Abstract
Secure enterprises have Local Area Networks (LANs) that store and process sensitive data that should not be accessed from outside. At the same time, no modern enterprise can successfully function without a LAN which provides the Internet access for the computers of the sales department, technical support service and E-mail server. In order to ensure information security, these two network segments are usually physically isolated from each other by means of exception of any cable interconnections. Enterprises with high demands for server uptime use server virtualization, which requires connecting physical servers to disk storage of virtual server image files. When highly reliable servers are needed only in one of two independent corporate network segments, the cost of creating such a server cluster is reasonable and fast paying off. But when a company encounters the need to place a small but highly reliable server into another network segment, the following problem arises: only server cluster with expensive components can provide the required reliability, but to solve the tasks assigned to the new server, the cluster computing capacity would be too high, and deploying of a cluster would be extremely costly and economically unjustified. On the other hand, the required computing capacity for a new server would be taken from the existing server cluster by creating a new virtual server without any expenses. However, in such case it is necessary to ensure isolation of the new virtual server from the network segment the physical hosts servers are connected to. The article examines the methods of configuring the LAN that allow to isolate virtual and physical servers at the network level. The authors also consider the episode when it is necessary to transfer files between the two computers located in the LAN segments isolated from each other and gives the appropriate solution.
Highlights
No modern enterprise can successfully function without a Local Area Networks (LANs) which provides the Internet access for the computers of the sales department, technical support service and E-mail server
When a company encounters the need to place a small but highly reliable server into another network segment, the following problem arises: only server cluster with expensive components can provide the required reliability, but to solve the tasks assigned to the new server, the cluster computing capacity would be too high, and deploying of a cluster would be extremely costly and economically unjustified
The required computing capacity for a new server would be taken from the existing server cluster by creating a new virtual server without any expenses
Summary
ИЗОЛЯЦИЯ ВЫЧИСЛИТЕЛЬНЫХ СЕТЕЙ ПРЕДПРИЯТИЯ С ИСПОЛЬЗОВАНИЕМ ВИРТУАЛИЗАЦИИ СЕРВЕРОВ. А.К. Но когда предприятие сталкивается с необходимостью установить в другой ЛВС один, хоть и малопроизводительный, но высоконадежный сервер, то возникает проблема: требуемую надежность может обеспечить только серверный кластер с дорогостоящими компонентами, но для решения возлагаемых на новый сервер задач вычислительная мощность кластера окажется многократно завышенной, и его построение окажется крайне затратным и экономически необоснованным. Ключевые слова: локальные вычислительные сети, ЛВС, виртуализация, Hyper-V, VirtualBox. В настоящее время практически ни одно предприятие, производственные процессы которого зависят от безотказности функционирования серверного оборудования, не может обойтись без ИТ-инфраструктуры, основанной на виртуализации серверов. Когда в одном сегменте сети присутствие серверного кластера полностью оправдано, а в другом сегменте требуется установить лишь единичный сервер, обладающий, однако, высокой надежностью, обеспечить которую может только виртуализация на дорогостоящем кластере. На рис. 1 изображена схема сети предприятия, в которой виртуальный сервер, имеющий IP-адрес из диапазона адресов внешней (имеющей доступ в интернет через маршрутизатор) подсети ЛВС-1, физически размещен на хост-сервере внутренней (изолированной от интернета) подсети ЛВС-2
Talk to us
Join us for a 30 min session where you can share your feedback and ask us any queries you have
Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.