Method and system for configuring management IP addresses for virtual security protection products

By building a local area network between the controller and the virtual security protection product and using a DHCP server to automatically assign IP addresses, the problem of cumbersome and inefficient IP address configuration for virtual security protection products in existing technologies is solved, and efficient automated configuration is achieved.

CN115801734BActive Publication Date: 2025-11-14BEIJING LIUFANG CLOUD TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211357965.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-01
Publication Date
2025-11-14
Estimated Expiration
2042-11-01

AI Technical Summary

Technical Problem

In a private cloud network environment, configuring the management IP address of a virtual security protection product requires manually accessing the console in the cloud environment, which is cumbersome and inefficient.

Method used

By building a local area network between the controller and multiple virtual security products, a DHCP server is used to assign a private IP address to each virtual security product, and the controller remotely distributes the management IP address configuration to achieve automated configuration.

Benefits of technology

It simplifies the process of configuring the management IP address for virtual security protection products, improves configuration efficiency, and avoids the tediousness of manual operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115801734B_ABST
    Figure CN115801734B_ABST
Patent Text Reader

Abstract

This invention provides a method and system for configuring the management IP address of virtual security protection products, belonging to the field of virtualization protection technology. The method for configuring the management IP address of virtual security protection products includes the following steps: constructing a local area network (LAN) between a controller and multiple virtual security protection products; assigning a private IP address to each virtual security protection product; the controller establishing a connection with each virtual security protection product through the private IP address and issuing a management IP address configuration for each virtual security protection product; and the virtual security protection product configuring its management IP address according to the management IP address configuration. This method and system solve the problem of cumbersome and inefficient manual configuration of virtual security protection product management IP addresses in existing technologies that require entering a cloud environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of virtualization protection technology, specifically to a method for configuring the management IP address of a virtual security protection product, a system for configuring the management IP address of a virtual security protection product, a private cloud network, a computer-readable storage medium, and an electronic device. Background Technology

[0002] Currently, in private cloud network environments, business protection is primarily achieved by accessing and managing virtual security products via their management IP addresses. However, configuring these management IP addresses requires manually entering the virtual security product's console within the cloud environment and using commands. In complex cloud environments with multiple clusters, the workload of configuring virtual security products increases dramatically, requiring manual configuration of each system through the console, resulting in low efficiency. This invention provides a method and system for configuring virtual security product management IP addresses. By configuring all virtual security product management IP addresses in the cloud environment in a single step within the controller, manual configuration of each product through the cloud environment's console is eliminated, simplifying the operation and significantly improving configuration efficiency. Summary of the Invention

[0003] The purpose of this invention is to provide a method for configuring the management IP address of a virtual security protection product, a system for configuring the management IP address of a virtualized security protection product, a private cloud network, a computer-readable storage medium, and an electronic device, so as to at least solve the problems of cumbersome and inefficient manual configuration of the management IP address of a virtual security protection product.

[0004] To achieve the above objectives, a first aspect of the present invention provides a method for configuring the management IP address of a virtual security protection product, the method comprising the following steps:

[0005] Establish a local area network between the controller and multiple virtual security products;

[0006] Assign a private IP address to each of the aforementioned virtual security protection products within a local area network;

[0007] The controller establishes a connection with each of the virtual security protection products through a private IP address, and issues the management IP address configuration of the virtual security protection products to the virtual security protection products.

[0008] The virtual security protection product configures the management IP address based on the management IP address configuration.

[0009] Preferably, the construction of the local area network between the controller and multiple virtual security protection products specifically includes:

[0010] A private network with the same VLAN segment is created on the controller and on the host where each of the virtual security protection products is located;

[0011] The controller and the virtual security protection product are both mounted on the private network.

[0012] Preferably, the controller is equipped with a DHCP server, which assigns private IP addresses to virtual security protection products in the local area network.

[0013] Preferably, before constructing the local area network, the DHCP server, private network, and management IP addresses of each virtual security protection product are pre-configured in the controller.

[0014] Preferably, after configuring the management IP address of the virtual security protection product, it is deleted from the local area network.

[0015] A second aspect of the present invention provides a system for configuring the management IP address of a virtual security protection product, implemented by the method for configuring the management IP address of a virtual security protection product as described above, comprising a controller and a plurality of virtual security protection products, wherein the controller and the plurality of virtual security protection products are connected via a local area network.

[0016] Preferably, the virtual security protection products include, but are not limited to, virtual firewalls, virtual IPS, virtual IDS, and virtual WAF.

[0017] A third aspect of the present invention provides a private cloud network, wherein the management IP address of the virtual security protection product is configured using the method described above for configuring the management IP address of the virtual security protection product.

[0018] A fourth aspect of the present invention provides a computer-readable storage medium storing computer instructions that, when executed on a computer, cause the computer to perform the method described above for configuring a virtual security protection product management IP address.

[0019] The fifth aspect of the present invention provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the method described above for configuring a virtual security protection product management IP address.

[0020] This invention establishes a local area network (LAN) between a controller and multiple virtual security protection products. The controller communicates with the virtual security protection products via this LAN. By simply configuring the management IP address of each virtual security protection product in the controller, the corresponding management IP address can be distributed to the virtual security protection products via the LAN, thus completing the configuration of the virtual security protection product management IP address. This solves the problem of cumbersome and inefficient manual configuration of virtual security protection product management IP addresses in existing technologies that require accessing a cloud environment.

[0021] Other features and advantages of the embodiments of the present invention will be described in detail in the following detailed description section. Attached Figure Description

[0022] The accompanying drawings are provided to further illustrate embodiments of the present invention and form part of the specification. They are used together with the following detailed description to explain the embodiments of the present invention, but do not constitute a limitation thereof. In the drawings:

[0023] Figure 1 This is a flowchart of a method for configuring the management IP address of a virtual security protection product, provided in Embodiment 1 of the present invention.

[0024] Figure 2 This is a system block diagram for configuring the management IP address of a virtual security protection product, provided in Embodiment 1 of the present invention;

[0025] Figure 3 This is a system block diagram for configuring the management IP address of a virtual security protection product, provided in Embodiment 2 of the present invention. Detailed Implementation

[0026] The specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.

[0027] Example 1

[0028] Figure 1 This is a flowchart illustrating the method for configuring the management IP address of a virtual security protection product, as provided in this embodiment. Figure 1 As shown in the figure, this embodiment of the invention provides a method for configuring the management IP address of a virtual security protection product, the method comprising the following steps:

[0029] S1. Establish a local area network between the controller and multiple virtual security products;

[0030] In this embodiment, the construction of the local area network between the controller and multiple virtual security protection products specifically refers to:

[0031] A. Create a private network with the same VLAN segment on the controller and on the host where each of the virtual security protection products is located;

[0032] B. Mount the controller and the virtual security protection product on the private network.

[0033] In this embodiment, the virtual security protection product is simply a virtual firewall. The controller and multiple virtual firewalls are located on the same local area network, enabling communication between the controller and the virtual firewalls. The controller sends management IP address configurations to the virtual firewalls, and the virtual firewalls configure their own management IP addresses based on the received management IP addresses. After configuration, management commands are sent through the management IP addresses to manage the virtual firewalls.

[0034] In this embodiment, the controller calls the private cloud platform API to create a private network with the same VLAN segment on the host where the controller and the virtual firewall are located. The controller then issues the private network to each virtual firewall through the private cloud platform API. After the network cards of the controller and the virtual firewall are mounted, the private network cards of the controller and the virtual firewall are in the same VLAN segment of the local area network, which can realize the communication interconnection between local area networks.

[0035] S2. Assign a private IP address for the local area network to each of the virtual security protection products;

[0036] In this embodiment, the controller is equipped with a DHCP server, which assigns private IP addresses to virtual security protection products in the local area network.

[0037] After the private network LANs are interconnected, the control assigns private network IP addresses to the private network cards of the virtual firewall via a DHCP server.

[0038] S3. The controller establishes a connection with each of the virtual security protection products through a private IP address, and issues the management IP address configuration of the virtual security protection products to the virtual security protection products;

[0039] After the DHCP server assigns private network IP addresses to the private network cards of multiple virtual firewalls, the controller remotely connects to the private network IP addresses of the virtual firewalls through the controller's private network IP address.

[0040] After the controller establishes a remote connection with the virtual firewall, the controller sends the pre-configured virtual firewall management IP configuration to the virtual firewall.

[0041] S4. The virtual security protection product configures the management IP address according to the management IP address configuration.

[0042] Configure a virtual firewall to manage network interface card (NIC) IPs.

[0043] In this embodiment, before constructing the local area network, the DHCP server, private network, and management IP addresses of each virtual security protection product are pre-configured in the controller.

[0044] This invention establishes a local area network (LAN) between a controller and multiple virtual firewalls. The controller communicates with the virtual firewalls via this LAN. By simply configuring the virtual firewall management IP in the controller, the corresponding management IP address can be sent to the virtual firewalls via the LAN, thus completing the virtual firewall management IP address configuration. This solves the problem of cumbersome and inefficient manual configuration operations requiring access to a cloud environment in existing technologies.

[0045] In this embodiment, after configuring the management IP address of the virtual security protection product, the local area network is deleted.

[0046] Figure 2 This is a system block diagram provided in this embodiment for configuring the management IP address of a virtual security protection product. For example... Figure 2 As shown, this embodiment of the invention provides a system for configuring the management IP address of a virtual security protection product, implemented using the method described above for configuring the management IP address of a virtual security protection product. The system includes a controller and multiple virtual security protection products, wherein the controller and the multiple virtual security protection products are connected via a local area network.

[0047] The controller and multiple virtual firewalls reside on the same local area network, enabling communication between the controller and the virtual firewalls. The controller sends management IP address configurations to the virtual firewalls, and the virtual firewalls configure their own management IP addresses accordingly. After configuration, management commands are sent via the management IP addresses to manage the virtual firewalls.

[0048] This embodiment also provides a private cloud network, which uses the method described above for configuring the management IP address of the virtual security protection product to configure the management IP address of the virtual security protection product.

[0049] This embodiment also provides a computer-readable storage medium storing computer program instructions thereon, which, when executed by a processor, implement the above-described method for configuring the management IP address of a virtual security protection product.

[0050] This embodiment also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the method described above for configuring the management IP address of a virtual security protection product.

[0051] Example 2

[0052] This invention provides a method for configuring the management IP address of a virtual security protection product, the method comprising the following steps:

[0053] S1. Establish a local area network between the controller and multiple virtual security products;

[0054] In this embodiment, the construction of the local area network between the controller and multiple virtual security protection products specifically refers to:

[0055] A. Create a private network with the same VLAN segment on the controller and on the host where each of the virtual security protection products is located;

[0056] B. Mount the controller and the virtual security protection product on the private network.

[0057] In this embodiment, the virtual security protection product includes a virtual firewall and a virtual IPS. The controller is located on the same local area network as multiple virtual firewalls and multiple virtual IPS, enabling communication between the controller, virtual firewalls, and virtual IPS. The controller sends management IP address configurations to the virtual firewalls and to the virtual IPSs. After the virtual firewalls and virtual IPSs complete their own management IP address configurations based on the received management IP addresses, they manage the virtual firewalls or virtual IPSs by sending management commands to the management IP addresses.

[0058] In this embodiment, the controller calls the private cloud platform API to create a private network with the same VLAN segment on the host where the controller, virtual firewall, and virtual IPS are located. The controller then issues the private network to each virtual firewall and virtual IPS via the private cloud platform API. After the network cards of the controller, virtual firewall, and virtual IPS are mounted, the private network cards of the controller, virtual firewall, and virtual IPS are in the same VLAN segment of the local area network, which can realize the communication interconnection between local area networks.

[0059] S2. Assign a private IP address for the local area network to each of the virtual security protection products;

[0060] In this embodiment, the controller is equipped with a DHCP server, which assigns private IP addresses to virtual security protection products in the local area network.

[0061] After the private network LANs are interconnected, the control is to assign private network IP addresses to the private network cards of the virtual firewall and the virtual IPS through the DHCP server.

[0062] S3. The controller establishes a connection with each of the virtual security protection products through a private IP address, and issues the management IP address configuration of the virtual security protection products to the virtual security protection products;

[0063] After the DHCP server assigns private network IP addresses to the private network cards of multiple virtual firewalls and virtual IPS, the controller remotely connects to the private network IP addresses of the virtual firewalls and virtual IPS through the controller's private network IP address.

[0064] After the controller establishes a remote connection with the virtual firewall and the virtual IPS, the controller sends the pre-configured virtual firewall management IP configuration to the virtual firewall and the pre-configured virtual IPS management IP configuration to the virtual IPS.

[0065] S4. The virtual security protection product configures the management IP address according to the management IP address configuration.

[0066] Configure the virtual firewall and the management network interface IP of the virtual IPS.

[0067] In this embodiment, before constructing the local area network, the DHCP server, private network, and management IP addresses of each virtual security protection product are pre-configured in the controller.

[0068] This invention establishes a local area network (LAN) between a controller and multiple virtual firewalls. The controller communicates with the virtual firewalls via this LAN. By simply configuring the virtual firewall management IP in the controller, the corresponding management IP address can be sent to the virtual firewalls via the LAN, thus completing the virtual firewall management IP address configuration. This solves the problem of cumbersome and inefficient manual configuration operations requiring access to a cloud environment in existing technologies.

[0069] In this embodiment, after configuring the management IP address of the virtual security protection product, the local area network is deleted.

[0070] Figure 3 This is a system block diagram provided in this embodiment for configuring the management IP address of a virtual security protection product. For example... Figure 3As shown, this embodiment of the invention provides a system for configuring the management IP address of a virtual security protection product, implemented using the method described above for configuring the management IP address of a virtual security protection product. The system includes a controller and multiple virtual security protection products, wherein the controller and the multiple virtual security protection products are connected via a local area network.

[0071] In this embodiment, the virtual security protection product includes a virtual firewall and a virtual IPS, and the controller, virtual firewall, and virtual IPS are interconnected in the same local area network.

[0072] The controller shares a local area network with multiple virtual firewalls and virtual IPS, enabling communication between the controller, virtual firewalls, and virtual IPS. The controller sends management IP address configurations to the virtual firewalls and virtual IPS. After the virtual firewalls and virtual IPS complete their own management IP address configurations based on the received management IP addresses, management commands are sent via the management IP addresses to manage the virtual firewalls.

[0073] This embodiment also provides a private cloud network, which uses the method described above for configuring the management IP address of the virtual security protection product to configure the management IP address of the virtual security protection product.

[0074] This embodiment also provides a computer-readable storage medium storing computer program instructions thereon, which, when executed by a processor, implement the above-described method for configuring the management IP address of a virtual security protection product.

[0075] This embodiment also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the method described above for configuring the management IP address of a virtual security protection product.

[0076] Those skilled in the art will understand that all or part of the steps in the methods of the above embodiments can be implemented by a program instructing related hardware. This program is stored in a storage medium and includes several instructions to cause a microcontroller, chip, or processor to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a portable hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0077] The optional embodiments of the present invention have been described in detail above with reference to the accompanying drawings. However, the embodiments of the present invention are not limited to the specific details described above. Within the scope of the technical concept of the embodiments of the present invention, various simple modifications can be made to the technical solutions of the embodiments of the present invention, and these simple modifications all fall within the protection scope of the embodiments of the present invention. It should also be noted that the various specific technical features described in the above specific embodiments can be combined in any suitable manner without contradiction. To avoid unnecessary repetition, the embodiments of the present invention will not further describe the various possible combinations.

[0078] Furthermore, various different embodiments of the present invention can be combined in any way, as long as they do not violate the spirit of the embodiments of the present invention, they should also be regarded as the content disclosed by the embodiments of the present invention.

Claims

1. A method for configuring the management IP address of a virtual security protection product, characterized in that, The method includes the following steps: Constructing a local area network between the controller and multiple virtual security protection products includes: creating a private network with the same VLAN segment on both the controller and the host where each of the virtual security protection products is located; and mounting the controller and the virtual security protection products on the private network. Assign a private IP address to each of the aforementioned virtual security protection products within a local area network; The controller establishes a connection with each of the virtual security protection products through a private IP address, and issues the management IP address configuration of the virtual security protection products to the virtual security protection products. The virtual security protection product configures its own management IP address based on the management IP address configuration received from the controller; After the virtual security protection product completes its own management IP address configuration, the local area network between the controller and multiple virtual security protection products is deleted.

2. The method for configuring the management IP address of a virtual security protection product according to claim 1, characterized in that, The controller is equipped with a DHCP server, which assigns private IP addresses to virtual security protection products in the local area network.

3. The method for configuring the management IP address of a virtual security protection product according to claim 2, characterized in that, Before constructing the local area network, the DHCP server, private network, and management IP addresses of each virtual security protection product are pre-configured in the controller.

4. A system for configuring the management IP address of a virtual security protection product, implemented using the method for configuring the management IP address of a virtual security protection product as described in any one of claims 1-3, characterized in that, It includes a controller and multiple virtual security protection products, and the controller and the multiple virtual security protection products are connected via a local area network.

5. The system for configuring the management IP address of a virtual security protection product according to claim 4, characterized in that, The virtual security protection products include, but are not limited to, virtual firewalls, virtual IPS, virtual IDS, and virtual WAF.

6. A private cloud network, characterized in that, The method for configuring the management IP address of a virtual security protection product according to any one of claims 1-3 is used to configure the management IP address of the virtual security protection product.

7. A computer-readable storage medium storing computer instructions, characterized in that, When the computer instructions are executed on the computer, the computer performs the method for configuring the management IP address of a virtual security protection product as described in any one of claims 1-3.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method for configuring the management IP address of a virtual security protection product as described in any one of claims 1-3.

Citation Information

Patent Citations

  • Network mode implementation method and device under public cloud architecture

    CN111510310A