Abstract: The objective of the invention is to reduce the power required to set virtual local area network (VLAN) information to be transmitted to the port of a communication node in a centralized control type of communication system. A control apparatus comprises: a connection detecting unit that detects the connection of a terminal or virtual machine to a communication node to be controlled; a first VLAN information determining unit that determines , on the basis of a virtual network to which the detected terminal or virtual machine belongs, VLAN information to be set to the port of the communication node to which the terminal or virtual machine is connected; and a VLAN setting unit that sets the determined VLAN information to the port.
1. A c o n t r o l a p p a r a t u s , c o m p r i s i n g : a c o n n e c t i o n d e t e c t i o n unit configured t o d e t e c t connection of a terminal or a v i r t u a l machine t o a c o n t r o l target communication node; a f i r s t VLAN i n f o r m a t i o n d e t e r ~ n i n a t i o n unit configured to deternline VLAN (Virtual L o c a l A r e a Network) infornlation that i s s e t in a p o r t of the c o m m u n i c a t i o n n o d e , the port having been connected to the t e r m i n a l or the v i r t u a l machine, on the b a s i s of a v i r t u a l network to which the d e t e c t e d terlninal o r v i r t u a l niachine belongs; and a VLAN i n f o r m a t i o n s e t t i n g u n i t c o n f i g u r e d to set the determined VLAN i n f o r n i a t i o n i n t h e p o r t .
2. The c o n t r o l a p p a r a t u s a c c o r d i n g to claitn 1; wherein the f i r s t VLAN i n f o r m a t i o n d e t e r t n i n a t i o n unit deternlines the VLAN inforniation if the port to which t h e t e r m i n a l h a s been c o n n e c t e d i n c l u d e s a f u n c t i o n of dropping a p a c k e t in w11ich s p e c i f i e d VLAN infornlation i s n o t s e t instead of t r a n s t n i t t i n g the packet.
3. 'The c o n t r o l a p p a r a t u s a c c o r d i n g to clainl 1 or 2; wherein the f i r s t VLAN i n f o r m a t i o n d e t e r m i n a t i o n unit determines the VLAN i n f o r ~ n a t i o n i f t h e port to which the t e r m i n a l has becn c o n n e c t e d i n c l u d e s a f u n c t i o n of dropping, when r e c e i v i n g a packet in w h i c h s p e c i f i e d VLAN i n f o r m a t i o n i s not s e t , the p a c k e t .
4. The c o n t r o l a p p a r a t u s a c c o r d i n g t o a n y one o f c l a i m s 1 to 3; \vhcrein the VLAN i n f o r m a t i o n s e t t i n g unit sets the VLAN i n f o r m a t i o n by t r a n s m i t t i n g a c o n t r o l nlcssage f o r c a u s i n g thc c o n t r o l target c o ~ n i n u n i c a t i on~o~de to sct the VLAN infornlation in a s p e c i f i e d port.
5. Tlic c o n t r o l a p p a r a t u s a c c o r d i n g to any one of clainis 1 to 4, further c o n ~ j ~ r i s i ~ ~ g : a s e c o n d VLAN i n f o r n l a t i o n d e t e r m i n a t i o n unit configured to detcrniirie VLAN inforniation that i s set in a p o r t of the control t a r g e t conimunication node, the port connected to an e x t e r n a l apparatus, on the basis o f v i r t u a l network c o n f i g u r a t i o n i n f o r n i a t i o n and topology i n f o r m a t i o n received froni the c o n t r o l target conimunication node.
6. The control apparatus according to any one of claims 1 to 5; wherein, on the basis of t h e v i r t u a l network configuration information and t h e topology infornlation received from the control target communication node, VLAN information is set in ports connecting control target con~munication nodes.
7. The c o n t r o l apparatus according to any o ~ i co f claini~s1 to 6; wherein the connection d e t e c t i o n unit detects connection of a t e r ~ n i n a lo r a virtual machine by receiving a c o n t r o l information settirig r e q u e s t from t h e control target comniunication node.
8. A com~nunications ysteni, coniprisitlg: a communication node configured to i n c l u d e a functiotl of dropping, when receiving an i n s t r u c t i o n f o r t r a n s m i t t i n g a packet i n which s p e c i f i e d VLAN (Virtual Local Area Network) informatioti is not s e t via a c e r t a i n port, the packet or a f u n c t i o n o f dropping, when receiving a packet i n ~ v h i c hs pecified VLAN information is not set via a c e r t a i n p o r t , t h e packet; and a c o n t r o l a p p a r a t u s , comprising: a connection d e t e c t i o n unit configured to detect connectiotl o f a terniinal or a v i r t u a l machine to t h e s p e c i f i e d port of the communication node; a first VLAN infortilation determination unit configured to determine VLAN i n f o r ~ l i a t i o nt hat is s e t i n a port of the conl~nunication node, the port having been cotinected to the terminal or the virtual tilachine, on the basis of a virtual network to whicli t h e detected terminal o r virtual machine belongs; and a VLAN information setting unit configured to set the determined VLAN information in the port.
9. A c o m ~ i ~ u n i c a t i onno de control metl~od,c omprising steps of: detecting c o n n e c t i o ~ lo f a t e r ~ i ~ i n aolr a virtual macl~inet o a control target c o ~ i ~ r n u n i c a t i on~odi e; determining VLAN (Virtual Local Area Network) i n f o r ~ ~ i a t i o n t h a t i s s e t in a p o r t o f the conlmunication node, the port having been connected to the t e r ~ l i i n a l or the v i r t u a l machine, on the basis o f a virtual network to w h i c l ~ the detected ternlinal or virtual machine belongs; and setting the d e t e r ~ n i n e dV LAN information in t h e p o r t .
10. A program, causing a c o n i l ~ t ~ t etrh at controls communication nodes to execute p r o c e s s i n g f o r : detecting connection of a terlililial or a virtual ~ n a c h i n e to a control target c o n i ~ n u l i i c a t i o ~nio de; determining VLAN (Virtual Local Area Network) i n f o r m a t i o n t h a t i s s e t i n a port o f t h e commullicatioll node, the port having been conliected to tlie terminal or tlie virtual machine, 011 the basis of a v i r t u a l network to which tlie detected terlninal or virtual machine belongs; and setting the deterlilined VLAN inforlnatioli in the port.
TITLE:
CONTROL APPARATUS, COMMUNICATION SYSTEM,
COMMUNICATION NODE CONTROL METHOD, AND PROGRAM
TECHNICAL FIELD
[OOOl]
(REFERENCE TO RELATED APPLICATION)
The present i n v e n t i o n is based upon and clainls the b e n e f i t o f the
priority o f Japanese patent application No. 2012-288378, filed on
Decetiiber 28, 2012, tlie disclosure o f w h i c h i s incorporated herein i n i t s
e n t i r e t y by r e f e r e n c e t h e r e t o .
The present i n v e n t i o n relates to a control apparatus, a co~iiniunicatioti
s y s t e m , a c o l n n ~ u n i c a t i o n node c o ~ l t r o l metliod, and a program. In
particular, it relates t o : a control apparatus t h a t c o n t r o l s conitiiunication
nodes in a centralized tnanner; a c o t n ~ n u n i c a t i o n s y s t e m ; , a
c o m m u ~ i i c a t i o nn ode coritrol method; and a program.
BACKGROUND
[0002]
Tn Non-patent Literatures 1 and 2 , a technique referred to as
OpenFlo\\r has been proposed. OpenFlow recognizes communications
as end-to-end flows and performs path c o n t r o l , failttre recovery, load
balancing, and optinlization on a per-flow basis. Each OpenPlow
switch according to Noti-patent Literature 2 has a secure channel f o r
communication w i t h an OpenFlow controller and opcrates according to a
flow table suitably added or rewritten by the OpenFlow controller. 111
the flow t a b l e , a set o f tlie following three i s d e f i n e d for each f l o w :
match conditions (Match Fields) against which a packet header is
matched; flow statistical infornlation ( C o u n t c r s ) ; and i n s t r u c t i o n s that
define at least one processing content ( s e e section " 5 . 2 F l o ~ v Table" in
Non-patent Literature 2 ) .
[0003]
For example, wlien an OpenFlow sxvitch receives a packet, tlie
OpenFlo\v s w i t c h s e a r c h e s the f l o w t a b l e for an e n t r y having a match
condition t h a t nlatchcs header infortnation of the received packet (see
" 5 . 3 "Matching" in Non-patent L i t e r a t u r e 2). If, as a result of tile
search, the OpcnFlow switch finds an e n t r y t h a t matches the received
packet, the OpenFlow switch updates the flow s t a t i s t i c a l i n f o r m a t i o n
(Counters) and p r o c e s s e s t h e reccived packet on the basis of a
processing content(s) (packet transmission froin a specified port,
f l o o d i n g , d r o p p i n g , e t c . ) written in the I n s t r u c t i o n s field of t h e e n t r y .
I f , a s a result o f t h e s e a r c h , t h e OpenFlow s\vitch does not find an entry
that matches the received packet, the OpenFlow switch transmits an
entry setting request to the OpenFlow controller v i a t h e s e c u r e c h a n n e l .
Namely, the OpenFlow s w i t c h r e q u e s t s the OpenFlow c o n t r o l l e r to
t r a n s m i t c o n t r o l information for p r o c e s s i n g t h e received packet
(Packet-In message). The OpenFlow switch r e c e i v e s a f l o w e n t r y that
d e f i n e s a p r o c e s s i n g content(s) and updates the flow table. In this way,
by using an entry stored in the flow table as control information, t h e
OpenFlow switch perfornls packet for\varding.
[0004]
I11 addition, Exanlple 2 in Non-patent Literature 1 d e s c r i b e s t h a t a
v i r t u a l network such as a VLAN ( V i r t u a l Local Area Network) call be
established by conlbining OpcnFlow switchcs and an OpcnFlow
c o n t r o l l e r that controls the OpenFlow switches in a c e n t r a l i z e d manner.
[0005]
I11 a d d i t i o n , t h e specification in Non-patent L i t e r a t u r e 2
describes that a c o n t r o l nlessage for an a d d i t i o n a l f u n c t i o n , which is
referred t o a s a n "Expermenter tnessage," can be exchanged between the
OpenFlow c o n t r o l l e r and an OpenFlow switch ("A.5.4 Expermcnter" in
Non-patent Literature 2).
CITATION LIST
PATEN?' LITERATURE
[0006]
Non-patent Literature 1:
Nick McKeown, and seven others, "OpenFlo\\~: Enabling Innovation in
Campus Net\vorks," [ o n l i n e ] , [searched on November 24, 20121, Internet
Non-patent Literature 2:
"OpenFlow Switch S p e c i f i c a t i o n " Version 1.3.1 (Wire Protocol Os04),
[online], [searched on Deceniber 11, 20 121, Internet IURL:
littps://w\\~w.ope~~~~et\vorki~ig.orgli~nageslstoriesldow~~loads/specificatio
nlopenflo\\r-spec-vl.3.1 .pdf>
SUMMARY
TECHNICAL PROBLEM
[0007]
The f o l l o w i n g a n a l y s i s h a s been given by t h e p r e s e n t i n v e n t o r s .
The above Non-patent Literatures 1 and 2 d i s c l o s e t h a t a v i r t u a l network
c a n b e established by s e t t i n g VLAN information as niatch conditions in
entries s t o r e d i n flow t a b l e s i n OpenFlow switches (which will simply
be referred to as a " s w i t c h , " as needed), respectively.
[OOOS]
However, anlong such switches that can configure a virtual
network by using OpenFlow, there are some s w i t c h e s whose p o r t needs
to be associated with appropriate VLAN information. Thus, when a11
unknown terminal or v i r t u a l machine i s connected to a n y o f the switches
or when change i s made in the configuration of t h e n e t w o r k , a p p r o p r i a t e
VLAN information n e e d s t o be associated nlith the relevant sxvitch
Some of the switches \vliose port needs to bc associated \\~itli
appropriate VLAN infornlation iticlutle a f u n c t i o n of dropping a packet
including VLAN information inappropriate i n r e l a t i o n t o a
c o r r e s p o n d i n g e g r e s s p o r t . I11 a d d i t i o n , some switches include a
function of dropping, when receiving a packet i n which specified VLAN
information is n o t s e t , t h e p a c k e t . These functions can be used in
place of flow entries for dropping packets having VLAN infortnation
inappropriate in relation to a port. Thus, these f ~ ~ n c t i o ncosn tribute to
reducing the nunnber of flow e n t r i e s stored in each switch and improving
the response of each switch.
[OOl 01
An o b j e c t o f the p r c s c n t i n v e n t i o n i s to provide a c o n t r o l
a p p a r a t u s , a c o ~ i l ~ i l u n i c a t i o nsy stem, a c o ~ i ~ ~ i i u n i c a t inoond e c o n t r o l
metliod, and a program t h a t c o n t r i b u t e to reducing tlie l a b o r r e q u i r e d for
s e t t i n g VLAN i n f o r n l a t i o n in the p o r t s of tlie c o ~ n ~ n u n i c a t i onno des in a
c e n t r a l i z e d - c o n t r o l - t y p e c o m m u n i c a t i o n s y s t e ~ na s t y p i f i e d by a system
using the above OpenFlow.
SOLUTION TO PROBLEM
[OOll]
According to a f i r s t a s p e c t , t h e r e i s p r o v i d e d a c o n t r o l a p p a r a t u s ,
i n c l u d i n g : a c o n n e c t i o n d e t e c t i o n u n i t configured to d e t e c t connection
of a t e r m i n a l or a v i r t u a l ~ i i a c h i n e to a c o n t r o l t a r g e t conimunication
node; a f i r s t VLAN i n f o r n i a t i o n d e t e r m i n a t i o n unit configured to
determine VLAN (Virtual L o c a l A r e a Network) i n f o r m a t i o n t h a t i s s e t in
a p o r t of the communication node, the p o ~ hta v i n g b e e n c o n n e c t e d to the
t e r m i n a l o r t h e v i r t u a l m a c h i n e , on the basis of a v i r t u a l n e t w o r k to
\vhich the d e t e c t e d t e r m i n a l or v i r t u a l machine b e l o n g s ; and a VLAN
i n f o r m a t i o n s e t t i n g unit configured to set the d e t e r m i n e d VLAN
i n f o r m a t i o n in the port.
[0012]
According to a s e c o n d a s p e c t , t h e r e i s provided a c o m n i u n i c a t i o n
s y s t e m , i n c l u d i n g : a c o n ~ n ~ u n i c a t i ono de configured to include a
f u n c t i o n o f dropping, when r e c e i v i n g a n i n s t r u c t i o n f o r t r a n s n i i t t i n g a
packet in which s p e c i f i c d VLAN ( V i r t u a l L o c a l A r e a Nctwork)
i n f o r m a t i o n is not set v i a a c e r t a i n p o r t , t h e packet or a f u n c t i o n of
dropping, when r e c e i v i n g a p a c k e t in which s p e c i f i e d VLAN
i n f o r ~ i l a t i o n is not s e t v i a a c e r t a i n p o r t , t h e p a c k e t ; and a c o n t r o l
a p p a r a t u s , i n c l u d i n g : a c o ~ i n c c t i o n d e t e c t i o n unit configured to d e t e c t
connection of a t e r m i n a l or a v i r t u a l machine to the s p e c i f i e d port of tlie
c o m m u ~ i i c a t i o n n o d e ; a f i r s t VLAN i n f o r ~ i ~ a t i o nd e t e r m i n a t i o n unit
configured to determine VLAN i n f o r m a t i o n that is s e t i n a p o r t o f the
communication nodc, the port having been connected to the ternlinal or
the v i r t u a l m a c h i n e , o n t h e b a s i s of a v i r t u a l network to which the
d e t e c t e d t e r m i n a l or v i r t u a l m a c h i n e belongs; and a VLAN i n f o r m a t i o n
s e t t i n g unit configured t o s e t t h e d e t e r m i n e d VLAN i n f o r n l a t i o n i n t h e
port.
[00 131
According to a third aspect, there is provided a c o ~ n ~ n u n i c a t i o n
node control method, includiag steps o f : d e t e c t i n g c o ~ i ~ i e c t i oo~f l a
terminal or a virtual ~ n a c h i n et o a c o n t r o l target c o ~ n m u n i c a t i o ~nio de;
determining VLAN (Virtual Local Area Network) i ~ i f o r n ~ a t i othna t is set
in a p o r t o f the c o n ~ n ~ u ~ l i c a tni oond e , t h e port having been connected t o
the ternlinal or the virtual ~ n a c h i ~ loen, t h e b a s i s of a v i r t u a l network to
which t h e d e t e c t e d t e r m i n a l o r virtual machine belongs; and s e t t i n g the
determined VLAN information in t h e p o r t . This method is associated
with a c e r t a i n tnachine, namely, with a c o n t r o l a p p a r a t u s t h a t s e t s VLAN
information in ports of c o ~ i l ~ n u n i c a t i onno des.
[00 141
According to a f o u r t h a s p e c t , there is provided a program,
c a u s i n g a colnputer t h a t c o n t r o l s commu~iication nodes to e s e c u t e
processing for: detecting co~itiection of a terininal or a virtual machine
to a c o n t r o l t a r g e t communicatio~l node; determining VLAN (Virtual
Local Area Network) informatioti that is set in a port of the
communication node, the port having beer1 connected t o t h e ternlinal or
the virtual machine, on the basis of a virtual network t o which the
detected terininal or virtnal machine belongs; and s e t t i n g thc
determined VLAN information in the port. 'This program c a n b e
recorded in a c o ~ n p u t e r - r e a d a b l e ( n o n - t r a n s i e a t ) s t o r a g e medium.
N a ~ n e l y ,t he present invention can be e ~ n b o d i e da s a c o ~ i l p u t e rp rogram
product.
ADVANTAGEOUS EFFECTS OF INVENTION
[00 151
The present invention contributes to reducing the l a b o r r e q u i r e d
for s e t t i n g VLAN i n f o r ~ n a t i o ni n the ports of the coii~~~municatinoond es
in a c e n t r a l i z e d - c o n t r o l - t j ~ p ec ommt~nications ystem.
BRIEF DESCRIPTION OF TI-IE DRAWINGS
[0016]
[Fig. I ]
Fig. 1 i l l u s t r a t e s a cotlfiguration of all e s e ~ i l p l a r ye mbodiment according
t o the present invention.
[Fig. 21
Fig. 2 i l l u s t r a t e s a configuration of a conl~nunication system according
to a f i r s t exemplary embodiment of the present invention.
[Fig. 31
Fig. 3 is a b l o c k diagram i l l u s t r a t i n g a configuration of a c o n t r o l
a p p a r a t u s a c c o r d i n g t o the first exenlptary etnbodinlent of t h e p r e s e n t
invention.
[Fig. 41
Fig. 4 i l l u s t r a t e s an exemplary topology e s t a b l i s h ~ n e n t operation
performed by the c o n t r o l a p p a r a t u s a c c o r d i n g t o the first exemplary
e~nbodiment of the present invention.
[Fig. 51
Fig. 5 i l l u s t r a t e s an e x e ~ n p l a r y configuration of a virtual network
configured by comn~utiication nodes a c c o r d i n g t o t h e f i r s t exenlplary
etnbodinlent of the present invention.
[Fig. 61
Fig. 6 i l l u s t r a t e s exenlplary VLAN gate control inforniation s t o r e d i n a
v i r t u a l network DB according to tlie f i r s t exemplary embodi~nent of the
present invention.
[Fig. 71
Fig. 7 i l l u s t r a t e s an exemplary VLAN i n f o r m a t i o n s e t t i n g operation
performed by the control a p p a r a t u s a c c o r d i n g t o the f i r s t exemplary
e~nbodiment of the present invention.
[Fig. 81
Fig. 8 i l l u s t r a t e s an operation performed when a communication node
receives a p a c k e t fro111 a terminal A accordirig to the first exemplary
embodiment of the present invention.
[Fig. 91
Fig. 9 i l l u s t r a t e s an exemplary operation of c a l c u l a t i n g a path
perfornled by the c o n t r o l a p p a r a t u s a c c o r d i n g to tlie first exemplary
embodiment of tlie present invention.
[Fig. 101
F i g . 10 i l l u s t r a t e s an exetnplary operation of setting VLAN information
in an entry conlnlunication node perforined by the control a p p a r a t u s
according to the f i r s t exeinplary e i n b o d i ~ n e n t of the p r e s e n t i n v e n t i o n .
[Fig. 111
Fig. 11 i l l u s t r a t e s a n e x e m p l a r y o p e r a t i o n of s e t t i n g VLAN i n f o r m a t i o n
in i n t e r f a c e s between c o m m u n i c a t i o n n o d e s performed by the c o n t r o l
a p p a r a t u s a c c o r d i n g to the f i r s t exetnplary cinbodiinent of the p r e s c n t
i n v e n t i o n .
[Fig. 121
Fig. 1 2 i l l u s t r a t e s a n o t h e r exenlplary o p e r a t i o n o f c a l c u l a t i n g a path and
of s e t t i n g VLAN i n f o r m a t i o n in an entry c o r n ~ n u ~ ~ i c antoidoe~ p~e rformed
by the control a p p a r a t u s a c c o r d i n g to the f i r s t exemplary e n l b o d i i n e ~ l t of
the p r e s e n t i n v e n t i o n .
[Fig. 131
Fig. 13 i l l u s t r a t e s another exeinplary o p e r a t i o n of s e t t i n g VLAN
infortnation in i n t e r f a c e s between c o m m u n i c a t i o n n o d e s perfornled by
the c o n t r o l a p p a r a t u s a c c o r d i n g to t h e f i r s t cxemplary embodiment o f
the present i n v e n t i o n .
[Fig. 141
Fig. 1 4 i l l u s t r a t e s VLAN i n f o r m a t i o n set in the i n t e r f a c e s o f the
c o t n ~ n u n i c a t i o n n o d e s a c c o r d i n g to the f i r s t e x e m p l a r y etnbodiment o f
the present i n v e n t i o n .
MODES FOR CARRYING OUT THE INVENTION
[00 171
F i r s t , an o u t l i n e of an exemplary embodiment o f the p r e s e n t
i n v e n t i o n will b e d e s c r i b e d with r c f c r c n c c t o a drawing. I n t h e
follo\ving o u t l i n e , v a r i o u s c o m p o n e n t s are denoted by r e f e r e n c e
c h a r a c t e r s f o r t h e sake of c o n v e n i e n c e . Namely, the f o l l o w i n g
reference c h a r a c t e r s are merely used as examples to f a c i l i t a t e
u n d e r s t a n d i n g of the p r e s e n t i n v e n t i o n , n o t t o l i ~ n i t t h e p r e s e n t
i n v e n t i o n t o t h e i l l u s t r a t e d m o d e s .
[00 181
As i l l u s t r a t e d in Fig. 1 , an exenlplary embodinlent of the p r e s e n t
i n v e n t i o n can b e r e a l i z e d by a c o n f i g u r a t i o n i n c l u d i n g : a p l u r a l i t y of
c o m m u n i c a t i o n n o d e s 2 0 ; and a c o n t r o l a p p a r a t u s 10 that c o n t r o l s t h e s e
c o ~ n ~ n ~ ~ n i cnaotdieos ~2~0. More specifically, the c o n t r o l a p p a r a t u s 10
i n c l u d e s : a collnection d c t c c t i o n u n i t 11 configured to detect connection
of a terminal or a virtual machine to a control t a r g e t communication
node 2 0 ; a first VLAN illforrnation d e t e r n l i n a t i o ~u~n it 12 configured to
determine VLAN (Virtual Local Area Network) i n f o r m a t i o n t h a t is set in
a port of the c o n ~ n ~ u t ~ i c a tni odne , the port having been connected to the
terminal or the v i r t u a l machine, on thc basis of a virtual network to
which the detected terrninal o r v i r t u a l machine belongs; and a VLAN
i n f o r ~ n a t i o n s e t t i n g u n i t 13 configured to s e t t h e deternlined VLAN
infortnation in t h e p o r t . When the VLAN i n f o r m a t i o n s e t t i n g unit 13
instructs a c o n ~ n ~ u n i c a t i onno de to set the VLAN i n f o r n ~ a t i o ni n the
specified port, a c o n t r o l message f o r an a d d i t i o n a l f u n c t i o n , which is
r e f e r r e d t o a s a n "Expermenter message" i n Non-patent Literature 2, can
be used. A l t e r n a t i v e l ~ l , a network setting protocol such as NETCONF
may be used. Alternatively, the VLAN infornlation tnay be set via an
external system.
[00 191
With this configuration, at least, appropriate VLAN infornlation
is set in a c o ~ n ~ n u n i c a t i onno de port to which a t c r n ~ i n a lo r a v i r t u a l
machine has been connected. Namely, when connection o f a n unknown
terminal or virtual nlachine t o a c o n ~ m u ~ ~ i c a t inoond e is detected,
a p p r o p r i a t e VLAN i n f o r m a t i o n is automatically set. T h u s , t h e labor on
the network administrator or the like can be reduced.
[0020]
As will be described belo\?!, to detect connection of a ternlinal or
a virtual nlachine, t h e c o n n e c t i o n detection unit 11 may be notified by
each c o ~ ~ ~ ~ n u n i c antoidoen of reception of a new packet. Alternatively,
the c o n n e c t i o n d e t e c t i o n unit 1 1 may b e n o t i f i e d by a virtual network
management a p p a r a t u s , a v i r t u a l machinc nlanagement apparatus, or the
like.
[002 11
[First exetnplary embodiment]
N e x t , a first exelnplary enlbodiincnt of thc p r e s e n t invention will be
dcscribed in detail \vith reference to the drawings. F i g . 2 i l l u s t r a t e s a
configuration o f a communication systetn accordi~ig t o a f i r s t exeniplary
embodiment o f tlie present invention. F i g . 2 i l l u s t r a t e s a plurality o f
c o l i i ~ n u ~ i i c a t i onno des 200A to 200C tliat are connected to each other t o
configure a tietwork (any one o f the c o r n ~ n u ~ i i c a t i ono~di es 200A to 200C
will be referred to as a " c o l i l ~ i i u ~ i i c a t i o n ode 200" unless tlie
comniunication nodes 2 0 0 A t o 200C need t o b e distinguished from eacli
o t h e r ) , a c o ~ i t r o l apparatus 100 tliat controls the network by setting
control i ~ i f o r n ~ a t i oi n~ it hese c o ~ i ~ r n u n i c a t i onno des 200, and a terminal
and a server that communicate with eacli other via tlie network
configured by the communication n o d e s 2 0 0 .
[0022]
Each c o ~ i l n i u ~ i i c a t i onno de 200 processes a packet by referring to
its own flow entry that is set as control i n f o r m a t i o n . An OpenFlow
switcli in Non-patent Literature 2 call be used as each communication
node. In a d d i t i o n , e a c h communication node 200 accordilig to the
present e x e m p l a r y embodiment includes a futiction o f dropping a packet,
t o w h i c h s p e c i f i e d VLAN i n f o r ~ n a t i o nis not set, instead o f outputting
the packet from a certain port ( t h i s function w i l l b e referred to as a
"VLAN gate f u t i c t i o n " ) . Each c o ~ n l i l ~ ~ n i c a t inoo~die 200 may be a
physical switcli or a virtual switch t l i a t operates on a virtual server or
tlie l i k e .
[0023]
The control apparatus I00 controls tlie cotnmunication nodes 200
by setting flo\v entries as control information in the communication
nodes 200. The OpetiFlow c o ~ i t r o l l e r in Non-patent Literature 2 can be
used as the c o ~ i t r o l apparatus.
[0024]
Fig. 3 i s a b l o c k diagram illustrating a c o n f i g u r a t i o n o f the
c o ~ i t r o l apparatus 100 according to the first esemplary e m b o d i ~ n e n t o f
tlie present i n v e n t i o n . As illustrated ill Fig. 3, the c o ~ i t r o l apparatus
100 includes a path c a l c u l a t i o n u n i t 1 0 1 , a control i n f o r m a t i o n
generation unit 102, a f i r s t VLAN information determination unit 103, a
second V L A N information determination u n i t 104, a topology
e s t a b l i s h t n e ~ l t unit 105, a virtual network database ( v i r t u a l net\vork
DB) 106, a physical topology database ( p h y s i c a l topology DB) 107, and
a communication unit 108 t h a t exchanges various types of c o ~ i t r o l
messages with each co~nmunication node 200 (corresponding to the
above VLAN information s e t t i n g u n i t 13).
[0025]
The topology establishmerlt unit 105 causcs t h e communication
nodes 200 to transmit topology check packets via the co~nmunication
unit 108. On the basis of thc result of t h i s o p e r a t i o n , t h e t o p o l o g y
establishment unit 105 e s t a b l i s h e s a network topology configured b y t h e
corn~nunication nodes 200 and s t o r e s the topology in the physical
topology database ( p h y s i c a l topology DB) 107.
[0026]
Fig. 4 i l l u s t r a t e s an exemplary t o p o l o g y e s t a b l i s h m e n t operation
performed by the control apparatus. In the example in Fig. 4, when the
c o n t r o l a p p a r a t u s 100 tratisnlits a t o p o l o g y check packet transmission
i n s t r u c t i o n t o t h e con~muilication node 200C, t h e communication node
200C tratismits a topology check p a c k e t from each of t h e p o r t s other
than the port that has reccivcd the topology check packet t r a n s m i s s i o n
i n s t r u c t i o n ( i f ally one of the p o r t s o u t p u t t i n g a topology check packet
includes the VLAN g a t e f u n c t i o n , the control apparatus 100 may
iustruct t r a n s n l i s s i o ~ i of a topology check packet in which a p p r o p r i a t e
VLAN information is set or outputting of a packet instructed by the
c o ~ ~ t r oapl paratus 100 rnay be eseinpt from the VLAN g a t e f u n c t i o n ) .
By detecting t h a t the c o ~ n ~ n u ~ i i c a t i~oi~oid e s 200A and 200B have
received the topology check packet fro111 the c o ~ n ~ n u ~ l i c a tniood~el 200C,
the c o n t r o l a p p a r a t u s 100 call establish thc llctwork topology configured
by the c o m ~ ~ ~ u n i c a t iloiond es 200. The control apparatus 100 may
e s t a b l i s h t h e network topolog). by u s i n g a method other tlian the above
method. For example, t h e c o n t r o l apparatus 100 may d e t e c t t h e
topology by using I,I,DP (Link Layer Discovery Protocol) or another
r o u t i n g p r o t o c o l .
[0027]
In addition, it i s p r e f e r a b l e that the control apparatus 100 collcct
information about the capability of each c o n l ~ n u ~ l i c a t i on~old e 200, in
addition to the information about t h e topology of the c o ~ i ~ ~ ~ i u n i c a t i o n
nodes 200. 111 this way, the c o n t r o l apparatus 100 c a n a u t o m a t i c a l l y
c o l l e c t information about the ports of the communication nodes 200 and
whether each p o r t includes the VLAN gate function.
[0028]
The virtual netlvork DB 106 is a database s t o r i n g i n f o r ~ ~ l a t i o ~ i
about a configuration of a v i r t u a l network configured by con~munication
nodes 200.
[0029]
Fig. 5 i l l u s t r a t e s an exenlplary c o ~ i f i g u r a t i o ~o fl a virtual net\vork
configured by c o ~ n ~ n u n i c a t i o nn odes 200 according to the first
exenlplary embodinlent of the p r e s e n t i n v e n t i o n . In the example in Fig
5, a v i r t u a l network including a v i r t u a l bridge 300 virtually configured
by controlling the comniunication nodes 200A to 200C is i l l u s t r a t e d .
Two endpoints of the v i r t u a l bridge are mapped with c e r t a i n p o r t s of the
c o n ~ m u ~ l i c a t i onno des 200A and 200C. By mapping a v i r t u a l network
with ports of the con~munication nodes 200A and 200C i n t h i s way, a
plurality of virtual letw works l o g i c a l l y separated from a single physical
network can be established.
[0030]
Fig. 6 i l l u s t r a t e s exemplary VLAN gate c o n t r o l information
stored in the virtual net\vork DB 106 according to the first exemplar)^
embodiment of the present i n v e n t i o n . I n t h e example i n F i g . 6, a gate
VLAN ID set on each t e r ~ n i n a l side, a core VLAN ID set in ports
connecting comnlunication nodes, and a server-side gate VLAN ID are
associated with each other pcr virtual network. For e x a n ~ p l e , a
co~nmunication through a virtual uetwork A whose VLAN ID is 100 and
a communication illrough a virtual netwo1.k B wllose VLAN ID is 300 are
aggregated to a con~munication having a shared core VLAN ID of 4094
in a c o r e network configured by the commnnication nodes 200A to 200C.
Thus, the VLAN ID of 4094 needs to be set in a core-net\vork,side port
o f a n e n t r y - s i d e comnlunication node. In this way, by using tllc above
VLAN gate function, the entry-side comn~unication node can drop a
packet which is addressed to a destination beyond the core network and
which does not i n d i c a t e t h e VLAN ID o f 4094. L i k e w i s e , the VLAN ID
o f 200 needs t o b e set i n a port o f an e x i t - s i d e communication node, the
port beiug connected to the server. In t h i s way, l i k e w i s e , an e x i t - s i d e
c o m m u ~ l i c a t i o nn ode c a n drop a packet which is addressed to the scrver
side and which does not indicate the VLAN ID o f 200. T h u s , according
to the present exemplary etnbodiment, s i n c e t h e r e is no need to set
control i n f o r m a t i o n ( f l o ~ v e n t r i e s ) for dropping packets in which
appropriate VLAN ID is not set, the number o f flow entries set in the
comnlunication n o d e s c a n be reduced.
[003 11
In addition, as described above, by using a certain shared VLAN
ID in the core network, the number o f flow entries set i n the
communication nodes 200 can be reduced. In a d d i t i o n , t h e r e d u c t i o n
in the number o f flow entries makes i t easier to implement the control
apparatus 100.
100321
On the basis o f the virtual n e t w o r k c o n f i g u r a t i o n i n f o r n ~ a t i o n
stored in the virtual network DB 106 and the t o p o l o g y i n f o r m a t i o n
stored in the pllysical topology DB, the secor~d VLAN i t i f o r m a t i o n
tlctcrrnination nnit 104 determines a VLAN ID that is set ill a port o f a
con~nmunication node 200, the port having been connected to an external
apparatus ( f o r example, the server A i n Fig. 5), and s e t s t h e determined
VLAN ID in the port via the c o ~ ~ ~ m u n i c a tui on int 1 0 8 .
[0033]
Fig. 7 i l l u s t r a t e s an exen1plary VLAN i ~ l f o r m a t i o n setting
operation performed by the second VLAN information deternlination
u n i t 1 0 4 . For exanlple, fro111 t h e i n f o r m a t i o n stored in the physical
topology DB 107, it is clear that the c o ~ n n ~ u n i c a t i onno de 200C is
connected to the scrver A. In addition, fro111 the infornlation stored in
the virtual network DB 106, it is clear that the port o f the
communication node 200C, the port connected t o the scrver A, is
n~apped with a virtual endpoint o f the virtual network. The second
VLAN information determination u n i t 104 r e f e r s to the VLAN gate
control i n f o r m a t i o n illustrated in F i g . 6 and sets "200" as a server-side
gate VI,AN ID in t h e p o r t of the c o t i ~ m u n i c a t i o n node 200C, the port
collrlected to the server A.
[0034]
In a d d i t i o n , if the i n f o r m a t i o n in the v i r t u a l network DB 106 or
the p h y s i c a l t o p o l o g y DB 107 i s u p d a t e d , tlie second VLAN i n f o r m a t i o n
d e t e r n l i n a t i o n unit 104 may s e t a VLAN ID on the basis of the updated
c o n t e n t . F o r e x a m p l e , if a server B is newly connected t o t h e
comtnunication node 200C, tlie second VI,AN i n f o r m a t i o n d e t e r m i n a t i o n
unit 104 s e t s "200" as a s e r v e r - s i d e gate VLAN ID in a p o r t of the
c o ~ n m u n i c a t i o l l node 200C, the p o r t h a v i n g b e e n c o n n e c t e d to the s e r v e r
B, as with the case of the a b o v e s e r v e r A. In a d d i t i o n , if the server A
i s d i s c o n n e c t e d from the comniunication node 200C, the VLAN ID may
be d e l e t e d from the port of the cornmutiication node 200C, the port
having been disconnected froin the s e r v e r A .
[0035]
When r e c e i v i n g a c o n t r o l i n f o r m a t i o n s e t t i n g r e q u e s t from a
communication n o d e 2 0 0 via the colnnlunication unit 108 ("Packet-In"
message in Non-patent L i t e r a t u r e 2 ) , the p a t h c a l c u l a t i o n unit 101
refers to i n f o r m a t i o n a b o u t the p o r t t h a t has received the packet which
causes the communication node 200 to transmit t h e c o n t r o l i n f o r n l a t i o n
s e t t i n g r e q u e s t , a n I D of the s o u r c e t e r m i n a l , and the like and
deternlilles a v i r t u a l network to which t h e s o u r c e ternlinal b e l o n g s .
Next, i f t h e v i r t u a l network i s deterniined, the path c a l c u l a t i o n tinit 101
c a l c u l a t e s a forwarding path froin the s t a r t - p o i n t c o ~ n m u n i c a t i o nn ode to
a c o m ~ n u n i c a t i o n nodc 200 connected to the d e s t i n a t i o n , o n t h e b a s i s of
the packet infornlatioll included in t h e c o n t r o l i n f o r m a t i o n s e t t i n g
r e q u e s t .
[0036]
To r e a l i z e p a c k e t forwarding on tlie forwarding path c a l c u l a t e d
by the p a t h c a l c u l a t i o n unit 101, the c o n t r o l i n f o r m a t i o n g e n e r a t i o n u n i t
1 0 2 g e n e r a t e s and s e t s c o n t r o l i n f o r m a t i o n ( f l o w e n t r i e s ) to bc set i n t h e
r e l e v a n t c o m m u n i c a t i o n n o d e s 200 on tlie calculated forwarding path
via the c o n ~ m u ~ i i c a t i ounn i t 1 0 8 . In a d d i t i o n , the c o n t r o l i n f o r m a t i o n
g e n e r a t i o n unit 1 0 2 r e f e r s t o t h e VLAN gate c o n t r o l i n f o r m a t i o n
illustrated in Fig. 6 and sets c o n t r o l i n f o r m a t i o n ( f l o w e n t r i e s ) for
p c r f o r ~ n i n g necessary header rewriting in the com~ilunication nodes on
t h e f o r w a r d i n g path.
[0037]
When the path calculation u n i t 101 c a l c u l a t e s a path in response
to a c o n t r o l information s e t t i n g r e q u e s t ("Packet-In" message in
Nan-patent Literature 2 ) , t h e f i r s t VLAN inforlnation determination
unit 103 determines a VLAN ID c o r r e s p o n d i n g t o the determined v i r t u a l
network for the port serving as t h e s t a r t point of the path and s e t s t h e
determined VLAN ID in the port via the c o r n ~ ~ l u n i c a t i ounn it 108.
Whether t h e p o r t serving as the s t a r t point of the p a t h i n c l u d e s t h e
VLAN gate function may be determined on the basis o f s e t t i n g
i n f o r ~ n a t i o n ( p o r t i n f o r m a t i o n i n d i c a t i n g a u t o m a t i c VLAN s e t t i n g )
s t o r e d i n advance in the c o n t r o l a p p a r a t u s 100 by a network
administrator or on the basis o f t h e i n f o r ~ n a t i o n about the capability of
each communication node 200 collected from each communication node
when the above t o p o l o g y c o l l e c t i o n opcration is performed.
[0038]
Each unit (processing means) o f the control apparatus 100
illostrated in F i g . 2 rrlay be realized by a computer program which
c a u s e s a computer t h a t c o n s t i t u t e s the control apparatus 100 to use i t s
hard\vare and execute t h e c o r r e s p o n d i n g processing described above.
[0039]
Next, an operation according to the present excmplar)r
e ~ n b o d i n ~ e nwti ll be described in detail with reference to the drawings.
Figs. 8 to 14 i l l u s t r a t e an operation performed w l ~ e nth e terminal A has
been connected to the co~nmunicationn ode 200A and the comn~unication
node 200A has received a p a c k e t addressed t o the server A from t h e
terminal A.
[0040]
When receiving t h e p a c k e t a d d r e s s e d to the server A from the
t e r m i n a l A , the c o m m u n i c a t i o ~n~o de 200.4 determines that the control
information stored t h e r e i n d o e s n o t include c o n t r o l information having
a match condition(s) that matches the packet a d d r e s s e d t o t h e server A
from the t e r ~ n i n a l A , T h u s , a s illustrated in Fig. 8, the c o n l n ~ ~ ~ n i c a t i o n
node 20014 transmits a control i n f o r m a t i o n setting request ( " P a c k e t - I n "
message Non-patent Literature 2 ) to tlie control apparatus 100.
[004 11
A f t e r receiving the control i n f o r n ~ a t i o n setting r e q u e s t , for
example, the control apparatus 100 d e t e r ~ n i n e s that the ternlinal A
belongs to the virtual network A and calculates a forwarding path for
forwarding the packet from the conlniunication node 200A to the server
A via t h e c o m m u n i c a t i o n node 200C, as illustrated i n Fig. 9. N e x t , the
control apparatus 100 sets control information ( f l o w e n t r i e s ) for
forwarding the packet on the forwarding path and perfornling rewriting
o f V L A N IDS on the basis o f the V L A N gatc control information in the
forwarding nodes 200A and 200C on the for\varding path.
[0042]
N e s t , as illustrated in Fig. 10, the control apparatus 100 allocates
"100" t o the port serving as the start point o f the calculated forwarding
path as the gate V L A N ID o f the virtual network A as indicated in the
V L A N gate control information i n Fig. 6 .
[a0431
In addition, as illustrated in Fig. 1 1 , the control apparatus 100
allocates "4094" to the ports connecting the conlnlunicatiort nodes on
the calculated forwarding path as the CORE V L A N ID o f the virtual
network A as indicated in the V L A N gate control i n f o r n ~ a t i o nin Fig. 6 .
[0044]
As illustrated in Fig. 7 , "200" as the server-side gate V L A N ID
has already been allocated by the second V L A N irtformation
determination unit 104 to the port o f the communication node 200C, the
port serving as the end point o f the path and connected to the server A .
111 t h i s way, preparation for packct forwarding f r o m t h e terminal A to
the server A has thus been completed.
[0045]
N e x t , an esanlplc in which a terminal B that belongs to the virtual
network B has been connected to the comtnunication node 200A and tlie
communication node 200A has received a packet addressed to the server
A fro111 the tcrnlinal B will be described. I11 t h i s c a s e , tlie control
apparatus 100 also calculatcs a for\varding path for forwarding tlic
packet frotn the communication node 200A to the server A via the
c o m n ~ u i ~ i c a t i onno des 200B and 200C, as i l l u s t r a t e d i n Fig. 12. N e s t ,
the control apparatus 100 sets c o n t r o l information ( f l o w e n t r i e s ) for
forwarding the packet 011 the forwarding path and perforlning rewriting
of VLAN IDS in t h e f o r w a r d i n g nodes 200A to 200C on the forwarding
path. In addition, the control apparatus 100 allocates "300" to the port
serving as the s t a r t point of the f o r w a r d i n g p a t h as t h e g a t e VLAN ID of
the v i r t u a l network B as indicated in the VLAN g a t e c o n t r o l i n f o r ~ n a t i o n
in Fig. 6.
[0046]
In addition, as i l l u s t r a t e d i n F i g . 13, the control apparatus 100
allocates "4094" in the ports connecting the comn~unication nodes on
tlie calculated forwarding path as the CORE VLAN ID o f t h e virtual
network B as indicated in the VLAN g a t e c o n t r o l information in Fig. 6 .
[0047]
As described with reference to Fig. 7, "200" as t h e s e r v e r - s i d e
gate VLAN ID has already been allocated by the second VLAN
information determination unit 104 t o the port of the conlmunication
node 200C, the port serving as the end point o f t h e p a t h and connected
t o the server A. In this way, preparation for packet forwarding fro111
the terminal R to thc servcr A has t l ~ u sb een completed.
[0048]
Fig. 14 i l l u s t r a t e s packet forwarding paths (a bold solid line and
a bold dashed line) realized by the above s e r i e s of o p e r a t i o n s a n d tlie
VLAN IDS set in the ports on the paths. Thus, according to t h e p r e s e n t
esetnplary embodiment, when tlie c o n t r o l a p p a r a t u s 100 sets a path,
VLAN IDS necessary for the relevant ports of the communicatio~i nodes
200 oil tlie pat11 can be s e t simultaneously. As a r e s u l t , the labor
required for setting tlie VLAN IDS in the relevant ports of each
c o n ~ n ~ u n i c a t i o n node is reduced. In addition, s i n c e t h e s e
c o t ~ ~ m u n i c a t i onno des use the set VLAN IDS as the VLAN gate functiotis.
respectively, the nutnber of f l o ~ ve ntries is reduced and the response of
each switch i s improved.
[0049]
In the above p r o c e d u r e , i t is desirable that the VLAN IDS set in
the ports of the communication nodes 200 by tlic control apparatus 100
be d e l e t e d a t appropriate t i m i n g . For example, a VLAN ID niay be
d e l e t e d a f t e r a c e r t a i n time period elapses (titile-out) or when control
information (flow entry) s e t i n a c o ~ n ~ n u n i c a t i ono~di e 200 i s deleted by
an explicit i n s t r u c t i o n fro111 the c o n t r o l a p p a r a t u s 1 0 0 .
[OOSO]
While e x e ~ i l p l a r ye mbodiments of the p r e s e n t invention have thus
been described, the p r e s e n t invention is not limited thereto. Further
variations, s u b s t i t u t i o n s , or adjusttilents can be made without departing
from the basic teclinical concept of the present invention. F o r example,
the c o n f i g u r a t i o ~ l s of the networks and elements illustrated in the
drawings are used only as exalilplcs to f a c i l i t a t e understanding of the
p r e s e n t i n v e n t i o n . Namely, the present invention is not limited to the
c o n f i g u r a t i o n s i l l u s t r a t e d in the dra\vings.
[OOS I ]
I11 addition, for example, while the above exemplary embodiments
have been d e s c r i b e d assuming that t h e c o n t r o l a p p a r a t u s 100 sets VLAN
IDS when r e c e i v i n g a control information s e t t i n g request from a
conimunication tiodc, the control apparatus 100 may set VLAN IDS when
the topology is changed by connection of a tertilinal or a virtual machine
t o a comn~unication node o r a d d i t i o n of a communication node, for
e x a n ~ p l e .
[0052]
I11 addition, for example, t h e above exeniplary e ~ i ~ b o d i r n e nht sa ve
been described assuming that each communication node 200 h a s a
function of dropping a packet in which s p e c i f i e d VLAN information is
not set instead of outputting the packet froni a certain port of the
c o ~ i ~ m u n i c a t i onno de 200 as the VLAN gate of each communication node
200. However, each conimu~iication node 200 may llavc a f u n c t i o n of
dropping, when receiving a packet in \vhich s p e c i f i e d VLAN
information i s n o t s e t , the packet. In s u c h c a s e , when a communication
node 200 r e c e i v e s a p a c k e t in which VLAN infornlation is not s e t ,
transtnission of a c o n t r o l information s e t t i n g request from the
communicatio~i node 200 t o the control apparatus 100 is prevented.
Thus, it is necessary to provide a mccl~anistn for notifying the control
apparatus 100 of change o f the topology by connection of a termillal or a
v i r t u a l machine t o a communication node o r a d d i t i o n of a
cominunication node, f o r example.
[0053]
Finally, suitable nlodes o f t h e p r e s e n t i n v e n t i o n will be
summarized.
[Mode 11
(See t h e c o n t r o l a p p a r a t u s according to the a b o v e f i r s t aspect)
[Mode 21
Tlie c o n t r o l a p p a r a t u s according to mode 1;
wherein the f i r s t VLAN information determination unit d e t e r ~ n i n e st he
VLAN infornlation if the port t o which the terminal has been connected
i n c l u d e s a function of dropping a packet i n ~ v h i c h specified VLAN
i n f o r n ~ a t i o nis n o t s e t instead of transtnitting the packet.
[Mode 31
The c o n t r o l a p p a r a t u s according to nlode 1 or 2;
wherein t h e f i r s t VLAN i ~ ~ f o r n l a t i odne ternlination unit d e t e r m i n e s t h e
VLAN information if the port t o which t h e t e r m i n a l has been connected
i n c l u d e s a function of dropping, when r e c e i v i n g a packet in which
specified VLAN information is not set, the packet.
[Mode 41
The c o n t r o l a p p a r a t u s a c c o r d i n g to any one of modes 1 t o 3 ;
wherein the VLAN information setting unit sets the VLAN infornlation
by t r a ~ l s m i t t i n g a control message for causing the control target
cotnmunication node to set the VLAN infornlation in a specified port.
[Mode 51
The c o n t r o l a p p a r a t u s a c c o r d i n g to any one of modes 1 to 4, f u r t h e r
including:
a second VLAN information determination u n i t configured to deterlnine
VI,AN i ~ l f o r m a t i o n that i s s e t i n a port of the c o n t r o l t a r g e t
c o ~ n m u ~ i i c a t i onno d e , t h e port connected to an external apparatus, on the
basis o f virtual network configuration information and topology
information received from the control target com~nunication node.
[Mode 61
The control apparatus according to any one o f modes 1 to 5;
wherein, on tlie basis o f the virtual network configuration information
and the topology information received from the control target
com~nunication node, VLAN information is set in ports connecting
control target co~nrnunication nodes.
[Mode 71
The control apparatus according to any one o f nlodes 1 to 6 ;
wherein the connection detection unit detects connection o f a terlninal
or a virtual machine by receiving a control infortnation setting request
from the control target co~n~iiunicationno de.
[Mode 81
(See the communication system according to the above second aspect)
[Mode 91
(See the contniunication node control method according to tlie above
third aspect)
[Mode 101
(See the program according to tlie above fourth aspect)
Modes 8 to 10 can be expanded in the sanie way as mode 1 is
expanded to modes 2 to 7 .
[0054]
The disclosure o f each o f the above Non-patent Literatures is
incorporated herein by reference thereto. Modifications and
adjustments o f the exemplary embodinients and the examples are
possible within the scope o f the overall disclosure (including tlle
clainis) o f the present invention and based on tlie basic technical
concept o f the present invention. 111 addition, various combinations
and selections o f various disclosed elenlents (including the elements in
each o f t h e c l a i m s , esetnplary embodiments, examples, drawings, e t c . )
arc possible w i t h i n t h e scope o f the claitns o f tlie present invention.
Namely, the present invention o f course includes various variations and
~ n o d i f i c a t i o n st hat could be made by t h o s e s k i l l e d in the art according to
the o v e r a l l d i s c l o s u r e including the claims and the technical concept.
In p a r t i c u l a r , t h e present d e s c r i p t i o n d i s c l o s e s numerical value ranges.
However, even if the description does not particularly d i s c l o s e a r b i t r a r y
numerical values or small ranges included in t h e r a n g e s , t h e s e values
and ranges should be deemed to have been s p e c i f i c a l l y d i s c l o s e d .
REFERENCE SIGNS LIST
[0055]
10, 100 c o n t r o l a p p a r a t u s
11 connection detection unit
12, 103 f i r s t VLAN i n f o r ~ n a t i o nd etermination u n i t
13 VLAN information setting unit
20, 200A to 200C communication node
101 path c a l c t ~ l a t i o nu nit
102 control information generation unit
104 second VLAN infornlation determination unit
105 t o p o l o g y e s t a b l i s h m e n t unit
106 virtual network d a t a b a s e ( v i r t u a l network DB)
107 p h y s i c a l topology database ( p h y s i c a l topology DB)
108 comniunication unit
300 virtual bridge
CLAIMS:
1. A c o n t r o l a p p a r a t u s , c o m p r i s i n g :
a c o n n e c t i o n d e t e c t i o n unit configured t o d e t e c t connection of a
terminal or a v i r t u a l machine t o a c o n t r o l target communication node;
a f i r s t VLAN i n f o r m a t i o n d e t e r ~ n i n a t i o n unit configured to
deternline VLAN (Virtual L o c a l A r e a Network) infornlation that i s s e t in
a p o r t of the c o m m u n i c a t i o n n o d e , the port having been connected to the
t e r m i n a l or the v i r t u a l machine, on the b a s i s of a v i r t u a l network to
which the d e t e c t e d terlninal o r v i r t u a l niachine belongs; and
a VLAN i n f o r m a t i o n s e t t i n g u n i t c o n f i g u r e d to set the determined
VLAN i n f o r n i a t i o n i n t h e p o r t .
2. The c o n t r o l a p p a r a t u s a c c o r d i n g to claitn 1;
wherein the f i r s t VLAN i n f o r m a t i o n d e t e r t n i n a t i o n unit
deternlines the VLAN inforniation if the port to which t h e t e r m i n a l h a s
been c o n n e c t e d i n c l u d e s a f u n c t i o n of dropping a p a c k e t in w11ich
s p e c i f i e d VLAN infornlation i s n o t s e t instead of t r a n s t n i t t i n g the
packet.
3. 'The c o n t r o l a p p a r a t u s a c c o r d i n g to clainl 1 or 2;
wherein the f i r s t VLAN i n f o r m a t i o n d e t e r m i n a t i o n unit
determines the VLAN i n f o r ~ n a t i o n i f t h e port to which the t e r m i n a l has
becn c o n n e c t e d i n c l u d e s a f u n c t i o n of dropping, when r e c e i v i n g a
packet in w h i c h s p e c i f i e d VLAN i n f o r m a t i o n i s not s e t , the p a c k e t .
4. The c o n t r o l a p p a r a t u s a c c o r d i n g t o a n y one o f c l a i m s 1 to 3;
\vhcrein the VLAN i n f o r m a t i o n s e t t i n g unit sets the VLAN
i n f o r m a t i o n by t r a n s m i t t i n g a c o n t r o l nlcssage f o r c a u s i n g thc c o n t r o l
target c o ~ n i n u n i c a t i on~o~de to sct the VLAN infornlation in a s p e c i f i e d
port.
5. Tlic c o n t r o l a p p a r a t u s a c c o r d i n g to any one of clainis 1 to 4,
further c o n ~ j ~ r i s i ~ ~ g :
a s e c o n d VLAN i n f o r n l a t i o n d e t e r m i n a t i o n unit configured to
detcrniirie VLAN inforniation that i s set in a p o r t of the control t a r g e t
conimunication node, the port connected to an e x t e r n a l apparatus, on the
basis o f v i r t u a l network c o n f i g u r a t i o n i n f o r n i a t i o n and topology
i n f o r m a t i o n received froni the c o n t r o l target conimunication node.
6. The control apparatus according to any one of claims 1 to 5;
wherein, on the basis of t h e v i r t u a l network configuration
information and t h e topology infornlation received from the control
target communication node, VLAN information is set in ports
connecting control target con~munication nodes.
7. The c o n t r o l apparatus according to any o ~ i co f claini~s1 to 6;
wherein the connection d e t e c t i o n unit detects connection of a
t e r ~ n i n a lo r a virtual machine by receiving a c o n t r o l information settirig
r e q u e s t from t h e control target comniunication node.
8. A com~nunications ysteni, coniprisitlg:
a communication node configured to i n c l u d e a functiotl of
dropping, when receiving an i n s t r u c t i o n f o r t r a n s m i t t i n g a packet i n
which s p e c i f i e d VLAN (Virtual Local Area Network) informatioti is not
s e t via a c e r t a i n port, the packet or a f u n c t i o n o f dropping, when
receiving a packet i n ~ v h i c hs pecified VLAN information is not set via a
c e r t a i n p o r t , t h e packet; and
a c o n t r o l a p p a r a t u s , comprising:
a connection d e t e c t i o n unit configured to detect connectiotl o f a
terniinal or a v i r t u a l machine to t h e s p e c i f i e d port of the communication
node;
a first VLAN infortilation determination unit configured to
determine VLAN i n f o r ~ l i a t i o nt hat is s e t i n a port of the conl~nunication
node, the port having been cotinected to the terminal or the virtual
tilachine, on the basis of a virtual network to whicli t h e detected
terminal o r virtual machine belongs; and
a VLAN information setting unit configured to set the determined
VLAN information in the port.
9. A c o m ~ i ~ u n i c a t i onno de control metl~od,c omprising steps of:
detecting c o n n e c t i o ~ lo f a t e r ~ i ~ i n aolr a virtual macl~inet o a
control target c o ~ i ~ r n u n i c a t i on~odi e;
determining VLAN (Virtual Local Area Network) i n f o r ~ ~ i a t i o n
t h a t i s s e t in a p o r t o f the conlmunication node, the port having been
connected to the t e r ~ l i i n a l or the v i r t u a l machine, on the basis o f a
virtual network to w h i c l ~ the detected ternlinal or virtual machine
belongs; and
setting the d e t e r ~ n i n e dV LAN information in t h e p o r t .
10. A program, causing a c o n i l ~ t ~ t etrh at controls communication
nodes to execute p r o c e s s i n g f o r :
detecting connection of a terlililial or a virtual ~ n a c h i n e to a
control target c o n i ~ n u l i i c a t i o ~nio de;
determining VLAN (Virtual Local Area Network) i n f o r m a t i o n
t h a t i s s e t i n a port o f t h e commullicatioll node, the port having been
conliected to tlie terminal or tlie virtual machine, 011 the basis of a
v i r t u a l network to which tlie detected terlninal or virtual machine
belongs; and
setting the deterlilined VLAN inforlnatioli in the port.
| # | Name | Date |
|---|---|---|
| 1 | 4896-DELNP-2015.pdf | 2015-06-16 |
| 2 | Other relevant documents.pdf | 2015-06-24 |
| 3 | GPA.pdf | 2015-06-24 |
| 4 | Form PCT-IB-304.pdf | 2015-06-24 |
| 5 | Form 5.pdf | 2015-06-24 |
| 6 | Form 3.pdf | 2015-06-24 |
| 7 | Form 2 + Specificiation.pdf | 2015-06-24 |
| 8 | Drawings.pdf | 2015-06-24 |
| 9 | Marked Version.pdf | 2015-07-13 |
| 10 | Form 13.pdf | 2015-07-13 |
| 11 | Amended documents.pdf | 2015-07-13 |
| 12 | 4896-delnp-2015-Form-1-(14-07-2015).pdf | 2015-07-14 |
| 13 | 4896-delnp-2015-Correspondence Others-(14-07-2015).pdf | 2015-07-14 |
| 14 | 4896-delnp-2015-Others-(16-11-2015).pdf | 2015-11-16 |
| 15 | 4896-delnp-2015-Correspondence Others-(16-11-2015).pdf | 2015-11-16 |
| 16 | 4896-DELNP-2015-FER.pdf | 2019-11-13 |
| 1 | Search-Strategy_4896_DELNP_2015_07-11-2019.pdf |