Packet Relay System and Packet Relay Method

The packet relay system addresses the inflexibility in setting changes and construction switching by using virtual network devices and logical or local address reassignment, enabling flexible operation while maintaining uninterrupted packet transmission and reception.

JP7687437B2Active Publication Date: 2025-06-03NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2023564377
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-12-02
Publication Date
2025-06-03
Estimated Expiration
2041-12-02

AI Technical Summary

Technical Problem

Existing packet relay systems face challenges in flexibly implementing setting changes or construction switching due to rigid IP address assignments and physical connections between routers.

Method used

A packet relay system that includes a tenant with virtual network devices terminating tunneling protocols, a relay device connecting the tenant to the outside, and a management device managing settings for packet transmission and reception between external devices and virtual network devices, allowing for logical or local address reassignment for flexible operation.

Benefits of technology

Enables flexible setting changes and construction switching in the packet relay system by allowing logical or local address reassignment, thereby continuing packet transmission and reception without interruption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007687437000001
    Figure 0007687437000001
  • Figure 0007687437000002
    Figure 0007687437000002
  • Figure 0007687437000003
    Figure 0007687437000003
Patent Text Reader

Abstract

This packet relay system (1) comprises a tenant (6) in which a plurality of tap devices (63, 64) for terminating a tunneling protocol are constructed, relay devices (41, 42) for connecting the tenant (6) and external devices (31, 32), and a management device (11) for managing the tenant (6) and the relay devices (41, 42) and submitting a setting under which a packet of the tunneling protocol is transmitted and received between the tap devices (63, 64) and the external devices (31, 32) connected to the relay devices (41, 42).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a packet relay system that performs packet transfer in a network device, and a packet relay method.

Background Art

[0002] With the development of SDN (Software Defined Network) technology and NFV (Network Function Virtualization) technology, it is required to flexibly connect between a mobile terminal and a server on the cloud. Therefore, there has emerged a service that enables packet transfer between a mobile terminal and a server by allowing a network user to control the packet transfer destination of a packet relay device on demand.

[0003] As an example of the conventional technology, a configuration can be considered in which tunneling protocols such as IPsec (Internet Protocol Security), VXLAN, and GRE (Generic Routing Encapsulation) are used, and routing software such as Open vSwitch is used for the packet relay device.

[0004] When a mobile terminal and a server on the cloud communicate packets with each other, it is common to realize the service by using the IP address assigned to the packet relay device as the packet transmission destination for both parties. As a technology that supports such a service, for example, there is GRE (Generic Routing Encapsulation).

Prior Art Documents

Non-Patent Documents

[0005]

Non-Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0006] FIG. 1 is a configuration diagram of a tunnel of a first comparative example. Routers 12 and 13 are packet relay devices. The IP address of 192.168.1.0 is assigned to the left interface of router 12. The IP address of 1.1.1.1 is assigned to the right interface of router 12. The IP address of 2.2.2.2 is assigned to router 13, and it is virtually connected to the right interface of router 12 via the Internet 7 by tunnel 8. The IP address of 192.168.2.0 is assigned to the left interface of router 12.

[0007] IP addresses are assigned to the right interface of router 12 and the left interface of router 13. Therefore, it is not possible to flexibly perform setting changes or switching due to construction related to these routers 12 and 13.

[0008] Therefore, an object of the present invention is to flexibly implement setting changes or construction switching in a packet relay system.

Means for Solving the Problems

[0009] To solve the above problems, a packet relay system according to the present invention includes a tenant that constructs a plurality of virtual network devices that terminate a tunneling protocol, a relay device that connects the tenant to the outside, and the tenant and the relay device are managed to input a setting for transmitting and receiving packets of the tunneling protocol between an external device connected to the relay device and the virtual network device. Each of the virtual network devices is assigned an IP address, and the relay device , front the packets addressed to the IP address of the First virtual network device constructed in the tenant When a packet arrives from an external device connected to the relay device, the destination address of the packet are The DNAT'ed to the address of the external device, and When relaying a packet to the external device from the relay device The the source address of the packet transmitted to the external device is SNAT'ed to the IP address of the virtual network device constructed in the tenant Second This is characterized by the following. Other means will be described in the mode for carrying out the invention.

Effect of the Invention

[0010] According to the present invention, in a packet relay system, setting changes and construction switching of this packet relay system can be flexibly carried out.

Brief Description of the Drawings

[0011]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Figure 20

Figure 21

Figure 22

Figure 23

Best Mode for Carrying Out the Invention

[0012] Hereinafter, the embodiments for carrying out the present invention will be described in detail with reference to each drawing. FIG. 2 is a configuration diagram of the transfer device 10 of the second comparative example. Conventionally, it is physically set in the transfer device 10 to which the opposing devices 31 and 32 are connected. This transfer device 10 includes a FIB (Forwarding Information Base: routing control table) 103, a left network interface (denoted as IF in the figure) 101, and a right network interface 102. A tunnel 81 is established between the device 31 and the network interface 101. A tunnel 82 is established between the network interface 102 and the device 32.

[0013] An IP address that is the termination of the transfer protocol recognized by the device 31 is set for the left network interface 101 of the transfer device 10. Address information of a transfer device (relay device) recognized by the device 32 is set for the right network interface 102 of the transfer device 10. The termination addresses of these tunnels 81 and 82 are IP addresses physically set in the transfer device 10.

[0014] FIG. 3 is a configuration diagram of the packet relay system 1 according to the present embodiment. The packet relay system 1 treats the IP address as a logical address, and controls each device in the packet relay system 1 to perform appropriate routing based on the logical address. The packet relay system 1 is a basic component of the present invention. The packet relay system 1 includes a management device 11, a tenant 6, and relay devices 41 and 42 arranged before and after it. This packet relay system 1 is connected to the device 31 via the tunnel 81 and connected to the device 32 via the tunnel 82.

[0015] Tenant 6 is a container configured as a Pod on Kubernetes (registered trademark). However, it is not limited to this, and Tenant 6 may be configured as a virtual machine or a physical device. Tenant 6 performs transfer processing based on a logical address independent of the physical addresses of the relay devices 41 and 42. A plurality of tap devices 63 and 64 that terminate the tunneling protocol are constructed in Tenant 6. These tap devices 63 and 64 are virtual network devices.

[0016] In addition to the function of setting Tenant 6 and the relay devices 41 and 42 when adding Tenant 6 from a user as shown in the above embodiment, the management device 11 also has functions for deleting Tenant 6 and relocating Tenant 6. This management device 11 manages Tenant 6 and the relay devices 41 and 42, and inputs settings for transmitting and receiving tunneling protocol packets between the external devices 31 and 32 connected to the relay devices 41 and 42 and the tap devices 63 and 64 of Tenant 6.

[0017] The devices 31 and 32 are terminals connected to the relay devices 41 and 42 of the packet relay system 1 and performing packet exchange with each other via this system, and are external devices through which packets are relayed by the packet relay system 1. The devices 31 and 32 are user terminals or maintenance terminals, are connected to the management device 11 of the packet relay system 1, and instruct changes in the settings for communication between the terminals.

[0018] The relay devices 41 and 42 are respectively connected via a network capable of transmitting and receiving IP packets to the devices 31 and 32. These relay devices 41 and 42 connect Tenant 6 to the outside. As a basic operation, the relay devices 41 and 42 have the role of transmitting the tunneling protocol packets transmitted from the devices 31 and 32 to Tenant 6 and transmitting the tunneling protocol packets transmitted from Tenant 6 to the devices 31 and 32.

[0019] Tenant 6 has network interfaces 61 and 62 connected to relay devices 41 and 42 via a network capable of transmitting and receiving IP packets. It also has tap devices (denoted as "tap" in the figure) 63 and 64 that terminate the transfer protocol. These two tap devices 63 and 64 are virtual network devices that terminate the tunneling protocol.

[0020] As a basic operation, when a packet of the tunneling protocol transmitted from device 31 arrives at network interface 61 of tenant 6, tenant 6 terminates the tunneling protocol with tap device 63. Then, if necessary, encapsulation is performed with the other tap device 64 and transferred to the opposite device 32.

[0021] When tenant 6 receives a packet of the tunneling protocol transmitted from device 32 at network interface 62 and receives the tunneling protocol, tenant 6 terminates the tunneling protocol with tap device 64. Then, if necessary, encapsulation is performed with the other tap device 63 and transferred to the opposite device 31.

[0022] As an embodiment, an embodiment will be described in which a GRE tunneling packet is transmitted from one of devices 31 and 32, the tunnel 81 is terminated by tenant 6, and encapsulation is performed again from tenant 6 and transferred to the other of devices 31 and 32. Since there are two forms of the logical address setting method, each will be described.

[0023] 《First Embodiment》 In the first embodiment, logical addresses are assigned to tap devices 63 and 64 to terminate the tunneling protocol with tap devices 63 and 64.

[0024] Figure 4 is a diagram showing the initial state of the packet relay system 1 of the first embodiment. In the first embodiment, for example, the relay devices 41 and 42 are physical servers equipped with the Linux (registered trademark) OS. As the tenant 6, an example of using containers is adopted, and the configuration is such that Kubernetes (registered trademark) manages the containers. In the initial state, the containers that are tenant 6 are in a state where they are not started.

[0025] FIG. 5 is a flowchart showing the tenant configuration process of the packet relay system 1. In step S10, the management device 11 inputs a setting to permit forwarding a packet received from one of the network interfaces 411 and 412 of the relay device 41 from the other to the FIB (Forwarding Information Base: routing control table) 413 of the relay device 41.

[0026] Next, the terminal 2 instructs the management device 11 to add the tenant 6 (step S11). This operation is shown in FIG. 6.

[0027] The management device 11 instructs the server 5 to start a container having two additional network interfaces 61 and 62 on the server 5 (step S12), and waits for the container to start (step S13). The operation in step S12 is shown in FIG. 7 described later. The started container functions as the tenant 6.

[0028] The management device 11 inputs settings to the container (step S14). The details of this process are shown in FIG. 8 described later.

[0029] Then, the management device 11 inputs route settings to the left relay device 41 (step S15), and also inputs route settings to the right relay device 42 (step S16), and then ends the process of FIG. 5. The operations in steps S15 and S16 are shown in FIG. 11. The details of the process in step S15 are shown in FIG. 9 described later. The details of the process in step S16 are shown in FIG. 10 described later.

[0030] FIG. 8 is a flowchart showing the logical address assignment process to the container. The management device 11 creates a tap device 63 for terminating the tunneling protocol for the left device 31 for the container (step S20). Then, the management device 11 assigns the logical address A of tenant 6 for the left device 31 to this tap device 63 (step S21). The management device 11 inputs static routing settings for the container so that packets addressed to the left device 31 are transferred to the left relay device 41 (step S22).

[0031] Next, the management device 11 creates a tap device 64 for terminating the tunneling protocol for the right device 32 for the container (step S23). Then, the management device 11 assigns the logical address B of tenant 6 for the right device 32 to this tap device 64 (step S24). When the management device 11 inputs static routing settings for the container so that packets addressed to the right device 32 are transferred to the right relay device 42 (step S25), the process of FIG. 8 ends.

[0032] FIG. 10 is a flowchart showing the route setting process for the left relay device 41. The management device 11 sets a route for the left relay device 41 so that packets addressed to the left device 31 are transferred from the left network interface 411 to the left device 31 (step S30). Then, when the management device 11 sets a route for the left relay device 41 so that packets addressed to the logical address A of tenant 6 are transferred from the left network interface 412 to tenant 6 (step S31), the process of FIG. 9 ends.

[0033] FIG. 10 is a flowchart showing the route setting process for the right relay device 42. The management device 11 sets a route for the management device 11 to transfer the packet addressed to the device 32 on the right side from the right network interface 422 to the device 32 on the right side to the relay device 42 on the right side (step S40). Then, when the management device 11 sets a route for the relay device 42 on the right side to transfer the packet addressed to the logical address B of the tenant 6 from the right network interface 421 to the tenant 6 (step S41), the process of FIG. 10 ends.

[0034] FIG. 12 is a diagram showing a state in which tunnels 81 and 82 are established from the left and right devices 31 and 32 to the tap devices 63 and 64 of the tenant 6. When a tunneling protocol addressed to the logical address A of the tenant 6 is transmitted from the device 31, it arrives at the network interface 61 of the tenant 6 via the relay device 41, and encapsulation is removed by the tap device 63. Then, it is encapsulated by the tap device 64 and transferred from the network interface 62 to the device 32 via the relay device 42. According to such a packet relay method, it is possible to flexibly perform setting changes and construction switching of this packet relay system.

[0035] FIG. 13 is a diagram showing a specific setting example of the first embodiment. In the configuration of FIG. 13, the terminal 33 and the router 35 use GRE as the transfer protocol, and the terminal 34 side does not use the transfer protocol and directly routes IP packets. The router 35 and the subordinate terminal 33 correspond to the device 31 of the first embodiment. The protocol unit 43 corresponds to the relay device 41 of the first embodiment. And the relay device 42 of the first embodiment is omitted, and the terminal 34 corresponds to the device 32 of the first embodiment.

[0036] For the terminal 33, a management device (not shown) executes the following commands. The following is an explanation of the command line for the console. In each command line, IP refers to the IP address.

[0037] (1-1) Static Routing Setting route add -host {IP of Terminal 34} gw {IP of Router 35}

[0038] For Router 35, a management device (not shown) executes the following command. (2-1) Static Routing Setting route add -host {IP of the first multus NIC of Container 66} gw {IP of Protocol Unit 43} Here, the first multus NIC of Container 66 refers to Network Interface 661. (2-2) GRE Tunnel Setting ip link add {IF name} type gretap local {IP of Router 35} remote {IP of the first multus NIC of Container 66} ip addr add {Any IP of the GRE NIC} / 24 dev {IF name} Here, the first multus NIC of Container 66 refers to Network Interface 661. (2-3) Static Routing Setting route add -host {IP of Terminal 34} gw {IP of the GRE NIC of Container 66} Here, the GRE NIC of Container 66 refers to Network Interface 663.

[0039] For Protocol Unit 43, a management device (not shown) executes the following command. (3-1) Confirmation of Transfer Permission Setting Confirm that sysctl net.ipv4.ip_forward is 1

[0040] For Container 66, a management device (not shown) executes the following command. (4-1) Static Routing Setting ip route add {IP of Router 35} / 32 via {IP of Protocol Unit 43} For the container 66, a management device (not shown) executes the following commands. (4-2) GRE Tunnel Setting ip link add {IF name} type gretap local {IP of container 66} remote {IP of router 35} ip addr add {Any IP for GRE NIC} / 24 dev {IF name} For the container 66, a management device (not shown) executes the following commands. (4-3) Static Routing Setting ip route add {IP of terminal 33} / 32 via {IP of GRE NIC of router 35} Here, the GRE NIC of router 35 refers to the network interface 351.

[0041] For the terminal 34, a management device (not shown) executes the following commands. (5-1) Static Routing Setting route add -host {IP of terminal 33} gw {IP of the second multus NIC of container 66} Here, the second multus NIC of container 66 refers to the network interface 662. As a result, a tunnel 83 is constructed between the router 35 and the container 66.

[0042] With such settings, the router 35 transmits and receives packets of the tunneling protocol. The packets of the tunneling protocol arriving at the router 35 are transmitted and received between the container 66 (tenant) by the protocol unit 43 which is a relay device. Then, a virtual network device (tap device) (not shown) constructed in this container 66 terminates the packets of the tunneling protocol.

[0043] 《Second Embodiment》 In the second embodiment, local addresses are assigned to the tap devices 63, 64 to cause the relay devices 41, 42 to perform NAT conversion.

[0044] FIG. 14 is a diagram showing the initial state of the packet relay system 1 according to the second embodiment. In the second embodiment, for example, the relay devices 41 and 42 are physical servers equipped with the linux (registered trademark) OS. As the tenant 6, an example of using a container is adopted, and the configuration is such that kubernetes (registered trademark) manages the container. In the initial state, the container that is the tenant 6 is in a state where it is not started.

[0045] FIG. 15 is a flowchart showing the tenant configuration process of the packet relay system 1. In step S50, the management device 11 inputs a setting to permit the packet received from one of the network interfaces 411 and 412 of the relay device 41 to be transferred from the other in the FIB (Forwarding Information Base: routing control table) 413 of the relay device 41. Then, the management device 11 activates a module for performing connection management of the tunneling protocol (step S51).

[0046] Next, the terminal 2 instructs the management device 11 to add the tenant 6 (step S52). This operation is shown in FIG. 16.

[0047] The management device 11 instructs the server 5 to start a container having two additional network interfaces 61 and 62 on the server 5 (step S53), and waits for the container to start (step S54). The operation of step S53 is shown in FIG. 17 described later. The started container functions as the tenant 6.

[0048] The management device 11 inputs settings to the container (step S55). The details of this process are shown in FIG. 18 described later.

[0049] Then, the management device 11 inputs route settings to the left relay device 41 (step S56). When the management device 11 also inputs route settings to the right relay device 42 (step S57), the process of FIG. 15 ends. The operations of steps S56 and S57 are shown in FIG. 21. Details of the process of step S56 are shown in FIG. 19 described later. Details of the process of step S57 are shown in FIG. 20 described later.

[0050] FIG. 18 is a flowchart showing the local address assignment process for the container. The management device 11 creates a tap device 63 for terminating the tunneling protocol for the left device 31 with respect to the container (step S60). Then, the management device 11 assigns a local address C that is only used within this system to this tap device 63 (step S61). The management device 11 inputs static routing settings so that packets addressed to the left device 31 with respect to the container are transferred to the left relay device 41 (step S62).

[0051] Next, the management device 11 creates a tap device 64 for terminating the tunneling protocol for the right device 32 with respect to the container (step S63). Then, the management device 11 assigns a local address D that is only used within this system to this tap device 64 (step S64). When the management device 11 inputs static routing settings so that packets addressed to the right device 32 with respect to the container are transferred to the right relay device 42 (step S65), the process of FIG. 18 ends.

[0052] FIG. 19 is a flowchart showing the route setting process for the left relay device 41. The management device 11 inputs a setting to perform DNAT on the destination address of the packet addressed to the logical address C of tenant 6 received at the left network interface 411 of the left relay device 41 to the address of the left network interface 61 of tenant 6 (step S70). Then, the management device 11 inputs a setting to perform SNAT on the source address of the packet transmitted from the right network interface 412 of the left relay device 41 to tenant 6 to the address of the right network interface 412 of the left relay device 41 (step S71).

[0053] The management device 11 inputs a setting to perform DNAT on the destination address of the packet addressed to the logical address D of tenant 6 received at the right network interface 412 of the left relay device 41 to the address of the left device 31 (step S72). Then, when the management device 11 inputs a setting to perform SNAT on the source address of the packet transmitted from the left network interface 411 of the left relay device 41 to the left device 31 to the logical address C of tenant 6 (step S73), the process of FIG. 19 ends.

[0054] FIG. 20 is a flowchart showing the route setting process for the right relay device 42. The management device 11 inputs a setting to perform DNAT on the destination address of the packet addressed to the logical address D of tenant 6 received at the right network interface 422 of the right relay device 42 to the address of the right network interface 62 of tenant 6 (step S80). Then, the management device 11 inputs a setting to perform SNAT on the source address of the packet transmitted from the left network interface 421 of the right relay device 42 to tenant 6 to the address of the left network interface 421 of the right relay device 41 (step S81).

[0055] The management device 11 inputs a setting to perform DNAT on the destination address of the packet addressed to the logical address D of tenant 6 received at the left network interface 421 to the address of the right device 32 for the right relay device 42 (step S82). Then, when the management device 11 inputs a setting to perform SNAT on the source address of the packet transmitted from the right network interface 422 to the right device 32 to the logical address D of tenant 6 for the right relay device 42 (step S83), it ends the process of FIG. 20.

[0056] FIG. 22 is a diagram showing a state in which tunnels 81 and 82 are established from the left and right devices 31 and 32 to the tap devices 63 and 64 of tenant 6. When a tunneling protocol addressed to the logical address C of tenant 6 is transmitted from device 31, it arrives at the network interface 61 of tenant 6 via relay device 41, and decapsulation is performed by tap device 63. Then, it is encapsulated by tap device 64 and transferred from network interface 62 to device 32 via relay device 42.

[0057] FIG. 23 is a diagram showing a specific setting example of the second embodiment. The configuration of FIG. 23 describes a configuration example in which the terminal 33 side uses GRE as the transfer protocol, the terminal 34 side does not use the transfer protocol, and directly routes IP packets. The router 35 and the subordinate terminal 33 correspond to the device 31 of the second embodiment. The protocol unit 43 corresponds to the relay device 41 of the second embodiment. The relay device 42 of the second embodiment is omitted, and the terminal 34 corresponds to the device 32 of the second embodiment.

[0058] For the terminal 33, a management device (not shown) executes the following commands. The following is an explanation of the command line for the console. In each command line, IP refers to the IP address. (1-1) Static routing setting route add -host {IP of Terminal 34} gw {IP of Router 35} For Router 35, a management device (not shown) executes the following commands. (2-1) Static Routing Configuration route add -host {Logical Address of Container 66} gw {IP of Protocol Unit 43} (2-2) GRE Tunnel Configuration: ip link add {IF Name} type gretap local {IP of Router 35} remote {Logical Address of Container 66} ip addr add {IP of GRE NIC} / 24 dev {IF Name} Here, the GRE NIC refers to Network Interface 351. (2-3) Static Routing Configuration route add -host {IP of Terminal 34} gw {IP of GRE NIC of Container 66} Here, the GRE NIC of Container 66 refers to Network Interface 663.

[0059] For Protocol Unit 43, a management device (not shown) executes the following commands. (3-1) Confirmation of Transfer Permission Setting Confirm that sysctl net.ipv4.ip_forward is set to 1 (3-2) Static Routing Configuration route add -host {IP of Terminal 33} gw {IP of Router 35} (3-3) NAT Conversion Setting on the NIC Connecting to Terminal 33 iptables -t nat -A PREROUTING -d {Logical Address of Tenant} -i {IF Name} -j DNAT --to-destination {IP of the First Multus NIC of Container 66} iptables -t nat -A POSTROUTING -s {IP of the first multus NIC of Container 66} -o {IF name} -j SNAT --to-source {tenant's logical address} Here, the first multus NIC of Container 66 refers to Network Interface 661.

[0060] (3-4) NAT conversion settings for the NIC connecting to Container 66: iptables -t nat -A PREROUTING -d {tenant's logical address} -i {IF name} -j DNAT --to-destination {IP of Router 35} iptables -t nat -A POSTROUTING -s {IP of Router 35} -o {IF name} -j SNAT --to-source {tenant's logical address} (3-5) Apply kernel modules to apply NAT conversion to GRE packets modprobe ip_gre modprobe nf_nat_proto_gre modprobe nf_conntrack_proto_gre

[0061] For Container 66, the management device (not shown) executes the following commands. (4-1) Static routing settings ip route add {tenant's logical address} / 32 via {protocol's IP} (4-2) GRE tunnel settings: ip link add {IF name} type gretap local {IP of Container 66} remote {tenant's logical address} ip addr add {IP of GRE NIC} / 24 dev {IF name} (4-3) Static routing settings: ip route add {IP of Terminal 34} / 32 via {IP of Router 35's GRE NIC} (4-4) Static Routing Setting ip route add {IP of Terminal 34} / 32 via {IP of Router 36}

[0062] For Router 36, a management device (not shown) executes the following command. (5-1) Transfer Permission Setting Check that sysctl net.ipv4.ip_forward is set to 1 (5-2) Static Routing Setting route add -host {IP of Terminal 33} gw {IP of the second multus NIC of Container 66} Here, the second multus NIC of Container 66 refers to Network Interface 662.

[0063] For Terminal 34, a management device (not shown) executes the following command. (6-1) Static Routing Setting route add -host {IP of Terminal 33} gw {IP of Router 36} Thereby, a tunnel 84 is constructed between Router 35 and Container 66.

[0064] (Modification Example) The present invention is not limited to the above-described embodiments, and can be implemented with modifications without departing from the spirit of the present invention. For example, there are the following (a) to (f). (a) The embodiments describe examples where both the left device 31 and the right device 32 use a tunneling protocol. However, a form in which an IP packet is directly transferred from a tenant (container) without using a tunneling protocol on only one side is also conceivable.

[0065] (b) The tunneling protocol of the left device 31 and the tunneling protocol of the right device 32 may be different protocols. (c) Since the setting instructions (step2 / step3) from the management device have no order, they may be executed in reverse order or simultaneously. (d) As a tenant, it may be a container, a Kubernetes (registered trademark) Pod, a virtual machine, or a physical device, etc.

[0066] (e) In addition to the function of setting the tenant (container) and the relay device when adding a tenant from the user as shown in the above embodiment, the management device may also have functions for deleting a tenant and relocating a tenant. (f) In addition to adding a tenant, the management device also has functions for deleting a tenant and relocating a tenant. The specific execution order is shown below.

[0067] 《Order of deleting a tenant》 (1) Delete the routing in the device or delete the setting of the tunneling protocol. (2) Delete the routing in the relay device or delete the NAT setting. (3) Delete the tenant (container).

[0068] 《Order of relocating a tenant》 (1) Newly place the tenant (container). (2) Switch the routing for the tenant (container) from the relay device from the old tenant (container) to the new tenant (container). At this point, the traffic switches to the new tenant (container) side. (3) Delete the old tenant (container).

[0069] With such settings, the router 35 transmits and receives packets of the tunneling protocol. The packets of the tunneling protocol arriving at the router 35 are transmitted and received between the protocol unit 43, which is a relay device, and the container 66 (tenant). Then, a virtual network device (tap device), not shown, constructed in this container 66 terminates the packets of the tunneling protocol.

[0070] 《Effect》 Hereinafter, the effects of the packet relay system and the like according to the present invention will be described.

[0071] <<Claim 1>> A tenant that constructs a plurality of virtual network devices that terminate a tunneling protocol, A relay device that connects the tenant to the outside, A management device that manages the tenant and the relay device and inputs settings for transmitting and receiving packets of the tunneling protocol between an external device connected to the relay device and the virtual network device, A packet relay system, characterized by comprising:

[0072] Thereby, by simply reconstructing the virtual network device, the packet transmission and reception of the previous tunneling protocol can be continued, so that the setting change and construction switching of this packet relay system can be flexibly implemented.

[0073] <<Claim 2>> Each of the virtual network devices is assigned a logical address, The packet relay system according to claim 1, characterized in that:

[0074] Thereby, by simply reassigning the logical address to the virtual network device, the packet transmission and reception of the previous tunneling protocol can be continued, so that the setting change and construction switching of this packet relay system can be flexibly implemented.

[0075] <<Claim 3>> Each of the virtual network devices is assigned a local address, The relay device DNATs a packet addressed to the logical address of the tenant received from the tenant to the address of the external device connected to the relay device, and SNATs the source address of a packet transmitted from the relay device to the external device to the logical address of the tenant, The packet relay system according to claim 1, characterized in that...

[0076] Thus, by simply reassigning the local address to the virtual network device, the packet transmission and reception of the previous tunneling protocol can be continued, so that the setting change and construction switching of this packet relay system can be flexibly implemented.

[0077] 《Claim 4》 The management device assigns a logical address to each of the virtual network devices, and when receiving a packet of the tunneling protocol from an external device connected to each of the relay devices, inputs a setting to terminate the tunneling protocol in the virtual network device. The packet relay system according to claim 1, characterized in that...

[0078] Thus, by simply reassigning the logical address to the virtual network device, the packet transmission and reception of the previous tunneling protocol can be continued, so that the setting change and construction switching of this packet relay system can be flexibly implemented.

[0079] 《Claim 5》 The management device assigns a local address to each of the virtual network devices, and inputs a setting for DNATting a packet addressed to the logical address of the tenant received from the tenant by the relay device to the address of the external device connected to the relay device, and a setting for SNATting the source address of a packet transmitted from the relay device to the external device to the logical address of the tenant. The packet relay system according to claim 1, characterized in that...

[0080] Thus, by simply reassigning the local address to the virtual network device, the packet transmission and reception of the previous tunneling protocol can be continued, so that the setting change and construction switching of this packet relay system can be flexibly implemented.

[0081] 《Claim 6》 The tenant is configured as any one of a container, a virtual machine, and a physical server. The packet relay system according to claim 1, characterized in that.

[0082] That is, the tenant is not limited to a container and may be configured by a virtual machine or a physical server.

[0083] 《Claim 7》 There are two virtual network devices. When one virtual network device receives a packet, it transfers the packet to the other virtual network device. The packet relay system according to claim 1, characterized in that.

[0084] Thereby, it is possible to transfer packets between virtual network devices and relay packets between opposing terminals.

[0085] 《Claim 8》 Steps of an external device transmitting and receiving packets of a tunneling protocol, Steps of a relay device relaying packets transmitted and received between a tenant and the external device, Steps of terminating a tunneling protocol on a virtual network device constructed on the tenant, A packet relay method characterized by executing.

[0086] Thereby, by simply reconstructing the virtual network device, the packet transmission and reception of the previous tunneling protocol can be continued, so that the setting change and construction switching of this packet relay system can be flexibly implemented.

Description of Signs

[0087] 1 Packet relay system 10 Transfer device 101, 102 Network interface 103 Routing table 11 Management device 12, 13 Router 2 Terminal 31, 32 Device 33, 34 Terminal 35, 36 Router 351 Network interface 41 Relay device 411, 412 Network interface 413 Routing table 42 Relay device 421, 422 Network interface 423 Routing table 43 Protocol section 5 Server 6 Tenant 61, 62 Network interface 63, 64 tap device 65 Routing table 66 Container 661~663 Network interface 7 Internet 8, 81~83 Tunnel

Claims

1. A tenant that has constructed a plurality of virtual network devices that terminate a tunneling protocol, A relay device that connects the tenant to the outside, A management device that manages the tenant and the relay device and inputs settings for transmitting and receiving packets of the tunneling protocol between an external device connected to the relay device and the virtual network device, Comprising: Each of the virtual network devices is assigned an IP address, When a packet addressed to the IP address of the first virtual network device constructed in the tenant arrives from an external device connected to the relay device, the relay device DNATs the destination address of the packet to the address of the external device, When relaying a packet to an external device, the relay device SNATs the source address of the packet transmitted from the relay device to the external device to the IP address of the second virtual network device constructed in the tenant, A packet relay system characterized by the above.

2. A tenant that has constructed a plurality of virtual network devices that terminate a tunneling protocol, A relay device that connects the tenant to the outside, A management device that manages the tenant and the relay device and inputs settings for transmitting and receiving packets of the tunneling protocol between an external device connected to the relay device and the virtual network device, Comprising: Each of the virtual network devices is assigned an IP address, When a packet addressed to the IP address of the second virtual network device constructed in the tenant arrives from an external device, the relay device DNATs the address to the address of the tenant's network interface provided in the link with the relay device, The relay device SNATs the source address of the packet relayed from the relay device to the tenant to the address of the network interface of the relay device provided in the link with the tenant, A packet relay system characterized by the above.

3. The IP address assigned to each of the virtual network devices is a local address used only within the packet relay system, The packet relay system according to claim 1, characterized by the above.

4. The management device assigns logical addresses to each of the virtual network devices, and when receiving a packet of a tunneling protocol from an external device connected to each of the relay devices, inputs settings to terminate the tunneling protocol at the virtual network device. The packet relay system according to claim 1, characterized in that.

5. The tenant is configured as any one of a container, a virtual machine, and a physical server. The packet relay system according to claim 1, characterized in that.

6. There are two virtual network devices. When one virtual network device receives a packet, it transfers the packet to the other virtual network device. The packet relay system according to claim 1, characterized in that.

7. Steps for an external device to transmit and receive packets of a tunneling protocol; Steps for a relay device to relay packets transmitted and received between a tenant and the external device; Steps for assigning an IP address to a virtual network device constructed on the tenant; Steps for terminating a tunneling protocol at the virtual network device constructed on the tenant; When a packet addressed to the IP address of the first virtual network device constructed on the tenant arrives at the relay device from an external device connected to the relay device, steps for DNAT-ing the destination address of the packet to the address of the external device; When the relay device relays a packet to an external device, steps for SNAT-ing the source address of the packet transmitted from the relay device to the external device to the IP address of the second virtual network device constructed on the tenant; A packet relay method characterized by executing the above.

8. Steps for an external device to transmit and receive packets of a tunneling protocol; Steps for a relay device to relay packets transmitted and received between a tenant and the external device; Steps for assigning an IP address to a virtual network device constructed on the tenant; Steps for terminating a tunneling protocol at the virtual network device constructed on the tenant; When a packet addressed to the IP address of the second virtual network device constructed for the tenant arrives from an external device, the relay device performs the step of DNAT to the address of the network interface of the tenant provided in the link with the relay device; The step of performing SNAT on the source address of the packet relayed from the relay device to the tenant to the address of the network interface of the relay device provided in the link with the tenant; A packet relay method characterized by executing the above.

Citation Information

Patent Citations

  • Data exchange system and method of setting environment enabling data exchange between virtual private clouds

    JP2014200010A

  • Communication control program, communication control method and communication control device

    JP2017224895A