ENSP-based intelligent mine network equipment establishment method
By adopting eNSP-based main and standby route planning in the smart coal mine network, and using VRRP+VGMP technology and heartbeat monitoring, the problem of insufficient network security and reliability is solved, and the efficient, safe and reliable operation of the network is achieved, ensuring the continuous operation of the system and data transmission.
Patent Information
- Application Number
- CN202510308110.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-17
- Publication Date
- 2025-07-18
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing smart coal mine network construction still has problems of insufficient network security and reliability based on the dual-machine hot backup technology, resulting in data loss and system pause, and high costs.
The smart mining network equipment establishment method based on eNSP is adopted. By setting up the main and standby route in the mining network planning, VRRP+VGMP technology and heartbeat monitoring mechanism are used to automatically switch to the backup equipment when the host fails, ensuring data synchronization and communication link stability.
It realizes efficient, safe and reliable operation of the network, ensures the continuous operation of the computer system, improves work quality and underground personnel safety, and reduces the risk of system pauses and data loss.
Smart Images

Figure CN120342846A_ABST
Abstract
Description
Technical Field
[0001] The present invention is a method for establishing intelligent mine network equipment based on eNSP software, belonging to the field of network planning, and specifically a primary and standby establishment method provided during network planning in eNSP. Background Art
[0002] With the development of the computer industry, the development of the intelligent coal mine industry has become increasingly dependent on computer systems. Once the data processing center fails to operate normally, irreparable losses will be caused. At present, most coal mines have built industrial ring networks and communication systems, including industrial Ethernet ring networks, 4G wireless networks, Wi-Fi wireless networks, emergency broadcasts, etc. Building an intelligent coal mine has become the only way for the intrinsic safety of coal mines.
[0003] eNSP is a free, extensible, and graphically operated network simulation tool platform provided by Huawei. It mainly conducts software simulation on enterprise network routers and switches, perfectly presenting the actual scenes of real devices and supporting large-scale network simulation. The present invention uses the eNSP simulator to simulate a network topology diagram related to mines. When planning the network topology, by using more primary and standby schemes, the security and efficiency of the network are increased.
[0004] At present, some coal mine enterprises have carried out the work of building intelligent coal mines, and the network construction and planning have also developed rapidly. However, the overall technical solution is still in the exploration stage, and there is still a certain gap from the industrial Internet platform standards of other industries in terms of integrity and advancement. Therefore, based on the dual-machine hot standby technology, a method for establishing intelligent mine network equipment based on eNSP is proposed. By setting two or more standby routes during the mine network planning process, when the primary device fails, it can automatically switch to the standby device, and a server cluster is used for important services, which are backed up with each other and serve together to ensure that data is never lost and the system never stops, while also being able to save a large amount of expenses for users. Summary of the Invention
[0005] The rapid development of modern computer technology has provided new opportunities and challenges for the planning and implementation of mine networks. The application of emerging technologies such as cloud computing, big data, the Internet of Things, and artificial intelligence has provided more innovative possibilities for mine networks, enabling resource sharing and allocation, intelligent analysis and utilization of data, intelligent interconnection of devices, and intelligent management of networks. Therefore, through research and practice, a mine network establishment method suitable for the characteristics and needs of mines can be explored to provide strong support for the informatization construction of mines.
[0006] The object of the present invention is to propose a method for establishing intelligent mine network equipment, providing a primary and standby establishment idea for future mine network planning. When building a network in a mine, this establishment method can be used, which can greatly improve the efficiency of the network, realize the timely transmission of data, ensure the normal operation of the network, further improve the work quality and ensure the safety of underground personnel. The basic principle of the present invention is to perform real-time backup of the data and services of a host. When the host fails, the standby machine will automatically take over all the functions and services of the host, thus realizing the seamless switching of services and ensuring the high availability of services. A high-speed and stable communication link needs to be established between the host and the standby machine to ensure real-time data synchronization. A heartbeat monitoring mechanism is adopted to detect the status of the host to ensure that the host failure is detected in time and the backup machine is enabled. Based on the dual-machine hot standby technology, the present invention proposes an idea of real-time backup, and considers whether a backup plan needs to be adopted in each step of network planning.
[0007] To achieve the above object, the technical solution adopted by the present invention is as follows: A method for establishing intelligent mine network equipment based on eNSP is proposed. Based on eNSP, in the planned topology diagram, the internal network is divided into the headquarters and branches, and two Huawei USG6000V firewalls are deployed at the exit of the mine network. Underground personnel can enter the distributed server group or access the external Internet through the network three-layer structure. IP addresses and security areas are divided for each part of the mine network, and corresponding security policies are configured for the firewalls in each area. A connection is established between the distributed servers in the headquarters and branches through the firewall security tunnel IPSes, and access control is established for each terminal, the external network, and these distributed server groups to achieve the secure storage of data and the protection of work computers. Beneficial effects
[0008] It is found through experiments that the network adopting the primary and standby strategy is more secure and reliable, can ensure the uninterrupted operation of the computer system, and comprehensively ensure the "safety, stability, and efficiency" of the computer system from the perspective of high availability. Description of the drawings
[0009] Figure 1 It is the overall architecture diagram of the mine network topology planning; Figure 2 It is the IP address division table of the topology headquarters; Figure 3 It is the heartbeat working process. Specific implementation manners
[0010] The following will describe this establishment method more clearly and completely in conjunction with the drawings in the embodiments of the present invention. Obviously, the described examples are only a part of the embodiments of the present invention, rather than all the embodiments. As Figure 1As shown in the figure, two firewalls are deployed at the core layer of the topology, two switches are deployed at the aggregation layer, and two firewall devices are also deployed at the connection between the server cluster at the headquarters and the switches. By using this establishment method of the primary and standby strategies multiple times, the purpose of increasing network security and reliability is achieved.
[0011] The access layer is the part of the network that directly faces user connections or accesses the network; the aggregation layer acts as an "intermediary", aggregating the terminal traffic and the like accessed by the access layer to reduce the burden on the core layer devices, and at the same time providing a function for forwarding internal network data. For example, the host PC1 in the figure can access the distributed servers 1, 2, and 3 of the distributed storage server cluster at the headquarters through the access layer and the aggregation layer; the core layer is the backbone of the network and the ultimate bearer and inheritor of all traffic. If the terminal devices of the staff need to access the Internet, they must access the Internet through the core layer. The implementation method mainly takes the headquarters as an example, and the primary and standby establishment method of the branch is similar to that of the headquarters.
[0012] At the junction of the aggregation layer and the distributed server cluster at the headquarters, the dual-active hot standby technology is adopted. When the primary device is unavailable, it will quickly switch to the standby device, thus ensuring the high-speed and stable communication of the network.
[0013] The dual-active hot standby of the firewall negotiates the primary and standby status and backup sessions between the firewalls through a backup link (heartbeat line), playing a role in protecting the server and improving redundancy.
[0014] Adopt the VRRP+VGMP technology, establish a heartbeat line, and enable the HRP function to finally achieve the primary and standby function. The VRRP technology ensures that when the primary firewall FW1 fails, the backup firewall FW3 can automatically replace the failed firewall to complete the task and ensure the security of the network. The VGMP technology is used for primary and standby machine status management and interface status monitoring, provides a VGMP management group, and solves the problem of inconsistent status of multiple VRRP backup groups. The interfaces running the VRRP function are uniformly added to a VGMP group, and the status of each interface in the same group is consistent. The HRP protocol realizes data synchronization between the two machines and backup of key commands. The primary firewall FW1 sends its own status information to the standby firewall FW3 through the heartbeat line, and the heartbeat packet detects whether the VGMP group of the other party is in the working state When configuring the firewall FW1 in the distributed server cluster at the headquarters, first configure the heartbeat line of FW1 and enable the dual-active hot standby function, establish a session table at the same time, enable the HRP function, and allow the firewall FW1 to remotely monitor another firewall FW3 with an IP address of 10.10.0.2 through the GE1 / 0 / 1 port.
[0015] Next, configure the IP address and gateway for firewall FW1. Enter port GE1 / 0 / 2, the IP address of this port is 192.168.1.1. Enter port GE1 / 0 / 0, the IP address of this port is 192.168.100.252. Set FW1 as the master device.
[0016] If the gateway address of one of the servers is 192.168.100.252, then access the Internet through firewall FW1.
[0017] Configure a new gateway address 192.168.100.254 through the VRRP protocol to achieve automatic switching, and set FW1 as the master device. If accessing the Internet, first access the Internet through FW1.
[0018] Configure the OSPF dynamic routing protocol for firewall FW1 to achieve internal communication, and configure the network segments contained in this area. When configuring firewall FW3, also enable the HRP function so that firewall FW3 can remotely monitor another firewall device FW1 with an IP address of 10.10.0.1 through port GE1 / 0 / 1. Next, configure the IP address and gateway for firewall FW3, and set FW3 as the standby device. To avoid the waste and inconvenience caused by manually switching the gateway address, configure a new gateway address 192.168.100.254 through the VRRP protocol to achieve automatic switching, and set FW3 as the standby device. When accessing the Internet, if FW1 has problems, access the Internet through FW3.
[0019] Configure the OSPF dynamic routing protocol for firewall FW3 to achieve internal communication, and configure the network segments contained in this area.
[0020] In the aggregation layer of the headquarters, when users or terminal devices in the first and second lines want to access the external network or servers in the distributed server group, multiple interfaces are required to reach through the aggregation layer. At the same time, the aggregation layer needs to provide an uplink to the core layer. Ordinary routers cannot meet the requirements. Therefore, two three-layer switches with higher performance, more interfaces, and higher speed need to be selected for primary and standby replacement. When the primary device stops working, the standby device starts working to improve reliability and redundancy.
[0021] Reasonably plan IPs and subnets in the aggregation layer, use DHCP to distribute addresses, and divide VLANs; to determine which firewall (FW1, FW3) the switches LSW3 and LSW4 should deliver to, configure the VRRP protocol here to achieve master-backup switching. Determine the master and backup through priorities. Once the master device fails, the priority is reduced by 30. The real IP address of VLAN1 on the interface where this device (LSW3) is connected to the firewall FW1 is 192.168.1.4, the virtual gateway of group 1 is 192.168.1.3, the priority of group 1 is 120, becoming the master gateway of Vlan1, and then track the uplink interfaces G0 / 0 / 1, G0 / 0 / 7, G0 / 0 / 2. If they break down, the priority is reduced by 30. The real IP address of VLAN2 on the interface where this device (LSW3) is connected to the headquarters VPN firewall is 192.168.2.1. The real IP address of VLAN3 on the interface where this device (LSW3) is connected to the headquarters export business firewall is 192.168.3.1. The real IP address of VLAN10 on the interface where the business department VLAN divided in this device (LSW3) is connected is 192.168.10.1, the virtual gateway of group 10 is 192.168.10.254, the priority of group 10 is 120, becoming the master gateway of Vlan10, and then track the uplink interfaces G0 / 0 / 7, G0 / 0 / 2. If they break down, the priority is reduced by 30. The real IP address of VLAN20 on the interface where the sales department VLAN divided in this device (LSW3) is connected is 192.168.20.1, the virtual gateway of group 20 is 192.168.20.254, the priority of group 20 is 120, becoming the master gateway of Vlan20, and then track the uplink interfaces G0 / 0 / 7, G0 / 0 / 2. If they break down, the priority is reduced by 30.
[0022] Configure the OSPF dynamic routing protocol on the switch to achieve internal network communication. Perform link aggregation between the switches LSW3 and LSW4, and at the same time configure the MSTP protocol to prevent loops and increase bandwidth to ensure the reliability of communication.
[0023] When configuring, first configure the trunk port, assign the switch port to the corresponding VLAN, and configure eth-trunk.
[0024] Next, configure the routing protocol OSPF to achieve internal network communication, then configure VRRP to achieve virtual gateway and backup, and finally configure SMTP to achieve load balancing and backup. When configuring LSW3, 3 is the primary and 4 is the backup; when configuring LSW4, LSW4 is the primary and LSW3 is the backup. Through the example of the primary-backup strategy adopted in the headquarters distributed server group and the aggregation layer, this method of establishing the primary-backup strategy can make the network more efficient, reliable and feasible. At the same time, it can further improve the communication quality of mine personnel and the utilization efficiency of mine intelligent devices.
Claims
1. The technical solution adopted by the present invention is as follows: A method for establishing intelligent mine network devices based on eNSP is proposed. Based on eNSP, in the planned topology diagram, the internal network is divided into a headquarters and branches, and two Huawei USG6000V firewalls are deployed at the exit of the mine network. Underground personnel can enter the distributed server group or access the external Internet through the network three-layer structure; IP addresses and security zones are divided for each part of the mine network, and corresponding security policies are configured for the firewalls in each zone. A connection is established between the distributed servers at the headquarters and branches through the firewall security tunnel IPSes, and access control is established for each terminal, the external network, and these distributed server groups to achieve secure storage of data and protection of work computers.
Citation Information
Patent Citations
MPLS-based medium and large-scale enterprise network and implementation method thereof
CN114338422A
Core, convergence and access three-layer network system based on infinite bandwidth network
CN118214731A
Instant messaging method of cloud communication platform
CN119254733A
Method for Managing Virtual Router Redundancy Protocol Backup Groups
US20070153765A1
Method and system for generating network configurations using graph neural network
US20230124663A1