Unlock instant, AI-driven research and patent intelligence for your innovation.

A distributed firewall definition method and system

A distributed firewall and firewall technology, applied in transmission systems, digital transmission systems, data exchange networks, etc., can solve problems such as network bandwidth bottlenecks, large network threats, and inability to achieve security protection and isolation

Active Publication Date: 2021-12-03
INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF8 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0002] The rapid development of Openstack (open source framework, applied in the field of cloud computing) cloud computing brings advantages of resource integration and also brings more risks in use, such as the bottleneck problem of network bandwidth; for network bandwidth problems, various methods are usually used However, these methods face relatively large network threats. Therefore, how to reasonably and efficiently realize the reasonable allocation of network bandwidth while ensuring network security is an unavoidable problem at present.
[0003] At present, in the application scenario of deploying a private cloud platform based on the Openstack framework, it is usually achieved by adding iptables (ip rule table) rules to the Openstack native Virtual Router (virtual router) to control data packets entering and leaving the virtual network; this With the help of adding iptables rules on the native Virtual Router, since the filtering of traffic is concentrated on the L3 agent, when there is a burst of traffic, security protection and isolation cannot be achieved, and network problems such as network congestion will also occur

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • A distributed firewall definition method and system
  • A distributed firewall definition method and system
  • A distributed firewall definition method and system

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0048] Next, the technical solutions in the embodiments of the present invention will be described in connection with the drawings of the embodiments of the present invention, and it is understood that the described embodiments are merely the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art are in the range of the present invention without making creative labor premise.

[0049] See figure 1 Which shows a flowchart of a method of distributed firewall is defined according to an embodiment of the present invention, comprising:

[0050] S11: real-time monitoring firewall events Firewall component, and is currently listening to firewall event corresponds to the firewall configuration information to OVN database.

[0051] Distributed firewall software-defined method of the embodiment defined in the present application can be implemented by a multi-arc...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a method and system for defining a distributed firewall. The method includes: a firewall component monitors firewall events in real time, and sends firewall configuration information corresponding to the currently monitored firewall events to an OVN database; the OVN database converts the firewall configuration information For the corresponding policy routing, use the policy routing to process the firewall event corresponding to the data stored by itself, and send the data that has changed in the data stored by the firewall event corresponding to the processing to the OVN located on each computing node. Controller; the OVN controller sends the received data to the OVS guard module on the computing node, and the OVS guard module stores the received data in the memory for message forwarding. It can be seen that the present application can realize security isolation and avoid network problems such as network congestion.

Description

Technical field [0001] Technical Field The present invention relates to the firewall, and more particularly, to a method and system for a distributed firewall definitions. Background technique [0002] Openstack the same time (open source framework used in the field of cloud computing) the rapid development of cloud computing, bring resource integration also brings the risk of more use, such as network bandwidth bottleneck problem; for network bandwidth issues, usually using a variety of speed limit or filter traffic diversion method to solve, but these methods are facing a greater threat to network, how to achieve a reasonable rational and efficient allocation of network bandwidth, while ensuring network security is currently an unavoidable problem. [0003] Currently the application scenario based Openstack frame deploy private cloud platform, typically by adding iptables (ip rule list) rules by Openstack native Virtual Router (virtual router), to achieve control and out of the...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L29/06H04L12/931H04L12/713H04L45/586
CPCH04L63/0218H04L63/0263H04L49/70H04L45/586
Inventor 张同剑秦海中
Owner INSPUR SUZHOU INTELLIGENT TECH CO LTD