Configuration rollback method, device and equipment for switch and storage medium
By collecting the configuration change information and operating status data of the switch and generating a rollback strategy based on abnormal status analysis, the complexity and compatibility issues of switch configuration management are resolved, and fast and accurate configuration rollback is achieved.
Patent Information
- Application Number
- CN202510999631.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-21
- Publication Date
- 2025-10-17
AI Technical Summary
In the existing technology, switch configuration management operations are complex and rely on administrators to manually save configurations. It is difficult to restore in time and cannot accurately roll back single or multiple configuration items. It lacks real-time and cross-platform compatibility, resulting in configuration loss and service interruption.
Collect configuration change information and operating status data of the switch, analyze abnormal status based on operating status data, preset security rules and historical configuration records, generate rollback strategies, and achieve precise and fine-grained configuration rollback.
It improves the recovery speed and compatibility of switch configuration management, realizes precise and fine-grained configuration rollback decision-making and execution, and reduces configuration loss and service interruption.
Smart Images

Figure CN120811897A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network configuration management, and particularly relates to a configuration rollback method and device for a switch, equipment and a storage medium. BACKGROUND
[0002] In the current network switch configuration management field, although some switches have basic configuration backup and recovery functions, such as allowing administrators to manually save configuration files and reload them to realize recovery when needed, and some enterprise-level switches also provide limited configuration version management, which can record the history of configuration changes, but these technologies still have significant defects. First, the operation of the current network switch configuration management is complex, and it depends on the administrator to manually save the configuration, which is easy to forget and may not be able to recover in time in an emergency, increasing the management cost and risk. Second, most systems only support restoring the configuration to a certain point in time as a whole, and cannot accurately roll back to a single or multiple specific configuration items, resulting in unnecessary configuration loss and service interruption. In addition, the current network switch configuration management lacks real-time performance and cannot monitor and record key information immediately after configuration changes, making it difficult to quickly locate and roll back to the problem configuration when a fault occurs. Moreover, the configuration file formats of different brands and models of switches are different, making it difficult to implement unified configuration rollback management and increasing the difficulty of cross-platform management.
[0003] Therefore, how to improve the recovery speed and compatibility of switch configuration rollback is a problem to be solved at present. SUMMARY
[0004] The main purpose of the present application is to provide a configuration rollback method, device, equipment and storage medium for a switch, aiming to solve the technical problem of how to improve the recovery speed and compatibility of switch configuration rollback.
[0005] To achieve the above-mentioned purpose, the present application provides a configuration rollback method for a switch, which comprises:
[0006] Collecting configuration change information and running state data of the switch, wherein the running state data includes CPU utilization, memory utilization, network delay, error packet rate and packet loss rate;
[0007] Obtaining a history configuration record with a time stamp according to the configuration change information;
[0008] Performing abnormal state analysis and rule judgment based on the running state data, a preset safety rule and the history configuration record to obtain a rollback strategy, wherein the rollback strategy is generated when the rollback trigger condition in the preset safety rule is met;
[0009] Performing a configuration rollback operation according to the rollback strategy and the history configuration record.
[0010] In an embodiment, the step of obtaining the rollback strategy based on the running state data, the preset security rule and the historical configuration record comprises:
[0011] obtaining a performance abnormality judgment rule and a configuration strategy abnormality judgment rule according to the preset security rule;
[0012] detecting a device performance abnormality event according to the performance abnormality judgment rule and the running state data;
[0013] detecting a configuration rule abnormality event according to the configuration strategy abnormality judgment rule and the historical configuration record;
[0014] when the device performance abnormality event and / or the configuration rule abnormality event is detected, determining a rollback strategy according to the device performance abnormality event and / or the configuration rule abnormality event and the preset security rule.
[0015] In an embodiment, the step of detecting the device performance abnormality event according to the performance abnormality judgment rule and the running state data comprises:
[0016] obtaining a CPU utilization rate threshold, an available memory ratio threshold, an error packet rate threshold, a network delay threshold and a packet loss rate threshold according to the performance abnormality judgment rule;
[0017] obtaining an available memory ratio according to the memory utilization rate;
[0018] when any one of the following conditions is met, determining that the switch has a device performance abnormality event: the CPU utilization rate is greater than the CPU utilization rate threshold, the available memory ratio is less than the available memory ratio threshold, the error packet rate is greater than the error packet rate threshold, the packet loss rate is greater than the packet loss rate threshold and the network delay is greater than the network delay threshold.
[0019] In an embodiment, the step of detecting the configuration rule abnormality event according to the configuration strategy abnormality judgment rule and the historical configuration record comprises:
[0020] obtaining an access control list rule, a network topology rule and a syntax conflict rule according to the configuration strategy abnormality judgment rule;
[0021] obtaining a configuration modification content according to the historical configuration record;
[0022] when any one of the configuration modification content does not meet the access control list rule, the network topology rule and the syntax conflict rule, determining that the switch has a configuration rule abnormality event.
[0023] In an embodiment, when the device performance abnormal event and / or the configuration rule abnormal event is detected, the step of determining a rollback strategy according to the device performance abnormal event and / or the configuration rule abnormal event and the preset security rule comprises:
[0024] When the device performance abnormal event and / or the configuration rule abnormal event is detected, a rollback strategy table is obtained, the rollback strategy table comprising a corresponding relationship between different fault levels and rollback strategies;
[0025] A fault level corresponding to the abnormal event is determined according to a preset security rule, the fault level being determined by the severity and the influence range of the abnormal event;
[0026] A corresponding rollback strategy is matched in the rollback strategy table according to the fault level.
[0027] In an embodiment, the step of performing a configuration rollback operation according to the rollback strategy and the historical configuration record comprises:
[0028] A rollback target is determined according to the historical configuration record and the rollback strategy, the rollback target comprising a target rollback version, a target rollback module and a target rollback configuration item;
[0029] A rollback delay is determined according to the rollback strategy, the rollback delay comprising a first rollback delay, a second rollback delay and a third rollback delay, the first rollback delay being smaller than the second rollback delay, and the second rollback delay being smaller than the third rollback delay;
[0030] A configuration rollback operation is performed according to the rollback delay and the rollback target.
[0031] In an embodiment, the step of obtaining a historical configuration record with a time stamp according to the configuration change information comprises:
[0032] An operator identifier of the configuration change, a configuration change time and configuration modification content are obtained according to the configuration change information;
[0033] The operator identifier, the configuration change time and the configuration modification content are stored in a database to obtain a historical configuration record with a time stamp.
[0034] In addition, to achieve the above-mentioned purpose, the present application further provides a configuration rollback device for a switch, the device comprising:
[0035] A configuration monitoring module is configured to collect configuration change information and running state data of the switch, the running state data comprising CPU utilization, memory utilization, network delay, error packet rate and packet loss rate;
[0036] a configuration record module configured to obtain a history configuration record with a time stamp according to the configuration change information;
[0037] a rollback decision module configured to perform abnormal state analysis and rule judgment based on the running state data, a preset safety rule, and the history configuration record to obtain a rollback strategy, the rollback strategy being generated when a rollback trigger condition in the preset safety rule is met;
[0038] a rollback execution module configured to perform a configuration rollback operation according to the rollback strategy and the history configuration record.
[0039] In addition, to achieve the above-mentioned purpose, the present application further provides a configuration rollback device for a switch, the device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the configuration rollback method for a switch as described above.
[0040] In addition, to achieve the above-mentioned purpose, the present application further provides a storage medium, which is a computer-readable storage medium, the storage medium storing a computer program, the computer program being executed by a processor to implement the steps of the configuration rollback method for a switch as described above.
[0041] In addition, to achieve the above-mentioned purpose, the present application further provides a computer program product, the computer program product comprising a computer program, the computer program being executed by a processor to implement the steps of the configuration rollback method for a switch as described above.
[0042] The present application provides a configuration rollback method for a switch, the method comprising: collecting configuration change information and running state data of the switch, the running state data comprising CPU utilization, memory utilization, network delay, error packet rate, and packet loss rate; obtaining a history configuration record with a time stamp according to the configuration change information; performing abnormal state analysis and rule judgment based on the running state data, a preset safety rule, and the history configuration record to obtain a rollback strategy, the rollback strategy being generated when a rollback trigger condition in the preset safety rule is met; and performing a configuration rollback operation according to the rollback strategy and the history configuration record. As can be seen from the above, the present application adopts different configuration rollback strategies for different abnormal states of the switch during configuration change, thereby realizing accurate and fine-grained configuration rollback decision and execution and improving the recovery efficiency of switch configuration management. BRIEF DESCRIPTION OF DRAWINGS
[0043] The accompanying drawings, which are incorporated herein and form part of the specification, illustrate embodiments consistent with the present application and, together with the description, further serve to explain the principles of the application.
[0044] In order to more clearly illustrate the technical solutions of the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or prior art description will be briefly introduced as follows. Obviously, those skilled in the art can obtain other drawings according to these drawings without any creative effort.
[0045] Figure 1 The flowchart provided by the first embodiment of the configuration rollback method for the switch of the present application;
[0046] Figure 2 The system architecture diagram of the configuration rollback system for the switch of the present application;
[0047] Figure 3 The flowchart provided by the second embodiment of the configuration rollback method for the switch of the present application;
[0048] Figure 4 The module structure diagram of the configuration rollback device for the switch of the embodiment of the present application;
[0049] Figure 5 The device structure diagram of the hardware running environment related to the configuration rollback method for the switch in the embodiment of the present application.
[0050] The object realization, functional features and advantages of the present application will be further explained with reference to the embodiments and the drawings. DETAILED DESCRIPTION
[0051] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application, and are not used to limit the present application.
[0052] In order to better understand the technical solutions of the present application, the following will be described in detail with reference to the drawings of the specification and the specific embodiments.
[0053] The main solution of the embodiment of the present application is: collecting configuration change information and running state data of the switch, the running state data including CPU utilization, memory utilization, network delay, error packet rate and packet loss rate; obtaining a history configuration record with a time stamp according to the configuration change information; performing abnormal state analysis and rule judgment based on the running state data, a preset security rule and the history configuration record to obtain a rollback strategy, the rollback strategy being generated when the rollback trigger condition in the preset security rule is met; and performing a configuration rollback operation according to the rollback strategy and the history configuration record.
[0054] In the current network switch configuration management field, although some switches have basic configuration backup and recovery functions, such as allowing administrators to manually save configuration files and reload them to achieve recovery when needed, and some enterprise-level switches also provide limited configuration version management, which can record the history of configuration changes, but these technologies still have significant defects. First, the existing technology is complex to operate, relies on administrators to actively save configurations manually, and is not only easy to forget, but also more likely to fail to recover in time in emergency situations, increasing management costs and risks. Second, most systems only support restoring the configuration to a certain point in time as a whole, and cannot accurately roll back to a single or multiple specific configuration items, resulting in unnecessary configuration loss and service interruption. In addition, the existing technology lacks real-time monitoring and recording of key information after configuration changes, making it difficult to quickly locate and roll back to the problem configuration when a fault occurs. Moreover, the configuration file formats of different brands and models of switches are different, making it difficult to implement unified configuration rollback management, increasing the difficulty of cross-platform management. Therefore, how to improve the recovery speed and compatibility of switch configuration rollback is a problem that needs to be solved at present.
[0055] The present application adopts different configuration rollback strategies for different abnormal states of the switch during configuration changes, realizes accurate and fine-grained configuration rollback decision and execution, and improves the recovery efficiency of switch configuration management.
[0056] Based on this, the embodiment of the present application provides a configuration rollback method for a switch. Figure 1 , Figure 1 The flowchart of the first embodiment of the configuration rollback method for the switch of the present application is shown in the figure.
[0057] In this embodiment, the configuration rollback method for the switch includes steps S10-S40:
[0058] Step S10: Collect configuration change information and running state data of the switch, and the running state data includes CPU utilization, memory utilization, network delay, error packet rate and packet loss rate.
[0059] It should be noted that, as Figure 2As shown, the execution subject of the embodiment is a configuration rollback system for a switch, which comprises a configuration monitoring module, a configuration recording module, a rollback decision module and a rollback execution module connected in sequence. The following takes the configuration rollback system for a switch as an example to describe the embodiment and each of the following embodiments. In this step, the configuration change information refers to any modification information in the switch configuration file, including the added, deleted or modified configuration items. The running state data is each performance index reflecting the current running state of the switch, which is used to evaluate the health status of the switch. Specifically, the system realizes real-time collection of data through the configuration monitoring module, which interacts with the switch through an API interface (such as a restful interface and a CLI interface of Web) to obtain the configuration change information in real time. At the same time, the running state data of the switch is collected through SNMP (Simple Network Management Protocol) or other monitoring tools, including but not limited to performance indexes such as CPU utilization, memory utilization, network delay, error packet rate and packet loss rate.
[0060] In addition, it should be noted that the switch used in the embodiment is an open source switch (such as a Sonic switch). It can be understood that the core reason why the Sonic switch is selected in the embodiment is its open source programmability and unified architecture. The open source interface supports atomic level configuration operation, which is helpful to realize accurate rollback of single configuration item; the structured storage based on database (such as Redis) can directly extract independent configuration items without complex text analysis; the hardware abstraction layer can shield the difference of the bottom layer to ensure the compatibility of the rollback system across models.
[0061] Step S20: obtaining a historical configuration record with a time stamp according to the configuration change information.
[0062] It should be noted that the historical configuration record refers to a record containing detailed information of configuration change and a time stamp, which is used for subsequent rollback operation. In this step, the configuration recording module receives the configuration change information from the configuration monitoring module, and stores these information together with the time stamp, operator and other information in the database or file. Each rollable configuration information file item is provided with a detailed time stamp, so as to accurately rollback according to the time point subsequently.
[0063] In a possible implementation, the step S20 specifically comprises:
[0064] Step S201: obtaining an operator identifier of the configuration change, a configuration change time and a configuration modification content according to the configuration change information.
[0065] It should be noted that in the process of real-time monitoring of Sonic switch configuration changes, the configuration monitoring module not only captures modifications to the configuration file itself, but also obtains additional metadata information through the interactive interface with the switch (such as CLI or RESTful API). These metadata include but are not limited to: operator identifier (i.e. administrator username performing configuration changes or system-generated unique identifier), specific time of configuration changes, and specific content of configuration modifications (such as newly added configuration items, deleted configuration items, or modified configuration values). The configuration monitoring module packages these information into structured data format for subsequent processing and storage.
[0066] Step S202: Store the operator identifier, configuration change time, and configuration modification content in the database to obtain a time-stamped historical configuration record.
[0067] It should be noted that the configuration record module receives structured data from the configuration monitoring module, which includes operator identifier, configuration change time, and configuration modification content. The configuration record module stores these data into a pre-configured database, with table structure including fields such as "operator ID", "change time", "change content", etc. to ensure data integrity and queryability. The database automatically generates or associates a unique timestamp for each record when storing data, which is consistent with or supplementary to the configuration change time, used to identify the creation or update time of the record.
[0068] It can be understood that by storing configuration change information in the database, centralized management and long-term preservation of configuration history are achieved, facilitating subsequent audit, analysis, and rollback operations. Time-stamped historical configuration records provide accurate time points and configuration content for rollback operations, making rollback operations more reliable and efficient.
[0069] Step S30: Based on the running state data, pre-set safety rules, and the historical configuration record, perform abnormal state analysis and rule judgment to obtain a rollback strategy, which is generated when the rollback trigger condition in the pre-set safety rules is met.
[0070] It should be noted that specifically, in this step, the rollback decision module obtains information from the configuration record module and the configuration monitoring module, including detailed records of configuration changes, running state data of the switch, etc. According to pre-set safety rules and network policies, the configuration changes are checked for compliance, and the running state data is analyzed to assess the health status of the switch. When detecting abnormalities or configuration changes violating pre-set rules, the rollback decision module triggers rollback instructions and generates corresponding rollback strategies.
[0071] Additionally, it should be noted that the preset security rule refers to a series of rules defined in advance for judging whether the configuration change is compliant, including but not limited to network topology rules, port security setting rules, access control list rules, etc. The rollback strategy refers to a specific scheme generated according to the running state data and the preset security rule for guiding the rollback operation, including the rollback target, the rollback priority, and the rollback range, etc.
[0072] Step S40: performing a configuration rollback operation according to the rollback strategy and the historical configuration record.
[0073] It should be noted that in this step, the rollback execution module receives the rollback instruction from the rollback decision module, which contains information such as the historical configuration version to be rolled back to and the rollback range. The rollback execution module exchanges with the Sonic switch through the API interface according to the instruction content to perform the configuration delivery operation and restore the switch configuration to the specified version.
[0074] In a possible implementation, the step S40 specifically includes:
[0075] Step S401: determining a rollback target according to the historical configuration record and the rollback strategy, the rollback target including a target rollback version, a target rollback module, and a target rollback configuration item.
[0076] It should be noted that in this step, the rollback decision module obtains the historical configuration record with a time stamp from the configuration record module, which records in detail the operator, the change time, and the change content of each configuration change. Meanwhile, the rollback decision module analyzes the historical configuration record according to the preset rollback strategy (which is formulated based on the running state of the switch, the severity of the configuration change, the business impact, etc.) to determine the target (such as the version, the module, and the single configuration item) to be rolled back.
[0077] Additionally, it should be noted that the target rollback version refers to the configuration version to be rolled back to, which is usually the latest stable version identified based on the time stamp or the version number. The target rollback module refers to the module in the switch that needs to be rolled back, such as the interface configuration module, the VLAN (Virtual Local Area Network) configuration module, etc. The target rollback configuration item refers to the specific configuration item that needs to be rolled back, such as the IP address of an interface, the ID of a VLAN, etc.
[0078] Step S402: determining a rollback delay according to the rollback strategy, the rollback delay including a first rollback delay, a second rollback delay, and a third rollback delay, the first rollback delay being less than the second rollback delay, and the second rollback delay being less than the third rollback delay.
[0079] It should be noted that in this step, the rollback decision module assigns different rollback delays to different rollback scenarios according to the fault level and the impact range defined in the rollback policy. For example, for critical faults (such as switch unavailability), a first rollback delay (within 3 seconds) is assigned; for serious faults (such as key service interruption), a second rollback delay (within 10 seconds) is assigned; for minor faults (such as a single configuration item error), a third rollback delay (within 30 seconds) is assigned.
[0080] It can be understood that assigning rollback delays according to the urgency and impact range of different faults can ensure that the switch returns to normal operation quickly within a short time, while avoiding unnecessary frequent rollback operations.
[0081] Step S403: performing a configuration rollback operation according to the rollback delay and the rollback target.
[0082] It should be noted that in this step, the rollback execution module receives the rollback instruction from the rollback decision module, which contains the determined rollback target and the assigned rollback delay. The rollback execution module sends a configuration rollback command to the Sonic switch within the specified time according to the rollback delay, and restores the rollback target to the latest stable version. During the execution of the rollback operation, the rollback execution module monitors the rollback progress in real time, and feeds back the rollback result to the rollback decision module after the rollback is completed.
[0083] The embodiment provides a configuration rollback method for a switch. The method comprises the following steps: collecting configuration change information and running state data of the switch, wherein the running state data comprises CPU utilization, memory utilization, network delay, error packet rate and packet loss rate; obtaining a historical configuration record with a time stamp according to the configuration change information; performing abnormal state analysis and rule judgment based on the running state data, a preset safety rule and the historical configuration record to obtain a rollback policy, wherein the rollback policy is generated when a rollback trigger condition in the preset safety rule is met; and performing a configuration rollback operation according to the rollback policy and the historical configuration record. As can be seen, the embodiment adopts different configuration rollback policies for different abnormal states of the switch during configuration change, realizes accurate and fine-grained configuration rollback decision and execution, and improves the recovery efficiency of the configuration management of the switch.
[0084] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as the above-mentioned first embodiment can be referred to the above introduction, and will not be repeated hereinafter. On this basis, please refer to Figure 3 , Figure 3 is a flowchart of the second embodiment of the configuration rollback method for a switch of the present application, and the step S30 specifically comprises:
[0085] Step S301: Obtain performance abnormality judgment rules and configuration policy abnormality judgment rules according to preset security rules.
[0086] It should be noted that the preset security rule library stores the performance abnormality judgment rules and the configuration policy abnormality judgment rules for the Sonic switch. When the system is initialized or the rules are updated, the rollback decision module loads these rules from the preset security rule library. The preset security rules include the performance abnormality judgment rules and the configuration policy abnormality judgment rules. The performance abnormality judgment rules include the judgment criteria for the abnormality of the running state of the switch (such as the excessively high CPU utilization, memory overflow, port error packet storm, etc.) and the prediction rules for the continuity risk of the switch (such as the sudden increase of the packet loss rate after the configuration change, the increase of the delay, etc.). The configuration policy abnormality judgment rules cover the security rules (such as the deletion of the ACL policy leading to the opening of the unauthorized port), the business rules (such as the deletion of the key VLAN configuration without the redundant path) and the syntax rules (such as the CLI command conflict).
[0087] Step S302: Detect a device performance abnormality event according to the performance abnormality judgment rules and the running state data.
[0088] It should be noted that in this step, the rollback decision module receives the running state data from the configuration monitoring module in real time, including the CPU utilization, the memory usage, the port state, the packet loss rate, the network delay, etc. According to the performance abnormality judgment rules, the rollback decision module analyzes the running state data in real time to detect whether there is a performance abnormality event. In addition, it should be noted that the device performance abnormality event refers to the event that the performance indicators of the switch exceed the normal range during the running process, such as the CPU overload, the insufficient memory, the sudden increase of the packet loss rate, etc.
[0089] Step S303: Detect a configuration rule abnormality event according to the configuration policy abnormality judgment rules and the historical configuration records.
[0090] It should be noted that in this step, the rollback decision module obtains the historical configuration records from the configuration record module, including the detailed content of each configuration change, the time of the configuration change, etc. According to the configuration policy abnormality judgment rules, the rollback decision module analyzes the historical configuration records one by one to detect whether there is a configuration rule abnormality event. In addition, it should be noted that the configuration rule abnormality event refers to the event that the configuration of the switch violates the security, business or syntax rules, such as the opening of the unauthorized port, the deletion of the key VLAN configuration, etc.
[0091] Step S304: When the device performance abnormality event and / or the configuration rule abnormality event is detected, determine a rollback strategy according to the device performance abnormality event and / or the configuration rule abnormality event and the preset security rules.
[0092] It should be noted that when the rollback decision module detects abnormal device performance events and / or abnormal configuration rule events, it will comprehensively evaluate whether a rollback operation is necessary based on the details of these events and the rollback trigger conditions in the preset security rules. If the rollback trigger conditions are met (such as performance anomalies causing the switch to be unavailable, or configuration violations causing security risks), the rollback decision module will generate a corresponding rollback strategy, including the rollback target (such as the latest stable version), the rollback scope (such as full configuration rollback or associated module rollback), and the rollback delay (such as within 3 seconds). After the rollback strategy is generated, the rollback decision module sends it to the rollback execution module to prepare for the rollback operation.
[0093] In a feasible implementation manner, step S302 specifically includes:
[0094] Step A10: According to the performance abnormality judgment rule, a CPU utilization threshold, an available memory ratio threshold, an error packet rate threshold, a network delay threshold, and a packet loss rate threshold are obtained.
[0095] It should be noted that during the system initialization phase or when the performance anomaly judgment rules are updated, the rollback decision module will load the performance anomaly judgment rules from the preset security rule library. Specific threshold parameters are parsed from the loaded performance anomaly judgment rules, including but not limited to the CPU utilization threshold (such as 85%), the available memory ratio threshold (such as 10%), the error packet rate threshold (such as 1000 error packets per second), the network delay threshold (such as 100ms), and the packet loss rate threshold (such as 50%). It can be understood that these thresholds serve as a benchmark for judging whether the performance of the device is abnormal, and are used to ensure that the system can accurately identify potential performance problems.
[0096] In addition, it should be noted that the CPU utilization threshold refers to the proportion of the CPU occupied per unit time. Exceeding this threshold may indicate CPU overload. The available memory ratio threshold refers to the proportion of the system's remaining available memory to the total memory. Below this threshold, it indicates insufficient system memory. The error packet rate threshold refers to the number of erroneous data packets received per unit time. Exceeding this threshold indicates a network transmission failure. The network delay threshold refers to the time required for a data packet to be sent and received. Exceeding this threshold indicates network congestion or excessive delay. The packet loss rate threshold refers to the proportion of data packets lost during network transmission. Exceeding this threshold indicates network instability or failure.
[0097] Step A20: Obtain the available memory ratio according to the memory utilization.
[0098] It should be noted that in this step, the rollback decision module obtains the memory usage of the switch in real time through the API interface (such as the restful interface of the Web or the CLI interface) of the Sonic switch, including the total memory and the used memory. According to the obtained total memory and used memory data, the memory utilization rate is calculated, and according to the memory utilization rate, the remaining available memory proportion (1-memory utilization rate) can be calculated.
[0099] Step A30: When any one of the conditions that the CPU utilization is greater than the CPU utilization threshold, the available memory proportion is less than the available memory proportion threshold, the error packet rate is greater than the error packet rate threshold, the packet loss rate is greater than the packet loss rate threshold, and the network delay is greater than the network delay threshold is met, it is determined that the device performance abnormal event of the switch occurs.
[0100] It should be noted that in this step, the rollback decision module receives the running state data from the configuration monitoring module in real time, including CPU utilization, available memory proportion, error packet rate, network delay and packet loss rate and other indicators. Compare these indicators with the threshold values obtained in step A10 to determine whether any indicator exceeds its corresponding threshold value. If any indicator exceeds the threshold value, it is determined that the device performance abnormal event of the switch occurs, and the abnormal event details such as the abnormal type, the occurrence time, etc. are recorded.
[0101] In a feasible implementation, the step S303 specifically includes:
[0102] Step B10: Obtain the access control list rule, network topology rule and syntax conflict rule according to the configuration policy abnormality judgment rule.
[0103] It should be noted that when the system is initialized or the configuration policy abnormality judgment rule is updated, the rollback decision module loads the configuration policy abnormality judgment rule from the preset security rule library. And parse the specific rule types from the loaded configuration policy abnormality judgment rule, including but not limited to ACL (Access Control Lists, Access Control List) rule, network topology rule and syntax conflict rule. For example, the access control list rule includes the provision of prohibiting access to the management port (such as port 22) from a specific IP address. The network topology rule requires that the key VLAN configuration must have a redundant path to ensure the high availability of the network. The syntax conflict rule prohibits conflict operations such as repeated allocation of IP addresses.
[0104] Step B20: Obtain the configuration modification content according to the historical configuration record.
[0105] It should be noted that in this step, the rollback decision module obtains the latest historical configuration records from the configuration record module, which contain detailed information of each configuration modification, such as modification time, operator, modification content, etc. Then the specific configuration modification content is parsed from the historical configuration records, including but not limited to added, deleted or modified configuration items.
[0106] Step B30: When any of the configuration modification contents does not meet the access control list rule, the network topology rule and the syntax conflict rule, it is determined that the switch has a configuration rule abnormal event.
[0107] It should be noted that in this step, the rollback decision module compares the configuration modification content with the rules obtained in step B10 one by one to verify whether the configuration modification violates the access control list rule, the network topology rule or the syntax conflict rule. If it is found that any of the configuration modification contents does not meet any of the above rules, it is determined that the switch has a configuration rule abnormal event, and the abnormal event details such as abnormal type, occurrence time, specific configuration modification content, etc. are recorded.
[0108] It can be understood that through this step, the system can timely find and handle the configuration rule abnormal event, preventing network failure or security vulnerabilities caused by configuration errors.
[0109] In a possible implementation, the step S304 specifically includes:
[0110] Step C10: When the device performance abnormal event and / or the configuration rule abnormal event is detected, a rollback policy table is obtained, the rollback policy table including a correspondence between different fault levels and rollback policies.
[0111] It should be noted that when the rollback decision module detects the device performance abnormal event or the configuration rule abnormal event, the operation of obtaining the rollback policy table is triggered. The rollback policy table is pre-stored in the database or the configuration file of the system, and contains the defined rollback policies for different fault levels. The rollback decision module reads the rollback policy table from the database or the configuration file and loads it into the memory for fast query. In addition, it should be noted that the rollback policy table is a pre-defined table that records the rollback measures to be taken under different fault levels, including but not limited to rollback range (full configuration rollback, associated module rollback, single configuration item repair), recovery target (latest stable version, key service recovery, eliminate syntax error) and execution delay requirement, etc.
[0112] Step C20: According to a preset security rule, a fault level corresponding to the abnormal event is determined, the fault level being determined by the severity and the influence range of the abnormal event.
[0113] It should be noted that in this step, the rollback decision module evaluates the detected abnormal event according to the preset safety rules. The safety rules define the severity and impact range of different types of abnormal events, as well as the corresponding fault levels. The rollback decision module determines the fault level corresponding to the abnormal event by comparing the characteristics of the abnormal event with the definitions in the safety rules. In this embodiment, the severity of the fault level is ranked from high to low as CRITICAL (critical), MAJOR (serious), and MINOR (minor). Among them, the rollback range corresponding to critical is all configurations, the rollback range corresponding to serious is part of the abnormal module, and the rollback range corresponding to minor is a single abnormal configuration.
[0114] Step C30: According to the fault level, match the corresponding rollback strategy in the rollback strategy table.
[0115] It should be noted that in this step, the rollback decision module will find the corresponding rollback strategy in the rollback strategy table according to the fault level determined in step C20. The rollback strategy table records the rollback measures that should be taken under different fault levels, including rollback range, recovery target, and delay requirements for execution. The rollback decision module will determine the specific rollback strategy according to the search results and prepare for execution.
[0116] It can be understood that this step ensures that the system can take the most appropriate rollback strategy according to different fault conditions, thereby improving the efficiency and accuracy of fault recovery.
[0117] In this embodiment, the performance and configuration strategy abnormality judgment rule is generated by presetting the safety rules, and the device performance and configuration rule abnormal event is detected according to the rule, and then the rollback strategy is determined according to the abnormal event and the preset rule, which realizes the automatic and accurate abnormal monitoring and rollback division of the Sonic switch configuration, solves the problems of low recovery accuracy and untimely rollback of the current switch, and improves the efficiency and accuracy of switch fault recovery.
[0118] The present application also provides a configuration rollback device for a switch, please refer to Figure 4 , the configuration rollback device for a switch comprises:
[0119] The configuration monitoring module 10 is used for collecting configuration change information and running state data of the switch, and the running state data includes CPU utilization, memory utilization, network delay, error packet rate and packet loss rate.
[0120] The configuration recording module 20 is used for obtaining historical configuration records with time stamp according to the configuration change information.
[0121] a rollback decision module 30 configured to perform abnormal state analysis and rule judgment based on the running state data, preset safety rules, and the historical configuration record to obtain a rollback strategy, the rollback strategy being generated when a rollback trigger condition in the preset safety rules is met;
[0122] a rollback execution module 40 configured to perform a configuration rollback operation according to the rollback strategy and the historical configuration record.
[0123] The configuration rollback device for a switch provided in the present application adopts the configuration rollback method for a switch in the above embodiments, and can solve the technical problem of how to improve the recovery speed and compatibility of configuration rollback of a switch. Compared with the prior art, the configuration rollback device for a switch provided in the present application has the same beneficial effects as the configuration rollback method for a switch provided in the above embodiments, and other technical features in the configuration rollback device for a switch are the same as the features disclosed in the above embodiments, which will not be described here.
[0124] In an embodiment, the configuration record module 20 is further configured to obtain an operator identifier of configuration change, a configuration change time, and configuration modification content according to the configuration change information, and store the operator identifier, the configuration change time, and the configuration modification content in a database to obtain a historical configuration record with a time stamp.
[0125] In an embodiment, the rollback decision module 30 is further configured to obtain a performance abnormality judgment rule and a configuration strategy abnormality judgment rule according to preset safety rules, detect a device performance abnormality event according to the performance abnormality judgment rule and the running state data, detect a configuration rule abnormality event according to the configuration strategy abnormality judgment rule and the historical configuration record, and determine a rollback strategy according to the device performance abnormality event and / or the configuration rule abnormality event and the preset safety rules when the device performance abnormality event and / or the configuration rule abnormality event is detected.
[0126] In an embodiment, the rollback decision module 30 is further configured to obtain a CPU utilization rate threshold, an available memory ratio threshold, an error packet rate threshold, a network delay threshold, and a packet loss rate threshold according to the performance abnormality judgment rule, obtain an available memory ratio according to the memory utilization rate, and determine that a device performance abnormality event occurs in the switch when any one of the following conditions is met: the CPU utilization rate is greater than the CPU utilization rate threshold, the available memory ratio is less than the available memory ratio threshold, the error packet rate is greater than the error packet rate threshold, the packet loss rate is greater than the packet loss rate threshold, and the network delay is greater than the network delay threshold.
[0127] In an embodiment, the rollback decision module 30 is further configured to obtain an access control list rule, a network topology rule and a syntax conflict rule according to the configuration policy exception judgment rule; obtain configuration modification content according to the historical configuration record; and determine that the switch has a configuration rule exception event when any one of the configuration modification content does not satisfy the access control list rule, the network topology rule and the syntax conflict rule.
[0128] In an embodiment, the rollback decision module 30 is further configured to obtain a rollback policy table when the device performance exception event and / or the configuration rule exception event is detected, the rollback policy table including a corresponding relationship between different fault levels and rollback policies; determine a fault level corresponding to the exception event according to a preset security rule, the fault level being determined by a severity and an influence range of the exception event; and match a corresponding rollback policy in the rollback policy table according to the fault level.
[0129] In an embodiment, the rollback execution module 40 is further configured to determine a rollback target according to the historical configuration record and the rollback policy, the rollback target including a target rollback version, a target rollback module and a target rollback configuration item; determine a rollback delay according to the rollback policy, the rollback delay including a first rollback delay, a second rollback delay and a third rollback delay, the first rollback delay being smaller than the second rollback delay, and the second rollback delay being smaller than the third rollback delay; and perform a configuration rollback operation according to the rollback delay and the rollback target.
[0130] The present application provides a configuration rollback device for a switch, which comprises at least one processor and a memory connected with the at least one processor in communication; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the configuration rollback method for a switch in the above-mentioned embodiment one.
[0131] Reference will now be made to the following description Figure 5 which shows a structural schematic diagram of the configuration rollback device for a switch suitable for implementing the embodiments of the present application. The configuration rollback device for a switch in the embodiments of the present application can include, but is not limited to, mobile terminals such as mobile phones, notebook computers, digital broadcast receivers, PDAs (Personal Digital Assistant), PADs (Portable Application Description), PMPs (Portable Media Player), vehicle-mounted terminals (such as vehicle-mounted navigation terminals) and the like, and fixed terminals such as digital TVs, desktop computers and the like.Figure 5 The configuration rollback device for a switch shown is merely an example and should not bring any limitation to the function and scope of use of the embodiments of the present application.
[0132] As shown in Figure 5 The configuration rollback device for a switch can include a processing device 1001 (e.g., a central processing unit, a graphics processing unit, etc.) that can perform various appropriate actions and processes according to programs stored in a ROM (Read Only Memory) 1002 or programs loaded from a storage device 1003 into a RAM (Random Access Memory) 1004. In the RAM 1004, various programs and data required for the operation of the configuration rollback device for a switch are also stored. The processing device 1001, the ROM 1002, and the RAM 1004 are connected to each other through a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, a touch screen, a touch pad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; output devices 1008 including, for example, an LCD (Liquid Crystal Display), a speaker, a vibrator, etc.; the storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the configuration rollback device for a switch to communicate with other devices wirelessly or by wire to exchange data. Although the configuration rollback device for a switch with various systems is shown in the figure, it should be understood that all the systems shown are not required to be implemented or possessed. More or fewer systems can be alternatively implemented or possessed.
[0133] In particular, the processes described above with reference to the flowcharts can be implemented as a computer software program according to the embodiments disclosed in the present application. For example, the embodiments disclosed in the present application include a computer program product including a computer program carried on a computer readable medium, the computer program containing program codes for executing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network through the communication device, or installed from the storage device 1003, or installed from the ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the methods of the embodiments disclosed in the present application are executed.
[0134] The configuration rollback device for the switch provided in the application adopts the configuration rollback method for the switch in the above embodiment, and can solve the technical problem of how to improve the recovery speed and compatibility of the configuration rollback of the switch. Compared with the prior art, the configuration rollback device for the switch provided in the application has the same beneficial effects as the configuration rollback method for the switch provided in the above embodiment, and other technical features in the configuration rollback device for the switch are the same as the features disclosed in the above embodiment method, and thus are not described herein.
[0135] It should be understood that parts of the present application can be realized by hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0136] The above is merely specific implementation of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
[0137] The present application provides a computer readable storage medium having stored thereon computer readable program instructions (i.e. computer programs) for performing the configuration rollback method for the switch in the above embodiment.
[0138] The computer readable storage medium provided in the present application may, for example, be a U disk, but is not limited to an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, system, or device, or any combination of the above. More specific examples of the computer readable storage medium can include, but are not limited to, an electrical connection with one or more conductive wires, a portable computer disk, a hard disk, a RAM (Random Access Memory), a ROM (Read Only Memory), an EPROM (Erasable Programmable Read Only Memory or flash memory), an optical fiber, a CD-ROM (CD-Read Only Memory), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present embodiment, the computer readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer readable storage medium can be transmitted by any suitable medium, including but not limited to an electrical wire, an optical cable, an RF (Radio Frequency), and the like, or any suitable combination of the above.
[0139] The above computer readable storage medium can be included in a configuration rollback device for a switch, or can exist separately and not be assembled into the configuration rollback device for the switch.
[0140] The above computer readable storage medium carries one or more programs, which, when executed by the configuration rollback device for the switch, cause the configuration rollback device for the switch to: collect configuration change information and running state data of the switch, the running state data including CPU utilization, memory utilization, network delay, error packet rate, and packet loss rate; obtain a time-stamped historical configuration record according to the configuration change information; perform abnormal state analysis and rule judgment based on the running state data, a preset safety rule, and the historical configuration record to obtain a rollback strategy, the rollback strategy being generated when a rollback trigger condition in the preset safety rule is met; and perform a configuration rollback operation according to the rollback strategy and the historical configuration record.
[0141] Computer program code for carrying out operations of the present application can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0142] The flow diagrams and the block diagrams in the drawings are illustrations of architectures, functionalities, and operations of possible implementations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flow diagrams or block diagrams can represent a module, a segment, or a portion of code, which comprises one or more executable instructions for implementing the specified logical function(s). It should also be noted that in some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently or the blocks may
[0143] The modules involved in the embodiments of the present application can be implemented in the form of software or in the form of hardware. In some cases, the name of the module does not constitute a limitation on the module itself.
[0144] The readable storage medium provided by the present application is a computer readable storage medium, which stores computer readable program instructions (i.e., a computer program) for executing the configuration rollback method for a switch, and can solve the technical problem of how to improve the recovery speed and compatibility of the configuration rollback of the switch. Compared with the prior art, the computer readable storage medium provided by the present application has the same beneficial effects as the configuration rollback method for a switch provided by the above-mentioned embodiments, and will not be described here.
[0145] The application further provides a computer program product comprising a computer program which, when executed by a processor, implements the steps of the configuration rollback method for a switch as described above.
[0146] The computer program product provided by the application can solve the technical problem of how to improve the recovery speed and compatibility of the configuration rollback of the switch. Compared with the prior art, the beneficial effects of the computer program product provided by the application are the same as those of the configuration rollback method for a switch provided by the above-mentioned embodiments, and are not described here.
[0147] The above only describes some embodiments of the application, and does not limit the patent scope of the application. Any equivalent structural transformation, direct / indirect application in other related technical fields, or the like made by using the content of the application specification and drawings within the technical concept of the application is included in the patent protection scope of the application.
Claims
1. A configuration rollback method for a switch, characterized in that: The method comprises: Collect switch configuration change information and operating status data, including CPU utilization, memory utilization, network latency, error packet rate, and packet loss rate; Obtaining a historical configuration record with a timestamp according to the configuration change information; An abnormal state analysis and rule judgment are performed based on the operating state data, the preset security rules, and the historical configuration records to obtain a rollback strategy, wherein the rollback strategy is generated when a rollback trigger condition in the preset security rules is met; A configuration rollback operation is performed according to the rollback policy and the historical configuration record.
2. The method according to claim 1, wherein The step of performing abnormal state analysis and rule judgment based on the operating state data, preset security rules, and the historical configuration records to obtain a rollback strategy includes: Obtain performance anomaly judgment rules and configuration policy anomaly judgment rules based on preset security rules; Detecting equipment performance abnormality events according to the performance abnormality judgment rules and the operating status data; Detecting configuration rule abnormality events according to the configuration policy abnormality judgment rule and the historical configuration records; When the device performance abnormality event and / or the configuration rule abnormality event is detected, a rollback strategy is determined according to the device performance abnormality event and / or the configuration rule abnormality event and the preset security rule.
3. The method according to claim 2, wherein The step of detecting an abnormal performance event of the device according to the abnormal performance judgment rule and the operating status data includes: According to the performance anomaly judgment rule, the CPU utilization threshold, the available memory ratio threshold, the error packet rate threshold, the network delay threshold and the packet loss rate threshold are obtained; Obtaining an available memory ratio according to the memory utilization; When any one of the following conditions is met: the CPU utilization is greater than the CPU utilization threshold, the available memory ratio is less than the available memory ratio threshold, the error packet rate is greater than the error packet rate threshold, the packet loss rate is greater than the packet loss rate threshold, and the network delay is greater than the network delay threshold, it is determined that an abnormal device performance event occurs in the switch.
4. The method according to claim 2, wherein The step of detecting configuration rule abnormality events according to the configuration policy abnormality judgment rule and the historical configuration record includes: Obtaining access control list rules, network topology rules, and grammatical conflict rules according to the configuration policy anomaly judgment rule; Obtaining configuration modification content according to the historical configuration record; When any one of the configuration modification contents does not satisfy the access control list rule, the network topology rule, and the syntax conflict rule, it is determined that a configuration rule abnormality event occurs in the switch.
5. The method according to claim 2, wherein The step of determining a rollback strategy according to the device performance abnormality event and / or the configuration rule abnormality event and the preset security rule when the device performance abnormality event and / or the configuration rule abnormality event is detected includes: When the device performance abnormality event and / or the configuration rule abnormality event is detected, a rollback policy table is obtained, wherein the rollback policy table includes a correspondence between different fault levels and rollback policies; Determine the fault level corresponding to the abnormal event according to preset safety rules, where the fault level is determined by the severity and impact scope of the abnormal event; According to the fault level, a corresponding rollback strategy is matched in the rollback strategy table.
6. The method according to claim 1, wherein The step of performing a configuration rollback operation according to the rollback policy and the historical configuration record includes: Determine a rollback target based on the historical configuration record and the rollback strategy, wherein the rollback target includes a target rollback version, a target rollback module, and a target rollback configuration item; Determining a rollback delay according to the rollback policy, the rollback delay including a first rollback delay, a second rollback delay, and a third rollback delay, the first rollback delay being shorter than the second rollback delay, and the second rollback delay being shorter than the third rollback delay; A configuration rollback operation is performed according to the rollback delay and the rollback target.
7. The method according to claim 1, wherein The step of obtaining a historical configuration record with a timestamp according to the configuration change information includes: Obtaining, according to the configuration change information, an operator identifier of the configuration change, a configuration change time, and configuration modification content; The operator identifier, the configuration change time, and the configuration modification content are stored in a database to obtain a historical configuration record with a time stamp.
8. A configuration rollback device for a switch, characterized in that: The device comprises: A configuration monitoring module is used to collect switch configuration change information and operating status data, including CPU utilization, memory utilization, network latency, error packet rate, and packet loss rate; A configuration record module, configured to obtain a historical configuration record with a timestamp according to the configuration change information; A rollback decision module, configured to perform abnormal state analysis and rule judgment based on the operating state data, preset security rules, and the historical configuration records to obtain a rollback strategy, wherein the rollback strategy is generated when a rollback trigger condition in the preset security rules is met; The rollback execution module is used to execute a configuration rollback operation according to the rollback strategy and the historical configuration record.
9. A configuration rollback device for a switch, characterized in that: The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the configuration rollback method for a switch according to any one of claims 1 to 7.
10. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the configuration rollback method for a switch are implemented as claimed in any one of claims 1 to 7.
Citation Information
Patent Citations
SNMP (Simple Network Management Protocol) based equipment configuration roll back method and SNMP network management equipment
CN101977127A
Configuration rollback method and apparatus
CN109361553A
System firmware option rollback configuration method and device, equipment and medium
CN114721874A
Security defense method, system and equipment of switch and medium
CN118041693A
Network security defense method and system and storage medium
CN119109707A
Cited By
Network equipment configuration management method and device, electronic equipment and storage medium
CN121037218A