Automatic configuration management method and device based on bastion host

A configuration management and bastion machine technology, applied in the computer field, can solve the problems of cumbersome, low operation and maintenance efficiency, password management problems, etc., to improve the efficiency of configuration management, avoid security risks, and achieve the effect of automatic backup

Active Publication Date: 2022-03-18
NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT +1
View PDF9 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0004] In order to meet the security compliance requirements of configuration management, IT operation and maintenance personnel must connect to the server through the bastion host to perform operation and maintenance management operations; however, automatic operation and maintenance tools such as scripts cannot use the bastion host, and remote operations cannot monitor and record. Meet security compliance requirements
[0005] 1. Operation and maintenance personnel can only manually complete some tedious and time-consuming operations using traditional bastion hosts, which cannot meet the current requirements of automated operation and maintenance, especially batch configuration management
For the operation and maintenance personnel of the traditional bastion machine, although the security is greatly enhanced, the operation and maintenance efficiency becomes low
[0006] 2. Traditional bastion hosts face the difficulty of password management for servers and virtual machines by operation and maintenance personnel, and cannot perform account inspections on managed servers, virtual machines, and network devices. coming security risk
Backup work is usually done by manual or script backup, it is difficult to achieve unified management of backup files
Traditional bastion hosts can only be backed up manually or through scripts

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Automatic configuration management method and device based on bastion host
  • Automatic configuration management method and device based on bastion host
  • Automatic configuration management method and device based on bastion host

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0053] The embodiment of the present invention provides an automatic configuration management method based on the bastion host, which is combined with the bastion host system, specifically:

[0054] 1. The embodiment of the present invention allows the bastion machine to support the execution of batch commands, scripts, or a combination of commands and scripts for managed servers, virtual machines, and network devices. By associating the operation and maintenance task with the execution plan, the operation and maintenance task can be set to be executed regularly or periodically. When there are batch tasks, it can not only make the operation and maintenance work more efficient and fast, but also make the operation and maintenance of enterprises safe and compliant.

[0055] 2. In the embodiment of the present invention, a network device configuration backup task is set on the bastion host, and the configuration of a batch of network devices (routers and switches) can be backed u...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention discloses an automatic configuration management method and device based on a bastion host, the method comprising: providing an automatic operation and maintenance entrance on the front-end management interface, collecting user input, and constructing an operation and maintenance task request according to the operation and maintenance task; Thrift service receiving front-end sending Ansible receives the call of the Thrift service, and logs in to the target host through SSH to execute the operation and maintenance task, and the task result is returned to the Thrift service in JSON format; Thrift converts the task result after Ansible is executed in JSON format Return to the front-end management interface; the front-end management interface displays the task result.

Description

technical field [0001] The present invention relates to the field of computer technology, in particular to an automatic configuration management method and device based on a bastion host. Background technique [0002] The bastion machine is an operation and maintenance security audit product for large-scale data centers. The operation and maintenance users can complete the operation and maintenance management of a large number of devices through the centralized management and authorization management functions of the bastion machine. At the same time, the bastion machine can audit the operation and maintenance. Dimension user's operation process. In the traditional operation and maintenance mode, the operation and maintenance user directly connects to the remote server through the local device to perform operation and maintenance management operations. The entire operation process is invisible and uncontrollable, and there are great risks; In the role of an intermediate age...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Patents(China)
IPC IPC(8): H04L41/0803H04L41/50H04L67/02H04L41/04
Inventor 刘晓明万磊李奕希
Owner NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products