Method and device for dividing virtual firewall

A technology of virtual firewalls and devices, which is applied in the direction of data exchange, electrical components, and transmission systems through path configuration. The effect of meeting demand and reducing hardware deployment costs

CN103973673BActive Publication Date: 2017-11-03OPZOON TECH
5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Publication Date
2017-11-03

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention discloses a virtual firewall partitioning method and equipment. The virtual firewall partitioning method includes steps of adding many virtual firewalls into a cloud network and setting identifiable message types and identifiable network identifiers ID of the virtual firewalls; judging whether types of messages are identifiable message types or not when detecting that the equipment of the cloud network receives the messages, if yes, judging whether the network identifiers ID carried by the messages are the identifiable network identifiers ID or not; removing the network identifiers ID if the network identifiers ID carried in the messages are the identifiable network identifiers ID, and transmitting inner messages of the messages to the corresponding virtual firewalls; subjecting the inner messages to service processing by the virtual firewalls, adding the corresponding original network identifiers into the inner messages after processing to be packaged into processed messages and transmitting the processed messages. By the virtual firewalls, safety services are isolated, hardware configuration cost is reduced and the requirements of the large cloud network are met.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The invention relates to the technical field of cloud network and virtual firewall, in particular to a method for dividing virtual firewalls and a device for dividing virtual firewalls. Background technique

[0002] Usually, a large cloud network can support hundreds of rental users, and each rental user can run multiple applications at the same time, and the traffic between users is isolated from each other. But in a large cloud environment, if each user is assigned an actual firewall, hundreds of firewalls are required, which is obviously unrealistic. In addition, traditional virtual firewalls distinguish traffic through VLANs (Virtual Local Area Networks), interfaces, and destination addresses. Since the number of them is limited, they are not suitable for large-scale cloud networks. Contents of the invention

[0003] The present invention is made in view of the above situation, and its purpose is to provide a method for dividing virtual firewall...

Examples

Embodiment Construction

[0022] In order to make the object, technical solution and advantages of the present invention clearer, the present invention will be further described in detail below in combination with specific embodiments and with reference to the accompanying drawings. It should be understood that these descriptions are exemplary only, and are not intended to limit the scope of the present invention. Also, in the following description, descriptions of well-known structures and techniques are omitted to avoid unnecessarily obscuring the concept of the present invention.

[0023] The concept and function of the virtual firewall will be described first below. A virtual firewall is a logical division of a firewall into multiple virtual firewalls. Each virtual firewall system can be regarded as a completely independent firewall device with independent system resources, administrators, security policies, and users. Authentication database, etc.

[0024] Usually, a large cloud network can supp...