Looking for breakthrough ideas for innovation challenges? Try Patsnap Eureka!

A proxy deployment system and method based on openstack

A deployment system and connection management technology, applied in the field of openstack-based proxy deployment systems, can solve problems such as hidden security risks, reduced proxy efficiency, and long forwarding paths, so as to improve operation and maintenance efficiency, improve proxy efficiency, and reduce workload Effect

Active Publication Date: 2020-01-14
WUHAN FIBERHOME INFORMATION INTEGRATION TECH CO LTD
View PDF8 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0004] (1) if figure 1 As shown, due to the design of the openstack architecture, the virtual machine can only communicate with the outside world through the business network, but the business network and the management network cannot communicate with each other, so the agent cannot communicate with the server, because the server is deployed in the operation and maintenance management area
If the system is to work normally, it is necessary to connect the management plane and the business plane, such as figure 2 As shown in the figure, a network cable is connected between the management firewall and the service firewall; however, this will leave potential safety hazards and does not meet the requirements of the third-level security protection
[0005] (2) if figure 2 As shown, in the case of forcibly connecting the management network and the business network, the proxy communicates with the server, and the data flow path becomes: proxy → business virtual switch → business access switch → business core switch → business firewall → management firewall → management Core switch → management access switch → server; the forwarding path is very long, which reduces the proxy efficiency and affects the network forwarding performance of the proxy virtual machine
[0006] (3) In the case of forcibly opening up the management network and the business network, it is necessary to set up corresponding firewall security policies to isolate the corresponding network segments, which increases additional configuration work. As the number of tenants increases, the policies also increase; Greatly increase the workload of operation and maintenance personnel in the later stage

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • A proxy deployment system and method based on openstack
  • A proxy deployment system and method based on openstack
  • A proxy deployment system and method based on openstack

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0038] The present invention will be described in further detail below in conjunction with the accompanying drawings and embodiments.

[0039] Such as image 3 As shown, the agent deployment system based on openstack of the present invention includes a server, a first management access switch, a second management access switch, a management core switch and at least one computing node; the server passes through the second management access switch Connect the management core switch, set the management firewall on the management core switch, and connect the management core switch to the first management access switch. Each computing node includes a user virtual machine, a business virtual switch (br-int), a proxy virtual machine, and a management virtual switch (br-mgnt); each computing node corresponds to a computing node management network card, and the computing node management network card is connected to the The port of the first management access switch, the management vir...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

An openstack-based agent deployment system and method, related to the field of cloud computing, including a server, a first management access switch, a second management access switch, a management core switch and at least one computing node, the server through the second The management access switch is connected to the management core switch, and the management core switch is connected to the first management access switch. It is characterized in that: each computing node includes a proxy virtual machine and a management virtual switch, and the proxy management network card of the proxy virtual machine is bound to the management A virtual switch: each computing node corresponds to a computing node management network card, the computing node management network card is connected to the port of the first management access switch, and the management virtual switch is bound to the computing node management network card. The invention meets the requirements of the third-level security guarantee, reduces the forwarding path, improves the network forwarding performance, and reduces the workload of operation and maintenance personnel in the later stage.

Description

technical field [0001] The invention relates to the field of cloud computing, in particular to an openstack-based agent deployment system and method. Background technique [0002] When building a cloud computing IAAS (Infrastructure as a Service) based on openstack, some agents, such as monitoring agents, antivirus agents, and database auditing, need to be deployed if the Class III security requirements are met. In general, when deploying a cloud computing IaaS platform that meets the Class III security requirements, the network must be divided into three networks: management network, business network, and storage network, and the three networks must be isolated from each other. [0003] Such as figure 1 As shown, in a cloud data center that meets the third-level security guarantee, the operation and maintenance monitoring management system, database audit system, and cloud anti-virus system must be deployed in the operation and maintenance management area, and these system...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L12/46H04L12/931H04L12/933H04L12/935H04L29/06H04L29/08H04L49/111
CPCH04L12/4641H04L49/10H04L49/15H04L49/30H04L49/70H04L63/02H04L67/1001H04L67/56
Inventor 胡新辉田松
Owner WUHAN FIBERHOME INFORMATION INTEGRATION TECH CO LTD
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Patsnap Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Patsnap Eureka Blog
Learn More
PatSnap group products