Network configuration verification device and method
The network configuration verification device automates the comparison of actual and designed network configurations, reducing manual workload and costs by identifying and generating restoration advice.
Patent Information
- Application Number
- JP2021043178
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-03-17
- Publication Date
- 2025-05-20
- Estimated Expiration
- 2041-03-17
AI Technical Summary
Existing network configuration verification methods require manual and visual comparison of actual and designed configurations, leading to a heavy workload and high costs in large-scale networks.
A network configuration verification device that includes a memory circuit for storing design configuration information and a control circuit to compare actual and designed configurations, automatically identifying differences and generating advice for restoration.
Facilitates easy verification of actual versus designed network configurations, reducing manual effort and costs, especially in large-scale networks.
Smart Images

Figure 0007680228000001 
Figure 0007680228000002 
Figure 0007680228000003
Abstract
Description
[Technical field]
[0001] The present invention relates to a network configuration verification technique for verifying the connection topology of various connected devices, such as communication control devices and terminal devices, connected to an IP network. [Background technology]
[0002] Conventionally, as a technology for visualizing a network configuration, Patent Document 1 proposes a technology for acquiring MAC address table information from a network device having a MAC address table, such as an L2 switch, using, for example, ARP (Address Resolution Protocol), and identifying the physical connection form of each connected device, i.e., the network configuration, from the acquired MAC address table information. This makes it possible to identify the network configuration remotely from any information processing terminal connected to an IP network, and makes it easy to identify the network configuration even for a large-scale network built in a large building such as a commercial building, office building, hospital, school, or factory. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] JP 2016-032226 A Summary of the Invention [Problem to be solved by the invention]
[0004] Such network configuration identification technology may be used to grasp the network configuration during expansion, reconstruction, or maintenance work on IP networks. In this case, it is important to verify whether the newly identified actual network configuration matches or differs from the design network configuration managed in the drawings and documents before starting the work.
[0005] However, such network configuration verification requires visual and manual comparison of the newly identified and obtained actual network configuration information with the drawings and documents showing the designed network configuration, which creates a problem of extremely heavy workload and costs in a large-scale network consisting of many connected devices.
[0006] The present invention has been made to solve these problems, and aims to provide a network configuration verification technology that can easily verify the differences between the actual network configuration and the designed network configuration, even in the case of a large-scale network. [Means for solving the problem]
[0007] In order to achieve this objective, the network configuration verification device of the present invention comprises a memory circuit that stores design configuration information indicating design contents related to the network configuration of a target IP network, and a control circuit that verifies the network configuration of the IP network based on the design configuration information, and the control circuit is configured to obtain actual configuration information obtained by actually identifying the network configuration of the IP network, and to verify the network configuration of the IP network by comparing the actual configuration information with the design configuration information.
[0008] In addition, one configuration example of the network configuration verification device according to the present invention is configured such that, during the comparison, the control circuit compares, for each port of each switch among the network devices constituting the IP network, an IP address of a connected device connected to that port, between the actual configuration information and the designed configuration information.
[0009] In addition, one configuration example of the network configuration verification device according to the present invention is configured so that the control circuit generates a connection status of each connected device to the network device based on a result of the comparison, and outputs the connection status as a verification result regarding the verification.
[0010] In addition, one configuration example of the network configuration verification device according to the present invention is configured so that the control circuit outputs, based on a result of the comparison, advice indicating the work content for restoring the IP network from the network configuration of the actual configuration information to the network configuration of the designed configuration information, as a verification result related to the IP network.
[0011] Furthermore, the network configuration verification method of the present invention is a network configuration verification method used in a network configuration verification device having a memory circuit that stores design configuration information indicating design contents related to the network configuration of a target IP network, and a control circuit that verifies the network configuration of the IP network based on the design configuration information, and includes a first step in which the control circuit acquires actual configuration information obtained by actually identifying the network configuration of the IP network, and a second step in which the control circuit verifies the network configuration of the IP network by comparing the actual configuration information with the design configuration information.
[0012] In addition, in one configuration example of the above-mentioned network configuration verification method according to the present invention, the second step includes a third step in which the control circuit, during the comparison, checks the connection status of each port by comparing, for each port of a switch among the network devices constituting the IP network, the IP address of a connected device connected to that port with the actual configuration information and the designed configuration information. Effect of the Invention
[0013] According to the present invention, even in the case of a large-scale network made up of a large number of connected devices, it is possible to easily verify the difference between the actual network configuration and the designed network configuration. [Brief description of the drawings]
[0014] [Figure 1]FIG. 1 is a block diagram showing the configuration of a network configuration verification device. [Diagram 2] FIG. 2 is an explanatory diagram showing the design configuration information. [Diagram 3] FIG. 3 is an explanatory diagram showing an example of a network configuration corresponding to the design configuration information of FIG. [Figure 4] FIG. 4 is an explanatory diagram showing actual configuration information. [Diagram 5] FIG. 5 is an explanatory diagram showing an example of a network configuration corresponding to the actual configuration information of FIG. [Figure 6] FIG. 6 is an explanatory diagram illustrating an example of a verification result. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0015] Next, an embodiment of the present invention will be described with reference to the drawings. [Network configuration verification device] First, a network configuration verification device 10 according to the present embodiment will be described with reference to Fig. 1. Fig. 1 is a block diagram showing the configuration of the network configuration verification device.
[0016] This network configuration verification device 10 is composed of information processing devices such as a PC or server device as a whole, and is configured to compare the network configuration of an IP network NW such as a LAN identified by the network configuration identification device 20 with the designed network configuration managed by drawings and documents.
[0017] [Network configuration identification device] The network configuration identification device 20 is generally composed of information processing devices such as a PC or a server device, and is connected to an IP network NW such as a LAN to be identified. The network configuration identification device 20 is configured to identify and visualize a network configuration indicating the connection form related to connected devices such as network devices and terminal devices connected to the IP network NW, based on a publicly known network configuration identification technology such as Patent Document 1, by performing data communication with these connected devices.
[0018] In the following, an example will be described in which the network configuration identifying device 20 is configured as a device separate from the network configuration verification device 10, but the network configuration identifying device 20 may also be implemented as a part of the configuration of the network configuration verification device 10.
[0019] In this embodiment, devices that control packet forwarding, such as L2 (Layer 2) switches, L3 (Layer 3) switches, hubs, routers, and gateways, are called network devices (communication control devices). Among the network devices, devices that have their own IP addresses and can externally obtain MAC address table information used for packet forwarding control, such as L2 (Layer 2) switches and L3 (Layer 3) switches, are called switches SW. Devices that do not have their own IP addresses and cannot externally obtain MAC address table information used for packet forwarding control are called hubs HUB.
[0020] In addition to information processing terminals such as PCs, various devices used in the Internet of Things (IoT), such as sensors, field devices, and controllers, are also referred to as terminal devices.
[0021] [Configuration of network configuration verification device] Next, with reference to FIG. 1, a configuration of the network configuration verification device 10 according to the present embodiment will be described in detail.
[0022] As shown in FIG. 1, the network configuration verification device 10 includes a communication I / F 11, an operation input circuit 12, a display circuit 13, a memory circuit 14, and a control circuit 15 as main circuit sections.
[0023] [Communication I / F] The communication I / F 11 is connected to the network configuration identification device 20 via a communication line L, and is configured to acquire network configuration information obtained by identifying the network configuration of the IP network NW to be verified by performing data communication with the network configuration identification device 20. [Operation input circuit] The operation input circuit 12 is made up of operation input devices such as a keyboard, a mouse, and a touch panel, and is configured to detect an operator's operation and output it to the control circuit 15.
[0024] [Display circuit] The display circuit 13 is made up of a screen display device such as an LCD, and is configured to display various types of screen information output from the control circuit 15, such as a menu screen, a setting screen, and a network configuration verification result screen.
[0025] [Memory circuit] The memory circuit 14 is made up of a storage device such as a hard disk or a semiconductor memory, and is configured to store various processing data and programs 14P used in the network configuration verification process in the control circuit 15.
[0026] [program] The program 14P is a program for implementing various processing units used for the network configuration verification process in the control circuit 15 by cooperating with the CPU of the control circuit 15. This program 14P is stored in advance in the storage circuit 14 from an external device or a recording medium (neither of which is shown) connected to the network configuration verification device 10 via the communication line L.
[0027] The main processing data stored in the memory circuit 14 include design configuration information 14A and actual configuration information 14B.
[0028] [Design configuration information] The design configuration information 14A is data showing design contents related to the network configuration of the target IP network NW. Fig. 2 is an explanatory diagram showing the design configuration information. Fig. 3 is an explanatory diagram showing an example of a network configuration corresponding to the design configuration information of Fig. 2.
[0029] As shown in FIG. 2, in the design configuration information 14A, for each port (connection port) of a network device, the IP address of a connection device connected to the port is registered.
[0030] In the configuration example of FIG. 3, two switches, SW#0 (IP address "192.168.1.100") and SW#1 (IP address "192.168.1.101"), and one hub, HUB#X (no IP address), are connected to the IP network NW. The design configuration information 14A of FIG. 2 shows that a terminal device PC#1 (IP address "192.168.1.1") is connected to port P1 (port number 1) of SW#0 as a connected device. The design configuration information 14A may be generated in advance using a PC or the like from design data of the IP network NW managed by drawings and documents.
[0031] [Actual composition information] The actual configuration information 14B is data indicating the actual contents related to the network configuration of the target IP network NW identified by the network configuration identifying device 20. Fig. 4 is an explanatory diagram showing the actual configuration information. Fig. 5 is an explanatory diagram showing an example of a network configuration corresponding to the actual configuration information of Fig. 4.
[0032] As shown in FIG. 4, in the actual configuration information 14B, for each port of a network device, the IP address of a connection device connected to the port is registered.
[0033] As shown in Fig. 5, two switches, SW#0 (IP address "192.168.1.100") and SW#1 (IP address "192.168.1.101"), and one hub, HUB#X (no IP address), are connected to the IP network NW. The actual configuration information 14B in Fig. 4 shows that the terminal device PC#1 (IP address "192.168.1.1") is connected as a connected device to the port P2 (port number 2) of SW#0.
[0034] [Control circuit] The control circuit 15 has a CPU and its peripheral circuits, and is configured to implement a processing section for executing a network configuration verification process by reading out the program 14P from the storage circuit 14 and cooperating with the CPU.
[0035] The main processing units realized by the control circuit 15 include a data acquisition unit 15A, a verification unit 15B, and a verification result generation unit 15C.
[0036] [Data Acquisition Section] The data acquisition unit 15A is configured to acquire design configuration information 14A indicating the network configuration of the IP network NW from an external device (not shown) via the communication I / F 11 and the communication line L, and store the information in the memory circuit 14.
[0037] Moreover, the data acquiring unit 15A is configured to acquire actual configuration information 14B indicating the network configuration of the IP network NW from the network configuration identifying device 20 via the communication I / F 11 and the communication line L, and store the information in the memory circuit 14. Regarding the actual configuration information 14B, a configuration information acquisition request may be notified from the data acquiring unit 15A, so that the network configuration identifying device 20 acquires the latest actual configuration information 14B.
[0038] [Verification Department] The verification unit 15B is configured to verify the network configuration of the IP network NW by comparing the actual configuration information 14B acquired by the data acquisition unit 15A with the design configuration information 14A pre-stored in the memory circuit 14.
[0039] In addition, when making the comparison, the verification unit 15B is configured to compare, for each port of each switch SW among the network devices that make up the IP network NW, the IP addresses of the connection devices connected to that port between the actual configuration information 14B and the design configuration information 14A, and to compare, for each hub HUB among the network devices that make up the IP network NW, the IP addresses of the connection devices connected to that hub HUB between the actual configuration information 14B and the design configuration information 14A.
[0040] [Verification result generation part] The verification result generation unit 15C is configured to generate a connection status of the connected devices to the network devices based on the comparison result obtained by the verification unit 15B, generate advice indicating the work content for restoring the IP network NW from the network configuration of the actual configuration information 14B to the network configuration of the design configuration information 14A based on the comparison result obtained by the verification unit 15B, and output the connection status and / or advice as the verification result for the IP network NW.
[0041] [Operation of this embodiment] Next, the operation of the network configuration verification method of the network configuration verification device 10 according to the present embodiment will be described.
[0042] In response to an operator's operation indicating the start of verification, the control circuit 15 starts verification of the network configuration of the target IP network NW. At this time, it is assumed that the design configuration information 14A and the actual configuration information 14B are stored in the storage circuit 14 in advance by the data acquisition unit 15A prior to the start of verification.
[0043] First, the verification unit 15B reads out the design configuration information 14A and the actual configuration information 14B from the memory circuit 14 (first step), and for each port of each switch SW among the network devices that make up the IP network NW, compares the IP addresses of the connected devices connected to that port between the actual configuration information 14B and the design configuration information 14A (second and third steps).
[0044] Furthermore, the verification unit 15B compares, for each hub HUB among the network devices constituting the IP network NW, the IP addresses of the connection devices connected to the hub in the actual configuration information 14B and the designed configuration information 14A.
[0045] Next, the verification result generating unit 15C generates the connection status of the connection device to the network device based on the comparison result obtained by the verifying unit 15B.
[0046] In addition, the verification result generation unit 15C generates advice indicating the work content for restoring the IP network NW from the network configuration of the actual configuration information 14B to the network configuration of the design configuration information 14A based on the comparison result obtained by the verification unit 15B.
[0047] Thereafter, the verification result generating unit 15C outputs the connection status and / or advice as the verification result regarding the IP network NW. The verification result thus obtained is displayed on the display circuit 13 by the verification result generating unit 15C, or is output to an external device (not shown) via the communication I / F 11 and the communication line L.
[0048] Fig. 6 is an explanatory diagram showing an example of a verification result. In Fig. 6, for each entry related to a port of a switch SW and a hub HUB among the network devices, the IP addresses of the connected devices are listed in the design configuration information 14A and the actual configuration information 14B. In addition, for each entry, the connection status of the connected devices and advice indicating the work content for restoring the IP network NW from the network configuration of the actual configuration information 14B to the network configuration of the design configuration information 14A are registered.
[0049] 6, according to the design configuration information 14A, PC1 (IP address "192.168.1.1") is connected to P1 (port number 1) of SW#0 (IP address "192.168.1.100"), but according to the actual configuration information 14B, it is clear that nothing is connected. On the other hand, according to the design configuration information 14A, nothing is connected to P2 (port number 2) of SW#0 (IP address "192.168.1.100"), but according to the actual configuration information 14B, it is clear that PC1 (IP address "192.168.1.1") is connected.
[0050] From these comparison results, a connection status is generated in which PC1 is not connected to P1 of SW#0 in the actual IP network NW, and PC1 is connected to another port, i.e., P2 of SW#0. Also, a connection status is generated in which PC1 is connected to P2 of SW#0 in the actual IP network NW, but according to the design, P1 of SW#0 should be connected to PC1.
[0051] In addition, based on the results of these comparisons, advice is generated to reconnect PC1 from P2 of SW#0 to P1 of SW#0 as a task to restore the network configuration of the actual IP network NW to the designed network configuration.
[0052] [Advantages of this embodiment] In this manner, in the network configuration verification device 10 of the present embodiment, the control circuit 15 acquires from the network configuration identification device 20 actual configuration information 14B obtained by actually identifying the network configuration of the target IP network NW, and compares the actual configuration information 14B with the designed configuration information 14A stored in advance in the memory circuit 14, thereby verifying the network configuration of the IP network NW.
[0053] More specifically, when making the comparison, for each port of each switch SW among the network devices that make up the IP network NW, the IP addresses of the connected devices connected to that port are compared between the actual configuration information 14B and the designed configuration information 14A.
[0054] This makes it possible to automatically verify the differences between the actual network configuration and the designed network configuration for an IP network NW, making it easy to verify the differences between the actual network configuration and the designed network configuration, even for a large-scale network consisting of many connected devices.
[0055] [Extended embodiment] Although the present invention has been described above with reference to the embodiment, the present invention is not limited to the above embodiment. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention. [Explanation of symbols]
[0056] 10...network configuration verification device, 11...communication I / F, 12...operation input circuit, 13...display circuit, 14...memory circuit, 14A...design configuration information, 14B...actual configuration information, 14P...program, 15...control circuit, 15A...data acquisition unit, 15B...verification unit, 15C...verification result generation unit, 20...network configuration identification device, NW...IP network, L...communication line.
Claims
1. A storage circuit for storing design configuration information indicating design contents related to a network configuration of a target IP network; a control circuit for verifying a network configuration of the IP network based on the design configuration information; the control circuit acquires actual configuration information obtained by actually identifying a network configuration of the IP network, and verifies the network configuration of the IP network by comparing the actual configuration information with the designed configuration information; the IP network includes a hub that does not have its own IP address and cannot externally acquire MAC address table information used for packet forwarding control; The control circuit compares the actual configuration information with the designed configuration information for each hub that does not have its own IP address and cannot externally acquire MAC address table information used for packet forwarding control among the network devices that make up the IP network, for the IP addresses of the devices connected to the hub. A network configuration verification device comprising:
2. 2. The network configuration verification device according to claim 1, The control circuit is a network configuration verification device characterized in that, during the comparison, the control circuit compares the IP addresses of the connected devices connected to the ports of each switch among the network devices that make up the IP network, between the actual configuration information and the design configuration information.
3. 3. The network configuration verification device according to claim 2, The network configuration verification device according to claim 1, wherein the control circuit generates a connection status of each connected device to the network device based on a result of the comparison, and outputs the connection status as a verification result regarding the verification.
4. 4. The network configuration verification device according to claim 2, further comprising: The control circuit outputs advice indicating the work required to restore the IP network from the network configuration of the actual configuration information to the network configuration of the design configuration information based on the result of the comparison as a verification result for the IP network.
5. A network configuration verification method for use in a network configuration verification device including a storage circuit for storing design configuration information indicating design contents related to a network configuration of a target IP network, and a control circuit for verifying a network configuration of the IP network based on the design configuration information, the method comprising: A first step in which the control circuit acquires actual configuration information obtained by actually identifying a network configuration of the IP network; a second step of the control circuit verifying a network configuration of the IP network by comparing the actual configuration information with the designed configuration information; Equipped with the IP network includes a hub that does not have its own IP address and cannot externally acquire MAC address table information used for packet forwarding control; The control circuit compares the actual configuration information with the designed configuration information for each hub that does not have its own IP address and cannot externally acquire MAC address table information used for packet forwarding control among the network devices that make up the IP network, for the IP addresses of the devices connected to the hub. A network configuration verification method comprising:
6. 6. The network configuration verification method according to claim 5, The second step includes a third step in which the control circuit, during the comparison, checks the connection status of each port by comparing the IP address of a connection device connected to the port of a switch among the network devices constituting the IP network, between the actual configuration information and the designed configuration information. A network configuration verification method comprising:
Citation Information
Patent Citations
Line concentration apparatus and network managing device using this
JP2001320393A
Network managing method and equipment thereof
JP2002325077A
Quarantine apparatus, quarantine system, quarantine method and program
JP2012080216A
Design support device for network system
JP2012194631A
Relay device and program
JP2015228629A