A protection subnetwork negotiation method and device
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING TOPSEC NETWORK SECURITY TECH
- Filing Date
- 2022-11-03
- Publication Date
- 2026-08-04
AI Technical Summary
[0005]而上述场景隐藏的两大问题:其一,如果需要访问总部3.3.3.0网段的分支很多,总部需要很多条保护子网,此时总部配置工作量加大,配置非常繁琐,并且同一条隧道保护子网配置个数往往都会受限制,比如有些情况下同一条隧道最大只支持32个保护子网;其二,总部需要限制6.6.6.0/24网段只能被5.5.5.0/24网段访问,被5.5.5.0/24包含的网段不可以访问6.6.6.0/24网段,此时设备如果只支持精确匹配,就需要配置多条隧道部署该场景,而此时设备如果支持模糊匹配,那么该场景久无法部署
[0038] Based on the disclosure of the above embodiments, it can be understood that the beneficial effects of the embodiments of the present invention include first determining the protection subnet to be configured, then customizing the negotiation mode of the protection subnet, including precise matching and fuzzy matching, and finally constructing a protection subnet negotiation message based on the protection subnet and the custom configuration information, and sending it to the system's process negotiation module, so that the process negotiation module can determine the target negotiation mode of the corresponding protection subnet by parsing the protection subnet negotiation message, and perform negotiation based on the target negotiation mode. The above solution in this embodiment can effectively solve the technical problem that the existing technology cannot freely select the matching method, i.e., the negotiation mode, for the same tunnel, and the usage method is too fixed and inflexible, limiting the communication needs of users in different usage scenarios.
Smart Images

Figure CN115695021B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the fields of network communication and network security technology, and in particular to a method and apparatus for protecting subnet negotiation. Background Technology
[0002] The IPsec protection subnet is the network segment where user services reside. The network segment to which the IP addresses used by users at both ends for business communication belong is the IPsec protection subnet. During the IPsec negotiation process, the protection network segment is negotiated in the second phase. The protection network segments at both ends must match successfully for the IPsec negotiation to succeed. Only then can IPsec routes based on the protection subnet be issued to the kernel, allowing user services to use the IPsec tunnel for encrypted service access. Therefore, matching the protection subnet is crucial to the entire negotiation process.
[0003] Negotiation of protection subnets generally defaults to either exact matching or fuzzy matching, and users cannot choose based on their application scenarios. Exact matching means the protection subnets must be completely identical, i.e., the IP address and subnet mask must be exactly the same. Fuzzy matching allows for inclusion matching of protection subnets; for example, 1.1.1.0 / 24 and 1.1.1.1 / 32 are inclusion relationships. When using fuzzy matching, negotiation can still succeed. A successfully negotiated protection subnet is a smaller subnet segment, which is then distributed to the kernel for forwarding.
[0004] Specifically, such as Figure 1 As shown, business access between the headquarters and three branches requires an IPsec tunnel. Branch 1 and Branch 2 belong to a single large network segment, while Branch 3 belongs to a separate segment. Therefore, it's necessary to restrict access to the headquarters' 3.3.3.0 / 24 network segment from both Branch 1 and Branch 2, and restrict access to the headquarters' 6.6.6.6 / 24 network segment from only Branch 3. The headquarters is configured with one tunnel and multiple protection subnets. Since most devices currently use exact matching for protection subnets by default, three protection subnets need to be configured to establish tunnels with the three branches respectively.
[0005] The above scenario presents two major problems: First, if many branches need to access the headquarters' 3.3.3.0 network segment, the headquarters will need many protection subnets, increasing the workload and complexity of configuration. Furthermore, the number of protection subnets that can be configured within the same tunnel is often limited; for example, in some cases, a single tunnel may only support a maximum of 32 protection subnets. Second, the headquarters needs to restrict the 6.6.6.0 / 24 network segment to only be accessible by the 5.5.5.0 / 24 network segment, and prevent network segments included in 5.5.5.0 / 24 from accessing the 6.6.6.0 / 24 network segment. If the device only supports exact matching, multiple tunnels need to be configured to deploy this scenario. However, if the device supports fuzzy matching, this scenario cannot be deployed.
[0006] As can be seen from the above, currently, after the IPsec tunnel protection subnet is in operation, it either performs precise matching or fuzzy matching, and only one of the two can be chosen. For the same tunnel, different protection subnets do not have the ability to freely choose the matching method, which makes the matching method of the protection subnet very inflexible and limits the user application scenarios. Summary of the Invention
[0007] This invention provides a protection subnet negotiation method and apparatus that allows for customized configuration of the negotiation mode of the protection subnet.
[0008] To address the aforementioned technical problems, embodiments of the present invention provide a method for protecting subnet negotiation, comprising:
[0009] Determine the protection subnet that needs to be configured;
[0010] The negotiation mode of the protection subnet can be customized, including exact matching and fuzzy matching;
[0011] Based on the protection subnet and custom configuration information, a protection subnet negotiation message is constructed and sent to the system's process negotiation module. The process negotiation module can then parse the protection subnet negotiation message to determine the target negotiation mode corresponding to the protection subnet and perform negotiation based on the target negotiation mode.
[0012] As an optional embodiment, determining the protection subnet to be configured includes:
[0013] The required protection subnets are determined based on the actual access needs of each network branch, the network segments where each network branch is located, and the network segment of the network headquarters.
[0014] As an optional embodiment, the custom configuration of the negotiation mode for the protection subnet includes:
[0015] Obtain information about the protection subnet, including information about the two communication objects at both ends and the network segment information of the communication objects;
[0016] Based on the information of the protection subnet, determine the target negotiation mode that is compatible with the protection subnet;
[0017] Custom configuration is performed based on the target negotiation mode.
[0018] As an optional embodiment, determining the target negotiation mode adapted to the protection subnet based on the information of the protection subnet includes:
[0019] The target negotiation mode for adapting the protected subnet is determined based on the actual access needs of each network branch, the network segment where each network branch is located, and the network segment of the network headquarters.
[0020] As an optional embodiment, the negotiation mode includes a default negotiation mode. When no custom configuration is performed, the negotiation mode of the protection subnet is the default negotiation mode.
[0021] The custom configuration based on the target negotiation mode includes:
[0022] Adjust the negotiation mode configuration switch based on the target negotiation mode to achieve customized configuration.
[0023] As an optional embodiment, when there are multiple protection subnets, the custom configuration based on the target negotiation mode includes:
[0024] Identify the target protection subnets that require adjustment of the default negotiation mode;
[0025] Based on the target protection subnet and the corresponding target negotiation mode of the target protection subnet, the negotiation mode configuration switch is adjusted to achieve custom configuration.
[0026] Another embodiment of the present invention also provides a subnet negotiation protection device, comprising:
[0027] The determination module is used to determine the protection subnet that needs to be configured;
[0028] The configuration module is used to customize the negotiation mode of the protection subnet, including precise matching and fuzzy matching.
[0029] The construction module is used to construct a protection subnet negotiation message based on the protection subnet and custom configuration information, and send it to the system's process negotiation module, so that the process negotiation module can determine the target negotiation mode corresponding to the protection subnet by parsing the protection subnet negotiation message, and perform negotiation based on the target negotiation mode.
[0030] As an optional embodiment, determining the protection subnet to be configured includes:
[0031] The required protection subnets are determined based on the actual access needs of each network branch, the network segments where each network branch is located, and the network segment of the network headquarters.
[0032] As an optional embodiment, the custom configuration of the negotiation mode for the protection subnet includes:
[0033] Obtain information about the protection subnet, including information about the two communication objects at both ends and the network segment information of the communication objects;
[0034] Based on the information of the protection subnet, determine the target negotiation mode that is compatible with the protection subnet;
[0035] Custom configuration is performed based on the target negotiation mode.
[0036] As an optional embodiment, determining the target negotiation mode adapted to the protection subnet based on the information of the protection subnet includes:
[0037] The target negotiation mode for adapting the protected subnet is determined based on the actual access needs of each network branch, the network segment where each network branch is located, and the network segment of the network headquarters.
[0038] Based on the disclosure of the above embodiments, it can be understood that the beneficial effects of the embodiments of the present invention include first determining the protection subnet to be configured, then customizing the negotiation mode of the protection subnet, including precise matching and fuzzy matching, and finally constructing a protection subnet negotiation message based on the protection subnet and the custom configuration information, and sending it to the system's process negotiation module, so that the process negotiation module can determine the target negotiation mode of the corresponding protection subnet by parsing the protection subnet negotiation message, and perform negotiation based on the target negotiation mode. The above solution in this embodiment can effectively solve the technical problem that the existing technology cannot freely select the matching method, i.e., the negotiation mode, for the same tunnel, and the usage method is too fixed and inflexible, limiting the communication needs of users in different usage scenarios.
[0039] In addition, this embodiment adds a configuration switch to enable or disable fuzzy matching or exact matching for the negotiation of the protection subnet. If the configuration switch is enabled, the network segment will perform fuzzy matching or exact matching. If the configuration switch is not enabled, the network segment will perform negotiation in the default negotiation mode. The method is simple, efficient and easy to implement, and effectively achieves the technical effect that different network segments of the same tunnel can freely choose the negotiation method.
[0040] Other features and advantages of the invention will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the application. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the written description, claims, and drawings.
[0041] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description
[0042] The accompanying drawings are provided to further illustrate the present application and form part of the specification. They are used together with the embodiments of the present application to explain the application and do not constitute a limitation thereof. In the drawings:
[0043] Figure 1 This is a diagram illustrating the structural relationship between headquarters and branches in existing technologies under practical application scenarios.
[0044] Figure 2 This is a flowchart of the protection subnet negotiation method in an embodiment of the present invention.
[0045] Figure 3 This is a diagram illustrating the application of the protection subnet negotiation method in a real-world scenario according to an embodiment of the present invention.
[0046] Figure 4 This is another flowchart of the protection subnet negotiation method in an embodiment of the present invention.
[0047] Figure 5 This is a flowchart illustrating the application of the protection subnet negotiation method in this embodiment of the invention.
[0048] Figure 6 This is a structural block diagram of the protection subnet negotiation device in an embodiment of the present invention. Detailed Implementation
[0049] The specific embodiments of the present invention will now be described in detail with reference to the accompanying drawings, but these are not intended to limit the scope of the invention.
[0050] It should be understood that various modifications can be made to the embodiments disclosed herein. Therefore, the following description should not be considered as limiting, but merely as an example of embodiments. Other modifications within the scope and spirit of this disclosure will be apparent to those skilled in the art.
[0051] The accompanying drawings, which are included in and form part of this specification, illustrate embodiments of the present disclosure and, together with the general description of the disclosure given above and the detailed description of the embodiments given below, serve to explain the principles of the disclosure.
[0052] These and other features of the invention will become apparent from the following description of preferred forms of embodiments given as non-limiting examples, with reference to the accompanying drawings.
[0053] It should also be understood that although the invention has been described with reference to some specific examples, those skilled in the art can certainly implement many other equivalent forms of the invention, which have the features described in the claims and are therefore all within the scope of protection defined herein.
[0054] The above and other aspects, features and advantages of this disclosure will become more apparent when taken in conjunction with the accompanying drawings and in view of the following detailed description.
[0055] Specific embodiments of the present disclosure are described thereafter with reference to the accompanying drawings; however, it should be understood that the disclosed embodiments are merely examples of the present disclosure and can be implemented in various ways. Well-known and / or repeated functions and structures are not described in detail to avoid unnecessary or redundant details that could obscure the present disclosure. Therefore, the specific structural and functional details disclosed herein are not intended to be limiting, but merely to serve as the basis and representative basis for the claims to teach those skilled in the art to use the present disclosure in a variety of substantially any suitable detailed structures.
[0056] This specification may use the phrases “in one embodiment,” “in another embodiment,” “in yet another embodiment,” or “in still another embodiment,” all of which may refer to one or more of the same or different embodiments according to this disclosure.
[0057] The embodiments of the present invention will now be described in detail with reference to the accompanying drawings.
[0058] like Figure 2 As shown, an embodiment of the present invention provides a method for protecting subnet negotiation, including:
[0059] Determine the protection subnet that needs to be configured;
[0060] Customize the negotiation mode for the protection subnet, including exact matching and fuzzy matching.
[0061] Based on the protection subnet and custom configuration information, a protection subnet negotiation message is constructed and sent to the system's process negotiation module. The process negotiation module can then parse the protection subnet negotiation message to determine the target negotiation mode of the corresponding protection subnet and conduct negotiation based on the target negotiation mode.
[0062] In other words, this embodiment first determines the protection subnet to be configured. This can be done automatically by the system based on requirements, or based on user-input commands. Next, the negotiation mode of the protection subnet is customized. This customization can also be done automatically by the system based on actual communication needs, or by the user. In this embodiment, the customization includes exact matching and fuzzy matching. After the customization is completed, the system constructs a protection subnet negotiation message based on the protection subnet and the customized configuration information, and sends it to the system's process negotiation module. The process negotiation module can then parse the protection subnet negotiation message to determine the target negotiation mode for the corresponding protection subnet and perform negotiation based on the target negotiation mode. The above solution in this embodiment effectively solves the technical problem that existing technologies cannot freely select the matching method (i.e., negotiation mode) for the same tunnel, and that the usage method is too fixed and inflexible, limiting users' communication needs in different usage scenarios. It realizes the function of freely selecting the matching method / negotiation mode for the protection subnet, improves product usability, enriches the scenarios for users to use IPsec tunnels for service forwarding, and enhances the user experience.
[0063] Furthermore, the protection subnets that need to be configured include:
[0064] The required protection subnets are determined based on the actual access needs of each network branch, the network segments where each network branch is located, and the network segment of the network headquarters.
[0065] For example, such as Figure 3 As shown, for Figure 3 In the scenario shown, the headquarters has network segments 3.3.3.0 / 24 to 1.1.0.0 / 24, 3.3.3.0 / 24 to 1.1.2.0 / 24, and 6.6.6.0 / 24 to 5.5.5.0 / 24. Branch 1 accesses the 1.1.1.0 / 24 to 3.3.3.0 / 24 network segment, and branch 2 accesses the 1.1.1.0 / 24 to 3.3.3.0 network segment. For the / 24 network segment, branch 3 accesses the 5.5.5.0 / 24---6.6.6.0 / 24 network segment. In this case, the headquarters can configure only one tunnel with the peer address "any" and two protection subnets. Specifically, protection subnet 1 is for the 1.1.0.0 / 24---3.3.3.0 / 24 network segment, and protection subnet 2 is for the 6.6.6.0 / 24---5.5.5.0 / 24 network segment. Then, configure the negotiation mode for the two protection subnets to match the current scenario, and the above access requirements of the three branches can be achieved based on the two protection subnets.
[0066] Furthermore, such as Figure 4 As shown, the negotiation mode for the protection subnet can be customized, including:
[0067] Obtain information about the protected subnet, including information about the two communicating parties and the network segment information of the communicating parties;
[0068] Determine the target negotiation mode for adapting to the protection subnet based on information from the protection subnet;
[0069] Custom configuration based on the target negotiation mode.
[0070] Specifically, the target negotiation mode for adapting to the protection subnet is determined based on information from the protection subnet, including:
[0071] The target negotiation mode for adapting and protecting subnets is determined based on the actual access needs of each network branch, the network segment where each network branch is located, and the network segment of the network headquarters.
[0072] For example, continue to combine Figure 3 As in the above embodiments, the specific negotiation mode configuration of the two protection subnets can be configured as follows: protection subnet 1 is configured as fuzzy matching, so that branch 1 and branch 2, or even multiple branches, can establish tunnels with protection subnet 1 to achieve secure access to the headquarters' 3.3.3.0 / 24 network segment. Meanwhile, protection subnet 2 is configured as exact matching, restricting the headquarters network segment 6.6.6.0 / 24 to be accessed only by branch 3, thereby fulfilling the access needs of each branch.
[0073] Furthermore, the negotiation mode in this embodiment includes the default negotiation mode. When no custom configuration is performed, the negotiation mode of the protection subnet is the default negotiation mode.
[0074] Custom configuration based on the target negotiation mode includes:
[0075] Adjust the negotiation mode configuration switch based on the target negotiation mode to achieve custom configuration.
[0076] For example, such as Figure 5As shown, a fuzzy matching and exact matching selection switch can be added to the configuration module used to configure the protection subnet. This configuration switch allows users to freely select and switch the negotiation mode of the protection subnet according to the application scenario. Alternatively, the system can comprehensively analyze historical data, the access requirements of various branches in the current scenario, and the network segments where the headquarters and various branches are located to determine whether to switch the negotiation mode of the protection subnet and which mode to switch to, thus achieving flexible use of the protection subnet matching mode. Once the target negotiation mode of the protection subnet is determined, the corresponding switch adjustment information can be sent to the background IPsec process pluto (process negotiation module) and stored in the connection information, i.e., in the constructed protection subnet negotiation packet. When the process negotiation module receives the packet, it analyzes and responds to it. Assuming the default negotiation mode is exact negotiation mode, if the module determines that the configured negotiation mode is fuzzy negotiation mode based on the packet analysis, it adjusts the corresponding protection subnet negotiation mode, for example, to fuzzy matching, adding a fuzzy matching process so that the negotiation process matches the protection subnet according to the fuzzy matching process.
[0077] Based on the above-described solution in this embodiment, both users and the system can customize the matching method of the protection subnet for different application scenarios, thereby deploying IPsec tunnel services adapted to the current scenario. Furthermore, this embodiment adds a configuration switch to the negotiation of the protection subnet, allowing for either fuzzy matching or exact matching. If the configuration switch is enabled, the network segment will perform either fuzzy or exact matching; otherwise, it will use the default negotiation mode. This method is simple, efficient, and easy to implement, more effectively achieving the technical effect of allowing different network segments within the same tunnel to freely choose their negotiation method.
[0078] Furthermore, when there are multiple protection subnets, custom configurations are performed based on the target negotiation mode, including:
[0079] Identify the target protection subnets that require adjustment of the default negotiation mode;
[0080] The negotiation mode configuration switch can be adjusted based on the target protection subnet and the corresponding target negotiation mode of the target protection subnet to achieve custom configuration.
[0081] In other words, the protection subnet negotiation message will contain the target negotiation mode corresponding to each protection subnet. The process negotiation module can set different negotiation procedures for different protection subnets based on the target negotiation mode corresponding to each protection subnet. For example, if the default mode is exact negotiation mode, a fuzzy matching switch can be configured first, and this field can be sent to the IPsec background process pluto. Secondly, a fuzzy matching process can be added. Since only exact matching is currently supported, a fuzzy matching process needs to be added in the background. Then, during the protection subnet negotiation process, different matching processes are entered according to the matching method configured for different network segments. When the network segment is matched with fuzzy matching, the fuzzy matching process is entered; when the network segment is configured with exact matching, the exact matching process is entered.
[0082] like Figure 6 As shown, another embodiment of the present invention also provides a protection subnet negotiation device, comprising:
[0083] The determination module is used to determine the protection subnet that needs to be configured;
[0084] The configuration module is used to customize the negotiation mode of the protection subnet, including precise matching and fuzzy matching.
[0085] The construction module is used to construct a protection subnet negotiation message based on the protection subnet and custom configuration information, and send it to the system's process negotiation module, so that the process negotiation module can determine the target negotiation mode corresponding to the protection subnet by parsing the protection subnet negotiation message, and perform negotiation based on the target negotiation mode.
[0086] As an optional embodiment, determining the protection subnet to be configured includes:
[0087] The required protection subnets are determined based on the actual access needs of each network branch, the network segments where each network branch is located, and the network segment of the network headquarters.
[0088] As an optional embodiment, the custom configuration of the negotiation mode for the protection subnet includes:
[0089] Obtain information about the protection subnet, including information about the two communication objects at both ends and the network segment information of the communication objects;
[0090] Based on the information of the protection subnet, determine the target negotiation mode that is compatible with the protection subnet;
[0091] Custom configuration is performed based on the target negotiation mode.
[0092] As an optional embodiment, determining the target negotiation mode adapted to the protection subnet based on the information of the protection subnet includes:
[0093] The target negotiation mode for adapting the protected subnet is determined based on the actual access needs of each network branch, the network segment where each network branch is located, and the network segment of the network headquarters.
[0094] As an optional embodiment, the negotiation mode includes a default negotiation mode. When no custom configuration is performed, the negotiation mode of the protection subnet is the default negotiation mode.
[0095] The custom configuration based on the target negotiation mode includes:
[0096] Adjust the negotiation mode configuration switch based on the target negotiation mode to achieve customized configuration.
[0097] As an optional embodiment, when there are multiple protection subnets, the custom configuration based on the target negotiation mode includes:
[0098] Identify the target protection subnets that require adjustment of the default negotiation mode;
[0099] Based on the target protection subnet and the corresponding target negotiation mode of the target protection subnet, the negotiation mode configuration switch is adjusted to achieve custom configuration.
[0100] Furthermore, another embodiment of the present invention also provides an electronic device, comprising:
[0101] One or more processors;
[0102] Memory, configured to store one or more programs;
[0103] When the one or more programs are executed by the one or more processors, the one or more processors implement the above-described protection subnet negotiation method.
[0104] Furthermore, one embodiment of the present invention also provides a storage medium storing a computer program thereon, which, when executed by a processor, implements the protection subnet negotiation method as described above. It should be understood that the various solutions in this embodiment have the corresponding technical effects in the above method embodiments, and will not be repeated here.
[0105] Furthermore, embodiments of the present invention also provide a computer program product tangibly stored on a computer-readable medium and comprising computer-readable instructions that, when executed, cause at least one processor to perform a protection subnet negotiation method such as those described in the embodiments above.
[0106] It should be understood that the various solutions in this embodiment have the same technical effects as those in the above method embodiments, and will not be repeated here.
[0107] It should be noted that the computer storage medium of this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. Computer-readable media can be, for example, but not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access storage media (RAM), read-only storage media (ROM), erasable programmable read-only storage media (EPROM or flash memory), optical fibers, portable compact disk read-only storage media (CD-ROM), optical storage media, magnetic storage media, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program configured for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, antenna, optical fiber, RF, etc., or any suitable combination thereof.
[0108] It should be understood that although this application is described according to various embodiments, not every embodiment contains only one independent technical solution. This way of describing the specification is only for clarity. Those skilled in the art should regard the specification as a whole. The technical solutions in each embodiment can also be appropriately combined to form other implementation methods that can be understood by those skilled in the art.
[0109] The above embodiments are merely exemplary embodiments of the present invention and are not intended to limit the present invention. The scope of protection of the present invention is defined by the claims. Those skilled in the art can make various modifications or equivalent substitutions to the present invention within its spirit and scope of protection, and such modifications or equivalent substitutions should also be considered to fall within the scope of protection of the present invention.
Claims
1. A method for negotiating a protected subnet, characterized in that, include: Determine the protection subnet that needs to be configured; The negotiation mode of the protection subnet can be customized, including exact matching and fuzzy matching; Exact matching means that the protected subnets are completely identical, that is, the IP address and subnet mask are exactly the same; fuzzy matching means that the protected subnets are matched by inclusion. Based on the protection subnet and custom configuration information, a protection subnet negotiation message is constructed and sent to the system's process negotiation module. This enables the process negotiation module to determine the target negotiation mode corresponding to the protection subnet by parsing the protection subnet negotiation message and to conduct negotiation based on the target negotiation mode. Determining the target negotiation mode adapted to the protection subnet based on the information of the protection subnet includes: The target negotiation mode for adapting the protected subnet is determined based on the actual access needs of each network branch, the network segment where each network branch is located, and the network segment of the network headquarters.
2. The protection subnet negotiation method according to claim 1, characterized in that, The determination of the protection subnet to be configured includes: The required protection subnets are determined based on the actual access needs of each network branch, the network segments where each network branch is located, and the network segment of the network headquarters.
3. The protection subnet negotiation method according to claim 1, characterized in that, The custom configuration of the negotiation mode for the protection subnet includes: Obtain information about the protection subnet, including information about the two communication objects at both ends and the network segment information of the communication objects; Based on the information of the protection subnet, determine the target negotiation mode that is compatible with the protection subnet; Custom configuration is performed based on the target negotiation mode.
4. The protection subnet negotiation method according to claim 1, characterized in that, The negotiation mode includes the default negotiation mode. When no custom configuration is performed, the negotiation mode of the protection subnet is the default negotiation mode. The custom configuration based on the target negotiation mode includes: Adjust the negotiation mode configuration switch based on the target negotiation mode to achieve customized configuration.
5. The protection subnet negotiation method according to claim 4, characterized in that, When there are multiple protection subnets, the custom configuration based on the target negotiation mode includes: Identify the target protection subnets that require adjustment of the default negotiation mode; Based on the target protection subnet and the corresponding target negotiation mode of the target protection subnet, the negotiation mode configuration switch is adjusted to achieve custom configuration.
6. A protection subnet negotiation device, characterized in that, include: The determination module is used to determine the protection subnet that needs to be configured; The configuration module is used to customize the negotiation mode of the protection subnet, including precise matching and fuzzy matching. Exact matching means that the protected subnets are completely identical, that is, the IP address and subnet mask are exactly the same; fuzzy matching means that the protected subnets are matched by inclusion. The construction module is used to construct a protection subnet negotiation message based on the protection subnet and custom configuration information, and send it to the system's process negotiation module, so that the process negotiation module can determine the target negotiation mode corresponding to the protection subnet by parsing the protection subnet negotiation message, and perform negotiation based on the target negotiation mode; The step of determining the target negotiation mode adapted to the protection subnet based on the information of the protection subnet includes: The target negotiation mode for adapting the protected subnet is determined based on the actual access needs of each network branch, the network segment where each network branch is located, and the network segment of the network headquarters.
7. The protection subnet negotiation device according to claim 6, characterized in that, The determination of the protection subnet to be configured includes: The required protection subnets are determined based on the actual access needs of each network branch, the network segments where each network branch is located, and the network segment of the network headquarters.
8. The protection subnet negotiation device according to claim 7, characterized in that, The custom configuration of the negotiation mode for the protection subnet includes: Obtain information about the protection subnet, including information about the two communication objects at both ends and the network segment information of the communication objects; Based on the information of the protection subnet, determine the target negotiation mode that is compatible with the protection subnet; Custom configuration is performed based on the target negotiation mode.