当前位置:网站首页>How does the hybrid cloud realize the IP sec VPN cloud networking dedicated line to realize the interworking between the active and standby intranet?
How does the hybrid cloud realize the IP sec VPN cloud networking dedicated line to realize the interworking between the active and standby intranet?
2022-06-23 21:42:00 【TCS-F】
Business scenario :
As shown in the figure below , The user is in VPC and IDC The central government has deployed business , In order to realize the business interaction between the cloud and the cloud , Users need to deploy network connection services to realize business interoperability , For high availability communication , The deployment scheme is as follows :
- Cloud networking ( Lord ): Local IDC Through the physical line , Connect to the cloud connected private line gateway , Dedicated line gateway and VPC Are connected to the cloud network , So as to realize the full service communication under the cloud and on the cloud . When the physical dedicated line link is normal . Local IDC And VPC All communication flows between the are forwarded through the cloud network via the physical dedicated line .
- VPN Connect ( To prepare ): Ben The earth IDC And on the cloud VPC Through establishment VPN Secure tunnel to realize cloud on cloud and cloud off cloud business communication , When the leased line link is abnormal , The traffic can be switched to this link , Ensure business availability :
Prerequisite
- User local IDC The gateway device has IPsec VPN function , It can also be used as the user side VPN Gateway device , And VPC Side VPN Equipment setup IPsec Tunnel communication .
- user IDC Side gateway device Configured static IP.
You can also set BFD static state IP - Data preparation is as follows : Configuration item example value network configuration VPC Information subnet CIDR192.168.1.0/24VPN Gateway public network IP203.xx.xx.82IDC Information subnet CIDR10.0.1.0/24, Gateway public network IP202.xx.xx.5
Operation process
- 1 Configure dedicated line access
- 2 To configure VPN Connect
- 3 Configure network probe
- 4 Configure alarms
- 5 Switch between active and standby routes
Operation steps
Step one : To configure IDC Through the cloud network
- Sign in Dedicated line access console , Click... On the left navigation bar 【 Physics line 】 Create a physical line .
- Click... On the left navigation bar 【 Dedicated gateway 】 Create a dedicated gateway , This example selects cloud networking
- Click cloud networking private line gateway ID Enter details page , stay 【IDC gateway 】 Enter the user in IDC Network segment , for example 10.0.1.0/24.
- Sign in Cloud networking console , single click 【 newly build 】 Create an instance of cloud networking .
- Sign in Dedicated channel console , single click 【 newly build 】 Create a dedicated channel to connect to the cloud networking dedicated gateway , Configure the channel name here 、 Select cloud networking as the access network , Select the created cloud networking private line gateway 、 Configure the interconnection between Tencent cloud side and user side IP、 Routing method selection BGP Routing, etc. , After the configuration is completed, download the configuration guide and click IDC The device is configured .
- take VPC Associate with the dedicated line gateway to the cloud networking instance , That is to say VPC and IDC Networking through the cloud 、 Cloud networking dedicated line gateway for interworking . explain : For more detailed configuration, please refer to IDC Through the cloud network .
Step two : To configure IDC adopt VPN Connect to the cloud
- Sign in VPN Gateway console , single click 【 newly build 】 establish VPN gateway , In this example, the associated network selects the private network .
- Click... On the left navigation bar 【 Peer gateway 】, Configure the peer gateway ( namely IDC Side VPN The logical object of the gateway ), Fill in IDC Side VPN The gateway's public network IP Address , for example 202.xx.xx.5.
- Click... On the left navigation bar 【VPN passageway 】, Please configure SPD Strategy 、IKE、IPsec Other configuration .
- stay IDC Configure on the local gateway device VPN Channel information , The configuration here requires and step 3 Medium VPN The channel information is consistent , otherwise VPN The tunnel cannot be connected normally .
- stay VPC Configure the next hop in the routing table associated with the communication subnet as VPN gateway 、 The destination is IDC Communication network segment The routing strategy of . explain : For more detailed configuration, please refer to :
- If it is 1.0 and 2.0 Version of VPN gateway , Please refer to establish VPC To IDC The connection of (SPD Strategy ).
- If it is 3.0 Version of VPN gateway , Please refer to establish VPC To IDC The connection of ( Routing table )
Step three : Configure network probe
explain : After the above two steps are configured ,VPC Go to IDC There are already two paths , The next hop is cloud networking 、VPN gateway , According to the route default priority : Cloud networking > VPN gateway , Cloud networking is the main path ,VPN The gateway is an alternate path .
To understand the connection quality of the active and standby paths , You need to configure network probes for two paths respectively , Real time monitoring of the delay to the network connection 、 Key indicators such as packet loss rate , To detect the availability of active and standby routes .
- Sign in Network probe console .
- single click 【 newly build 】, Create a network probe , Fill in the network probe name , choice Private networks 、 subnet 、 Detection purpose IP, And specify the next hop route at the source , Such as cloud networking .
- Please execute again step 2, Specify that the next hop route at the source end is VPN gateway . When the configuration is complete , You can view cloud networking and VPN Network detection delay and packet loss rate of connecting the active and standby paths . explain : For more detailed configuration, please refer to Network detection .
Step four : Configure alarms
In order to detect the abnormal link in time , Configurable alarm strategy for network detection , In order to detect the abnormal link , The alarm information can be obtained in time through e-mail and SMS , Help you to forewarn risks in advance .
- Log in to... Under cloud monitoring Alarm strategy console .
- single click 【 newly build 】, Fill in the strategy name 、 Policy type selection 【 Private networks / Network detection 】, Alarm object selection Specific examples of network detection , Configure triggering conditions, alarm notification and other information , And click 【 complete 】 that will do .
Step five : Switch between active and standby routes
When the network detection abnormal alarm of the main path of cloud networking is received , You need to manually disable the primary route , Switch the flow to VPN Gateway backup route .
- Sign in Routing table console .
- single click VPC Communication subnet associated routing table ID, Enter the routing details page , Click open
Disable the next hop as the primary route for cloud networking , here VPC Go to IDC Traffic will switch from cloud networking to VPN gateway .
PS: When we practice , Find out IDC Transparent network segment , There are limits , We need to pay attention to , Can't publish 0.0.0.0/0 To the cloud , Split required ; Pit point
边栏推荐
- Explain the rainbow ingress universal domain name resolution mechanism
- 手机卡开户的流程是什么?在线开户安全么?
- Selenium batch query athletes' technical grades
- How to batch generate UPC-A codes
- Cool 3D sphere text cloud effect!
- Global and Chinese markets of natural starch 2022-2028: Research Report on technology, participants, trends, market size and share
- Retrofit magic, reject duplicate code!
- Cloud database smooth disassembly scheme
- Surprise! Edge computing will replace cloud computing??
- How to calculate individual income tax? You know what?
猜你喜欢

《阿里云天池大赛赛题解析》——O2O优惠卷预测

嵌入式开发:嵌入式基础——重启和重置的区别

CAD图在线Web测量工具代码实现(测量距离、面积、角度等)

蓝牙芯片|瑞萨和TI推出新蓝牙芯片,试试伦茨科技ST17H65蓝牙BLE5.2芯片

Find My资讯|苹果可能会推出第二代AirTag,试试伦茨科技Find My方案

微信小程序中发送网络请求

New SQL syntax quick manual!

Find my information | Apple may launch the second generation airtag. Try the Lenz technology find my solution

Gradle asked seven times. You should know that~

How does PMO select and train project managers?
随机推荐
Build DNS server in Intranet
TDD开发模式推荐流程
[same origin policy - cross domain issues]
Find My资讯|苹果可能会推出第二代AirTag,试试伦茨科技Find My方案
Salesforce heroku (IV) application in salesforce (connectedapp)
Uncover the secrets of Huawei cloud enterprise redis issue 16: acid'true' transactions beyond open source redis
Dart series: look at me for security. The security feature in dart is null safety
Global and Chinese market of American football catch gloves 2022-2028: Research Report on technology, participants, trends, market size and share
What is the reason for the error when calling API prompt 401 after easycvr replaces the version?
Stm32 w5500 implements TCP, DHCP and web server
What causes the applet SSL certificate to expire? How to solve the problem when the applet SSL certificate expires?
Open source C # WPF control library --newbeecoder UI User Guide (II)
Go language limits the number of goroutines
Framework not well mastered? Byte technology Daniel refined analysis notes take you to learn systematically
I'm in Shenzhen. Where can I open an account? Is online account opening safe?
How PMO uses two dimensions for performance appraisal
Open source C # WPF control library --newbeecoder UI usage guide (III)
HR SaaS is finally on the rise
Analysis of Alibaba cloud Tianchi competition -- prediction of o2o coupon
Cloud native practice of meituan cluster scheduling system