Vpn tunnel backup guarantee method and device based on ping detection mechanism, equipment and medium
Through the VPN tunnel backup protection method based on the ping detection mechanism, the TCP communication of the primary and backup routes and the ping detection results are used to achieve fast switching of VPN tunnels, solve the data loss and transmission instability problems caused by VPN tunnel disconnection, and provide a more reliable data transmission environment.
Patent Information
- Application Number
- CN202411389811.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-08
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2044-10-08
AI Technical Summary
In the existing technology, after a VPN tunnel is successfully established, it is easy to be disconnected due to network fluctuations, resulting in data loss or unstable transmission. In addition, the existing security mechanism does not respond in time, resulting in excessive delay.
A VPN tunnel backup protection method based on the ping detection mechanism is adopted. Through TCP communication between the main route and the backup route, the ping detection results are used to judge the tunnel status, and the VPN tunnel mechanism of the backup route is regularly detected or switched to ensure the stability of data transmission.
It provides a more responsive backup mechanism that can switch tunnels in time when the network environment is unstable, ensuring the integrity and stability of data transmission, adapting to complex network environments, and avoiding data loss.
Smart Images

Figure CN119276776B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of vpn tunnel transmission, and particularly relates to a vpn tunnel backup guarantee method and device based on a ping detection mechanism, equipment and medium. BACKGROUND
[0002] In the existing gateway device, if data delay is large and transmission efficiency is low after the vpn tunnel is successfully established, it causes some troubles in actual application, and easily causes data loss or unstable situation. Moreover, under the condition of unstable network environment, the vpn tunnel is easily disconnected frequently and for a long time, which easily causes data loss. This is because, in the actual network environment, network fluctuation and instability are very normal, so the problem caused by such situation is avoided, therefore, when the problem occurs, the backup vpn tunnel is enabled, and data can reach the set destination IP, so the stable network environment for vpn data transmission can be provided.
[0003] Briefly speaking, in the actual industrial application, after the vpn tunnel is established, the original guarantee mechanism restarts for a long time after the tunnel is disconnected, which easily causes unstable and lost data, or because the tunnel is unstable and the delay is too large, which leads to data loss and the like, therefore, a vpn tunnel backup guarantee mechanism is needed to be provided, which can better switch the tunnel after the tunnel is disconnected or exceeds the set delay threshold, so as to ensure the stability of the vpn tunnel, the integrity of the transmitted data and the like.
[0004] Therefore, the present application is provided. SUMMARY
[0005] The present application provides a vpn tunnel backup guarantee method and device based on a ping detection mechanism, equipment and medium, which can at least partially improve the above problems.
[0006] To achieve the above purpose, the present application adopts the following technical solutions:
[0007] A vpn tunnel backup guarantee method based on a ping detection mechanism, comprising:
[0008] Obtaining preset configuration information, configuring a main route and a backup route according to the preset configuration information, and starting a vpn tunnel mechanism function of the main route, and establishing a pptp tunnel of the main route, wherein the main route and the backup route belong to the same local area network;
[0009] When it is judged that the pptp tunnel of the main route is established successfully, the tcp communication unit controls the main route to establish tcp communication with the backup route, and informs the backup route of the pptp tunnel situation of the main route, wherein the pptp tunnel situation of the main route includes address ping detection result.
[0010] The route switching unit is used for judging whether the address ping detection result reaches a threshold value, generating a judgment result, and starting the vpn tunnel mechanism function of the backup route according to the judgment result to establish the pptp tunnel of the backup route.
[0011] The application further provides a vpn tunnel backup guarantee device based on a ping detection mechanism, which comprises:
[0012] The main route tunnel establishment unit is used for obtaining preset configuration information, configuring the main route and the backup route according to the preset configuration information, and starting the vpn tunnel mechanism function of the main route to establish the pptp tunnel of the main route, wherein the main route and the backup route belong to the same local area network.
[0013] The tcp communication unit is used for controlling the main route to establish tcp communication with the backup route when it is judged that the pptp tunnel of the main route is established successfully, and informing the backup route of the pptp tunnel situation of the main route, wherein the pptp tunnel situation of the main route includes address ping detection result.
[0014] The route switching unit is used for judging whether the address ping detection result reaches a threshold value, generating a judgment result, and starting the vpn tunnel mechanism function of the backup route according to the judgment result to establish the pptp tunnel of the backup route.
[0015] The application further provides a vpn tunnel backup guarantee device based on a ping detection mechanism, which comprises a memory and a processor, the memory stores a computer program, and the computer program can be executed by the processor to realize the vpn tunnel backup guarantee method based on the ping detection mechanism.
[0016] The application further provides a computer readable storage medium, which stores a computer program, and the computer program can be executed by a processor of a device where the computer readable storage medium is located to realize the vpn tunnel backup guarantee method based on the ping detection mechanism.
[0017] In summary, the VPN tunnel backup guarantee method based on the ping detection mechanism provides a method of more rapid response detection and a backup solution, based on the TCP / IP protocol and the ping instruction, by analyzing the direct result of the ping and using the TCP / IP protocol to monitor the VPN tunnel, if the disconnection occurs, the method can make a timely judgment, and according to the configuration and the set parameters, corresponding processing is performed, and according to the result, it is judged whether to enable the backup VPN tunnel. The method can provide a more stable and reliable VPN tunnel transmission environment in the application process of the gateway device VPN. BRIEF DESCRIPTION OF DRAWINGS
[0018] Figure 1 is a flowchart of the VPN tunnel backup guarantee method based on the ping detection mechanism provided by the first aspect of the application;
[0019] Figure 2 is a flowchart of the VPN tunnel backup guarantee method based on the ping detection mechanism provided by the second aspect of the application;
[0020] Figure 3 is a network topology diagram of the VPN tunnel backup guarantee method based on the ping detection mechanism provided by the embodiment of the application;
[0021] Figure 4 is a first configuration diagram of the VPN tunnel backup guarantee method based on the ping detection mechanism provided by the embodiment of the application;
[0022] Figure 5 is a second configuration diagram of the VPN tunnel backup guarantee method based on the ping detection mechanism provided by the embodiment of the application;
[0023] Figure 6 is a module schematic diagram of the VPN tunnel backup guarantee device based on the ping detection mechanism provided by the second embodiment of the application. DETAILED DESCRIPTION
[0024] In order to make the purpose, technical scheme and advantages of the application more clear, the application will be further described in detail below with embodiments. It should be understood that the specific embodiments described herein are only used to explain the application, and are not used to limit the application.
[0025] Reference Figure 1 、 Figure 2 The first embodiment of the application discloses a VPN tunnel backup guarantee method based on a ping detection mechanism, which can be executed by a VPN tunnel backup guarantee device based on a ping detection mechanism (hereinafter referred to as a guarantee device), and in particular, by one or more processors in the guarantee device to execute the following method:
[0026] In practical applications, the existing embedded device is prone to disconnection after the tunnel is successfully established, resulting in long tunnel abnormalities or large delay, thereby causing data communication loss. Therefore, the vpn tunnel backup guarantee method based on the ping detection mechanism is proposed, which is a more convenient and efficient guarantee mechanism that can provide more stable vpn tunnel services in actual production applications.
[0027] S1, obtain preset configuration information, configure the main route and the backup route according to the preset configuration information, and start the vpn tunnel mechanism function of the main route to establish the pptp tunnel of the main route, wherein the main route and the backup route belong to the same local area network;
[0028] Specifically, step S1 includes: obtaining preset configuration information, and configuring the main route and the backup route according to the preset configuration information;
[0029] Enabling the pptp backup mechanism of the main route to establish the pptp tunnel of the main route.
[0030] S2, when it is judged that the pptp tunnel of the main route is successfully established, controlling the main route and the backup route to establish tcp communication, and informing the backup route of the pptp tunnel situation of the main route, wherein the pptp tunnel situation of the main route includes the address ping detection result;
[0031] In this embodiment, the application system device used by the method is an industrial routing device, but the method is not limited to industrial routing devices. The actual application of the vpn tunnel backup guarantee method based on the ping detection mechanism is roughly as shown in Figure 3 , in the public network, there are four routers, wherein R1 and R2 belong to the same local area network, and R3 and R4 belong to the same local area network. As shown in Figure 4 and Figure 5 , according to the configuration, the pptp backup mechanism is enabled, and one route is selected as the main route and one as the backup route. The main route and the backup route are directly connected in the same local area network, and a tcp connection is established to inform each other of the current state. The backup route will decide whether to establish the pptp tunnel after receiving the pptp state message from the main route. In the ip in Figure 4 , the ip is the ip that can communicate with the opposite end of the tunnel, and the backup ip is the ip address of the backup route in the local area network, Figure 5 , the port is the tcp port opened by the current route.
[0032] S3, judging whether the address ping detection result reaches a threshold value, generating a judgment result, and performing timing detection or switching on the vpn tunnel mechanism function of the backup routing to establish the pptp tunnel of the backup routing according to the judgment result.
[0033] Specifically, step S3 comprises: when the address ping detection result is that the number of ping detection failures does not reach a threshold value or the average delay of ping detection does not reach a threshold value, performing timing detection, and continuously judging whether the address ping detection result reaches a threshold value;
[0034] When the address ping detection result is that the number of ping detection failures reaches a threshold value or the average delay of ping detection reaches a threshold value, informing the backup routing to turn on the vpn tunnel mechanism function through tcp communication, establishing the pptp tunnel of the backup routing, and simultaneously turning off the vpn tunnel mechanism function of the main routing.
[0035] Please refer to Figure 3 In the embodiment, for example, when the pptp tunnel of the main routing is successfully established, but the address ping detection of 192.168.8.88 fails three times, the current pptp tunnel establishment application is closed, and the backup routing is informed through tcp protocol that the pptp tunnel of the main routing has been closed, so that the backup routing establishes the pptp tunnel according to the configured pptp tunnel information. Alternatively, when the average delay of the address ping detection of 192.168.8.88 exceeds 500 ms for three times, Figure 4 and Figure 5 the current network is considered unstable, and the routing is switched. Meanwhile, the scheme is also applicable to l2tp, openvpn, ipsec, gre, gretap and other vpn protocols.
[0036] Preferably, the method further comprises:
[0037] When it is judged that the pptp tunnel establishment of the main routing fails, judging whether the pptp tunnel establishment time of the main routing exceeds a preset time value;
[0038] If not, turning on the vpn tunnel mechanism function of the main routing to establish the pptp tunnel of the main routing;
[0039] If yes, informing the backup routing to turn on the vpn tunnel mechanism function through tcp communication, establishing the pptp tunnel of the backup routing, and simultaneously turning off the vpn tunnel mechanism function of the main routing.
[0040] In the embodiment, the experimental process of the VPN tunnel backup guarantee method based on the ping detection mechanism mainly includes the following steps: first, the VPN tunnel mechanism function of the primary and backup routes is started; second, after the VPN tunnel of the primary route is established, the TCP communication with the backup route is established to inform the tunnel situation of the primary route; third, if the VPN tunnel of the primary route is not established for ten minutes, the backup route is switched to establish; fourth, the backup route also establishes the VPN tunnel according to the VPN tunnel information configured by itself; and fifth, in the use process, when the threshold value is triggered, the tunnel is switched.
[0041] In summary, the VPN tunnel backup guarantee method based on the ping detection mechanism provides a VPN tunnel backup guarantee mechanism scheme based on the ping detection mechanism through the ping tool and the TCP protocol. Through the mechanism, a more stable VPN tunnel switching mechanism can be provided to guarantee the integrity of the communication data. Compared with the prior art, a more reliable guarantee mechanism is provided, which can better adapt to a relatively complex network environment, avoid the unstable data transmission caused by the network environment problem, and provide better protection for production application.
[0042] Please refer to Figure 6 The second embodiment of the present application provides a VPN tunnel backup guarantee device based on a ping detection mechanism, which comprises:
[0043] The primary route tunnel establishment unit 201 is configured to obtain preset configuration information, configure the primary route and the backup route according to the preset configuration information, start the VPN tunnel mechanism function of the primary route, and establish the PPTP tunnel of the primary route. The primary route and the backup route belong to the same local area network.
[0044] The TCP communication unit 202 is configured to control the primary route and the backup route to establish TCP communication when it is judged that the PPTP tunnel of the primary route is successfully established, and inform the backup route of the PPTP tunnel situation of the primary route. The PPTP tunnel situation of the primary route includes the address ping detection result.
[0045] The route switching unit 203 is configured to judge whether the address ping detection result reaches the threshold value, generate a judgment result, and perform timing detection or switching according to the judgment result to start the VPN tunnel mechanism function of the backup route and establish the PPTP tunnel of the backup route.
[0046] Preferably, the primary route and the backup route are configured according to the preset configuration information, and the VPN tunnel mechanism function of the primary route is started. Specifically, the following steps are performed:
[0047] The preset configuration information is obtained, and the primary route and the backup route are configured according to the preset configuration information.
[0048] Enabling the pptp backup mechanism of the main route, establishing the pptp tunnel of the main route.
[0049] Preferably, it is judged whether the address ping detection result reaches a threshold value, a judgment result is generated, and the vpn tunnel mechanism function of the backup route is started according to the judgment result, the pptp tunnel of the backup route is established, and specifically:
[0050] When the address ping detection result is that the number of ping detection failures does not reach a threshold value or the average delay of ping detection does not reach a threshold value, timing detection is performed, and it is continuously judged whether the address ping detection result reaches a threshold value;
[0051] When the address ping detection result is that the number of ping detection failures reaches a threshold value or the average delay of ping detection reaches a threshold value, the backup route is informed to start the vpn tunnel mechanism function through tcp communication, the pptp tunnel of the backup route is established, and the vpn tunnel mechanism function of the main route is closed.
[0052] Preferably, it further includes:
[0053] When it is judged that the pptp tunnel establishment of the main route fails, it is judged whether the pptp tunnel establishment time of the main route exceeds a preset time value;
[0054] If not, the vpn tunnel mechanism function of the main route is started, and the pptp tunnel of the main route is established;
[0055] If yes, the backup route is informed to start the vpn tunnel mechanism function through tcp communication, the pptp tunnel of the backup route is established, and the vpn tunnel mechanism function of the main route is closed.
[0056] The third embodiment of the application provides a vpn tunnel backup guarantee device based on a ping detection mechanism, including a memory and a processor, the memory stores a computer program, and the computer program can be executed by the processor to realize the vpn tunnel backup guarantee method based on the ping detection mechanism in any one of the above.
[0057] The fourth embodiment of the application provides a computer readable storage medium, which stores a computer program, and the computer program can be executed by the processor of the device where the computer readable storage medium is located to realize the vpn tunnel backup guarantee method based on the ping detection mechanism in any one of the above.
[0058] Exemplarily, each of the above-described devices and each of the above-described flow steps can be implemented by a computer program, which can be divided into one or more units stored in the memory and executed by the processor to complete the present application.
[0059] The processor can be a central processing unit (CPU), and can also be other general-purpose processors, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor.
[0060] The memory can be used to store the computer program and / or modules, and the processor realizes various functions of the present application by running or executing the computer program and / or modules stored in the memory and calling data stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application required by a function (such as a sound playing function, an image playing function, etc.), etc.; and the data storage area can store data created based on use of the mobile phone (such as audio data, a phone book, etc.), etc. In addition, the memory can include a high-speed random access memory, and can also include a nonvolatile memory, for example, a hard disk, a memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one disk storage device, a flash storage device, or other volatile solid-state storage devices.
[0061] The electronic device or the printer integrated unit, if implemented in the form of a software function unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, all or part of the processes in the above-mentioned embodiment methods can also be completed by a computer program instructing related hardware, and the computer program can be stored in a computer readable storage medium. The computer program can implement the steps of each method embodiment when executed by a processor. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or some intermediate forms. The computer readable medium can include any entity or device capable of carrying the computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc. It should be noted that the contents of the computer readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction, for example, in some jurisdictions, according to legislation and patent practice, the computer readable medium does not include electrical carrier signals and telecommunication signals.
[0062] It should be noted that the above-described device embodiments are only schematic, and the units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or distributed on multiple network units. Part or all of the modules can be selected to achieve the purpose of the embodiment scheme according to actual needs. In addition, the connection relationship between the modules in the device embodiment provided by the present application indicates that there is a communication connection between them, which can be implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement it without creative labor.
[0063] The above is the preferred embodiment of the present application. It should be noted that for those skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can be made, which are also considered within the scope of protection of the present application.
Claims
1. A VPN tunnel backup guarantee method based on a ping detection mechanism, characterized in that, The method comprises the following steps: acquiring preset configuration information, configuring a primary route and a backup route according to the preset configuration information, and starting a VPN tunnel mechanism function of the primary route to establish a PPTP tunnel of the primary route, wherein the primary route and the backup route belong to the same local area network; when it is judged that the PPTP tunnel of the primary route is successfully established, controlling the primary route to establish TCP communication with the backup route to inform the backup route of the PPTP tunnel situation of the primary route, wherein the PPTP tunnel situation of the primary route comprises an address ping detection result; judging whether the address ping detection result reaches a threshold value, generating a judgment result, and performing timing detection or switching according to the judgment result to start the VPN tunnel mechanism function of the backup route to establish a PPTP tunnel of the backup route.
2. The method of claim 1, wherein the ping detection mechanism based VPN tunnel backup assurance method further comprises: According to the preset configuration information, the primary route and the backup route are configured, and the VPN tunnel mechanism function of the primary route is started, specifically as follows: acquiring preset configuration information, and configuring a primary route and a backup route according to the preset configuration information; enabling a PPTP backup mechanism of the primary route to establish a PPTP tunnel of the primary route.
3. The method of claim 1, wherein the ping detection mechanism based VPN tunnel backup assurance method further comprises: judging whether the address ping detection result reaches a threshold value, generating a judgment result, and performing timing detection or switching according to the judgment result to start the VPN tunnel mechanism function of the backup route to establish a PPTP tunnel of the backup route, specifically as follows: when the address ping detection result is that the number of failed ping detections does not reach a threshold value or the average delay of ping detection does not reach a threshold value, timing detection is performed, and it is continuously judged whether the address ping detection result reaches a threshold value; when the address ping detection result is that the number of failed ping detections reaches a threshold value or the average delay of ping detection reaches a threshold value, the backup route is informed through TCP communication to start the VPN tunnel mechanism function to establish a PPTP tunnel of the backup route, and the VPN tunnel mechanism function of the primary route is closed.
4. The method of claim 1, wherein the ping detection mechanism based VPN tunnel backup assurance method further comprises: Further comprising: when it is judged that the PPTP tunnel of the primary route is unsuccessfully established, judging whether the PPTP tunnel establishment time of the primary route exceeds a preset time value; if not, starting the VPN tunnel mechanism function of the primary route to establish a PPTP tunnel of the primary route; if yes, informing the backup route through TCP communication to start the VPN tunnel mechanism function to establish a PPTP tunnel of the backup route, and closing the VPN tunnel mechanism function of the primary route.
5. A VPN tunnel backup guarantee device based on a ping detection mechanism, characterized in that, The method comprises the following steps: a primary route tunnel establishment unit is configured to acquire preset configuration information, configure a primary route and a backup route according to the preset configuration information, and start a VPN tunnel mechanism function of the primary route to establish a PPTP tunnel of the primary route, wherein the primary route and the backup route belong to the same local area network; a TCP communication unit is configured to, when it is judged that the PPTP tunnel of the primary route is successfully established, control the primary route to establish TCP communication with the backup route to inform the backup route of the PPTP tunnel situation of the primary route, wherein the PPTP tunnel situation of the primary route comprises an address ping detection result; A routing switching unit is configured to determine whether the address ping detection result reaches a threshold value, generate a determination result, and perform timing detection or switching to start the vpn tunnel mechanism function of the backup routing and establish the pptp tunnel of the backup routing according to the determination result.
6. The apparatus for VPN tunnel backup guarantee based on ping detection mechanism according to claim 5, wherein, The main routing and the backup routing are configured according to preset configuration information, and the vpn tunnel mechanism function of the main routing is started, specifically as follows: The preset configuration information is acquired, and the main routing and the backup routing are configured according to the preset configuration information; The pptp backup mechanism of the main routing is enabled, and the pptp tunnel of the main routing is established.
7. The apparatus for VPN tunnel backup guarantee based on ping detection mechanism according to claim 5, wherein, The address ping detection result is determined whether to reach a threshold value, a determination result is generated, and timing detection or switching to start the vpn tunnel mechanism function of the backup routing is performed according to the determination result, and the pptp tunnel of the backup routing is established, specifically as follows: When the address ping detection result is that the number of ping detection failures does not reach a threshold value or the average delay of ping detection does not reach a threshold value, timing detection is performed, and it is continuously determined whether the address ping detection result reaches a threshold value; When the address ping detection result is that the number of ping detection failures reaches a threshold value or the average delay of ping detection reaches a threshold value, the backup routing is informed to start the vpn tunnel mechanism function through tcp communication, the pptp tunnel of the backup routing is established, and the vpn tunnel mechanism function of the main routing is closed.
8. The apparatus for VPN tunnel backup guarantee based on ping detection mechanism according to claim 5, wherein, Further comprising: When it is determined that the pptp tunnel of the main routing fails to be established, it is determined whether the pptp tunnel establishment time of the main routing exceeds a preset time value; If not, the vpn tunnel mechanism function of the main routing is started, and the pptp tunnel of the main routing is established; If yes, the backup routing is informed to start the vpn tunnel mechanism function through tcp communication, the pptp tunnel of the backup routing is established, and the vpn tunnel mechanism function of the main routing is closed.
9. A VPN tunnel backup guarantee device based on a ping detection mechanism, characterized in that, A memory and a processor are included, the memory stores a computer program, the computer program can be executed by the processor to implement the vpn tunnel backup guarantee method based on the ping detection mechanism as claimed in any one of claims 1 to 4.
10. A computer-readable storage medium, characterized in that, A computer program is stored, the computer program can be executed by the processor of the device where the computer readable storage medium is located to implement the vpn tunnel backup guarantee method based on the ping detection mechanism as claimed in any one of claims 1 to 4.
Citation Information
Patent Citations
Method and data for transmitting data between local area networks
CN102833167A
Route detection method and apparatus
CN107547376A