Network access control method, device and electronic device based on security group
By dividing security groups through micro-segmentation, decoupling user identities and VLANs, and using security group policies for permission control, it solves the problem of user permission control fineness and flexibility in large-scale networks, and realizes the effect of policy accompanying users when migrating.
Patent Information
- Application Number
- CN202210427769.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-22
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2042-04-22
AI Technical Summary
In larger-scale networks, the number of VLANs is limited, resulting in low user permission control and poor flexibility. User identity is strongly coupled with VLAN, so permission control cannot be flexibly controlled.
Through micro-segmentation of security groups, the user identity is decoupled from VLAN, the security group policy is used for permission control, the security group scale is expanded to more than 4k, and the mapping relationship between user IP and security group is synchronized through the network management system, so as to realize flexible planning of security group policies and policy accompanying users during migration.
It improves the precision, flexibility and management efficiency of user network access rights management, supports security group configurations of more than 4k scale, and does not need to adjust security group policies when users migrate.
Smart Images

Figure CN115037506B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of communication and cloud computing, and particularly to a network access control method, apparatus, and electronic device based on security groups. Background Art
[0002] In the traditional Virtual Local Area Network (VLAN) networking scenario, the networking levels are generally: core layer, aggregation layer, and access layer. Users enter the VLAN network through access devices. The VLAN gateway is located at the aggregation device. User terminals are configured with static IP addresses or obtain IP addresses dynamically through the Dynamic Host Configuration Protocol (DHCP). After passing authentication by the Authentication, Authorization, and Accounting (AAA) server, users can access other resources within the same VLAN. If there is a need for mutual access between multiple VLANs, the routes can be connected through dynamic routing protocols. At this time, the user's access network and the accessed VLAN represent the user's permissions, and the user permissions can be controlled by configuring Access Control List (ACL) rules. However, the number of VLANs is limited, and the maximum only supports 4K security groups, which cannot meet the fine-grained division and control of user permissions in large-scale scenarios. For users connected within a VLAN gateway, their identities can only belong to the current VLAN, that is, the user IP and VLAN are strongly coupled, and it is impossible to flexibly control user permissions. Summary of the Invention
[0003] In view of this, the present invention provides a network access control method, apparatus, and electronic device based on security groups, which are used to solve the technical problems of limited user permission control by the number of VLANs, low precision, and poor flexibility of access control in a relatively large-scale network.
[0004] On the one hand based on the embodiments of the present invention, the present invention provides a network access control method based on security groups. This method is applied to network devices managed and controlled by a network management system, and the method includes:
[0005] Receiving the mapping relationship between user IP addresses and security groups sent by the network management system, and recording the security group corresponding to the user IP address in the host route of the user;
[0006] Receiving the Policy Based Routing (PBR) of the security group sent by the network management system, where the PBR includes a matching condition and an execution action field;
[0007] When receiving a user packet, performing access control on the user packet based on the PBR; the access control means that the network device matches the source security group and the destination security group in the user packet through the matching condition in the PBR, and performs control operations on the packets that hit the PBR according to the execution action specified by the PBR.
[0008] Further, the method further includes: receiving the mapping relationship between the default security group and the subnet sent by the network management system; and in the case that the network device does not receive the mapping relationship between the user IP address and the security group issued by the network management system, recording the missing security group corresponding to the subnet where the user is located in the host route of the user.
[0009] Further, the mapping relationship between the user IP address and the security group includes: the mapping relationship between the IP addresses of different users within the same VLAN and the same security group and / or the mapping relationship between the IP addresses of different users within the same VLAN and different security groups.
[0010] Further, in the case that the user migrates to a different VLAN and the security group to which the user belongs remains unchanged, the network device within the VLAN to which the user migrates performs access control on the user packets based on the same PBR.
[0011] On the other hand based on the embodiment of the present invention, a network access control device based on a security group, which is applied to a network device managed and controlled by a network management system, the device includes:
[0012] A mapping relationship recording module, configured to receive the mapping relationship between the user IP address and the security group sent by the network management system, and record the security group corresponding to the user IP address in the host route of the user;
[0013] A security group policy module, configured to receive the security group policy route PBR sent by the network management system, where the PBR includes a matching condition and an execution action field;
[0014] An access control module, configured to perform access control on the user packets based on the PBR when receiving the user packets; the access control refers to matching the source security group and the destination security group in the user packets through the matching condition in the PBR, and performing control operations on the packets that hit the PBR according to the execution action specified by the PBR.
[0015] Further, the device further includes: a default relationship recording module, configured to receive the mapping relationship between the default security group and the subnet sent by the network management system; and in the case that the network device does not receive the mapping relationship between the user IP address and the security group issued by the network management system, recording the missing security group corresponding to the subnet where the user is located in the host route of the user.
[0016] Further, the mapping relationship between the user IP address and the security group includes: the mapping relationship between the IP addresses of different users within the same VLAN and the same security group and / or the mapping relationship between the IP addresses of different users within the same VLAN and different security groups.
[0017] Further, when a user migrates to a different VLAN and the security group to which the user belongs remains unchanged, the access control module within the VLAN to which the user migrates performs access control on user packets based on the same PBR.
[0018] Through the method of micro-segmenting security groups, the present invention decouples the user identity from the VLAN, binds the user identity to the security group, the scale of the security group can be extended to more than 4k, and the network access control policy between security groups can be flexibly planned through the security group policy. Moreover, the user IP address is decoupled from the VLAN, the user network access permission is controlled by the security group policy, and the security group policy does not need to change when the user migrates, thus achieving policy follow-up when the user migrates, and improving the fineness, flexibility and management efficiency of user network access permission management and control. Description of the Drawings
[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required to be used in the description of the embodiments of the present invention or the prior art. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings of the embodiments of the present invention.
[0020] Figure 1 It is a schematic flow chart of the steps of a network access control method based on security groups provided by an embodiment of the present invention;
[0021] Figure 2 It is a schematic diagram of the network architecture and configuration for implementing fine-grained access control of user permissions by applying the network access control method based on security groups provided by the present invention in an embodiment of the present invention;
[0022] Figure 3 It is a schematic diagram of the network architecture and configuration for implementing aggregated access control of user permissions by applying the network access control method based on security groups provided by the present invention in an embodiment of the present invention;
[0023] Figure 4 It is a schematic diagram of the network architecture and configuration for implementing policy follow-up of user permissions by applying the network access control method based on security groups provided by the present invention in an embodiment of the present invention;
[0024] Figure 5 It is a schematic diagram of the structure of an electronic device for implementing the network access control method based on security groups provided by an embodiment of the present invention. Detailed Embodiments
[0025] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, rather than limiting the embodiments of the present invention. The singular forms "a", "said" and "the" used in the embodiments of the present invention are also intended to include plural forms, unless the context clearly indicates other meanings. The term "and / or" used in the present invention refers to any or all possible combinations of one or more associated listed items.
[0026] It should be understood that although the terms first, second, third, etc. may be used to describe various information in embodiments of the present invention, these information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of embodiments of the present invention, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, in addition, the word "if" used may be interpreted as "at the time of" or "when" or "in response to determining".
[0027] Micro-segmentation is a grouping of network endpoints (such as one or a group of servers) according to certain principles. Each micro-segment has a globally unique ID. In the network management system (or network management platform), micro-segmentation is represented as a user security group. User permission control no longer matches the user VLAN or the network segment where the user is located, but uses security groups for policy control. Micro-segmentation of the network can support the planning of security groups exceeding 4k, thereby breaking the limit on the number of VLANs.
[0028] Traditional network devices do not have the ability to synchronize user micro-segment information, so the present invention uses the network management system to synchronize user micro-segment information. When a user accesses the VLAN network and passes the authentication, the corresponding relationship between the user IP address and the security group can be carefully planned on the network management system, that is, the mapping relationship between the user IP and the micro-segment, and then the information is distributed to the devices that need to be controlled by the policy, so as to achieve cross-device synchronization of user identity information.
[0029] After micro-segmentation, when you need to configure policy routing to control user traffic and / or access rights, you only need to configure the policies between security groups on the network management system without having to worry about the user's specific access location, thereby decoupling user permissions from VLANs and achieving the purpose of policy mobility.
[0030] If the micro-segmentation information containing the user network segment is manually configured on the aggregation and core devices of the entire network, decoupling the VLAN from the user identity, using the micro-segmentation information as the user identity, and then configuring the ACL to control the user traffic and permissions, the configuration work will be very complex and huge. Moreover, due to the uncertainty of the user access traffic and the policy control points, sometimes it is necessary to dynamically adjust the relationship between the user's IP address and the micro-segmentation on the specified device or even on all the devices in the network, and the manual maintenance cost is extremely high.
[0031] The object of the present invention is to provide an efficient configuration ability for security groups with a scale of more than 4k for a relatively large-scale network, and to solve the requirements of fine planning of user permissions and policy follow-up in a relatively large-scale network. The basic idea of the present invention is: using the micro-segmentation identifier as the security group identifier of the user, establishing the mapping relationship between the user IP and the security group and establishing the policy routing between the security groups through the network management system, and synchronizing the mapping relationship and the policy routing to the network devices, so as to realize more refined, flexible and efficient permission control for users in a relatively large-scale network.
[0032] Figure 1 It is a schematic diagram of the step flow of a network access control method based on security groups provided by an embodiment of the present invention. This method is applied to a relatively large-scale network with a demand for micro-segmentation (i.e., security group division) of more than 4k. The network includes a network management system for managing the network devices in the network. The network devices described in the present invention include: routers, switches, SDN controllers, firewalls, etc. The network management system described in the present invention is a general term for the software and hardware systems responsible for managing and controlling network devices. The network management system includes a software-defined network (SDN) controller for controlling network devices, (such as an EIA server, an AAA server, etc.) for authenticating, authorizing and charging user devices, a DHCP server for allocating and managing IP addresses for users, a network management server for managing and maintaining network devices, etc.
[0033] Step S11. Create user security groups and default security groups;
[0034] When doing network planning, divide the users into security groups based on business requirements, and plan the network users with the same security policy requirements into a security group through micro-segmentation. Create the planned security groups through the network management system, and assign a micro-segmentation identifier ID to each security group.
[0035] In the present invention, when planning the security groups for users, the security groups may not be bound to the network segment or the VLAN. The purpose of the present invention is to realize the binding of user permissions and IPs through the security groups. Different users within the same network segment can be planned into different security groups or the same security group, and users in different network segments can also be planned into the same security group, and the network access permissions are controlled based on the security groups.
[0036] In order to improve security and flexibility, you can also plan and create a default security group to bind the user's IP address to the default security group when the network device does not obtain the user's security group. For example, if the network management network connection between the network device and the network management system fails, the network management system cannot synchronize the mapping relationship between the newly online user's IP address and the security group, i.e., the micro-segment, to the network device in time. At this time, the network device can assign the user to the default security group that the network management system pre-configured for the user's subnet, and the network management system sends the default security group and subnet mapping relationship to the user device in advance. If the user goes online without authentication, or after authentication, before the mapping relationship between the user's security group and IP is sent to the network device, the network device performs access control on the user's message by matching the default security group to hit the relevant security group policy to avoid uncontrolled user permissions. On the network device, the priority of the mapping relationship between the security group, i.e., the micro-segment, and the IP address is higher than the mapping relationship between the micro-segment and the subnet.
[0037] Step S12. Create VLAN and subnet, and associate the default security group;
[0038] When creating VLANs and subnets, the network management system can associate the subnets with default security groups.
[0039] Step S13. The network management system issues a default security group and subnet mapping relationship to the network device;
[0040] When network devices (such as switches and routers) are online, the network management system can issue a mapping between the subnet and the default security group to the network device. In this way, if the network device does not obtain the mapping between the user security group and the IP address, the default security group bound to the subnet can be assigned to the user according to the subnet where the user is located.
[0041] Step S14. The network management system establishes a mapping relationship between the online user's IP address and the security group according to the security group pre-assigned to the user and synchronizes it to the network device;
[0042] When registering a user on the network management system, you can configure the security group to which the user belongs. After the user passes the authentication server in the network management system and goes online, the DHCP server assigns an IP address to the user. The network management system binds the user's IP address to the security group according to the security group pre-assigned to the user, thus establishing a mapping relationship.
[0043] The network management system synchronizes the mapping relationship between the user IP address and the security group to the relevant network device set through a network configuration protocol (such as Netconf, etc.), a network management protocol (such as SNMP, etc.), or a private protocol channel. The network device that receives the mapping relationship between the user IP address and the security group records the corresponding security group information in the host route of the user. In this way, when the user accesses other devices across network devices, the network devices on the relevant paths will all record the security group information of the user.
[0044] When a network device pre-receives the mapping relationship between the default security group and the subnet issued by the network management system during online operation, or the network administrator configures the mapping relationship between the default security group and the subnet for the network device, and the network device does not receive the mapping relationship between the user IP address and the security group issued by the network management system, the missing security group corresponding to the subnet where the user is located is recorded in the host route of the user.
[0045] Step S15. The network management system creates and configures a security group policy, and converts the security group policy into a security group policy-based route (PBR) and synchronizes it to the network device;
[0046] Configure the security group policy between security groups on the network management system, including the security group policy related to the default security group, and then convert the security group policy into a policy-based route (PBR) and synchronize it to the network device. Among them, PBR includes a matching condition and an execution action. The matching condition is expressed by an ACL, and the matching condition includes the micro-segmentation field information of the source security group and the destination security group. The execution action can be control operations such as allow, deny, forward, mirror, discard, etc.
[0047] Step S16. The network management system issues the security group policy-based route PBR to the network device;
[0048] The network management system can synchronize the PBR to the network device through a protocol channel such as a network configuration protocol (such as Netconf) or a network management protocol (such as SNMP).
[0049] Step S17. The network device performs access control on user packets based on the PBR;
[0050] When users access each other and user traffic flows through the network device, the network device matches the source security group and the destination security group in the packet through the matching condition (i.e., ACL) in the PBR, and performs corresponding access control on the packet that hits the PBR according to the execution action of the PBR.
[0051] Figure 2This is a networking and configuration schematic diagram for implementing refined user permission access control using the network access control method based on security groups provided by the present invention in an embodiment of the present invention. In this embodiment, the network management system consists of software-defined network (SDN) control server components, authentication server components (such as the End-user Intelligent Access, EIA component), DHCP server components, configuration management server components, etc. After the security group policy configuration is completed through the network management system, the SDN controller component synchronizes the security group policy policy-based routing (PBR) to the aggregation layer network devices. The EIA component in the network management system establishes a mapping relationship between the online user IP addresses and security groups according to the security groups pre-assigned to users and synchronizes it to the network devices at the aggregation layer.
[0052] As shown in the example, two security group policies are established through the network management system. The source security group tag (SGT) of Policy 1 is 100, the destination SGT is 200, and the action is allowed. The control function executed by this policy is to allow users belonging to SGT 100 to access users or services in the security group with SGT 200. Similarly, the control function executed by Policy 2 is to not allow users belonging to SGT 100 to access users or services in the security group with SGT 300.
[0053] As shown in the example, online users A and C are in VLAN 10, and online user B is in VLAN 20. Through the network management system configuration, user A belongs to security group 100, user B belongs to security group 200, and user C belongs to security group 300. The gateway system establishes a mapping relationship between the user IP addresses and the security group SGT and synchronizes the mapping relationship to the aggregation layer network devices.
[0054] Users A and C are different users within the same VLAN and belong to different security groups. User B has a different VLAN from users A and C, and the three users belong to different security groups.
[0055] By synchronizing security group policies 1 and 2 to the aggregation layer network devices, network access control can be achieved as follows: User A can access user B (matching security group policy 1), and user A cannot access user C (matching security group policy 2).
[0056] When users access each other, by matching the mapping relationship between the user IP addresses and the security group representation SGT, and then hitting the corresponding security group policy, refined user access control can be achieved.
[0057] Figure 3This is a network architecture and configuration diagram for implementing aggregated access control of user permissions using the network access control method based on security groups provided by the present invention in an embodiment of the present invention. In this embodiment, user A is online in VLAN 10, user B is online in VLAN 20, and user C is online in VLAN 30. User A belongs to security group 100, and users B and C belong to security group 200. The security group policy is to prohibit users in security group 100 from accessing users in security group 200. By synchronizing security group policy 1 to the aggregation layer network device, the effect of aggregated access control of user A not being able to access users B and C can be achieved.
[0058] Figure 3 In the exemplary embodiment, users in different VLAN networks are planned to belong to the same security group on the network management system to achieve the purpose of aggregated user permissions. Then, by configuring the access policies between security groups and distributing the security group-based policies on the switch, when these users in different VLANs belonging to the same security group access externally, by matching the mapping relationship between the user IP address and the security group, the ACL rules of the same security group policy can be hit, achieving the purpose of saving ACL resources on the network device.
[0059] Figure 4 This is a network architecture and configuration diagram for implementing user permission policy following using the network access control method based on security groups provided by the present invention in an embodiment of the present invention. In this example, user A is online in VLAN 10 and user B is online in VLAN 20. User A needs to migrate from the network of VLAN10 to the network of VLAN30. Before migration, user A belongs to security group 100 and user B belongs to security group 200. After migration, user A still belongs to security group 100. The gateway system configures security group policy 1 to prohibit users in security group 100 from accessing users in security group 200 and synchronizes security group policy 1 to the aggregation layer network device. When user A migrates to the aggregation layer network device where VLAN30 is located, the distributed security group policy 1 does not need to be adjusted.
[0060] Figure 4 The example plans the security groups to which users belong on the network management system, configures the access policies between security groups, and distributes the configuration to the relevant aggregation layer network devices in advance. When users belonging to the same security group migrate between different VLAN networks without changing the security group policy, after the users are re-authenticated and go online, they are still subject to the access control of the security group policy without the need to modify and re-synchronize the security group policy. That is, when a user migrates to a different VLAN and the security group to which the user belongs remains unchanged, the newly accessed network device performs access control on the user packets based on the same PBR, thereby achieving the purpose of user permission policy following and effectively reducing the maintenance pressure on system administrators.
[0061] In summary, in a traditional network, the user identity is bound to a VLAN, which cannot support the control of user access policies for a scale of more than 4K users. Moreover, when a user migrates, the access permissions and policies based on the VLAN need to change accordingly, and the control fineness and flexibility of the user network permissions are insufficient. Through the method of micro-segmenting security groups, the present invention decouples the user identity from the VLAN, binds the user identity to the security group, and the scale of the security group can be extended to more than 4K. The network access control policies between security groups can be flexibly planned through security group policies. In addition, the user IP address is decoupled from the VLAN, and the user network access permissions are controlled by security group policies. When a user migrates, the security group policies do not need to change, thus achieving policy follow-up during user migration and improving the accuracy, flexibility, and efficiency of user network access permission management and control.
[0062] Figure 5 FIG. 4 is a schematic structural diagram of an electronic device for implementing the network access control method based on security groups provided in an embodiment of the present invention. The device 500 includes a processor 510 such as a central processing unit (CPU), a communication bus 520, a communication interface 540, and a machine-readable storage medium 530. Among them, the processor 510 and the storage medium 530 can communicate with each other through the communication bus 520. The storage medium 530 stores a computer program, and when the computer program is executed by the processor 510, the functions of the network access control method based on security groups provided in the embodiment of the present invention can be realized.
[0063] Among them, the storage medium may include a random access memory (RAM), and may also include a non-volatile memory (NVM), such as at least one disk memory. In addition, the storage medium may also be at least one storage device located far from the aforementioned processor. The processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0064] It should be recognized that embodiments of the present invention can be implemented or carried out by computer hardware, a combination of hardware and software, or by computer instructions stored in a non-transitory memory. The methods can be implemented in a computer program using standard programming techniques, including a non-transitory storage medium configured with the computer program, where the storage medium so configured causes the computer to operate in a specific and predefined manner. Each program can be implemented in a high-level procedural or object-oriented programming language to communicate with a computer system. However, if desired, the program can be implemented in assembly or machine language. In any case, the language can be a compiled or interpreted language. Additionally, for this purpose the program is capable of running on a programmed application-specific integrated circuit. Further, the operations of the processes described in the present invention can be performed in any suitable order, unless the present invention otherwise indicates or is otherwise clearly contradicted by the context. The processes described in the present invention (or variations and / or combinations thereof) can be executed under the control of one or more computer systems configured with executable instructions and can be implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) executed jointly on one or more processors, by hardware, or by a combination thereof. The computer program includes a plurality of instructions executable by one or more processors.
[0065] Furthermore, the methods can be implemented in any type of computing platform operably connected, including but not limited to personal computers, minicomputers, mainframes, workstations, network or distributed computing environments, separate or integrated computer platforms, or communicating with charged particle tools or other imaging devices, etc. Aspects of the present invention can be implemented in machine-readable code stored on a non-transitory storage medium or device, whether removable or integrated into the computing platform, such as a hard disk, optical read and / or write storage medium, RAM, ROM, etc., such that it is readable by a programmable computer and, when read by the computer, can be used to configure and operate the computer to perform the processes described herein. Additionally, the machine-readable code, or portions thereof, can be transmitted via a wired or wireless network. When such media include instructions or programs that implement the above-described steps in conjunction with a microprocessor or other data processor, the present invention includes these and other different types of non-transitory computer-readable storage media. When programmed according to the methods and techniques of the present invention, the present invention also includes the computer itself.
[0066] The above are only embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.
Claims
1. A network access control method based on security groups, characterized in that The method is applied to network devices managed and controlled by a network management system. The method includes: Receiving the mapping relationship between user IP addresses and security groups sent by the network management system, and recording the security group corresponding to the user IP address in the host route of the user. After the user passes the authentication of the authentication server in the network management system and goes online, the DHCP server assigns an IP address to the user. The network management system binds the user's IP address and security group according to the security group pre-assigned to the user, and establishes a mapping relationship; Receiving the security group policy-based routing (PBR) sent by the network management system, where the PBR includes a matching condition and an execution action field; When receiving a user packet, performing access control on the user packet based on the PBR; the access control means that the network device matches the source security group and the destination security group in the user packet through the matching condition in the PBR, and controls the packet that hits the PBR according to the execution action specified by the PBR; Receiving the mapping relationship between the default security group and the subnet sent by the network management system; In the case where the network device does not receive the mapping relationship between the user IP address and the security group sent by the network management system, recording the default security group corresponding to the subnet where the user is located in the host route of the user.
2. The method according to claim 1, wherein The mapping relationship between the user IP address and the security group includes: the mapping relationship between the IP addresses of different users within the same VLAN and the same security group and / or the mapping relationship between the IP addresses of different users within the same VLAN and different security groups.
3. The method according to claim 1, wherein In the case where the user migrates to a different VLAN and the security group to which the user belongs remains unchanged, the network device in the VLAN to which the user migrates performs access control on the user packet based on the same PBR.
4. A network access control device based on a security group, characterized in that, The apparatus is applied to network devices managed and controlled by a network management system. The apparatus includes: A mapping relationship recording module, configured to receive the mapping relationship between user IP addresses and security groups sent by the network management system, and record the security group corresponding to the user IP address in the host route of the user. After the user passes the authentication of the authentication server in the network management system and goes online, the DHCP server assigns an IP address to the user. The network management system binds the user's IP address and security group according to the security group pre-assigned to the user, and establishes a mapping relationship; A security group policy module, configured to receive the security group policy-based routing (PBR) sent by the network management system, where the PBR includes a matching condition and an execution action field; An access control module, configured to perform access control on the user packet based on the PBR when receiving the user packet; the access control means matching the source security group and the destination security group in the user packet through the matching condition in the PBR, and controlling the packet that hits the PBR according to the execution action specified by the PBR; A default relationship recording module, configured to receive the mapping relationship between the default security group and the subnet sent by the network management system; in the case where the network device does not receive the mapping relationship between the user IP address and the security group sent by the network management system, recording the default security group corresponding to the subnet where the user is located in the host route of the user.
5. The apparatus according to claim 4, wherein The mapping relationship between the user IP address and the security group includes: the mapping relationship between the IP addresses of different users within the same VLAN and the same security group and / or the mapping relationship between the IP addresses of different users within the same VLAN and different security groups.
6. The device according to claim 4, wherein When a user migrates to a different VLAN and the security group to which the user belongs remains unchanged, the access control module within the VLAN into which the user migrates performs access control on user packets based on the same PBR.
7. An electronic device, characterized in that, It includes a processor, a communication interface, a storage medium, and a communication bus. Among them, the processor, the communication interface, and the storage medium complete mutual communication through the communication bus; The storage medium is used to store computer programs; The processor, when executing the computer programs stored on the storage medium, implements the method steps described in any one of claims 1-3.
8. A storage medium having a computer program stored thereon, characterized in that, The computer program, when executed by the processor, implements the method steps described in any one of claims 1 to 3.
Citation Information
Patent Citations
Traffic control method and device
CN111541616A
Data forwarding method based on packet label strategy
CN114039910A