machines in the local area network can access each other through the virtual network center. Member machines in different local area networks cannot access each other without verification.
2. The virtual networking method according to claim 1, characterized in that, When the central switch connects to other switches, the first port of the newly connected other switch is the management port, and the second port is the uplink port. The management port of the newly connected other switch is connected to other ports except the first port of the management switch, the uplink port of the newly connected other switch is connected to other ports except the second port of the central switch, and the other ports of the newly connected other switch are connected to member machines. The system iterates through the database of the virtual network center. If an initialization script matching the model of the newly connected switch exists, the virtual network center directly uses the matching initialization script to initialize the newly connected switch. After initialization, the newly connected switch is configured in port isolation mode. If no initialization script matching the model of the newly connected switch exists, the system imports the model, default address, IP address, port number, default username, default password, and isolation commands of the newly connected switch into the database of the virtual network center.
3. The virtual networking method according to claim 2, characterized in that, After the model, default address, IP address, port number, default account, default password, and isolation commands of the newly connected other switches are compiled into an initialization script and imported into the database of the virtual network center, the virtual network center uses the newly entered initialization script to initialize the newly connected other switches. If the initialization is successful, the newly connected other switches are successfully connected to the center switches.
4. The virtual networking method according to claim 1, characterized in that, When a local area network formed by a group needs to access an external network, add the IP address of the external network to the local area network.
5. The virtual networking method according to claim 1, characterized in that, Different virtual network centers establish connections via dedicated lines or VPNs. Once the connection is established, member machines mounted under different virtual network centers can be grouped into the same group.
6. The virtual networking method according to any one of claims 1 to 5, characterized in that, Verification between member machines that need to communicate with each other on different local area networks includes: Verification of member machine accounts registered with the virtual network center and verification of member machine virtual addresses.
7. The virtual networking method according to any one of claims 1 to 5, characterized in that, The virtual networking method further includes a program grouping step, which includes the following sub-steps: Member machines that need to use the same program will be further divided and assigned to the same program group; Add the required programs to the program group, and the added programs are distributed by the virtual network center to the member machines in the program group; Member machines on different local area networks can access each other after being grouped into the same program group.
8. The virtual networking method according to any one of claims 1 to 5, characterized in that, The virtual networking method further includes a permission grouping step, which includes the following sub-steps: Member machines that need to be assigned the same permissions are further divided and placed into the same permission group; The necessary permissions are set for the permission group, and the set permissions are distributed from the virtual network center to the member machines within the permission group; Member machines on different local area networks can access each other after being assigned to the same permission group.
9. The virtual networking method according to any one of claims 1 to 5, characterized in that, The virtual networking method further includes a functional grouping step, which includes the following sub-steps: Member machines that need to use the same function will be further divided and assigned to the same function group; Add the required functions to the function group, and the added functions are configured by the virtual network center to the member machines in the group; Member machines in different local area networks can access each other after being assigned to the same functional group.
10. The virtual networking method according to any one of claims 1 to 5, characterized in that, The virtual networking method further includes an access packet step, which includes the following sub-steps: Member machines that need to perform the same access are further divided into the same access group. The same access means accessing the same member machine, the same network segment, or the same server. Add the IP addresses that need to be accessed to the access group; Member machines on different local area networks can access each other after being assigned to the same access group.
11. The virtual networking method according to any one of claims 1 to 5, characterized in that, The other switches also include redundant interfaces and backup interfaces, which are among the other ports of the other switches. The backup interface is connected to a backup member machine to back up data in the local area network. The redundant interface is connected to a member machine to start when the link of the member machine in the local area network is lost.
12. A computer topology network, characterized in that, The computer topology network includes a management switch, a central switch, other switches connected to the central switch, and member machines connected to the other switches; The management switch, central switch, and other switches are configured in port isolation mode. Port 1 of the other switches is the management port, port 2 is the uplink port, and the other ports are isolation ports. The management ports of the other switches are connected to the other ports of the management switch except for port 1. The uplink ports of the other switches are connected to the other ports of the central switch except for port 2. The isolation ports of the other switches are connected to the member machines. Port 1 of the management switch and port 2 of the central switch are connected to the virtual network center. The member machines in the computer topology network are configured into one or more local area networks using the virtual networking method described in any one of claims 1 to 11.
Citation Information
Patent Citations
Network equipment and setting method thereof
CN102904741A
Generic communication channel for information exchange between a hypervisor and a virtual machine
US20190273683A1