Quick method for realizing authentication function of firewall
An implementation method and firewall technology, applied in digital transmission systems, electrical components, transmission systems, etc., can solve problems such as the increase of firewall internal rules, the degradation of system operation performance, and the impact on the overall performance of user networks, so as to reduce rule matching entries and quickly Firewall authentication, the effect of improving the speed of label setting
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Publication Date
- 2009-06-10
- Estimated Expiration
- Not applicable · inactive patent
Abstract
Description
Technical field:
[0001] The invention relates to the technical field of firewalls, in particular to a method for realizing a fast firewall authentication function. Background technique:
[0002] The firewall organizes rules mainly according to the packet header information of the network layer and the transport layer, that is, sets rules according to information such as IP addresses and ports. During processing, the IP packets to be forwarded are matched against the rules sequentially, and corresponding processing actions are taken according to the matching results. At present, a small number of firewalls have an authentication function. In its implementation, ACL rules are often dynamically added to the firewall according to user authentication information. As the number of users continues to increase, the system's operating performance decreases rapidly, which eventually affects the overall performance of the user network. Invention content:
[0003] The purpose of the...
Examples
Embodiment 1
[0022] Embodiment 1: the present invention comprises the following steps successively:
[0023] (1) Label definition
[0024] The length of the label is 4 bytes. For the convenience of processing, the length of each information field is one byte, as shown in the following table:
[0025] Extended Information ACL rules Downlink Bandwidth Rules Uplink Bandwidth Rules
[0026] 1) Extended information:
[0027] The length is one byte, mainly for future expansion;
[0028] 2) ACL rules:
[0029] The length is one byte, mainly used to control the scope of user access, corresponding to the ACL rules;
[0030] 3) Downlink bandwidth rules:
[0031] The length is one byte, mainly used to control the user's downlink bandwidth, corresponding to the downlink bandwidth rules;
[0032] 4) Uplink bandwidth rules:
[0033] The length is one byte, mainly used to control the user's uplink bandwidth, corresponding to the uplink bandwidth rules;
[0034] Since the length...
Embodiment 2
[0046] Embodiment 2: In order to realize label setting quickly, further improve the label search speed, in step (3), adopted fast mapping method to optimize, concrete implementation steps are as follows:
[0047] 1) After receiving the user IP and tag, the secure access authentication platform checks whether the index array corresponding to the IP address exists, and if it exists, writes the tag tag to the location corresponding to IP-IP&FFFFFFOO; if it does not exist, the kernel creates a length It is an array of 256, and write the array address and the IP address range of the index (IP&FFFFFFOO~IP&FFFFFFOO+255) into a specific linked list (list) in the kernel, and write the tag into the corresponding position of the index array, that is, write To the element of IP-IP&FFFFFFOO of the array;
[0048] 2) When the data message is forwarded through the secure access authentication platform, the kernel searches the linked list list according to the IP header information of the mes...