A method and system for simulating VPN access in a network range

By combining routing and network elements on the cloud platform, a simulation environment that simulates VPN access and using VPN management module for access control, the complex problem of VPN resource occupation and operation and maintenance in the network shooting range is solved, and the effect of resource conservation and operation and maintenance is achieved.

CN119583366BActive Publication Date: 2025-05-02SAINING WANGAN
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510112111.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-02
Estimated Expiration
2045-01-24

AI Technical Summary

Technical Problem

In network shooting ranges, the existing technology requires additional VPN server deployment, which occupies resources and operates and maintenance personnel need to manually control the effectiveness and failure of VPN accounts, which is inconvenient to operate and prone to errors.

Method used

By combining routing and network elements on the cloud platform, a simulation environment that simulates VPN access is built, and a VPN management module is used for resource management and access control is provided, and a timing mechanism and a graphical interface are provided to flexibly control the VPN access timing of the operating machine.

Benefits of technology

Reduce the consumption of resources, reduce operation and maintenance costs, improve operation and maintenance convenience and operation flexibility, and avoid the use of real VPN services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119583366B_ABST
    Figure CN119583366B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for simulating VPN access in a network range, the method comprising: constructing a business topology, placing a VPN service as a topology element in a topology diagram, and setting a network that the VPN needs to access by connecting lines; starting a simulation environment, creating a simulation environment for business use including VPN services; registering information related to the VPN service in the simulation environment to the VPN management module by calling an interface of a VPN management module; using a timing mechanism to control the VPN access time and exit time of each operating machine in the simulation environment; or providing a VPN client module with a graphical interface, allowing a user to apply for VPN access or actively disconnect VPN access. The present invention can avoid using a real VPN service, reduce resource consumption, and increase the convenience of operation and maintenance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to a method and system for simulating VPN access in a network target range, belonging to the technical field of network security. Background Art

[0002] In the use of the network range, it is often necessary to temporarily connect a virtual machine to a network to use business services. For example, in some types of network security competitions, each player or team will be assigned a separate operating machine, and each operating machine can only access the network during a specific period of time to attack the target machine inside the network.

[0003] To achieve this function, VPN technology is usually used. A VPN connection redirects data packets from one device to another VPN server, and then sends the data packets to a third party through the VPN server. Generally, a VPN account is assigned to each operating machine, and different VPN accounts can only be used in different time periods. For example, Team A can only use VPN to access the competition environment between 10 and 11 o'clock, and the operation time is only 1 hour. Team B can only use VPN to access the competition environment between 12 and 13 o'clock.

[0004] When the network range is built in a cloud environment, such as the openstack cloud, these virtual cloud environments generally only provide basic network elements such as networks and routing, and do not have VPNs. Therefore, when using VPN software to control network access, VPN servers must be deployed additionally, which takes up a lot of resources. When VPN accounts take effect and when they expire often requires manual control by operation and maintenance personnel, which is extremely inconvenient and prone to errors. Summary of the invention

[0005] Purpose of the invention: In view of the problems existing in the above-mentioned prior art, the purpose of the present invention is to provide a method and system for simulating VPN access in a network target range, which can support temporary access of virtual machines in the network target range to a certain network, and can complete the permission control of whether the network is available, so as to reduce the resource occupation of the network target range and reduce operation and maintenance costs.

[0006] Technical solution: To achieve the above-mentioned invention object, the present invention adopts the following technical solution:

[0007] In a first aspect, the present invention provides a method for simulating VPN access in a network range, comprising the following steps:

[0008] Build the service topology, place the VPN service as a topology element in the topology map, and set the network that the VPN needs to access by connecting lines;

[0009] Start the simulation environment and create a simulation environment including the business use of VPN service; wherein the VPN service is implemented by combining the routing and network elements of the cloud platform;

[0010] By calling the interface of the VPN management module, registering the information related to the VPN service in the simulation environment to the VPN management module; the VPN management module is used for the management of VPN related resources, the processing of VPN access and disconnection, and the processing of VPN client requests;

[0011] A timing mechanism is used to control the VPN access time and exit time of each operating machine in the simulation environment; or, a VPN client module with a graphical interface is provided to allow the user to apply for VPN access or actively disconnect the VPN access.

[0012] Furthermore, the VPN management module constructs a series of storage tables to store the simulation environment and VPN service related information, the storage tables including a simulation environment information table, an operation machine information table, and an operation machine application access management table and / or an operation machine scheduled access management table;

[0013] The simulation environment information table stores the simulation environment id, name and virtual routing resource id;

[0014] The operation machine information table stores the simulation environment id, the operation machine name, the operation machine host name, the operation machine resource id, whether it has been connected, the bridge network id, the bridge network cidr, the operation machine bridge port id and the routing bridge port id;

[0015] The operation machine application access management table stores the operation machine host name, application time, application status and processing time;

[0016] The operating machine scheduled access management table stores the operating machine host name, designated time, and processing action.

[0017] Further, the registering information related to the VPN service in the simulation environment to the VPN management module includes:

[0018] Receive parameters of the simulation environment, the parameters including a simulation environment ID, a simulation environment name, a network list, and a host list parameter; wherein each element in the host list includes a host name and an instance ID;

[0019] Create a bridge route and obtain the resource id of the route;

[0020] Connect the created bridge route to each network in the network list;

[0021] Record the simulation environment id, simulation environment name and routing resource id into the simulation environment information table;

[0022] Record each item in the host list into the operating machine information table, set the "connected" field in each record to "no", and set the bridge network id to "empty".

[0023] Furthermore, the VPN access process of the operating machine includes:

[0024] Query the corresponding operation machine resource id, virtual routing resource id and simulation environment id according to the operation machine host name;

[0025] Create a bridge network and get the network id;

[0026] Connect the virtual router and bridge network;

[0027] Connect the operating machine and the bridge network;

[0028] Update the relevant fields in the operation machine information table.

[0029] Furthermore, the VPN exit process of the operating machine includes:

[0030] According to the host name of the operating machine, query the corresponding operating machine resource ID, virtual routing resource ID, bridge network ID, operating machine bridge port ID and routing bridge port ID;

[0031] Delete the port on the virtual router;

[0032] Delete the port on the operating machine;

[0033] Delete the bridge network;

[0034] Update the relevant fields in the operation machine information table.

[0035] Furthermore, the process of the VPN management module deregistering the simulation environment includes:

[0036] Query the operating machine in the VPN according to the simulation environment ID, and execute the VPN exit process of the operating machine for each operating machine found;

[0037] Query the virtual routing resource ID according to the simulation environment ID, and delete the route in the simulation environment;

[0038] The operating machine access application management table and / or the operating machine scheduled access management table, as well as the relevant information in the operating machine information table and the simulation environment information table are deleted in sequence.

[0039] In a second aspect, the present invention provides a system for simulating VPN access in a network range, including a simulation service module, a VPN client module and a VPN management module:

[0040] The simulation service module is used to construct a service topology, place the VPN service as a topology element in the topology map, and set the network that the VPN needs to access by connecting lines; start the simulation environment, create a simulation environment for business use including the VPN service, wherein the VPN service is implemented by combining the routing and network elements of the cloud platform; and register information related to the VPN service in the simulation environment to the VPN management module by calling the interface of the VPN management module;

[0041] The VPN client module runs on the operating machine and is used by the user to access the simulation environment; and provides a graphical interface to allow the user to apply for VPN access or actively disconnect VPN access;

[0042] The VPN management module is used for managing VPN related resources, processing VPN access and disconnection, and processing VPN client requests; and using a timing mechanism to control the VPN access time and exit time of each operating machine in the simulation environment.

[0043] Furthermore, the VPN management module provides a management page for displaying the simulation environments registered in the system, viewing a list of all operating machines in a simulation environment, and managing scheduled tasks and / or reviewing access requests from operating machines.

[0044] Furthermore, the process of registering the simulation environment by the VPN management module includes:

[0045] Receive parameters of the simulation environment, the parameters including a simulation environment ID, a simulation environment name, a network list, and a host list parameter; wherein each element in the host list includes a host name and an instance ID;

[0046] Create a bridge route and obtain the resource id of the route;

[0047] Connect the created bridge route to each network in the network list;

[0048] Record the simulation environment id, simulation environment name and routing resource id into the simulation environment information table;

[0049] Record each item in the host list into the operating machine information table, set the "connected" field in each record to "no", and set the bridge network id to "empty".

[0050] Furthermore, the process of the VPN management module deregistering the simulation environment includes:

[0051] Query the operating machine in the VPN according to the simulation environment ID, and execute the VPN exit process of the operating machine for each operating machine found;

[0052] Query the virtual routing resource ID according to the simulation environment ID, and delete the route in the simulation environment;

[0053] The operating machine access application management table and / or the operating machine scheduled access management table, as well as the relevant information in the operating machine information table and the simulation environment information table are deleted in sequence.

[0054] Beneficial effects: The present invention provides a simulated VPN access method based on cloud platform-based routing and network elements, and simulates a VPN network by combining elements, which can avoid using real VPN services and reduce resource consumption. The present invention can provide application access and scheduled task access, so that the timing of the operating machine accessing the VPN can be flexibly controlled, which increases the convenience of operation and maintenance. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] Figure 1 Build a schematic diagram for your business topology.

[0056] Figure 2 The diagram is a schematic diagram of configuring a VPN service in an embodiment of the present invention.

[0057] Figure 3 The figure is a schematic diagram of the VPN access process in an embodiment of the present invention.

[0058] Figure 4 Schematic diagram of VPN exit process in an embodiment of the present invention.

[0059] Figure 5 The figure is a schematic diagram of the simulation environment registration interface process in an embodiment of the present invention.

[0060] Figure 6 The figure is a schematic diagram of the simulation environment logout interface process in an embodiment of the present invention.

[0061] Figure 7 This is an example diagram of a list page in an embodiment of the present invention.

[0062] Figure 8 This is an example diagram of an operating machine list page in an embodiment of the present invention.

[0063] Fig. 9 This is an example diagram of a scheduled task management page in an embodiment of the present invention.

[0064] Fig.10 1 is an example diagram of a pop-up window page for adding a scheduled task in an embodiment of the present invention, where (a) is a adding page and (b) is an editing page.

[0065] Fig.11 This is an example diagram of an operating machine application access list page in an embodiment of the present invention.

[0066] Fig.12 This is an example diagram of a VPN client home page in an embodiment of the present invention.

[0067] Fig.13 This is an example diagram showing the VPN client VPN connected status in an embodiment of the present invention.

[0068] Fig.14 This is an example diagram showing the VPN client VPN not connected state in an embodiment of the present invention.

[0069] Fig.15 This is an example diagram showing the VPN application status of the VPN client in an embodiment of the present invention. DETAILED DESCRIPTION

[0070] The technical solution of the present invention will be clearly and completely described below in conjunction with the accompanying drawings and specific embodiments.

[0071] The embodiment of the present invention discloses a method for simulating VPN access in a network range, which is based on cloud platform-based routing and network elements and can reduce resource occupation and operation and maintenance costs. The specific steps include:

[0072] Build the service topology, place the VPN service as a topology element in the topology map, and set the network that the VPN needs to access by connecting lines;

[0073] Start the simulation environment and create a simulation environment for business use including VPN services;

[0074] By calling the interface of the VPN management module, registering the information related to the VPN service in the simulation environment to the VPN management module;

[0075] Use a timing mechanism to control the VPN access time and exit time of each operating machine in the simulation environment; or provide a VPN client module with a graphical interface to allow users to apply for VPN access or actively disconnect VPN access.

[0076] A system for simulating VPN access in a network range for implementing the above-mentioned embodiment method mainly includes a simulation business module, a VPN management module, and a VPN client module.

[0077] The simulation business module is mainly used to realize business needs, such as network topology construction, simulation environment construction, topology element management and other functions. In this embodiment, when constructing the business topology, the VPN service is placed in the topology map as a topology element, and the network that the VPN needs to access is set by connecting lines; the simulation business module also creates a simulation environment for business use including the VPN service when starting the simulation environment; and registers information related to the VPN service in the simulation environment to the VPN management module by calling the interface of the VPN management module.

[0078] The VPN client module is a software that can be run on the user's operating machine and is used by the user to access the simulation environment; and provides a graphical interface to allow the user to apply for VPN access or actively disconnect VPN access.

[0079] The VPN management module is mainly composed of http services and a group of pages. It is used to manage VPN related resources, handle VPN access and disconnection, and process VPN client requests. It also uses a timing mechanism to control the VPN access time and exit time of each operating machine in the simulation environment.

[0080] Specifically, based on the above-mentioned system for simulating VPN access, the use process of VPN access may include: Step 1: Building a service topology, such as Figure 1 ; Step 2: Drag in the VPN service node and set the network that the VPN needs to access by connecting. Figure 2 ; Step 3: Start the simulation environment; Step 4: Manage VPN access. There are two ways to manage. The first is to set timed access and timed exit for each operation machine in the simulation environment on the VPN management service page; the second is that the user applies for access through the VPN client on the operation machine, and the operation and maintenance personnel can decide whether to approve the access in the VPN management service.

[0081] The following describes the detailed implementation details of the simulation service module, VPN management module, and VPN client module involved in the embodiment of the present invention.

[0082] 1. Simulation business module

[0083] The simulation business module builds a simulation environment according to the topology. If there is a VPN service node in the topology, after creating the simulation environment used by the business, it calls the simulation environment registration interface of the VPN management module to report the VPN service-related information in the simulation environment to the VPN management module.

[0084] When the simulation service module starts the operation machine in the simulation environment, it usually needs to meet the following requirements: (1) Each operation machine adds a network card, which is connected to a configuration network so that the operation machine can communicate with the VPN service; (2) Each operation machine is set with a host name, which is unique in the system to ensure that the VPN service can accurately identify the operation machine. Taking openstack as an example, the parameter --meta hostname=${hostname} can be used when starting the virtual machine. The complete command is: openstack server create --image ubuntu20.04 --meta hostname=host_001.

[0085] 2. VPN Management Module

[0086] The VPN management module builds a series of storage tables to save information related to the simulation environment and VPN services; it maintains a set of http interfaces to interact with the simulation business module and the VPN client module.

[0087] The storage table includes a simulation environment information table, an operation machine information table, an operation machine application access management table, and an operation machine scheduled access management table.

[0088] Table 1 Simulation environment information table

[0089]

[0090] Table 2 Operating machine information table

[0091]

[0092] Table 3 Operation machine application access management table

[0093]

[0094] Table 4 Operation machine scheduled access management table

[0095]

[0096] Based on the information in the storage table, the core VPN access and disconnection process of the VPN management module is as follows: Figure 3 and Figure 4 shown.

[0097] like Figure 3 As shown in the figure, the VPN access process includes the following steps:

[0098] S101: Enter the host name parameter of the operating machine, recorded as ${hostname}.

[0099] S102: query the operation machine resource id and the virtual routing resource id corresponding to the simulation environment according to ${hostname}, and use the following query statement: [select a. operation machine resource id, b. virtual routing resource id, b. simulation environment idfrom operation machine information table a, simulation environment information table b where a. simulation environment id = b. simulation environment id anda. operation machine host name = ${hostname}]; record the operation machine resource id as ${resource_id}, the virtual routing resource id as ${router_id}, and the simulation environment id as ${id}.

[0100] S103: Create a bridge network. Query the cidr used in the simulation environment. The query statement is: [select a. bridge network cidr from operating machine information table a, simulation environment information table b where a. simulation environment id = b. simulation environment id and a. operating machine host name = ${hostname}], set all cidrs as the set ${cidrs}, randomly generate a cidr value that is not in the set ${cidrs} as the network segment of the bridge network, record it as ${cidr}, use the command to create a network, take openstack as an example, the command is as follows:

[0101] openstack network create vpn_network_${id}

[0102] openstack subnet create --network ${id}_${resource_id} --subnet-range${cidr} subnet

[0103] Remember the generated network id is ${network_id}.

[0104] S104: Connect the router and the network. Taking openstack as an example, the command is as follows:

[0105] openstack router add subnet ${router_id} ${network_id}

[0106] Note that the port ID on the router after access is ${r_port_id}.

[0107] S105: Connect the operating machine to the network. Taking openstack as an example, the command is as follows:

[0108] openstack server add network ${resource_id} ${network_id}

[0109] Note that the port ID on the operating machine after access is ${h_port_id}.

[0110] S106: Update the corresponding information in the operator information table, write the bridge network id into ${network_id}, write the routing bridge port id into ${r_port_id}, write the operator bridge port id into ${h_port_id}, write the bridge network cidr into ${cidr}, and change the access field to yes. The process ends.

[0111] like Figure 4 As shown in the figure, the VPN exit process includes the following steps:

[0112] S201: Enter the host name parameter of the operating machine, recorded as ${hostname}.

[0113] S202: query the operation machine resource id, the virtual routing resource id corresponding to the simulation environment, the bridge network id, the operation machine bridge port id and the routing bridge port id according to ${hostname}, and use the following query statement: [select a. simulation environment id, a. operation machine resource id, a. bridge network id, a. operation machine bridge port id, a. routing bridge port id, b. virtual routing resource id from operation machine information table a, simulation environment information table b where a. simulation environment id = b. simulation environment id and a. operation machine host name = ${hostname}];

[0114] The operation machine resource id is recorded as ${resource_id}, the virtual routing resource id is recorded as ${router_id}, the simulation environment id is recorded as ${id}, the routing bridge port id is recorded as ${r_port_id}, and the operation machine bridge port id is recorded as ${h_port_id}.

[0115] S203: Delete the port on the bridge router. Taking openstack as an example, the command used is:

[0116] openstack router remove port ${router_id} ${r_port_id}.

[0117] S204: Delete the port on the operating machine. Taking openstack as an example, the command used is:

[0118] openstack server remove port ${resource_id} ${h_port_id}.

[0119] S205: Delete the bridge network. Taking openstack as an example, the command used is:

[0120] openstack subnet delete ${network_id}.

[0121] S206: Update the information in the table, clear the bridge network id, bridge port id, bridge port id, bridge network id, and bridge network cidr fields of the corresponding data in the operator information table, and change whether it has been connected to no. The process ends.

[0122] The http interfaces provided by the VPN management module include a simulation environment registration interface, a simulation environment deregistration interface, an operation machine access status query interface, an operation machine application access interface, an operation machine application logout interface, and an operation machine application cancellation interface.

[0123] Table 5 Simulation environment registration interface input parameters

[0124]

[0125] like Figure 5 As shown, the simulation environment registration interface processing flow includes the following steps:

[0126] S301: Input simulation environment id, simulation environment name, network list, and host list parameters, which are recorded as ${id}, ${name}, ${networks}, and ${devices} respectively. Each element of the host list contains hostname and resource_id fields, which are recorded as ${devices[index].hostname} and ${devices[index].resource_id}. Index is the position subscript of the element in the host list.

[0127] S302: Create a bridge route and connect the route to each network in ${networks}. Taking openstack as an example, the command to create a route is as follows: openstack router create vpn_router_1. After executing the command, the resource id of the route can be obtained, which is recorded as ${router_id}.

[0128] Loop through each element in ${networks}, denoted as ${networks[index]}, where index is the subscript of the element in ${networks}. Taking openstack as an example, the command to add a network is: openstack router addsubnet ${router_id} ${networkd[index]}.

[0129] S303: Write each part of the information into the storage table. Write ${id}, ${name}, and ${router_id} into the simulation environment information table; write the elements in ${devices} into the operator information table, one line for each element, ${id}, ${devices[index].name}, ${devices[index].hostname}, and ${devices[index].resource_id} into the simulation environment id, operator name, operator host name, and operator resource id fields, respectively. The fields for whether they have been connected are all no, and the bridge network id is empty. The process ends.

[0130] Table 6 Input parameters of simulation environment logout interface

[0131]

[0132] like Figure 6 As shown, the simulation environment logout interface processing flow includes the following steps:

[0133] S401: Input parameter simulation environment id, recorded as ${id}.

[0134] S402: Query information of an operating machine using VPN, using the query conditions:

[0135] [select operator host name from operator information table where simulation environment id = ${id} limit1]

[0136] Note that the host name of the operating machine is ${hostname}.

[0137] S403: If ${hostname} exists, go to subprocess S404, otherwise go to step S405.

[0138] S404: Enter the VPN exit process with ${hostname} as the input parameter, and then enter step S402.

[0139] S405: Query the bridge route information and then delete the route. The query conditions used are:

[0140] [select virtual routing resource id from simulation environment information table where simulation environment id = ${id}]

[0141] Note that the virtual router resource id is ${router_id}, and then delete the route. Taking openstack as an example, the command used is:

[0142] openstack router delete ${router_id}.

[0143] S406: Delete the relevant information in the operator access application management table, the operator scheduled access management table, the operator information table, and the simulation environment information table in sequence. The deletion statement used is:

[0144] [delete from operator application access management table where operator host name in (select operator host name from operator information table where simulation environment id = ${id})]

[0145] [delete from operator scheduled access management table where operator host name in (select operator host name from operator information table where simulation environment id = ${id})]

[0146] [delete from operating machine information table where simulation environment id = ${id}]

[0147] [delete from simulation environment information table where simulation environment id = ${id}]

[0148] The process ends.

[0149] Table 7 Operation machine access status query interface

[0150]

[0151] The logic of the operation machine access status query interface is: query whether it has been connected in the operation machine information table according to the hostname, and return it from the interface. The query used is: [select whether it has been connected from the operation machine information table where ${operation machine host name} = hostname].

[0152] Table 8 Input parameters for the operator application access interface

[0153]

[0154] The implementation logic of the operating machine application access interface is: add a row of data to the operating machine application access management table, and write the operating machine host name into hostname; the application time is the current time, in the format of year-month-day hour-minute-second; the application status is waiting for review, and the processing time is empty.

[0155] Table 9 Input parameters of the operator application cancellation interface

[0156]

[0157] The logic of the operation machine application cancellation interface time is: delete the data of the operation machine host name = hostname in the operation machine application access management table.

[0158] Table 10 Input parameters of the operator application exit interface

[0159]

[0160] The implementation logic of the operation machine application logout interface is: using hostname as input parameter, enter the VPN logout process.

[0161] The VPN management module provides management pages such as Figures 7 to 11 shown.

[0162] Figure 7 The following is the simulation environment list page. The page contains a simulation environment list and two buttons: scheduled task management button and audit management button.

[0163] The simulation environment list displays the simulation environments registered in the current system. The query conditions used are as follows:

[0164] [Select simulation environment id, simulation environment name from simulation environment information table]

[0165] Each line in the list represents a simulation environment. Each line has a view button. Click it and enter the operation machine list page with the simulation environment ID parameter.

[0166] Figure 8 The page shown is the operating machine list page, which contains a list of all operating machines in a simulation environment. The page can display the status of the operating machine's access to the VPN and control the access and disconnection of the operating machine's VPN.

[0167] Assume that the input simulation environment parameter is ${id}, and the query conditions are as follows:

[0168] [select operation machine name, operation machine host name, whether it has been connected from operation machine information table where simulation environment id = ${id}]

[0169] Each row displays information about an operating machine. If the machine is connected, a disconnect button is displayed in the operation column of the row. If the machine is not connected, a connect button is displayed in the operation column of the row.

[0170] After clicking Access, the VPN access process of the operating machine will be entered and the operating machine list page will be refreshed;

[0171] After clicking Disconnect, the operation machine will be disconnected from the VPN process and the operation machine list page will be refreshed.

[0172] Fig. 9 The following is the scheduled task management page, which contains a new button and a scheduled task list.

[0173] The query logic of the scheduled task list page is as follows:

[0174] [select c.simulation environment name, b.operator name, a.operator host name, a.specified time, a.processing action from operator scheduled access management table a, operator information table b, simulation environment information table cwhere a.operator host name = b.operator host name and b.simulation environment id = c.simulation environment id]

[0175] Each row shows a scheduled task, and each row has an update button and a delete button;

[0176] Click the Add button to open the scheduled task pop-up window, such as Fig.10 The pop-up window contains four input boxes: simulation environment drop-down selection, operation machine drop-down selection, time input, and action drop-down selection. The simulation environment drop-down selection box displays the name of the simulation environment in the current system, and the operation machine drop-down selection box displays the list of operation machines in the simulation environment specified in the simulation environment selection box. The time needs to be entered by the user in the format of year-month-day hour-minute-second. The action drop-down can be connected or disconnected. After clicking OK, the information is written into the operation machine timed access management table.

[0177] Click the Update button to open the scheduled task update pop-up window, which includes the simulation environment display box, the operation machine display box, the time display box, and the action display box. The time and action can be modified. After modification, click Confirm to update the operation machine scheduled access management table.

[0178] Click the Delete button to delete the data corresponding to the operating machine scheduled access management table.

[0179] Fig.11 The following is the operator access application list page, which contains an access application list. The query conditions are as follows:

[0180]

select c.Simulation environment name, b.Operation machine name, a.Operation machine host name, a.Application time, a.Application result, a.Processing time from Operation machine scheduled access management table a, Operation machine information table b, Operation machine application access management table c where a.Operation machine host name = b.Operation machine host name and b.Simulation environment id = c.Simulation environment id

[0181] If the review status is passed or rejected, there is no button in the action column;

[0182] If the review status is Waiting for Review, the operation will display two buttons: Approve and Reject.

[0183] If you click Approve, the VPN access process will be executed on the operating machine of the bank and the review status will be changed to Approved; if you click Reject, the review status will be directly changed to Reject.

[0184] 3. VPN Client Module

[0185] The VPN client module communicates with the VPN management module through the http interface and provides an operation page to facilitate access and disconnection of the VPN network;

[0186] Open the client and enter the VPN client homepage. Fig.12 , you need to enter the IP address of the VPN management terminal.

[0187] After input, click Confirm, the client calls the operation machine access status query interface to query the VPN network status of the current operation machine and display it. If it is already connected, it will display the following Fig.13 , and there is an exit button. Clicking the exit button will call the operator to apply for the exit interface. If it is not connected, it will be displayed as follows Fig.14 , and there is an application button. Clicking the application button will call the operation machine to apply for access interface. If you have applied, it will show Fig.15 , and there is a cancel button. Clicking the cancel button will call the operator to apply for the cancellation interface.

Claims

1. A method for simulating VPN access in a network range, characterized in that: The following steps are involved: Build the service topology, place the VPN service as a topology element in the topology map, and set the network that the VPN needs to access by connecting lines; Start the simulation environment and create a simulation environment for business use including VPN services; The VPN service is implemented by combining the routing and network elements of the cloud platform; the VPN access process of the operator includes: querying the corresponding operator resource id, virtual routing resource id and simulation environment id according to the operator host name; creating a bridge network and obtaining the id of the network; connecting the virtual routing and the bridge network; connecting the operator and the bridge network; updating the relevant fields in the operator information table; the VPN exit process of the operator includes: querying the corresponding operator resource id, virtual routing resource id, bridge network id, operator bridge port id and router bridge port id according to the operator host name; deleting the port on the virtual routing; deleting the port on the operator; deleting the bridge network; updating the relevant fields in the operator information table; By calling the interface of the VPN management module, registering the information related to the VPN service in the simulation environment to the VPN management module; the VPN management module is used for the management of VPN related resources, the processing of VPN access and disconnection, and the processing of VPN client requests; A timing mechanism is used to control the VPN access time and exit time of each operating machine in the simulation environment; or, a VPN client module with a graphical interface is provided to allow the user to apply for VPN access or actively disconnect the VPN access.

2. The method for simulating VPN access in a network range according to claim 1, characterized in that: The VPN management module constructs a series of storage tables to store the simulation environment and VPN service related information, the storage tables including a simulation environment information table, an operation machine information table, and an operation machine application access management table and / or an operation machine scheduled access management table; The simulation environment information table stores the simulation environment id, name and virtual routing resource id; The operation machine information table stores the simulation environment id, the operation machine name, the operation machine host name, the operation machine resource id, whether it has been connected, the bridge network id, the bridge network cidr, the operation machine bridge port id and the routing bridge port id; The operation machine application access management table stores the operation machine host name, application time, application status and processing time; The operating machine scheduled access management table stores the operating machine host name, designated time, and processing action.

3. The method for simulating VPN access in a network range according to claim 1, characterized in that: The registering the information related to the VPN service in the simulation environment to the VPN management module includes: Receive parameters of the simulation environment, the parameters including a simulation environment ID, a simulation environment name, a network list, and a host list parameter; wherein each element in the host list includes a host name and an instance ID; Create a bridge route and obtain the resource id of the route; Connect the created bridge route to each network in the network list; Record the simulation environment id, simulation environment name and routing resource id into the simulation environment information table; Record each item in the host list into the operating machine information table, set the "Accessed" field in each record to "No" and the bridge network id to "None".

4. The method for simulating VPN access in a network range according to claim 1, characterized in that: The process of the VPN management module deregistering the simulation environment includes: Query the operating machine in the VPN according to the simulation environment ID, and execute the VPN exit process of the operating machine for each operating machine found; Query the virtual routing resource ID according to the simulation environment ID, and delete the route in the simulation environment; The operating machine access application management table and / or the operating machine scheduled access management table, as well as the relevant information in the operating machine information table and the simulation environment information table are deleted in sequence.

5. A system for simulating VPN access in a network range, characterized in that: Including simulation business module, VPN client module and VPN management module: The simulation service module is used to construct a service topology, place the VPN service as a topology element in the topology map, and set the network that the VPN needs to access by connecting lines; Start the simulation environment, create a simulation environment for business use including VPN service, wherein the VPN service is realized by combining the routing and network elements of the cloud platform, and the VPN access process of the operation machine includes: querying the corresponding operation machine resource id, virtual routing resource id and simulation environment id according to the host name of the operation machine; creating a bridge network and obtaining the id of the network; connecting the virtual routing and the bridge network; connecting the operation machine and the bridge network; updating the relevant fields in the operation machine information table; the VPN exit process of the operation machine includes: querying the corresponding operation machine resource id, virtual routing resource id, bridge network id, operation machine bridge port id and routing bridge port id according to the host name of the operation machine; deleting the port on the virtual routing; deleting the port on the operation machine; deleting the bridge network; updating the relevant fields in the operation machine information table; and registering the information related to the VPN service in the simulation environment to the VPN management module by calling the interface of the VPN management module; The VPN client module runs on the operating machine and is used by the user to access the simulation environment; and provides a graphical interface to allow the user to apply for VPN access or actively disconnect VPN access; The VPN management module is used for managing VPN related resources, processing VPN access and disconnection, and processing VPN client requests; and using a timing mechanism to control the VPN access time and exit time of each operating machine in the simulation environment.

6. The system for simulating VPN access in a network range according to claim 5, characterized in that: The VPN management module provides a management page for displaying the simulation environments registered in the system, viewing a list of all operating machines in a simulation environment, and managing scheduled tasks and / or reviewing access requests from operating machines.

7. The system for simulating VPN access in a network range according to claim 5, characterized in that: The process of registering the simulation environment with the VPN management module includes: Receive parameters of the simulation environment, the parameters including a simulation environment ID, a simulation environment name, a network list, and a host list parameter; wherein each element in the host list includes a host name and an instance ID; Create a bridge route and obtain the resource id of the route; Connect the created bridge route to each network in the network list; Record the simulation environment id, simulation environment name and routing resource id into the simulation environment information table; Record each item in the host list into the operating machine information table, set the "Accessed" field in each record to "No" and the bridge network id to "None".

8. The system for simulating VPN access in a network range according to claim 5, characterized in that: The process of the VPN management module deregistering the simulation environment includes: Query the operating machine in the VPN according to the simulation environment ID, and execute the VPN exit process of the operating machine for each operating machine found; Query the virtual routing resource ID according to the simulation environment ID, and delete the route in the simulation environment; The operating machine access application management table and / or the operating machine scheduled access management table, as well as the relevant information in the operating machine information table and the simulation environment information table are deleted in sequence.

Citation Information

Patent Citations

  • Multitask security isolation system and method under virtual-real interconnected environment of cloud platform

    CN107426152A

  • Network range user remote access system and method

    CN111711557A