Method and system for realizing IPv6 (Internet Protocol Version 6) communication based on VPN (Virtual Private Network) tunnel of IPv4
By building an IPv6 VPN tunnel in an IPv4-based VPN tunnel and configuring appropriate IPv6 addresses and routing policies for the local area network, the problem of not being able to directly support IPv6 communication in the IPv4 network is solved, and seamless integration and secure transmission of IPv6 communication is achieved.
Patent Information
- Application Number
- CN202510111212.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-30
AI Technical Summary
In the prior art, IPv4-based VPN tunnels cannot directly support IPv6 communication, especially in IPv4 network environments, and VPN tunnels need to be frequently rebuilt to adapt to changes in IPv6 address range.
Build an IPv6 VPN tunnel in an IPv4-based VPN tunnel. By configuring IPv4 and IPv6 addresses for VPN servers and switches of each LAN, planning the private network address range, and enabling routing and forwarding function. Use OpenVPN to build a VPN tunnel and configure a VPN environment for the local area network at both ends of the IPv6 tunnel, including the IPv6 address range and routing policy for internal and external communication.
It realizes seamless integration of IPv6 communication in the existing IPv4 network, reduces the cost of IPv6 communication, avoids large-scale network transformation and upgrading, ensures the correct and stable transmission of IPv6 data packets, and improves the security of communication.
Smart Images

Figure CN120074984A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network communication technologies, and particularly to a method and system for implementing IPv6 communication based on an IPv4-based VPN tunnel. Background Art
[0002] With the rapid development of the Internet, more and more intelligent devices such as computers, smart phones, smart wearable devices, and smart home appliances are connected to the Internet. The problem of IPv4 address exhaustion has become increasingly prominent, and IPv4 addresses can no longer meet daily use. As the next-generation IP protocol to replace IPv4, IPv6 can provide sufficient network addresses and broad innovation space, and IPv6 has become the mainstream of the new generation of Internet protocols.
[0003] Compared with IPv4, IPv6 has advantages such as a larger address space, more efficient route aggregation, better security, and built-in multicast support. However, although the promotion and deployment of IPv6 have made significant progress globally, there are still a large number of network devices and applications built based on IPv4.
[0004] In the actual network deployment and upgrade process, many enterprises and organizations still face the challenge of transitioning from IPv4 to IPv6. Especially in environments where complex IPv4 network architectures have been established, directly upgrading to IPv6 may bring high costs and huge technical challenges.
[0005] In the current Internet environment, VPN (Virtual Private Network) technology is an important means to ensure network security, achieve remote access, and data transmission. Especially in enterprise networks, VPN technology can not only provide cross-regional internal network connections but also ensure the security and privacy of data transmission.
[0006] The R & D and test environments of IT enterprises, etc., require IPv6 network support. However, the existing local area networks of enterprises are mainly IPv4 networks, and most of the VPN tunnels between local area networks are based on IPv4, which cannot directly support IPv6 communication. Moreover, when the IPv6 address ranges between two regions change, it is necessary to reconstruct the VPN tunnel. Summary of the Invention
[0007] Aiming at the deficiencies in the prior art, the present invention provides a method and system for implementing IPv6 communication based on an IPv4-based VPN tunnel, and constructs an IPv6 VPN tunnel in the IPv4-based VPN tunnel between local area networks to achieve IPv6 remote communication.
[0008] The first object of the present invention is to provide a method for implementing IPv6 communication based on an IPv4-based VPN tunnel, including:
[0009] Configure IPv4 addresses and IPv6 addresses for the VPN servers and switches of each local area network, plan the private network address range of the VPN, and enable the routing forwarding functions of the VPN servers and switches; wherein, each local area network is an IPv4 network, and each local area network supports the IPv6 protocol;
[0010] Build a VPN tunnel based on IPv4 between each local area network, build an IPv6 VPN tunnel in the IPv4-based VPN tunnel, and configure a VPN environment for each local area network at both ends of the IPv6 VPN tunnel;
[0011] IPv6 devices within each local area network send data packets to the switch of the local area network where they are located. The switch of the local area network consults the routing table based on the destination IP address in the data packet and determines whether the target IPv6 device is within the local area network;
[0012] If so, the switch of the local area network sends the data packet to the target IPv6 device in the local area network;
[0013] If not, the switch of the local area network sends the data packet to the VPN server of the local area network. The VPN server of the local area network consults the routing table based on the destination IP address in the data packet and forwards the data packet through the IPv6 VPN tunnel to the VPN server of the target local area network. The VPN server of the target local area network consults the routing table based on the destination IP address of the data packet and forwards the data packet to the target IPv6 device within the target local area network.
[0014] As a further improvement of the present invention, the IPv4-based VPN tunnel and the IPv6 VPN tunnel are built based on OpenVPN.
[0015] As a further improvement of the present invention, configuring a VPN environment for each local area network at both ends of the tunnel includes:
[0016] Install OpenVPN software on the VPN servers of each local area network and configure the corresponding service support files;
[0017] Configure the IPv6 address range for internal communication of each local area network, and configure the IPv6 address range for external communication of each local area network.
[0018] As a further improvement of the present invention, configuring a VPN environment for each local area network at both ends of the tunnel further includes: configuring the IPv6 routing policy for external communication of each local area network.
[0019] As a further improvement of the present invention, the IPv6 routing policy for external communication of each local area network includes: configuring IPv6 firewall rules and access control lists for the VPN servers of each local area network.
[0020] As a further improvement of the present invention, the service support files corresponding to the configuration include: a configuration file defining the basic parameters of the VPN connection, and the corresponding certificate file.
[0021] As a further improvement of the present invention, the switch has at least a three-layer forwarding function.
[0022] As a further improvement of the present invention, the data packet is encrypted during the forwarding process by an encryption algorithm to ensure communication security.
[0023] The second object of the present invention is to provide a system for implementing IPv6 communication based on an IPv4-based VPN tunnel for implementing the above method, including:
[0024] A local area network configuration module, configured to configure IPv4 addresses and IPv6 addresses for the VPN servers and switches of each local area network, plan the private network address range of the VPN, and enable the routing forwarding functions of the VPN servers and switches; the local area network is an IPv4 network, and the local area network supports the IPv6 protocol;
[0025] A VPN tunnel construction module, configured to construct an IPv6 VPN tunnel in the IPv4-based VPN tunnel between the local area networks, and configure a VPN environment for each local area network at both ends of the IPv6 VPN tunnel;
[0026] A communication module, configured to forward the data packets sent by the IPv6 devices in each local area network to the target IPv6 device.
[0027] As a further improvement of the present invention, the step in which the communication module forwards the data packets sent by the IPv6 devices in each local area network to the target IPv6 device includes:
[0028] The IPv6 devices in each local area network send the data packets to the switch in the local area network where they are located, and the switch in the local area network where they are located determines whether the target IPv6 device is in the local area network according to the destination IP address in the data packet and the routing table;
[0029] If so, the switch in the local area network where they are located sends the data packet to the target IPv6 device in the local area network where they are located;
[0030] If not, the switch in the local area network where they are located sends the data packet to the VPN server in the local area network where they are located, and the VPN server in the local area network where they are located forwards the data packet through the IPv6 VPN tunnel to the VPN server in the target local area network according to the destination IP address in the data packet and the routing table, and the VPN server in the target local area network forwards the data packet to the target IPv6 device in the target local area network according to the destination IP address and routing table of the data packet.
[0031] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0032] Build an IPv6 VPN tunnel in the IPv4-based VPN tunnel between each IPv4 local area network to realize the remote communication of IPv6 devices within each local area network, making full use of the existing infrastructure of the IPv4 network, without large-scale network transformation and upgrade, and effectively reducing the communication cost of IPv6.
[0033] Use the IPv6 VPN tunnel built in the IPv4 VPN tunnel to carry IPv6 data packets, realizing the seamless integration of IPv6 communication on the IPv4 network, and ensuring that IPv6 data packets can be correctly and stably transmitted in the existing IPv4 network.
[0034] By configuring IPv6 firewall rules and access control lists, and encrypting data packets using encryption algorithms, the risk of data packets being stolen or tampered with during transmission can be effectively prevented, ensuring the security and privacy of communication. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 It is a flowchart of the method disclosed by the present invention;
[0036] Figure 2 It is a communication flowchart of applying the method disclosed by the present invention;
[0037] Figure 3 It is a schematic structural diagram of the system disclosed by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0038] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0039] The present invention will be further described in detail below with reference to the accompanying drawings:
[0040] Please refer to Figure 1 , this embodiment provides a method for realizing IPv6 communication based on an IPv4 VPN tunnel, including:
[0041] Configure IPv4 addresses and IPv6 addresses for the VPN servers and switches of each local area network, plan the private network address range of the VPN, and enable the routing forwarding function of the VPN servers and switches; wherein, each local area network is an IPv4 network, and each local area network supports the IPv6 protocol;
[0042] Build a VPN tunnel based on IPv4 between the local area networks, build a VPN tunnel of IPv6 in the VPN tunnel based on IPv4, and configure a VPN environment for each local area network at both ends of the VPN tunnel of IPv6; both the VPN tunnel based on IPv4 and the VPN tunnel of IPv6 are built based on OpenVPN;
[0043] The IPv6 devices within each local area network send data packets to the switch of the local area network where they are located. The switch of the local area network looks up the routing table according to the destination IP address in the data packet and determines whether the target IPv6 device is within the local area network;
[0044] If so, the switch of the local area network sends the data packet to the target IPv6 device in the local area network; if not, the switch of the local area network sends the data packet to the VPN server of the local area network. The VPN server of the local area network looks up the routing table according to the destination IP address in the data packet and forwards the data packet through the VPN tunnel of IPv6 to the VPN server of the target local area network. The VPN server of the target local area network looks up the routing table according to the destination IP address of the data packet and forwards the data packet to the target IPv6 device within the target local area network.
[0045] The R & D and test environments of IT enterprises, etc. require IPv6 network support. However, the existing local area networks of enterprises are mainly IPv4 networks, and most of the VPN tunnels between local area networks are based on IPv4 and cannot directly support IPv6 communication. The method provided in this embodiment builds a VPN tunnel of IPv6 in the VPN tunnel based on IPv4 between each IPv4 local area network to realize the remote communication of IPv6 devices within each local area network, makes full use of the existing infrastructure of the IPv4 network, and does not require large-scale network transformation and upgrade, effectively reducing the communication cost of IPv6.
[0046] Furthermore, the switch has at least three-layer forwarding function.
[0047] A switch is a network device mainly used to realize the forwarding and exchange of data packets within a local area network. It forwards the data packet from the source port to the target port by identifying the target address of the data packet, thereby realizing the communication between different devices.
[0048] The forwarding function of the switch is usually divided into different levels, mainly including two-layer forwarding and three-layer forwarding.
[0049] Two-layer forwarding is mainly applicable to the communication between devices within the same local area network. In this case, the data packet does not need to go through three-layer processing and can be directly forwarded by the switch.
[0050] Three-layer forwarding is mainly applicable to device communication between different local area networks (LANs). It mainly forwards data packets based on the IP addresses of the data packets. This requires the switch to have the three-layer forwarding function to identify and process IP data packets. At this time, the switch needs to look up the routing table to determine the forwarding path of the data packet, and then forward the data packet to the corresponding port or the next-hop device.
[0051] In this embodiment, the switch is a device with both two-layer forwarding and three-layer forwarding functions, and has a built-in routing protocol and routing table. It can not only achieve fast forwarding of data packets within the same LAN, but also handle the forwarding of data packets between different LANs. When the data packet needs to be transmitted between different network segments of different LANs, the three-layer switch can forward it according to the routing table.
[0052] Furthermore, configuring the VPN environment for each LAN at both ends of the tunnel includes:
[0053] Installing OpenVPN software on the VPN server of each LAN and configuring the corresponding service support files;
[0054] Configuring the IPv6 address range for internal communication of each LAN, and configuring the IPv6 address range for external communication of each LAN;
[0055] Configuring the IPv6 routing policy for external communication of each LAN.
[0056] Specifically:
[0057] The configuration of the corresponding service support files includes: a configuration file defining the basic parameters of the VPN connection, and the corresponding certificate file.
[0058] The IPv6 routing policy for external communication of each LAN includes: configuring IPv6 firewall rules and access control lists for the VPN server of each LAN. By configuring the firewall rules and access control lists, data packets can be filtered and restricted, improving network security and effectively preventing the risk of data packets being stolen or tampered with during transmission.
[0059] The data packet is encrypted by an encryption algorithm during the forwarding process to ensure communication security.
[0060] Next, in combination with Figure 2 , the specific implementation process of the above method will be elaborated with specific examples.
[0061] An IT enterprise has offices in two cities in different provinces. The networks of Office A and Office B are both IPv4 networks (hereinafter referred to as LAN A and LAN B).
[0062] In order to enable the IPv6 network for applications such as R & D and production to communicate between the two offices, first, the following configurations are made for the two LANs:
[0063] Configure IPv4 addresses, IPv6 addresses, and routing tables for the VPN servers and switches of two local area networks respectively, configure the IPv6 address ranges for internal communication, the IPv6 address ranges for external communication, and the IPv6 routing policies for external communication for the two local area networks respectively, and enable the routing forwarding functions of the VPN servers and switches;
[0064] Install OpenVPN software on the VPN servers of the two local area networks, and configure configuration files and corresponding certificate files that define the basic parameters of the VPN connection.
[0065] When an IPv6 device in Local Area Network A initiates a communication request to an IPv6 device in Local Area Network B, it first sends the data packet to the switch of Local Area Network A. The switch queries the routing table according to the destination IP address in the data packet and sends the data packet to the VPN server of Local Area Network A;
[0066] The VPN server of Local Area Network A queries the routing table according to the destination IP address in the data packet and sends the data packet to the VPN server of Local Area Network B;
[0067] The VPN server of Local Area Network B queries the routing table according to the destination IP address in the data packet and sends the data packet to the target VPN device in Local Area Network B, thereby realizing IPv6 communication between Local Area Network A and Local Area Network B.
[0068] Among them, each VPN device in Local Area Network A / B can communicate through the switch of the local area network where it is located, and Local Area Network A / B can perform IPv4 communication through the IPv4 VPN tunnel between the two local area networks.
[0069] Please refer to Figure 3 , this embodiment provides a system for realizing IPv6 communication based on an IPv4 VPN tunnel for realizing the above method, including:
[0070] A local area network configuration module for configuring IPv4 addresses and IPv6 addresses for the VPN servers and switches of each local area network, planning the private network address range of the VPN, and enabling the routing forwarding functions of the VPN servers and switches; the local area network is an IPv4 network, and the local area network supports the IPv6 protocol;
[0071] A VPN tunnel construction module for constructing an IPv6 VPN tunnel in the IPv4 VPN tunnel between the local area networks and configuring a VPN environment for each local area network at both ends of the IPv6 VPN tunnel;
[0072] A communication module, configured to forward data packets sent by IPv6 devices within each local area network to the target IPv6 device; the IPv6 devices within each local area network send the data packets to the switch of the local area network where they are located, and the switch of the local area network looks up the routing table according to the destination IP address in the data packet and determines whether the target IPv6 device is within the local area network where it is located;
[0073] If so, the switch of the local area network sends the data packet to the target IPv6 device within the local area network;
[0074] If not, the switch of the local area network sends the data packet to the VPN server of the local area network. The VPN server of the local area network looks up the routing table according to the destination IP address in the data packet and forwards the data packet to the VPN server of the target local area network through the IPv6 VPN tunnel. The VPN server of the target local area network looks up the routing table according to the destination IP address of the data packet and forwards the data packet to the target IPv6 device within the target local area network.
[0075] Building an IPv6 VPN tunnel in the IPv4-based VPN tunnels between IPv4 local area networks to achieve remote communication of IPv6 devices within each local area network makes full use of the existing infrastructure of the IPv4 network, and can ensure the correct and stable transmission of IPv6 data packets in the existing IPv4 network without large-scale network transformation and upgrade.
[0076] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for implementing IPv6 communication based on an IPv4 VPN tunnel, characterized in that: include: Configure IPv4 addresses and IPv6 addresses for VPN servers and switches of each LAN, plan the private network address range of VPN, and enable the routing and forwarding functions of the VPN servers and switches; wherein each LAN is an IPv4 network and supports the IPv6 protocol; Constructing an IPv4-based VPN tunnel between the local area networks, constructing an IPv6 VPN tunnel in the IPv4-based VPN tunnel, and configuring a VPN environment for each local area network at both ends of the IPv6 VPN tunnel; The IPv6 device in each LAN sends the data packet to the switch of the LAN. The switch of the LAN consults the routing table according to the destination IP address in the data packet and determines whether the target IPv6 device is in the LAN. If so, the switch in the local area network sends the data packet to the target IPv6 device in the local area network; If not, the switch in the local area network sends the data packet to the VPN server in the local area network. The VPN server in the local area network consults the routing table according to the destination IP address in the data packet, and forwards the data packet to the VPN server in the target LAN through the IPv6 VPN tunnel. The VPN server in the target LAN consults the routing table according to the destination IP address of the data packet, and forwards the data packet to the target IPv6 device in the target LAN.
2. The method for implementing IPv6 communication based on an IPv4 VPN tunnel according to claim 1, characterized in that: The IPv4-based VPN tunnel and the IPv6-based VPN tunnel are constructed based on OpenVPN.
3. The method for implementing IPv6 communication based on an IPv4 VPN tunnel according to claim 2, characterized in that: Configuring the VPN environment for each LAN at both ends of the tunnel includes: Install OpenVPN software for each LAN VPN server and configure the corresponding service support files; Configure an IPv6 address range for internal communication for each LAN, and configure an IPv6 address range for external communication for each LAN.
4. The method for implementing IPv6 communication based on an IPv4 VPN tunnel according to claim 3, characterized in that: Configuring the VPN environment for each LAN at both ends of the tunnel also includes: configuring an IPv6 routing strategy for each LAN to communicate with the outside.
5. The method for implementing IPv6 communication based on an IPv4 VPN tunnel according to claim 4, characterized in that: The IPv6 routing strategy for each LAN to communicate with the outside world includes: configuring IPv6 firewall rules and access control lists for the VPN servers in each LAN.
6. The method for implementing IPv6 communication based on an IPv4 VPN tunnel according to claim 3, characterized in that: The service support files corresponding to the configuration include: a configuration file defining basic parameters of VPN connection, and a corresponding certificate file.
7. The method for implementing IPv6 communication based on an IPv4 VPN tunnel according to claim 1, characterized in that: The switch has at least a three-layer forwarding function.
8. The method for implementing IPv6 communication based on an IPv4 VPN tunnel according to claim 1, characterized in that: The data packet is encrypted by an encryption algorithm during forwarding to ensure communication security.
9. A system for implementing IPv6 communication based on an IPv4 VPN tunnel, used to implement a method for implementing IPv6 communication based on an IPv4 VPN tunnel as claimed in any one of claims 1 to 8, characterized in that: include: A LAN configuration module is used to configure IPv4 addresses and IPv6 addresses for VPN servers and switches in each LAN, plan the private network address range of VPN, and enable the routing and forwarding functions of the VPN servers and switches; The local area network is an IPv4 network, and the local area network supports the IPv6 protocol; A VPN tunnel construction module, used to construct an IPv6 VPN tunnel in the IPv4-based VPN tunnel between the local area networks, and configure a VPN environment for each local area network at both ends of the IPv6 VPN tunnel; The communication module is used to forward the data packets sent by the IPv6 devices in each local area network to the target IPv6 device.
10. A system for implementing IPv6 communication based on an IPv4 VPN tunnel according to claim 9, characterized in that: The step of the communication module forwarding the data packets sent by the IPv6 devices in each local area network to the target IPv6 device includes: The IPv6 device in each LAN sends the data packet to the switch of the LAN. The switch of the LAN consults the routing table according to the destination IP address in the data packet and determines whether the target IPv6 device is in the LAN. If so, the switch in the local area network sends the data packet to the target IPv6 device in the local area network; If not, the switch in the local area network sends the data packet to the VPN server in the local area network. The VPN server in the local area network consults the routing table according to the destination IP address in the data packet, and forwards the data packet to the VPN server in the target LAN through the IPv6 VPN tunnel. The VPN server in the target LAN consults the routing table according to the destination IP address of the data packet, and forwards the data packet to the target IPv6 device in the target LAN.