Distributed network target range interconnection method based on VCPE

By adopting a distributed network shooting range based on VCPE in distributed network shooting ranges, using virtual client devices to connect to multi-level shooting ranges, drawing on the centralized control strategy of SD-WAN, the problem of network interconnection between multi-level shooting ranges is solved, and efficient data packet forwarding and network optimization are achieved.

CN120223608APending Publication Date: 2025-06-27BEIJING INST OF COMP TECH & APPL
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510330417.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

In distributed network shooting ranges, it is difficult for the prior art to achieve network interconnection between multi-level shooting ranges, especially when the intranet IP addresses are converted by NAT or there is multi-level interconnection isolation.

Method used

The distributed network shooting range interconnection method based on VCPE is adopted to connect the networks between different distributed network shooting ranges through virtual client devices (VCPE) to realize the forwarding and control of routing data. This method draws on the centralized control and orchestration of the entire network strategy in SD-WAN to realize intelligent management of WAN traffic.

Benefits of technology

It significantly improves the efficiency of data packet forwarding, optimizes the network forwarding strategy, realizes the construction and design of distributed shooting range networks, and solves the problem of network interconnection between multi-level shooting ranges.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223608A_ABST
    Figure CN120223608A_ABST
Patent Text Reader

Abstract

The invention relates to a distributed network target range interconnection method based on VCPE, and belongs to the technical field of network target ranges. According to the method, the advantage of intelligent management of wide area network traffic is realized by referring to a strategy of centralized control and arrangement of the whole network in an SD-WAN, a routing and forwarding strategy is issued to the VCPE equipment through the centralized controller, and after a message enters the VCPE equipment, the VCPE equipment forwards the data packet to the next hop of VCPE equipment by packaging a source VCPEID, a target VCPEID, a source Cyber Range ID, a target Cyber Range ID and other data packet headers, so that the flow of the VCPE equipment is forwarded to the next hop of VCPE equipment. The intermediate VPCE device only needs to parse and identify the data packet header and forward the data packet without parsing the IP message header, and the last hop VCPE device parses the IP message header, so that the data packet forwarding efficiency is significantly improved, the network forwarding strategy is optimized, and the construction and design of the distributed target range network are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network ranges, and particularly relates to a method for interconnecting distributed network ranges based on VCPE. Background Art

[0002] Distributed network ranges need to achieve network interconnection between multiple remote / trans-regional ranges. For example, the internal local area network A1 in a sub-range network A is connected to an external private network through the DMZ (Demilitarized Zone) area, and the opposite end of the private network is connected to another network B, which includes a DMZ area and an internal local area network B1. At this time, if A1 and B1 are to be connected in network planning and deployment, currently, the VXLAN (Virtual eXtensible Local Area Network) technology and the SD-WAN (Software-Defined Wide Area Network) technology are mostly used.

[0003] The VXLAN technology uses the MAC in UDP (where MAC is the abbreviation of Media Access Control Address and UDP is the abbreviation of User Datagram Protocol) encapsulation method to achieve large-scale layer 2 network connectivity, which can ensure layer 2 network intercommunication between different regions in the same large network. If there are routable IPs between two ranges, a layer 2 virtualized network is established based on the layer 3 network through NVE (Network Virtualization Edge) and network intercommunication is achieved in combination with the VXLAN tunnel. However, in a distributed network range, there are cases where the internal network IP addresses are subject to NAT (Network Address Translation) conversion or there are multiple levels of interconnection isolation, and the VXLAN technology cannot solve such cases temporarily.

[0004] SD-WAN technology mainly combines SDN (Software Defined Network) technology to reshape the complex routing protocols and transmission control technologies during WAN network interconnection by decoupling control and forwarding, enhancing security, and making intelligent adjustments. However, in a distributed network range, the goal of network construction is to achieve connectivity of virtualized layer-2 networks, rather than physical layer network intercommunication, which has a hierarchical difference from the design of SD-WAN. At the same time, SD-WAN technology solves the problem of decoupling data and control planes in layer-1 networks, while in a distributed network range, the problem of separating data planes and control planes between multiple ranges needs to be solved. This results in the necessity to deploy multi-layer SD-WAN technology to meet the interconnection capabilities of a multi-polar distributed network range, which will greatly increase the complexity of configuration and implementation. Summary of the Invention

[0005] (1) Technical problems to be solved

[0006] The technical problem to be solved by the present invention is to provide a method for interconnecting distributed network ranges based on VCPE to achieve network interconnection and intercommunication in a multi-level distributed network range.

[0007] (2) Technical solutions

[0008] To solve the above technical problems, the present invention provides a method for interconnecting distributed network ranges based on VCPE. In this method, a virtual client device, namely a VCPE device, is used to connect the networks between different distributed network ranges. The internal network is divided into a local area network region and an isolation zone DMZ region. The VCPE device is a distributed logical device that realizes the interconnection of different distributed network ranges. It connects to the upper-level range network upward and the lower-level range network downward. Each distributed network range accessing the VCPE device realizes the forwarding and control of routing data through this VCPE device.

[0009] The internal network of the first-level range network includes a local area network (LAN) area and a DMZ area. The LAN area is connected to n computing servers through a core switch. Each computing server respectively virtualizes one or more virtual switches and m virtual machines through virtualization technology. Each virtual switch is connected to m virtual machines. Among them, virtual switch 1 is connected to virtual machines 1, 2, ..., m, enabling data communication between the m virtual machines; the DMZ area includes relay server 1 and border firewall 1. The devices in the internal LAN area communicate with other range networks through relay server 1 and border firewall 1. Relay server 1 has two network cards. One network card is configured with an internal network address for communicating with the LAN area, and the other network card is configured with an external network address for connecting to other range networks. The VCPE device VCPE_01 accessed by the first-level range network is connected to border firewall 1 to achieve three-layer routing forwarding and communication; the internal structures of other levels of range networks are the same as that of the first-level range network.

[0010] The present invention also provides a cross-range remote network composed of multiple levels of range networks connected to each other based on the above method.

[0011] The present invention also provides a system for implementing the above method.

[0012] The present invention also provides an application of the above method in network communication.

[0013] The present invention also provides an application of the above remote network in network communication.

[0014] (III) Beneficial Effects

[0015] In order to better meet the requirements of distributed range network construction and fast forwarding of network traffic packets, the present invention provides a method for interconnecting distributed network ranges based on VCPE. By drawing on the advantages of centralized control and orchestration of the whole network strategy in SD-WAN to achieve intelligent management of wide area network traffic, through a centralized controller, routing and forwarding policies are issued to VCPE devices. When a packet enters a VCPE device, the VCPE device encapsulates data packet headers such as source VCPE_ID, destination VCPE_ID, source Cyber RangeID, and destination Cyber Range ID and forwards the data packet to the next-hop VCPE device. Intermediate VPCE devices only need to parse and identify the data packet headers and forward the data packets without parsing the IP packet headers. The last-hop VCPE device parses the IP packet headers, significantly improving the data packet forwarding efficiency, optimizing the network forwarding strategy, and realizing the construction and design of a distributed range network. Description of the Drawings

[0016] Figure 1It is a diagram of a distributed range network interconnection architecture based on VCPE provided in an embodiment of the present invention;

[0017] Figure 2 It is a schematic diagram of a multi-level range network interconnection based on VCPE provided in an embodiment of the present invention. In the figure, the SDN controller ensures reachability with other network links, and this device needs to send routing and forwarding policy configurations to all VCPE devices in the network. Detailed implementation manners

[0018] To make the objectives, content, and advantages of the present invention clearer, the following further describes the detailed implementation manners of the present invention in conjunction with the accompanying drawings and embodiments.

[0019] To better meet the requirements of distributed range network construction and fast forwarding of network traffic packets, the present invention provides a distributed network range interconnection method based on VCPE. By drawing on the advantages of centralized control and orchestration of network-wide policies in SD-WAN to achieve intelligent management of wide-area network traffic, through a centralized controller such as an SDN controller, routing and forwarding policies are sent to VCPE devices. When a packet enters a VCPE device, the CVPE device encapsulates data packet headers such as source VCPE_ID, destination VCPE_ID, source Cyber Range ID, and destination Cyber Range ID and forwards the data packet to the next-hop VCPE device. Intermediate VPCE devices only need to parse and identify the data packet headers and forward the data packets without parsing the IP packet headers. The last-hop VCPE device parses the IP packet headers, significantly improving the data packet forwarding efficiency, optimizing the network forwarding policy, and realizing the construction and design of a distributed range network.

[0020] This architecture design is as Figure 1 shown. Networks between different distributed range networks are connected by VCPE devices. The network is divided into a local area network region and a DMZ region. The VCPE device is the core of this architecture design and is a distributed logical device that realizes the interconnection of different distributed range networks. It connects to the upper-level range network upward and the lower-level range network downward. Each distributed range network accessing the VCPE device realizes the forwarding and control of routing data through this VCPE device. In the figure, the SDN controller ensures reachability with other network links, and this device needs to send routing and forwarding policy configurations to all VCPE devices in the network.

[0021] As Figure 1As shown, the first-level range network includes an internal LAN area and a DMZ area. The internal LAN area is connected to n computing servers through one or more core switches. Each computing server virtualizes one or more virtual switches and m virtual machines through virtualization technology. Each virtual switch connects m virtual machines. For example, virtual switch 1 connects virtual machine 1, virtual machine 2, ..., virtual machine m, and data communication between m virtual machines can be realized; the DMZ area includes relay server 1 and border firewall 1. The devices in the internal LAN area communicate with other range networks through relay server 1 and border firewall 1. Relay server 1 has two network cards, one of which is configured with an intranet address, which is used to communicate with the internal LAN area, and the other is configured with an external network address, which is used to connect with other external range networks. VCPE_01 is connected to border firewall 1 to realize three-layer routing forwarding and communication.

[0022] When communicating with the external network, such as when relay server 1 (an external network card and an internal network card) communicates with relay server 2 (an external network card and an internal network card), each of them registers its own external network address to the other party, that is, the external network address of relay server 1 is written into the communication address of relay server 2, and vice versa. Then relay server 1 sends a UDP or TCP data packet to relay server 2. This data packet is called a hole punching packet. After sending the data packet, a routing record can be generated on the VCPE. Then, subsequent data packets sent between relay server 1 and relay server 2 will not be discarded. The communication methods between other relay servers are similar and will not be repeated here.

[0023] Note: Each level of range network, such as CR001, includes an internal LAN area and a DMZ area. The internal device connections and deployments of the areas can be changed, but the implementation methods are similar.

[0024] The network structures of the secondary range network, the tertiary range network, the m-level range network and the n-level range network are similar to those of the primary range network, and no further explanation is given here. The VCPE_01, VCPE_02, VCPE_03, VCPE_m, VCPE_n and other devices connect the primary range network, the secondary range network, the tertiary range network, the m-level range network and the n-level range network to form a cross-range remote network.

[0025] When virtual machine 1 in the primary range network (marked in purple in the figure) communicates data with virtual machine 1 in the secondary range network (marked in purple in the figure), the communication link is the purple-marked route in the figure, and the complete communication link is:

[0026] Virtual Machine 1 -> Virtual Switch 1 -> Core Switch 1 -> Relay Server 1 -> Border Firewall 1 -> VCPE_01 -> VCPE_02 -> Border Firewall 2 -> Relay Server 2 -> Core Switch 2 -> Virtual Switch 1 -> Virtual Machine 1.

[0027] Among them, passing through two VCPE devices, the data format sent by Virtual Machine 1 is [ETH / VLAN / Destination IP / Source IP / Payload]. When the data packet is sent from the first-level range network to the second-level range network, first, Relay Server 1 in the DMZ area of the first-level range network encapsulates the external UDP or TCP header and modifies the source IP to the external network IP of Relay Server 1, and modifies the port to the port of Relay Server 1. The output data format is [Protocol / ETH / VLAN / Destination IP / Source IP / Payload]. The VCPE_01 device encapsulates the external VCPE ID header and Cyber Range ID header for the data packet, and the output data format is [Destination VCPE ID / Source VCPE ID / Destination Cyber Range ID / Source Cyber Range ID / Protocol / ETH / VLAN / Destination IP / Source IP / Payload]. When passing through the next-hop VCPE_02 device, the external VCPE ID header and CyberRange ID header will be removed, and the destination IP will be modified to the external network IP address of Relay Server 1. The output data format is [Protocol / ETH / VLAN / Destination IP / Source IP / Payload]. Relay Server 2 in the DMZ area of the second-level range network will replace the source IP, destination IP, port, and VLAN, and the output data format is [Protocol / ETH / VLAN / Destination IP / Source IP / Payload]. Finally, the data packet is sent to Virtual Machine 21 through Core Switch 2 and Virtual Switch 1. The finally received data packet is [ETH / VLAN / Destination IP / Source IP / Payload]. The routing calculations of the VCPE_01 device and the VCPE_02 device are shown in Table 1 and Table 2. The VCPE_01 device is responsible for routing forwarding and communication with VCPE_02 and VCPE_03, and will send the data in the first-level range network connected to the VCPE_01 device to the second-level range network and the third-level range network, and exchange data with the networks in the corresponding range networks. The VCPE_02 device is responsible for routing forwarding and communication with the VCPE_01 device and the VCPE_04 device, and will send the data in the second-level range network connected to the VCPE_02 device to the first-level range network and the fourth-level range network, and exchange data with the networks in the corresponding range networks.

[0028] When the virtual machine m (orange marked in the figure) in the first-level range network communicates with the virtual machine m (orange marked in the figure, m≥1) in the n-level (n≥2 generally) range network, the communication link is the orange marked route in the figure, and the complete communication link is as follows:

[0029] Virtual machine m -> Virtual switch n -> Core switch 1 -> Relay server 1 -> Border firewall 1 -> VCPE_01 -> VCPE_03 -> VCPE_n -> Border firewall n -> Relay server n -> Core switch 5 -> Virtual switch 2 -> Virtual machine m.

[0030] Among them, after passing through multiple VCPE devices, the data format sent by virtual machine m is in the form of [ETH / VLAN / destination IP / source IP / Payload]. When the data packet is sent from the first-level range network to the third-level range network, first, the DMZ relay server 1 in the first-level range network encapsulates the external UDP or TCP header and modifies the source IP to the external network IP of relay server 1, and modifies the port to the port of relay server 1. The output data format is [Protocol / ETH / VLAN / destination IP / source IP / Payload]. The VCPE_01 device encapsulates the external VCPE ID header and Cyber Range ID header, and the output data format is [destination VCPE ID / source VCPE ID / destination Cyber Range ID / source Cyber Range ID / Protocol / ETH / VLAN / destination IP / source IP / Payload]. When passing through the next-hop VCPE_03 device, the external VCPE ID header will be replaced, and the output data format is [destination VCPE ID / source VCPE ID / destination Cyber Range ID / source Cyber Range ID / Protocol / ETH / VLAN / destination IP / source IP / Payload]. When passing through the next-hop VCPE_n device, the external VCPE ID header and Cyber Range ID header will be removed, and the destination IP address will be modified to the external network IP address of relay server n. The output data format is [Protocol / ETH / VLAN / destination IP / source IP / Payload]. The DMZ area relay server n in the n-level range network will replace the source IP, destination IP, port, and VLAN, and the output data format is [Protocol / ETH / VLAN / destination IP / source IP / Payload]. Finally, the data packet is sent to virtual machine m through the core switch 5 and virtual switch 2, and the finally received data packet is [ETH / VLAN / destination IP / source IP / Payload]. The routing calculations of VCPE_01, VCPE_02, and VCPE_05 are shown in Table 2, Table 3, and Table 4. The VCPE_01 device is responsible for routing forwarding and communication with VCPE_02 and VCPE_03, and will send the data in the first-level range network connected to the VCPE_01 device to the second-level range network and the third-level range network, and perform data exchange with the networks in the corresponding range networks. The VCPE_03 device is responsible for routing forwarding and communication with VCPE_01 and VCPE_n, and will send the data in the third-level range network connected to the VCPE_03 device to the first-level range network and the n-level range network, and perform data exchange with the networks in the corresponding range networks.The VCPE_n device is responsible for routing and communication with VCPE_03. It will send the data in the n-level range network connected by the VCPE_n device to the third-level range network and exchange data with the networks in the corresponding range network.

[0031] Table 1 VCPE_01 Routing Table

[0032]

[0033] Table 2 VCPE_02 Routing Table

[0034]

[0035] Table 3 VCPE_03 Routing Table

[0036]

[0037] Table 4 VCPE_05 Routing Table

[0038]

[0039] As Figure 2 shown, the first-level range network (Cyber Range ID: CR001) includes an internal local area network zone and a DMZ zone. Its network ID is 0x0011. The internal local area network zone is connected to computing servers 1, 2, and 3 through core switch 1. Computing servers 1, 2, and 3 respectively virtualize virtual switches 1, virtual machines 11, 12, 13, virtual switch 2, virtual machines 14, 15, 16, virtual switch 3, virtual machines 17, 18, and 19 through virtualization technology. Each virtual switch is connected to 3 virtual machines. Virtual switch 1 connects virtual machines 11, 12, and 13, enabling data communication between the 3 virtual machines; virtual switch 2 connects virtual machines 14, 15, and 16, enabling data communication between the 3 virtual machines; virtual switch 3 connects virtual machines 17, 18, and 19, enabling data communication between the 3 virtual machines. The DMZ zone includes relay server 1 and border firewall 1. The firewall configuration policy prevents abnormal access. The devices in the internal local area network zone communicate with other range networks through relay server 1 and border firewall 1. Relay server 1 has two network cards. One network card is configured with an internal network address 192.168.1.100 for communication with the internal local area network zone, and one network card is configured with an external network address 33.10.10.100 for connection to other external networks. VCPE_01 is connected to border firewall 1 to achieve three-layer routing and communication.

[0040] When communicating with the external network, for example, when Relay Server 1 (one external network network card and one internal network network card) communicates with Relay Server 2 (one external network network card and one internal network network card), they respectively register their external network addresses with each other, that is, the external network address of Relay Server 1 is written into the communication address of Relay Server 2, and vice versa. Then Relay Server 1 sends a UDP or TCP data packet to Relay Server 2, and this data packet is called a hole punching packet. After sending the data packet, a routing record can be generated on the VCPE. Then, data packets sent between Relay Server 1 and Relay Server 2 subsequently are not discarded. The communication method between other relay servers is similar and will not be elaborated here.

[0041] The secondary cyber range network (Cyber Range ID: CR002) includes an internal local area network zone and a DMZ zone. Its network ID is 0x0022. The internal local area network zone is connected to Computing Server 4, Computing Server 5, and Computing Server 6 through Core Switch 2. Computing Server 4, 5, and 6 respectively virtualize Virtual Switch 4, Virtual Machine 21, Virtual Machine 22, Virtual Machine 23, Virtual Switch 5, Virtual Machine 24, Virtual Machine 25, Virtual Machine 26, Virtual Switch 6, Virtual Machine 27, Virtual Machine 28, and Virtual Machine 29 through virtualization technology. Each virtual switch connects 3 virtual machines. Virtual Switch 4 connects Virtual Machine 21, Virtual Machine 22, and Virtual Machine 23, enabling data communication between the 3 virtual machines; Virtual Switch 5 connects Virtual Machine 24, Virtual Machine 25, and Virtual Machine 26, enabling data communication between the 3 virtual machines; Virtual Switch 6 connects Virtual Machine 27, Virtual Machine 28, and Virtual Machine 29, enabling data communication between the 3 virtual machines. The DMZ zone includes Relay Server 2 and Border Firewall 2. The firewall configuration policy prevents abnormal access. Devices in the internal local area network zone communicate with other cyber range networks through Relay Server 2 and Border Firewall 2. Relay Server 2 has two network cards. One network card is configured with the built-in internal network address 192.168.2.100, and the internal network address is used to communicate with the internal local area network zone. One network card is configured with the external network address 33.10.20.100, and the external network address is used to connect to other external networks. VCPE_02 is connected to Border Firewall 2 to achieve three-layer routing forwarding and communication.

[0042] The Cyber Range ID: CR003 (Three-level Cyber Range) includes an internal local area network zone and a DMZ zone. Its network ID is 0x0033. The internal local area network zone is connected to computing servers 7, 8, and 9 through core switch 3. Computing servers 7, 8, and 9 respectively virtualize virtual switches 7, virtual machines 31, 32, 33, virtual switch 8, virtual machines 34, 35, 36, virtual switch 9, virtual machines 37, 38, 39 through virtualization technology. Each virtual switch is connected to 3 virtual machines. Virtual switch 7 is connected to virtual machines 31, 32, and 33, enabling data communication between the 3 virtual machines; virtual switch 8 is connected to virtual machines 34, 35, and 36, enabling data communication between the 3 virtual machines; virtual switch 9 is connected to virtual machines 37, 38, and 39, enabling data communication between the 3 virtual machines. The DMZ zone includes relay server 3 and border firewall 3. The firewall configuration policy prevents abnormal access. Devices in the internal local area network zone communicate with other cyber ranges through relay server 3 and border firewall 3. Relay server 3 has two network cards. One network card is configured with an internal network address for communication with the internal local area network zone, and the other network card is configured with an external network address for connection to other external networks. Since data forwarding by relay server 3 is not involved in this instance, the internal and external network IP addresses do not need to be configured. VCPE_03 is connected to border firewall 3 to achieve three-layer routing forwarding and communication.

[0043] The Cyber Range ID: CR004 at the fourth level includes an internal local area network zone and a DMZ zone, with a network ID of 0x0044. The internal local area network zone is connected to computing servers 10, 11, and 12 through the core switch 4. Computing servers 10, 11, and 12 respectively virtualize virtual switches 10, virtual machines 41, 42, 43, virtual switch 11, virtual machines 44, 45, 46, virtual switch 12, virtual machines 47, 48, and 49 through virtualization technology. Each virtual switch is connected to 3 virtual machines. Virtual switch 10 connects virtual machines 41, 42, and 43, enabling data communication between the 3 virtual machines; virtual switch 11 connects virtual machines 44, 45, and 46, enabling data communication between the 3 virtual machines; virtual switch 12 connects virtual machines 47, 48, and 49, enabling data communication between the 3 virtual machines. The DMZ zone includes a relay server 4 and a border firewall 4. The firewall configuration policy prevents abnormal access. The devices in the internal local area network zone communicate with other cyber range networks through the relay server 4 and the border firewall 4. The relay server 4 has two network cards. One network card is configured with an internal network address for communication with the internal local area network zone, and the other network card is configured with an external network address for connection to other external networks. Since data forwarding by the relay server 4 is not involved in this instance, the internal and external network IP addresses do not need to be configured. VCPE_04 is connected to the border firewall 4 to achieve three-layer routing forwarding and communication.

[0044] The Cyber Range ID: CR005 at the fifth level contains an internal local area network zone and a DMZ zone. Its network ID is 0x0055. The internal local area network zone is connected to computing servers 13, 14, and 15 through the core switch 5. Computing servers 13, 14, and 15 respectively virtualize virtual switches 13, virtual machines 51, 52, 53, virtual switch 14, virtual machines 54, 55, 56, virtual switch 15, virtual machines 57, 58, and 59 through virtualization technology. Each virtual switch is connected to 3 virtual machines. Virtual switch 13 connects virtual machines 51, 52, and 53, enabling data communication between the 3 virtual machines; virtual switch 14 connects virtual machines 54, 55, and 56, enabling data communication between the 3 virtual machines; virtual switch 15 connects virtual machines 57, 58, and 59, enabling data communication between the 3 virtual machines. The DMZ zone contains a relay server 5 and a border firewall 5. The firewall configuration policy prevents abnormal access. Devices in the internal local area network zone communicate with other cyber range networks through the relay server 5 and the border firewall 5. The relay server 5 has two network cards. One network card is configured with an internal network address of 192.168.2.200 for communication with the internal local area network zone, and the other network card is configured with an external network address of 33.10.50.200 for connection to other external networks. VCPE_05 is connected to the border firewall 5 to achieve three-layer routing forwarding and communication.

[0045] When virtual machine 11 (purple identifier in the figure) in the first-level cyber range network communicates with virtual machine 21 (purple identifier in the figure) in the second-level cyber range network, the communication link is the purple identifier route in the figure. The complete communication link is:

[0046] Virtual machine 11 -> Virtual switch 1 -> Core switch 1 -> Relay server 1 -> Border firewall 1 -> VCPE_01 -> VCPE_02 -> Border firewall 2 -> Relay server 2 -> Core switch 2 -> Virtual switch 4 -> Virtual machine 21.

[0047] Among them, after passing through two VCPE devices, the data format sent by virtual machine 11 is [eth1 / 100 / 192.168.2.21 / 192.168.1.11 / communication payload Payload]. When the data packet is sent from range CR001 to range CR002, first, the DMZ relay server 1 in range CR001 encapsulates the data packet with an external UDP or TCP header, modifies the source IP to the external network IP of relay server 1, and modifies the port to the external network port of relay server 1. The output data format is [UDP / eth2 / 100 / 192.168.2.21 / 33.10.10.100 / communication payload Payload] (this example uses the UDP protocol, and the TCP protocol is similar). The VCPE_01 device encapsulates the data packet with an external VCPE ID header and a Cyber Range ID header, and the output data format is [VCPE_02 / VCPE_01 / CR002 / CR001 / UDP / eth2 / 100 / 192.168.2.21 / 33.10.10.100 / communication payload Payload]. When passing through the next-hop VCPE_02 device, the external VCPE ID header and the Cyber Range ID header will be removed, and the destination IP will be modified to the external network IP address of relay server 1. The output data format is [UDP / eth2 / 100 / 33.10.20.100 / 33.10.10.100 / communication payload Payload]. The DMZ area relay server 2 in range CR002 will replace the source IP, destination IP, port, and VLAN, and the output data format is [UDP / eth1 / 200 / 192.168.2.21 / 192.168.2.100 / communication payload Payload]. Finally, the data packet is sent to virtual machine 21 through core switch 2 and virtual switch 4. The finally received data packet is [eth1 / 200 / 192.168.2.21 / 192.168.2.100 / communication payload Payload]. The routing calculations of VCPE_01 and VCPE_02 are shown in Table 1 and Table 2. The VCPE_01 device is responsible for routing forwarding and communication with VCPE_02 and VCPE_03, and will send the data in the range network CR001 connected to the VCPE_01 device to range network CR002 and range network CR003, and exchange data with networks 0x0022 and 0x0033 in the corresponding range networks. The VCPE_02 device is responsible for routing forwarding and communication with VCPE_01 and VCPE_04, and will send the data in the range network CR002 connected to the VCPE_02 device to range network CR001 and range network CR004, and exchange data with networks 0x0011 and 0x0044 in the corresponding range networks.

[0048] When the virtual machine 19 (orange - marked in the figure) in the first - level range network communicates with the virtual machine 56 (orange - marked in the figure) in the fifth - level range network, the communication link is the orange - marked route in the figure, and the complete communication link is as follows:

[0049] Virtual machine 19 -> Virtual switch 3 -> Core switch 1 -> Relay server 1 -> Border firewall 1 -> VCPE_01 -> VCPE_03 -> VCPE_05 -> Border firewall 5 -> Relay server 5 -> Core switch 5 -> Virtual switch 14 -> Virtual machine 56.

[0050] Among them, after passing through three VCPE devices, the data format sent by virtual machine 19 is [eth1 / 100 / 192.168.2.56 / 192.168.1.19 / communication payload Payload]. When the data packet is sent from the range CR001 to the range CR003, first, the DMZ relay server 1 in the range CR001 encapsulates the external UDP or TCP header for the data packet and modifies the source IP to the external network IP of the relay server 1, and modifies the port to the external network port of the relay server 1. The output data format is [TCP / eth2 / 100 / 192.168.2.56 / 33.10.10.100 / communication payload Payload] (this example takes the TCP protocol as an example, and the UDP protocol is similar). The VCPE_01 device encapsulates the external VCPE ID header and the Cyber Range ID header for the data packet, and the output data format is [VCPE_03 / VCPE_01 / CR003 / CR001 / TCP / eth2 / 100 / 192.168.2.56 / 33.10.10.100 / communication payload Payload]. When passing through the next-hop VCPE_03 device, the external VCPE ID header and the Cyber Range ID header will be replaced, and the output data format is [VCPE_05 / VCPE_03 / CR005 / CR001 / TCP / eth2 / 100 / 192.168.2.56 / 33.10.10.100 / communication payload Payload]. When passing through the next-hop VCPE_05 device, the external VCPE ID header and the Cyber Range ID header will be removed, and the destination IP address will be modified to the external network IP address of the relay server 5. The output data format is [TCP / eth2 / 100 / 33.10.50.200 / 33.10.10.100 / communication payload Payload]. The DMZ relay server 5 in the range CR005 will replace the source IP, destination IP, port, and VLAN, and the output data format is [TCP / eth1 / 200 / 192.168.2.56 / 192.168.2.200 / communication payload Payload]. Finally, the data packet is sent to the virtual machine 56 through the core switch 5 and the virtual switch 14. The finally received data packet is [eth1 / 200 / 192.168.2.56 / 192.168.2.200 / communication payload Payload]. The routing calculations of VCPE_01, VCPE_02, and VCPE_05 are shown in Tables 2, 3, and 4 respectively.The VCPE_01 device is responsible for routing and communication with VCPE_02 and VCPE_03. It will send the data in the range network CR001 connected to the VCPE_01 device to the range networks CR002 and CR003, and exchange data with the networks 0x0022 and 0x0033 in the corresponding range networks. The VCPE_03 device is responsible for routing and communication with VCPE_01 and VCPE_05. It will send the data in the range network CR003 connected to the VCPE_03 device to the range networks CR001 and CR005, and exchange data with the networks 0x0011 and 0x0055 in the corresponding range networks. The VCPE_05 device is responsible for routing and communication with VCPE_03. It will send the data in the range network CR005 connected to the VCPE_05 device to the range network CR003, and exchange data with the network 0x0033 in the corresponding range network.

[0051] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art of this technology, without departing from the technical principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.

Claims

1. A distributed network range interconnection method based on VCPE, characterized in that: In the method, a virtual client device, namely a VCPE device, is used to connect the networks between different distributed network ranges, and the network is divided into a local area network area and a demilitarized zone (DMZ) area; the VCPE device is a distributed logical device that realizes the interconnection of different distributed network ranges, and is connected to the upper range network upward and to the lower range network downward. Each distributed network range connected to the VCPE device realizes the forwarding and control of routing data through the VCPE device; The first-level shooting range network includes a LAN area and a DMZ area. The LAN area is connected to n computing servers through a core switch. Each computing server virtualizes one or more virtual switches and m virtual machines through virtualization technology. Each virtual switch connects m virtual machines. Among them, virtual switch X1 connects virtual machines x1, virtual machine x2,..., virtual machine xm, and can realize data communication between m virtual machines; the DMZ area includes relay server Z1 and border firewall B1. The devices in the internal LAN area communicate with other shooting range networks through relay server Z1 and border firewall B1. Relay server Z1 has two network cards, one of which is configured with an intranet address, which is used to communicate with the LAN area, and the other is configured with an external network address, which is used to connect to other shooting range networks. The VCPE device VCPE_01 accessed by the first-level shooting range network is connected to the border firewall B1 to realize three-layer routing forwarding and communication; the internal structure of the shooting range networks at other levels is the same as that of the first-level shooting range network.

2. The method according to claim 1, characterized in that When the relay server Z1 in the primary shooting range network communicates with the relay server Z2 in the secondary shooting range network, they register their own external network addresses to each other, that is, the external network address of relay server Z1 is written into the communication address of relay server Z2, and vice versa. Then relay server Z1 sends a UDP or TCP data packet to relay server Z2. This data packet is called a hole punching packet. After sending the data packet, a routing record is generated on the VCPE device VCPE_01. Then, subsequent data packets sent between relay server Z1 and relay server Z2 will not be discarded.

3. The method according to claim 1, characterized in that When virtual machine x1 in the primary range network communicates data with virtual machine x1 in the secondary range network, the complete communication link is: Virtual machine x1->virtual switch X1->core switch H1->relay server Z1->border firewall B1->VCPE_01->VCPE_02->border firewall B2->relay server Z2->core switch H2->virtual switch X1->virtual machine x1; VCPE_02 is a VCPE device connected to the secondary shooting range network, border firewall B2 is a border firewall in the DMZ area inside the secondary shooting range network, and core switch H2 is a core switch in the LAN area inside the secondary shooting range network; The data format sent by virtual machine x1 after passing through two VCPE devices is [ETH / VLAN / destination IP / source IP / Payload]. When the data packet is sent from the primary range network to the secondary range network, the relay server Z1 in the DMZ area of ​​the primary range network first encapsulates the data packet with an external UDP or TCP header and modifies the source IP to the external network IP of relay server Z1, and modifies the port to the port of relay server Z1. The output data format is [Protocol / ETH / VLAN / destination IP / source IP / Payload]. The VCPE_01 device encapsulates the data packet with an external VCPE ID header and Cyber ​​Range ID header, and the output data format is [destination VCPEID / source VCPEID / destination Cyber ​​Range ID / source Cyber RangeID / Protocol / ETH / VLAN / destination IP / source IP / Payload]. When passing through the next-hop VCPE_02 device, the external VCPEID header and CyberRangeID header are removed, and the destination IP is modified to the external network IP address of the relay server Z1. The output data format is [Protocol / ETH / VLAN / destination IP / source IP / Payload]. The relay server Z2 in the DMZ area of ​​the secondary target range network replaces the source IP, destination IP, port, and VLAN. The output data format is [Protocol / ETH / VLAN / destination IP / source IP / Payload]. Finally, the data packet is sent to a virtual machine in the secondary target range network through the core switch H2 and the virtual switch X1. The data packet finally received is [ETH / VLAN / destination IP / source IP / Payload].

4. The method according to claim 3, characterized in that The VCPE_01 device is responsible for routing, forwarding and communicating with VCPE_02 and the VCPE device VCPE_03 connected to the third-level target range network, sending the data in the first-level target range network connected to the VCPE_01 device to the second-level target range network and the third-level target range network, and exchanging data with the network in the corresponding target range network; the VCPE_02 device is responsible for routing, forwarding and communicating with the VCPE_01 device and the VCPE device VCPE_04 in the fourth-level target range network, sending the data in the second-level target range network connected to the VCPE_02 device to the first-level target range network and the fourth-level target range network, and exchanging data with the network in the corresponding target range network.

5. The method according to claim 4, characterized in that When the message enters the VCPE device, the VCPE device encapsulates the source VCPE_ID, destination VCPE_ID, source network target range Cyber ​​RangeID, destination Cyber ​​RangeID and other data packet headers and forwards the data packet to the next-hop VCPE device. The intermediate VPCE device only needs to parse and identify the data packet header and forward the data packet without parsing the IP packet header. The last-hop VCPE device parses the IP packet header.

6. The method according to claim 4, characterized in that The relay server Z1 in the first-level shooting range network is also connected to an SDN controller as a centralized controller, which is used to send routing and forwarding strategies to all VCPE devices.

7. A remote network across shooting ranges, implemented based on the method as claimed in any one of claims 1 to 6, which is composed of multiple levels of shooting range networks connected to form a shooting range.

8. A system for implementing the method according to any one of claims 1 to 6.

9. Application of the method according to any one of claims 1 to 6 in network communication.

10. An application of the remote network as claimed in claim 7 in network communications.