Firewall configuration delivery method and device

By receiving data from the configuration management terminal to create a configuration change table and distributing firewall configurations based on field status, the problem of frequent firewall configuration retrieval by the centralized network management terminal is solved, achieving fast and stable configuration management and improving the efficiency and stability of firewall configuration distribution.

CN115865655BActive Publication Date: 2026-05-19HILLSTONE NETWORKS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HILLSTONE NETWORKS CO LTD
Filing Date
2022-12-08
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing firewall configuration methods require the centralized network management terminal to frequently retrieve the latest firewall configuration file, resulting in high firewall load and low configuration management efficiency.

Method used

By receiving configuration modification data from the configuration management terminal, a configuration change table is created and stored. Firewall configuration is then distributed based on field status and the target configuration change table. A weak consistency and strong consistency distribution process is adopted to reduce invalid difference comparisons and improve configuration management efficiency.

Benefits of technology

It enables rapid and stable distribution of firewall configuration changes, reducing firewall load and improving configuration management efficiency and stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115865655B_ABST
    Figure CN115865655B_ABST
Patent Text Reader

Abstract

The application provides a firewall configuration issuing method and device, the method comprises the following steps: receiving configuration modification data of a preset configuration change table sent by a configuration management end; modifying the configuration change table according to the configuration modification data to obtain a target configuration change table; determining the field state of a current configuration change field in the target configuration change table after receiving a configuration issuing instruction triggered by a user; and issuing the firewall configuration according to the field state and the target configuration change table. It can be seen that the method and device can quickly issue the firewall configuration change, reduce the pressure of the firewall, and thus improve the efficiency of the configuration management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of firewall technology, and more specifically, to a firewall configuration distribution method and apparatus. Background Technology

[0002] Currently, with the widespread adoption of enterprise informatization, network information security has attracted increasing attention. To ensure the information security of network devices, firewalls are typically used to implement strict access control. Existing firewall configuration methods generally involve the centralized network management system handling the use and maintenance of the firewall, with all access control policies processed by the network administrator. In practice, it has been found that every small configuration change at the centralized network management system requires a timely retrieval of the latest configuration file from the firewall to ensure correct configuration distribution. This not only puts pressure on the firewall but also affects the efficiency of configuration management. Summary of the Invention

[0003] The purpose of this application is to provide a firewall configuration distribution method and apparatus that can quickly distribute firewall configuration changes, reduce firewall pressure, and thus improve the efficiency of configuration management.

[0004] The first aspect of this application provides a method for distributing firewall configurations, including:

[0005] Receive configuration modification data for a preset configuration change table sent by the configuration management terminal;

[0006] The configuration change table is modified according to the configuration modification data to obtain the target configuration change table;

[0007] After receiving the configuration issuance instruction triggered by the user, determine the field status of the current configuration change field in the target configuration change table;

[0008] Firewall configurations are distributed based on the field status and the target configuration change table.

[0009] In the above implementation process, this method can first receive configuration modification data for a preset configuration change table sent by the configuration management terminal; then, modify the configuration change table according to the configuration modification data to obtain the target configuration change table; after receiving a configuration distribution command triggered by the user, determine the field status of the current configuration change field in the target configuration change table; finally, distribute the firewall configuration based on the field status and the target configuration change table. It is evident that this method can quickly distribute firewall configuration changes, reduce firewall load, and thus improve the efficiency of configuration management.

[0010] Furthermore, before receiving configuration modification data for a preset configuration change table sent by the configuration management terminal, the method further includes:

[0011] Create a configuration change table; wherein the configuration change table includes configuration type, configuration item identifier, configuration change content, configuration change occurrence time, and configuration change fields;

[0012] The configuration change table is stored in a preset data format; wherein the preset data format is a data format that the firewall can recognize.

[0013] In the above implementation process, this method pre-creates a configuration change table including configuration type, configuration item identifier, configuration change content, configuration change occurrence time, and configuration change fields, and stores the configuration change table according to a preset data format. Therefore, this method can pre-set configuration change requirements, thereby achieving personalized firewall configuration distribution.

[0014] Furthermore, the step of distributing firewall configurations based on the field status and the target configuration change table includes:

[0015] Determine whether the currently configured change field is in an inconsistent state;

[0016] If so, the firewall configuration will be distributed according to the target configuration change table and the preset strong consistency distribution process.

[0017] Furthermore, the step of distributing firewall configurations according to the target configuration change table and the preset strong consistency distribution process includes:

[0018] Obtain the first full configuration data from the target configuration change table, and obtain the second full configuration data currently in operation from the firewall;

[0019] By comparing the first full configuration data and the second full configuration data, a set of differentiated configurations is obtained;

[0020] The differentiated configuration set is converted into configuration operation data in a preset data format;

[0021] The configuration operation data is then passed to the firewall for configuration update.

[0022] Furthermore, the method also includes:

[0023] When it is determined that the current configuration change field is not in an inconsistent state, the configuration change data is retrieved from the target configuration change table in chronological order.

[0024] Based on the configuration change data, generate configuration data in a preset data format;

[0025] The configuration data is then transmitted to the firewall.

[0026] Furthermore, after the firewall configuration is distributed based on the field status and the target configuration change table, the method further includes:

[0027] Receive the configuration feedback result sent by the firewall;

[0028] Determine whether the configuration was successfully distributed based on the feedback results.

[0029] If so, generate a configuration distribution success record based on the configuration distribution feedback result, and clear the target configuration change table.

[0030] Furthermore, the method also includes:

[0031] When it is determined from the feedback result of the configuration distribution that the distribution was unsuccessful, the configuration data is distributed to the firewall according to the preset strong consistency distribution process, and the target configuration change table is cleared.

[0032] A second aspect of this application provides a firewall configuration distribution device, the firewall configuration distribution device comprising:

[0033] The receiving unit is used to receive configuration modification data for a preset configuration change table sent by the configuration management terminal;

[0034] The modification unit is used to modify the configuration change table according to the configuration modification data to obtain the target configuration change table;

[0035] The determining unit is used to determine the field status of the current configuration change field in the target configuration change table after receiving a configuration issuance instruction triggered by the user;

[0036] The configuration distribution unit is used to distribute firewall configurations based on the field status and the target configuration change table.

[0037] In the above implementation process, the device can receive configuration modification data for a preset configuration change table sent by the configuration management terminal through the receiving unit; modify the configuration change table according to the configuration modification data through the modification unit to obtain the target configuration change table; determine the field status of the current configuration change field in the target configuration change table after receiving the configuration distribution command triggered by the user through the determining unit; and then distribute the firewall configuration according to the field status and the target configuration change table through the configuration distribution unit. It is evident that this device can quickly distribute firewall configuration changes, reduce firewall load, and thus improve the efficiency of configuration management.

[0038] Furthermore, the firewall configuration distribution device also includes:

[0039] A creation unit is used to create a configuration change table before receiving configuration modification data for a preset configuration change table sent by the configuration management terminal; wherein, the configuration change table includes configuration type, configuration item identifier, configuration change content, configuration change occurrence time, and configuration change field;

[0040] A storage unit is used to store the configuration change table according to a preset data format; wherein the preset data format is a data format that the firewall can recognize.

[0041] Furthermore, the configuration distribution unit includes:

[0042] The judgment subunit is used to determine whether the currently configured change field is in an inconsistent state;

[0043] The distribution subunit is used to distribute firewall configuration according to the target configuration change table and the preset strong consistency distribution process when the current configuration change field is in an inconsistent state.

[0044] Furthermore, the sending subunit includes:

[0045] The acquisition module is used to acquire first full configuration data from the target configuration change table and second full configuration data currently in operation from the firewall;

[0046] The comparison module is used to compare the first full configuration data and the second full configuration data to obtain a set of differentiated configurations;

[0047] A conversion module is used to convert the differentiated configuration set into configuration operation data in a preset data format;

[0048] The update module is used to transmit the configuration operation data to the firewall for configuration update operations.

[0049] Furthermore, the configuration distribution unit also includes:

[0050] The acquisition sub-unit is used to acquire configuration change data from the target configuration change table in chronological order when it is determined that the current configuration change field is not in an inconsistent state.

[0051] A generation subunit is used to generate configuration data in a preset data format based on the configuration change data;

[0052] The sending subunit is also used to transmit the configuration data to the firewall.

[0053] Furthermore, the firewall configuration distribution device also includes:

[0054] The receiving unit is further configured to receive the configuration distribution feedback result sent by the firewall after the firewall configuration is distributed according to the field status and the target configuration change table;

[0055] The judgment unit is used to determine whether the configuration was successfully issued based on the configuration issuance feedback result.

[0056] The generation unit is used to generate a configuration distribution success record based on the configuration distribution feedback result when the distribution is successful, and to clear the target configuration change table.

[0057] Furthermore, the configuration distribution unit is also used to distribute the configuration data to the firewall according to a preset strong consistency distribution process and clear the target configuration change table when the distribution fails.

[0058] A third aspect of this application provides an electronic device, including a memory and a processor. The memory stores a computer program, and the processor runs the computer program to cause the electronic device to perform the firewall configuration distribution method described in any one of the first aspects of this application.

[0059] A fourth aspect of this application provides a computer-readable storage medium storing computer program instructions, which, when read and executed by a processor, perform the firewall configuration distribution method described in any one of the first aspects of this application.

[0060] It is evident that when a computer-readable storage medium storing computer program instructions can trigger a firewall configuration distribution method, certain characteristics of that medium can be inherited by the method. For example, using a computer-readable storage medium makes it easier for users to trigger the method; furthermore, it ensures that the medium is used exclusively, avoiding the retention of corresponding data and thus improving data confidentiality. On the other hand, this type of storage medium only needs to be read and executed by the processor to execute the firewall configuration distribution method, but this can be divided into two types: direct execution and triggered execution. Specifically, the former stores the data corresponding to the firewall configuration distribution method in the storage medium for later use, while the latter can serve as a unique trigger instruction to execute the method, further enhancing its ease of use. In summary, it is easy to see that using this type of storage medium improves the ease of use, flexibility, and confidentiality of the firewall configuration distribution method, making it adaptable to more scenarios. Attached Figure Description

[0061] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0062] Figure 1 A flowchart illustrating a firewall configuration distribution method provided in an embodiment of this application;

[0063] Figure 2 A flowchart illustrating another firewall configuration distribution method provided in this application embodiment;

[0064] Figure 3 This application provides a schematic diagram of the structure of a firewall configuration distribution device.

[0065] Figure 4 This is a schematic diagram of another firewall configuration distribution device provided in an embodiment of this application. Detailed Implementation

[0066] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.

[0067] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0068] Example 1

[0069] Please refer to Figure 1 , Figure 1 This embodiment provides a flowchart illustrating a firewall configuration distribution method. The firewall configuration distribution method includes:

[0070] S101. Receive configuration modification data for the preset configuration change table sent by the configuration management terminal.

[0071] S102. Modify the configuration change table according to the configuration modification data to obtain the target configuration change table.

[0072] S103. After receiving the configuration issuance instruction triggered by the user, determine the field status of the current configuration change field in the target configuration change table.

[0073] S104. Deploy firewall configurations based on field status and target configuration change table.

[0074] In this embodiment, the subject executing the method can be a computing device such as a computer or server, and no limitation is made in this embodiment.

[0075] In this embodiment, the subject executing the method can also be a smart device such as a smartphone or tablet, and no limitation is made in this embodiment.

[0076] As can be seen, implementing the firewall configuration distribution method described in this embodiment can improve overall efficiency by eliminating the need for the centralized management end to retrieve the latest firewall configuration each time under normal configuration distribution conditions. Furthermore, it avoids comparing and distributing configurations to unchanged modules during distribution, thus improving overall efficiency. Moreover, it prevents configuration distribution failures caused by issues with these modules, significantly enhancing overall stability.

[0077] Example 2

[0078] Please refer to Figure 2 , Figure 2 This embodiment provides a flowchart illustrating a firewall configuration distribution method. The firewall configuration distribution method includes:

[0079] S201. Create a configuration change table; the configuration change table includes configuration type, configuration item identifier, configuration change content, configuration change occurrence time, and configuration change fields.

[0080] In this embodiment, the configuration change field is the process_status field. This process_status field is used to record whether the relevant configuration on the firewall side has changed during the configuration period.

[0081] S202. Store the configuration change table according to the preset data format; wherein, the preset data format is a data format that the firewall can recognize.

[0082] S203. Receive configuration modification data for the preset configuration change table sent by the configuration management terminal.

[0083] S204. Modify the configuration change table according to the configuration modification data to obtain the target configuration change table.

[0084] S205. After receiving the configuration issuance instruction triggered by the user, determine the field status of the current configuration change field in the target configuration change table.

[0085] S206. Determine whether the current configuration change field is in an inconsistent state. If yes, proceed to steps S207 to S212; otherwise, proceed to steps S215 to S217.

[0086] S207. Obtain the first full configuration data from the target configuration change table, and obtain the second full configuration data currently in operation from the firewall.

[0087] S208. Compare the first full configuration data and the second full configuration data to obtain the differentiated configuration set.

[0088] S209. Convert the differentiated configuration set into configuration operation data in a preset data format.

[0089] S210. Pass the configuration operation data to the firewall for configuration update operation.

[0090] S211. Receive the configuration feedback result sent by the firewall.

[0091] S212. Determine whether the configuration was successfully distributed based on the feedback result. If yes, proceed to step S213; otherwise, proceed to step S214.

[0092] S213. Generate a configuration distribution success record based on the configuration distribution feedback result, clear the target configuration change table, and end this process.

[0093] S214. According to the preset strong consistency distribution process, the configuration data is distributed to the firewall, the target configuration change table is cleared, and the process ends.

[0094] S215. Obtain configuration change data from the target configuration change table in chronological order.

[0095] S216. Generate configuration data in a preset data format based on the configuration change data.

[0096] S217. Transfer the configuration data to the firewall.

[0097] In this embodiment, the method uses Table 1 as an example to illustrate the configuration storage results of the centralized management terminal. Table 1 is the security policy table (i.e., the two-dimensional relationship table shown in Table 1).

[0098] Table 1

[0099]

[0100] In this embodiment, strong consistency delivery refers to the traditional delivery process. The specific delivery process is as follows:

[0101] ① Obtain the full configuration from the data storage of the centralized network management terminal;

[0102] ② Obtain the full configuration currently in operation from the firewall;

[0103] ③ Compare the differences between the two configurations and generate a set of differentiated configurations;

[0104] ④ The differentiated configuration set is transformed and sorted to generate a configuration operation XML that the firewall can recognize;

[0105] ⑤ Pass the configuration operation XML to the firewall and perform the update operation;

[0106] ⑥ Parse the firewall's execution results and complete the configuration distribution operation.

[0107] In this embodiment, weak consistency delivery refers to the process of translating user actions into configuration operation XML that the firewall can recognize in real time and recording it. Specifically, when a user triggers a delivery action, the system can retrieve the corresponding configuration from the configuration change table, assemble it into an XML set, and pass it to the XML for execution.

[0108] In this embodiment, taking a security policy as an example, the specific operation process can be as follows:

[0109] ① Create a two-dimensional relationship table (i.e., a configuration change table). This table records the changes to each configuration item at the centralized management end and converts it into XML that the firewall can recognize for storage, as shown in Table 2.

[0110] Table 2

[0111]

[0112] The process_status field is used to record whether the firewall-related configurations have changed during the configuration process.

[0113] ②With the centralized management terminal and the firewall configured identically, users can modify the first policy rule.

[0114] The change removed addr2 from the source address book attributes. The specific results are shown in Table 3 below.

[0115] Table 3

[0116]

[0117]

[0118] ③ The user modified the first policy rule, and the destination address book was associated with addr3. This action was recorded, and the results are shown in Table 4.

[0119] Table 4

[0120]

[0121] ④ If the user modifies the source security domain of policy 2 to zone1, the action will be recorded, and the results are shown in Table 5.

[0122] Table 5

[0123]

[0124]

[0125] ⑤ After the user completes the configuration operation they want to modify, the action is triggered.

[0126] If process_status is found to be inconsistent, it indicates that other configuration sources have changed the firewall configuration, and the system distribution process will switch to strongly consistent distribution.

[0127] If process_status is consistent, the system retrieves the corresponding configuration changes from the configuration change table in chronological order, assembles them into an XML file to be sent to the firewall.

[0128]

[0129]

[0130] ⑥ The system parses the firewall's return result to determine whether the distribution was successful. If a successful distribution record is found, the system exits.

[0131] Regardless of whether the distribution is successful, the configuration change table must be cleared.

[0132] ⑦ If the distribution fails, it will switch to strong consistency distribution. Ultimately, the goal of configuration management is achieved.

[0133] As can be seen, this method defines a weakly consistent configuration distribution approach (i.e., assuming the centralized management system is the primary configuration management source). This method can balance performance and stability, thereby significantly improving configuration distribution efficiency. In certain situations, it can even improve configuration distribution performance by several times or even tens of times.

[0134] In this embodiment, the method can significantly improve the performance of issuing single or multiple configurations, thereby meeting users' needs for real-time awareness and real-time blocking. Specifically, this method is applicable to any offline configuration management system.

[0135] In this embodiment, the subject executing the method can be a computing device such as a computer or server, and no limitation is made in this embodiment.

[0136] In this embodiment, the subject executing the method can also be a smart device such as a smartphone or tablet, and no limitation is made in this embodiment.

[0137] As can be seen, implementing the firewall configuration distribution method described in this embodiment can improve overall efficiency by eliminating the need for the centralized management end to retrieve the latest firewall configuration each time under normal configuration distribution conditions. Furthermore, it avoids comparing and distributing configurations to unchanged modules during distribution, thus improving overall efficiency. Moreover, it prevents configuration distribution failures caused by issues with these modules, significantly enhancing overall stability.

[0138] Example 3

[0139] Please refer to Figure 3 , Figure 3 This is a schematic diagram of a firewall configuration distribution device provided in this embodiment. Figure 3 As shown, the firewall configuration distribution device includes:

[0140] The receiving unit 310 is used to receive configuration modification data for a preset configuration change table sent by the configuration management terminal;

[0141] Modification unit 320 is used to modify the configuration change table according to the configuration modification data to obtain the target configuration change table;

[0142] The determination unit 330 is used to determine the field status of the current configuration change field in the target configuration change table after receiving the configuration issuance instruction triggered by the user.

[0143] Configuration distribution unit 340 is used to distribute firewall configurations based on field status and target configuration change table.

[0144] In this embodiment, the device can record the configuration management process in real time, thereby improving configuration management performance and enhancing configuration management stability at minimal cost.

[0145] In this embodiment, the explanation of the firewall configuration distribution device can be found in the description in Embodiment 1 or Embodiment 2, and will not be repeated here.

[0146] As can be seen, implementing the firewall configuration distribution device described in this embodiment can improve overall efficiency by eliminating the need for the centralized management end to retrieve the latest firewall configuration each time during normal configuration distribution. Furthermore, it avoids comparing and distributing configurations to unchanged modules, thus improving overall efficiency. Moreover, it prevents configuration distribution failures caused by issues with these modules, significantly enhancing overall stability.

[0147] Example 4

[0148] Please refer to Figure 4 , Figure 4 This is a schematic diagram of a firewall configuration distribution device provided in this embodiment. Figure 4 As shown, the firewall configuration distribution device includes:

[0149] The receiving unit 310 is used to receive configuration modification data for a preset configuration change table sent by the configuration management terminal;

[0150] Modification unit 320 is used to modify the configuration change table according to the configuration modification data to obtain the target configuration change table;

[0151] The determination unit 330 is used to determine the field status of the current configuration change field in the target configuration change table after receiving the configuration issuance instruction triggered by the user.

[0152] Configuration distribution unit 340 is used to distribute firewall configurations based on field status and target configuration change table.

[0153] As an optional implementation, the firewall configuration distribution device further includes:

[0154] The creation unit 350 is used to create a configuration change table before receiving configuration modification data for a preset configuration change table sent by the configuration management terminal; wherein, the configuration change table includes configuration type, configuration item identifier, configuration change content, configuration change occurrence time, and configuration change fields;

[0155] Storage unit 360 is used to store the configuration change table according to a preset data format; wherein the preset data format is a data format that the firewall can recognize.

[0156] As an optional implementation, the configuration distribution unit 340 includes:

[0157] Judgment subunit 341 is used to determine whether the currently configured change field is in an inconsistent state;

[0158] Subunit 342 is used to distribute firewall configuration based on the target configuration change table and the preset strong consistency distribution process when the current configuration change field is in an inconsistent state.

[0159] As an optional implementation, the sending subunit 342 includes:

[0160] The acquisition module is used to obtain the first full configuration data from the target configuration change table and the second full configuration data currently in operation from the firewall;

[0161] The comparison module is used to compare the first full configuration data and the second full configuration data to obtain a set of differentiated configurations;

[0162] The conversion module is used to convert the differentiated configuration set into configuration operation data in a preset data format;

[0163] The update module is used to pass configuration operation data to the firewall for configuration update operations.

[0164] As an optional implementation, the configuration distribution unit 340 further includes:

[0165] Get sub-unit 343, which is used to retrieve configuration change data from the target configuration change table in chronological order when it is determined that the current configuration change field is not in an inconsistent state;

[0166] Generating subunit 344 is used to generate configuration data in a preset data format based on configuration change data;

[0167] Subunit 342 is also used to transmit configuration data to the firewall.

[0168] As an optional implementation, the firewall configuration distribution device further includes:

[0169] The receiving unit 310 is also used to receive the configuration distribution feedback result sent by the firewall after the firewall configuration is distributed according to the field status and the target configuration change table;

[0170] The judgment unit 370 is used to determine whether the configuration was successfully distributed based on the feedback result of the distributed configuration.

[0171] The generation unit 380 is used to generate a configuration distribution success record based on the configuration distribution feedback result when the distribution is successful, and to clear the target configuration change table.

[0172] As an optional implementation, the configuration distribution unit 340 is also used to distribute the configuration data to the firewall according to a preset strong consistency distribution process and clear the target configuration change table when the distribution fails.

[0173] In this embodiment, the device can record the configuration management process in real time, thereby improving configuration management performance and enhancing configuration management stability at minimal cost.

[0174] In this embodiment, the explanation of the firewall configuration distribution device can be found in the description in Embodiment 1 or Embodiment 2, and will not be repeated here.

[0175] As can be seen, implementing the firewall configuration distribution device described in this embodiment can improve overall efficiency by eliminating the need for the centralized management end to retrieve the latest firewall configuration each time during normal configuration distribution. Furthermore, it avoids comparing and distributing configurations to unchanged modules, thus improving overall efficiency. Moreover, it prevents configuration distribution failures caused by issues with these modules, significantly enhancing overall stability.

[0176] This application provides an electronic device, including a memory and a processor. The memory stores a computer program, and the processor runs the computer program to enable the electronic device to execute the firewall configuration distribution method in embodiment 1 or embodiment 2 of this application.

[0177] This application provides a computer-readable storage medium storing computer program instructions. When the computer program instructions are read and executed by a processor, the firewall configuration distribution method in embodiment 1 or embodiment 2 of this application is performed.

[0178] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0179] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0180] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0181] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application. It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0182] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0183] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

Claims

1. A method for distributing firewall configurations, characterized in that, include: Receive configuration modification data for a preset configuration change table sent by the configuration management terminal; The configuration change table is modified according to the configuration modification data to obtain the target configuration change table; After receiving the configuration issuance instruction triggered by the user, determine the field status of the current configuration change field in the target configuration change table; The field status is used to indicate whether the relevant configuration on the firewall side has changed; Determine whether the currently configured change field is in an inconsistent state; If so, the firewall configuration will be distributed according to the target configuration change table and the preset strong consistency distribution process; If not, retrieve the configuration change data from the target configuration change table in chronological order; Based on the configuration change data, generate configuration data in a preset data format; The configuration data is then transmitted to the firewall.

2. The firewall configuration distribution method according to claim 1, characterized in that, Before receiving configuration modification data for a preset configuration change table sent by the configuration management terminal, the method further includes: Create a configuration change table; wherein the configuration change table includes configuration type, configuration item identifier, configuration change content, configuration change occurrence time, and configuration change fields; The configuration change table is stored in a preset data format; wherein the preset data format is a data format that the firewall can recognize.

3. The firewall configuration distribution method according to claim 1, characterized in that, The step of distributing firewall configurations according to the target configuration change table and the preset strong consistency distribution process includes: Obtain the first full configuration data from the target configuration change table, and obtain the second full configuration data currently in operation from the firewall; By comparing the first full configuration data and the second full configuration data, a set of differentiated configurations is obtained; The differentiated configuration set is converted into configuration operation data in a preset data format; The configuration operation data is then passed to the firewall for configuration update.

4. The firewall configuration distribution method according to any one of claims 1 to 3, characterized in that, After transmitting the configuration data to the firewall, the method further includes: Receive the configuration feedback result sent by the firewall; Determine whether the configuration was successfully distributed based on the feedback results. If so, generate a configuration distribution success record based on the configuration distribution feedback result, and clear the target configuration change table.

5. The firewall configuration distribution method according to claim 4, characterized in that, The method further includes: When it is determined from the feedback result of the configuration distribution that the distribution was unsuccessful, the configuration data is distributed to the firewall according to the preset strong consistency distribution process, and the target configuration change table is cleared.

6. A firewall configuration distribution device, characterized in that, The firewall configuration distribution device includes: The receiving unit is used to receive configuration modification data for a preset configuration change table sent by the configuration management terminal; The modification unit is used to modify the configuration change table according to the configuration modification data to obtain the target configuration change table; The determining unit is used to determine the field status of the current configuration change field in the target configuration change table after receiving a configuration issuance instruction triggered by the user; the field status is used to indicate whether the relevant configuration on the firewall side has changed; The configuration distribution unit is used to distribute firewall configurations based on the field status and the target configuration change table. The configuration distribution unit includes: The judgment sub-unit is used to determine whether the currently configured change field is in an inconsistent state; The distribution subunit is used to distribute firewall configuration based on the target configuration change table and the preset strong consistency distribution process when the current configuration change field is in an inconsistent state. The sub-unit is used to retrieve configuration change data from the target configuration change table in chronological order when it is determined that the current configuration change field is not in an inconsistent state. The generation sub-unit is used to generate configuration data in a preset data format based on configuration change data; The sub-unit is also used to transmit configuration data to the firewall.

7. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory being used to store a computer program, and the processor running the computer program to cause the electronic device to perform the firewall configuration distribution method according to any one of claims 1 to 5.

8. A readable storage medium, characterized in that, The readable storage medium stores computer program instructions, which, when read and executed by a processor, perform the firewall configuration distribution method according to any one of claims 1 to 5.