Processing Method and Device of Firewall, Processor
By using the Redis database in the firewall system to record the connection status of the firewall and selecting the device manager through the load balancer, the device manager load imbalance problem caused by firewall connection forwarding is solved, and the balancing establishment of the firewall connection and the balanced allocation of the device manager load is achieved.
Patent Information
- Application Number
- CN202211698093.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-28
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2042-12-28
AI Technical Summary
In the prior art, the connection of the firewall is forwarded to the device manager through IP, resulting in the problem of unbalanced load of the device manager.
By receiving the second long connection request of the target firewall, the connection status of the long connection is read from the Redis database based on its identification information, and selecting the second device manager from multiple device managers through a load balancer to establish a second long connection between the second device manager and the target firewall, and updating the target data information in the Redis database.
It effectively avoids the problem of unbalanced load of the device manager. The connection status of the firewall is accurately read through the Redis database, and the device manager is selected through the load balancer to achieve the balancing establishment of the firewall connection.
Smart Images

Figure CN115883249B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer security technologies, and more particularly, to a processing method and apparatus for a firewall, and a processor. Background Art
[0002] Firewall technology is a technology that helps build a relatively isolated protection barrier between the internal and external networks of a computer network by organically combining various software and hardware devices for security management and screening, so as to protect the security of user data and information.
[0003] The functions of firewall technology mainly lie in timely detecting and handling possible security risks, data transmission and other problems during the operation of a computer network. The handling measures include isolation and protection. At the same time, it can record and detect various operations in computer network security to ensure the security of computer network operation, guarantee the integrity of user data and information, and provide users with a better and more secure computer network usage experience.
[0004] With the development of the times, users' computer networks are becoming increasingly large. The traditional single-machine management method has become increasingly powerless, and the horizontal expansion function of the network management system has become increasingly important for modern user networks. As the user network continues to expand, the network management system also needs to be able to flexibly support the expansion of firewall devices by expanding server nodes.
[0005] From Figure 1 It can be seen that the management method of traditional firewalls is usually that users create configurations by logging in to the UI interface (WebUI) and transfer them to the firewall proxy module in the form of the netconf protocol, and finally the configuration of the firewall is realized.
[0006] After the centralized network management system appears, the firewall device establishes a TCP long connection with the network management system, configures centrally on the network management, and sends the xml conforming to the netconf protocol to the firewall through the TCP long connection, so as to achieve the purpose of centralized configuration of a batch of firewall devices. Such as Figure 2 And Figure 3As shown in the figure. In the prior art, load balancing components such as Nginx are used to forward the registration requests of the firewall to achieve the purpose of balancing. Nginx (engine x) is a high-performance HTTP and reverse proxy web server, and also provides IMAP / POP3 / SMTP services. The Nginx server is an intermediary between the client and the server. Through its reverse proxy function, the requests sent by the client first pass through Nginx, and then Nginx distributes the requests to the corresponding services or servers according to the corresponding rules. The main problem brought by this technical solution is that if the load forwarding is performed in the way of ip / hash, the firewall device will be unbalanced due to the snat environment.
[0007] In view of the problem that in the related technology, the connection of the firewall is forwarded to the device manager through the IP, resulting in unbalanced load of the device manager, no effective solution has been proposed yet. Summary of the Invention
[0008] The main purpose of this application is to provide a processing method, device and processor for a firewall, so as to solve the problem that in the related technology, the connection of the firewall is forwarded to the device manager through the IP, resulting in unbalanced load of the device manager.
[0009] To achieve the above object, according to one aspect of this application, a processing method for a firewall is provided. The method includes: receiving a second long connection request of a target firewall, where at least the identification information of the target firewall is included in the second long connection request; reading the connection status of the long connection of the target firewall from a Redis database according to the identification information of the target firewall, where the target data information of the target firewall is stored in the Redis database, and the target data information at least includes: the identification information of the target firewall, the connection status of the long connection, and the identification information of the first device manager corresponding to the first long connection, and the first long connection is the long connection between the first device manager and the target firewall; if the connection status of the long connection is that the first long connection has been connected, select a second device manager from multiple device managers through a load balancer; establish a second long connection between the second device manager and the target firewall according to the second long connection request, and after the second long connection is established, perform an update process on the target data information in the Redis database.
[0010] Further, selecting a second device manager from multiple device managers through a load balancer includes: obtaining the current load conditions of each device manager; the load balancer selects a second device manager from multiple device managers according to the load conditions.
[0011] Further, establishing a second long connection between the second device manager and the target firewall according to the second long connection request includes: the target firewall sending a first message to the second device manager; after receiving the first message, the second device manager processes the first message to obtain a second message and sends the second message to the target firewall; the target firewall verifies the second message, and if the verification passes, it indicates that the second long connection between the second device manager and the target firewall has been established.
[0012] Further, before receiving the second long connection request from the target firewall, the method further includes: receiving a first long connection request from the target firewall; selecting the first device manager from multiple device managers through the load balancer and establishing a first long connection between the target firewall and the first device manager; after the first long connection is established, storing the target data information in the Redis database.
[0013] Further, performing an update process on the target data information in the Redis database includes: updating the connection status of the long connection to the second long connection being connected; adding the identification information of the second device manager corresponding to the second long connection to the target data information.
[0014] Further, after performing the update process on the target data information in the Redis database, the method further includes: determining whether there are any other long connection requests from the target firewall; if there are no other long connection requests from the target firewall, it indicates that the long connection of the target firewall has been completed.
[0015] Further, after the long connection of the target firewall has been completed, the method further includes: if an operation instruction for the target firewall is received, determining the target device manager corresponding to the operation instruction; sending the operation instruction to the target device manager so that the operation instruction can be sent to the target firewall through the target device manager.
[0016] Further, determining the target device manager corresponding to the operation instruction includes: determining the operation type according to the operation instruction; determining the target long connection from multiple long connections corresponding to the target firewall according to the operation type; determining the target device manager corresponding to the target long connection from the target data information stored in the Redis database according to the target long connection and the identification information of the target firewall.
[0017] To achieve the above object, according to another aspect of the present application, there is provided a processing device for a firewall. The device includes: a first receiving unit, configured to receive a second long connection request of a target firewall, where the second long connection request at least includes identification information of the target firewall; a reading unit, configured to read the connection status of the long connection of the target firewall from a Redis database according to the identification information of the target firewall, where the Redis database stores target data information of the target firewall, and the target data information at least includes: identification information of the target firewall, connection status of the long connection, and identification information of a first device manager corresponding to a first long connection, and the first long connection is a long connection between the first device manager and the target firewall; a selection unit, configured to, if the connection status of the long connection is that the first long connection is connected, select a second device manager from multiple device managers through a load balancer; a establishing unit, configured to establish a second long connection between the second device manager and the target firewall according to the second long connection request, and after the second long connection is established, perform an update process on the target data information in the Redis database.
[0018] Further, the selection unit includes: an obtaining module, configured to obtain the current load condition of each device manager; a selection module, configured to the load balancer select a second device manager from multiple device managers according to the load condition.
[0019] Further, the establishing unit includes: a sending module, configured to the target firewall send a first message to the second device manager; a processing module, configured to after receiving the first message, the second device manager process the first message to obtain a second message, and send the second message to the target firewall; a verification module, configured to the target firewall verify the second message, and if the verification passes, it indicates that the second long connection between the second device manager and the target firewall has been established.
[0020] Further, the device further includes: before receiving the second long connection request of the target firewall, receive a first long connection request of the target firewall; a second receiving unit, configured to select the first device manager from multiple device managers through the load balancer, and establish a first long connection between the target firewall and the first device manager; a storage unit, configured to after the first long connection is established, store the target data information in the Redis database.
[0021] Further, the establishing unit includes: an updating module, configured to update the connection state of the long connection to the second long connection being connected; an adding module, configured to add the identification information of the second device manager corresponding to the second long connection to the target data information.
[0022] Further, the apparatus further includes: a determining unit, configured to determine whether there are any other long connection requests for the target firewall after updating the target data information in the Redis database; a first determining unit, configured to indicate that the long connection of the target firewall is completed if there are no other long connection requests for the target firewall.
[0023] Further, the apparatus further includes: a second determining unit, configured to determine the target device manager corresponding to the operation instruction if an operation instruction for the target firewall is received after the long connection of the target firewall is completed; a sending unit, configured to send the operation instruction to the target device manager, so as to send the operation instruction to the target firewall through the target device manager.
[0024] Further, the second determining unit includes: a first determining module, configured to determine an operation type according to the operation instruction; a second determining module, configured to determine a target long connection from multiple long connections corresponding to the target firewall according to the operation type; a third determining module, configured to determine the target device manager corresponding to the target long connection from the target data information stored in the Redis database according to the target long connection and the identification information of the target firewall.
[0025] To achieve the above object, according to one aspect of the present application, there is provided a processor, which is configured to run a program, wherein when the program runs, it executes the processing method of the firewall described in any one of the above.
[0026] To achieve the above object, according to one aspect of the present application, there is provided an electronic device, which includes one or more processors and a memory, and the memory is configured to store the processing method of the firewall described in any one of the above implemented by one or more processors.
[0027] Through this application, the following steps are adopted: receiving a second long connection request of a target firewall, where the second long connection request at least includes the identification information of the target firewall; reading the connection status of the long connection of the target firewall from the Redis database according to the identification information of the target firewall, where the Redis database stores the target data information of the target firewall, and the target data information at least includes: the identification information of the target firewall, the connection status of the long connection, and the identification information of the first device manager corresponding to the first long connection, and the first long connection is the long connection between the first device manager and the target firewall; if the connection status of the long connection is that the first long connection is connected, selecting a second device manager from multiple device managers through a load balancer; establishing a second long connection between the second device manager and the target firewall according to the second long connection request, and after the second long connection is established, performing an update process on the target data information in the Redis database, which solves the problem in the related technology that the connection of the firewall is forwarded to the device manager through the IP, resulting in uneven load of the device manager. In this solution, by establishing a high-performance Redis database and recording the connection status of each firewall in the Redis database, the problem of status confusion can be effectively avoided. When receiving the long connection request of the target firewall, the previous connection status of the target firewall can be accurately read through the Redis database. When the connection status of the long connection is that the first long connection is connected, a second device manager is evenly selected from multiple device managers through the load balancer to establish the current long connection, thereby achieving the effect of balancing the load of the device manager. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] The accompanying drawings constituting a part of this application are used to provide a further understanding of this application. The schematic embodiments of this application and their descriptions are used to explain this application and do not constitute an improper limitation to this application. In the drawings:
[0029] Figure 1 is a schematic diagram of the firewall WebUI communication architecture in the prior art;
[0030] Figure 2 is a schematic diagram of the communication architecture between the network management system and the firewall in the prior art;
[0031] Figure 3 is a schematic diagram of the long connection between the network management system and the firewall in the prior art;
[0032] Figure 4 is a flowchart of the processing method of the firewall provided according to the embodiment of this application;
[0033] Figure 5 is a schematic diagram of adding a Redis database in the network management system provided according to the embodiment of this application;
[0034] Figure 6 It is a schematic diagram of executing an operation instruction on a firewall provided according to an embodiment of the present application;
[0035] Figure 7 It is a schematic diagram of a processing device of a firewall provided according to an embodiment of the present application;
[0036] Figure 8 It is a schematic diagram of an electronic device provided according to an embodiment of the present application. Detailed implementation manners
[0037] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other. The present application will be described in detail below with reference to the drawings and in combination with the embodiments.
[0038] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0039] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so as to describe the embodiments of the present application here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these process, method, product or device.
[0040] For the convenience of description, some nouns or terms related to the embodiments of the present application are described below:
[0041] CM: Configuration Manager, a component in the network management system, responsible for the module that manages the firewall configuration.
[0042] DM: Device Manager, a component in the network management system, responsible for maintaining the online status of the firewall and data transmission work.
[0043] Nginx: Nginx (engine x) is a high-performance HTTP and reverse proxy web server, and also provides IMAP / POP3 / SMTP services. The Nginx server acts as an intermediary between the client and the server. Through its reverse proxy function, the requests sent by the client first pass through Nginx, and then Nginx distributes the requests to the corresponding services or servers according to the corresponding rules.
[0044] Redis: Redis is a high-performance key-value database. Redis supports various sorting methods. To ensure efficiency, the data is cached in memory. Redis periodically writes the updated data to disk or writes the modification operations to an append-only log file, and on this basis, it realizes master-slave synchronization.
[0045] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties. For example, an interface is set up between this system and relevant users or institutions. Before obtaining relevant information, a request for acquisition needs to be sent to the aforementioned user or institution through the interface, and after receiving the consent information feedback from the aforementioned user or institution, the relevant information is obtained.
[0046] In the prior art, the network management system provides multiple device managers DM, and a reverse proxy service such as Nginx is set before the DM. When the firewall registers with the network management system, the TCP layer proxy forwarding is performed via Nginx, and the registration request is forwarded to different DMs to achieve the purpose of load balancing. However, there are the following problems with this method: The load forwarding is performed in the way of ip / hash, that is, the forwarding is performed through the IP of the firewall. However, in actual applications, there may be a large number of firewalls from the same manufacturer. For network security, the gateway will hide the IP of the firewall when all firewalls are connected. The firewalls from the same manufacturer are defaulted to one IP address, which will cause the connection requests of all firewalls from the same manufacturer to be forwarded to the same device manager, resulting in uneven load on the firewall devices. To solve the above problems, a processing method for firewalls is proposed.
[0047] The present invention will be described below in conjunction with the preferred implementation steps. Figure 4 is a flowchart of the processing method for firewalls provided by an embodiment of the present application, as Figure 4 shown. The method includes the following steps:
[0048] Step S401: Receive the second long connection request of the target firewall, where the second long connection request includes at least the identification information of the target firewall;
[0049] Step S402: Read the connection status of the long connection of the target firewall from the Redis database according to the identification information of the target firewall. The Redis database stores the target data information of the target firewall, and the target data information includes at least: the identification information of the target firewall, the connection status of the long connection, and the identification information of the first device manager corresponding to the first long connection. The first long connection is the long connection between the first device manager and the target firewall;
[0050] Step S403: If the connection status of the long connection is that the first long connection is already connected, select a second device manager from multiple device managers through the load balancer;
[0051] Step S404: Establish a second long connection between the second device manager and the target firewall according to the second long connection request, and after the second long connection is established, update the target data information in the Redis database.
[0052] Specifically, the target firewall initiates a second long connection request, and the second long connection request includes at least the identification information of the target firewall. Generally, the sn is the identifier that uniquely distinguishes a firewall, such as 2006123456789, etc. It should be noted that the current target firewall has established a first long connection request with the first device manager.
[0053] After receiving the second long connection request initiated by the target firewall, read the connection status of the long connection of the target firewall from the Redis database according to the identification information of the target firewall. The Redis database stores the connection status of the long connection of each firewall and which DM each connection is maintained on. Storing the connection status of the long connection of each firewall in the Redis database can effectively avoid the problem of the long connection failure of the target firewall caused by the confusion of the connection status of the long connection.
[0054] If the connection status of the long connection is that the first long connection is already connected, it means that the current first long connection has been successfully established, and the next long connection can be established. Therefore, select a second device manager from multiple device managers through the load balancer. It should be noted that the first device manager and the second device manager can be the same device manager or different device managers.
[0055] After determining the second device manager, establish a second long connection between the second device manager and the target firewall according to the second long connection request. After the second long connection is established, update the target data information in the Redis database. Updating the target data information in the Redis database includes updating the long connection status and storing the identification information of the second device manager, etc.
[0056] In summary, a firewall often needs to establish multiple TCP long connections with a device manager or a network management system. Each long connection needs to be established when the previous long connection has been established. Therefore, this application proposes to add a high-performance key-value database Redis to the network management system. Redis records the current long connection status of each firewall and which DM each long connection is maintained on. Storing the connection status of the long connections of each firewall in the Redis database can effectively avoid the problem of long connection failure of the target firewall caused by the confusion of the connection status of the long connections. By using a load balancer to evenly select the second device manager from multiple device managers to establish the current long connection, the effect of evenly loading the device managers can be effectively achieved.
[0057] To balance the load of the device managers, in the firewall processing method provided in the embodiments of this application, the process of using a load balancer to select the second device manager from multiple device managers includes: obtaining the current load conditions of each device manager; the load balancer selects the second device manager from multiple device managers according to the load conditions.
[0058] Specifically, the load balancer will obtain the current load conditions of each device manager. For example, the number of long connections that have been established for each device manager currently, etc. Then the load balancer selects the second device manager from multiple device managers according to the load conditions of each device manager. The effect of load balancing for the device managers is achieved through the load balancer.
[0059] How to establish a long connection between the target firewall and the device manager is crucial. Therefore, in the firewall processing method provided in the embodiments of this application, establishing the second long connection between the second device manager and the target firewall according to the second long connection request includes: the target firewall sends a first message to the second device manager; after receiving the first message, the second device manager processes the first message to obtain a second message and sends the second message to the target firewall; the target firewall verifies the second message. If the verification passes, it indicates that the second long connection between the second device manager and the target firewall has been established.
[0060] Specifically, the target firewall sends a first message to the second device manager. After receiving the first message, the second device manager processes the first message to obtain a second message and sends the second message to the target firewall. The target firewall verifies the second message. If the verification passes, it indicates that the second long connection between the second device manager and the target firewall has been established. The three-way handshake connection can effectively ensure the stability of the long connection between the target firewall and the device manager.
[0061] Optionally, in the firewall processing method provided in the embodiments of the present application, before receiving the second long connection request from the target firewall, the method further includes: receiving a first long connection request from the target firewall; selecting a first device manager from multiple device managers through a load balancer and establishing a first long connection between the target firewall and the first device manager; after the first long connection is established, storing the target data information in the Redis database.
[0062] Specifically, after receiving the first long connection request from the target firewall (the target firewall SN is sn01), a first device manager is selected from multiple device managers through a load balancer, and a first long connection between the target firewall and the first device manager is established. After the first long connection is established, the target data information of the target firewall is stored in the Redis database so that when establishing other long connections later, the long connection status of the target firewall can be accurately read.
[0063] Optionally, in the firewall processing method provided in the embodiments of the present application, updating the target data information in the Redis database includes: updating the connection status of the long connection to the second long connection has been connected; adding the identification information of the second device manager corresponding to the second long connection to the target data information.
[0064] Specifically, after the second long connection is established, it is necessary to update the target data information of the target firewall in the Redis database, mainly including updating the connection status of the long connection to the second long connection has been connected, and adding the identification information of the second device manager corresponding to the second long connection to the target data information, so that if there is still a third long connection request from the target firewall, the connection status of the second long connection can be accurately read to ensure the accurate establishment of the third long connection.
[0065] Optionally, in the firewall processing method provided in the embodiments of the present application, after updating the target data information in the Redis database, the method further includes: determining whether there are other long connection requests from the target firewall; if there are no other long connection requests from the target firewall, it indicates that the long connection of the target firewall has been completed.
[0066] Specifically, after the second longest connection is established and the target data information in the Redis database is updated, it is also necessary to determine whether there are other long connection requests for the target firewall. If there are other long connection requests, other long connections are established, and the establishment method is the same as that of the second longest connection. If there are no other long connection requests for the target firewall, it indicates that the long connection of the target firewall is completed. The target firewall communicates with the network management system through these long connections.
[0067] Optionally, in the firewall processing method provided in the embodiments of the present application, after the long connection of the target firewall is completed, the method further includes: if an operation instruction for the target firewall is received, determining the target device manager corresponding to the operation instruction; and sending the operation instruction to the target device manager, so that the target device manager sends the operation instruction to the target firewall.
[0068] Determining the target device manager corresponding to the operation instruction includes: determining the operation type according to the operation instruction; determining the target long connection from the multiple long connections corresponding to the target firewall according to the operation type; and determining the target device manager corresponding to the target long connection from the target data information stored in the Redis database according to the target long connection and the identification information of the target firewall.
[0069] Specifically, after the long connection of the target firewall is completed, if an operation instruction for the target firewall is received, the operation type is determined according to the operation instruction, then the target long connection is determined from the multiple long connections corresponding to the target firewall according to the operation type, and the target device manager corresponding to the target long connection is determined from the target data information stored in the Redis database according to the target long connection and the identification information of the target firewall. Finally, the operation instruction is sent to the target firewall through the target device manager.
[0070] In an optional embodiment, assume that four long connections are established between the target firewall and the network management system, and the four long connections transmit different data and correspond to different service types. Assume that the first long connection carries type A services, the second long connection carries type B services, the third long connection undertakes type C services, and the fourth long connection carries type D services. When the CM receives a user instruction to perform a type A operation on the firewall, it will first query in Redis on which DM the first long connection is established, and then send the corresponding command to the DM to complete the communication with the firewall. When the CM receives a user instruction to perform a type B operation on the firewall, it will query in Redis on which DM the second long connection is established, and then send the corresponding command to the DM to complete the communication with the firewall through the DM.
[0071] In an optional embodiment, a high-performance key-value database Redis is added to the network management system. As Figure 5 shown, Redis is used to record the current status of each firewall and on which DM each connection is maintained.
[0072] After the network management system receives a registration request from a firewall (the firewall SN is sn01), it randomly forwards the request to a DM node through a load balancer. For example, it is forwarded to the DM1 node at this time. DM1 interacts with the firewall normally like a single machine and completes the establishment of the control channel. At this time, the DM1 node needs to write the current information into Redis and wait for the firewall to initiate a request for the next connection. The Redis information is shown in Table 1:
[0073] Table 1
[0074] SN Current Status Connection Status sn01 The first long connection has been established The first long connection: DM1
[0075] The network management system continues to receive long connection requests from other channels of the firewall. At this time, it is necessary to obtain the long connection status of the current firewall from Redis according to the firewall's sn. In the case where the first long connection has been established, a second long connection is established, and the latest status and connection information are stored in Redis, as shown in Table 2.
[0076] Table 2
[0077]
[0078] Continue to establish connections until all long connections are established, as shown in Table 3.
[0079] Table 3
[0080]
[0081] At this point, four connections have been successfully established for communication between the firewall and the network management system. For ease of maintenance, the services that the four connections can undertake are generally different. We assume that the first connection carries type A services, the second connection carries type B services, the third connection undertakes type C services, and the fourth connection carries type D services. When the CM receives a user instruction to perform a type A operation on the firewall, it will first query from Redis on which DM node the first connection is established, and then send the corresponding command to that DM to complete the communication with the firewall, as Figure 6 shown.
[0082] The processing method of the firewall provided by the embodiment of the present application receives a second long connection request of the target firewall, where the second long connection request at least includes the identification information of the target firewall; reads the connection status of the long connection of the target firewall from the Redis database according to the identification information of the target firewall, where the Redis database stores the target data information of the target firewall, and the target data information at least includes: the identification information of the target firewall, the connection status of the long connection, and the identification information of the first device manager corresponding to the first long connection, and the first long connection is the long connection between the first device manager and the target firewall; if the connection status of the long connection is that the first long connection is connected, selects a second device manager from multiple device managers through a load balancer; establishes a second long connection between the second device manager and the target firewall according to the second long connection request, and after the second long connection is established, updates the target data information in the Redis database, solving the problem that in the related art, the connection of the firewall is forwarded to the device manager through the IP, resulting in uneven load of the device manager. In this solution, by establishing a high-performance Redis database and recording the connection status of each firewall in the Redis database, the problem of state confusion can be effectively avoided. When receiving the long connection request of the target firewall, the previous connection status of the target firewall can be accurately read through the Redis database. When the connection status of the long connection is that the first long connection is connected, a second device manager is evenly selected from multiple device managers through the load balancer to establish the current long connection, thereby achieving the effect of balancing the load of the device manager.
[0083] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0084] The embodiment of the present application also provides a processing device for a firewall. It should be noted that the processing device for the firewall in the embodiment of the present application can be used to execute the processing method for the firewall provided by the embodiment of the present application. The following introduces the processing device for the firewall provided by the embodiment of the present application.
[0085] Figure 7 is a schematic diagram of the processing device for the firewall according to the embodiment of the present application. As Figure 7 shown, the device includes: a first receiving unit 701, a reading unit 702, a selecting unit 703, and a establishing unit 704.
[0086] The first receiving unit 701 is configured to receive a second long connection request of the target firewall, where the second long connection request at least includes the identification information of the target firewall;
[0087] The reading unit 702 is used to read the connection state of the persistent connection of the target firewall from the Redis database according to the identification information of the target firewall, wherein the Redis database stores the target data information of the target firewall, and the target data information at least includes: the identification information of the target firewall, the connection state of the persistent connection, and the identification information of the first device manager corresponding to the first persistent connection, where the first persistent connection is the persistent connection between the first device manager and the target firewall;
[0088] A selection unit 703, configured to select a second device manager from a plurality of device managers through a load balancer if the connection state of the persistent connection is that the first persistent connection is connected;
[0089] The establishing unit 704 is used to establish a second long connection between the second device manager and the target firewall according to the second long connection request, and update the target data information in the Redis database after the second long connection is established.
[0090] Specifically, the target firewall initiates a second long connection request, which includes at least the identification information of the target firewall. Generally speaking, sn is an identification that uniquely distinguishes a firewall, such as 2006123456789. It should be noted that the current target firewall has established a first long connection request with the first device manager.
[0091] After receiving the second long connection request initiated by the target firewall, the connection status of the long connection of the target firewall is read from the Redis database through the identification information of the target firewall. The Redis database stores the connection status of the long connection of each firewall and the DM on which each connection is maintained. Storing the connection status of the long connection of each firewall in the Redis database can effectively avoid the problem of long connection failure of the target firewall due to confusion of the connection status of the long connection.
[0092] If the connection status of the persistent connection is that the first persistent connection is connected, it means that the current first persistent connection has been successfully established and the next persistent connection can be established. Therefore, the second device manager is selected from the multiple device managers through the load balancer. It should be noted that the first device manager and the second device manager can be the same device manager or different device managers.
[0093] After determining the second device manager, establish a second long connection between the second device manager and the target firewall according to the second long connection request. After the second long connection is established, update the target data information in the Redis database. Updating the target data information in the Redis database includes updating the long connection status and storing the identification information of the second device manager, etc.
[0094] In summary, a firewall often needs to establish multiple TCP long connections with a device manager or a network management system. Each long connection needs to be established on the premise that the previous long connection has been established. Therefore, this application proposes to add a high-performance key-value database Redis to the network management system. Redis records the current long connection status of each firewall and which DM each long connection is maintained on. Storing the connection status of each firewall's long connection in the Redis database can effectively avoid the problem of long connection failure of the target firewall caused by the confusion of the long connection status. By using a load balancer to evenly select a second device manager from multiple device managers to establish the current long connection, the effect of evenly loading the device manager can be effectively achieved.
[0095] The processing device of the firewall provided by the embodiment of the present application receives a second long connection request of the target firewall through the first receiving unit 701, where the second long connection request at least includes the identification information of the target firewall; the reading unit 702 reads the connection status of the long connection of the target firewall from the Redis database according to the identification information of the target firewall, where the Redis database stores the target data information of the target firewall, and the target data information at least includes: the identification information of the target firewall, the connection status of the long connection, and the identification information of the first device manager corresponding to the first long connection, and the first long connection is the long connection between the first device manager and the target firewall; the selection unit 703, if the connection status of the long connection is that the first long connection has been connected, selects a second device manager from multiple device managers through the load balancer; the establishment unit 704 establishes a second long connection between the second device manager and the target firewall according to the second long connection request, and after the second long connection is established, updates the target data information in the Redis database, which solves the problem in the related technology that the connection of the firewall is forwarded to the device manager through the IP, resulting in uneven load of the device manager. In this solution, by establishing a high-performance Redis database and recording the connection status of each firewall in the Redis database, the problem of state confusion can be effectively avoided. When receiving the long connection request of the target firewall, the previous connection status of the target firewall can be accurately read through the Redis database. When the connection status of the long connection is that the first long connection has been connected, the second device manager is evenly selected from multiple device managers through the load balancer to establish the current long connection, thereby achieving the effect of balancing the load of the device manager.
[0096] Optionally, in the processing device of the firewall provided by the embodiment of the present application, the selection unit includes: an acquisition module, configured to acquire the current load condition of each device manager; a selection module, configured to enable the load balancer to select a second device manager from multiple device managers according to the load condition.
[0097] Specifically, the load balancer will acquire the current load condition of each device manager. For example, the number of long connections that have been established for each device manager currently, etc. Then the load balancer selects a second device manager from multiple device managers according to the load condition of each device manager. The effect of load balancing of the device manager is achieved through the load balancer.
[0098] Optionally, in the processing device of the firewall provided in the embodiments of the present application, the establishment unit includes: a sending module, configured to send a first message to a second device manager for a target firewall; a processing module, configured to, after the second device manager receives the first message, process the first message to obtain a second message, and send the second message to the target firewall; a verification module, configured to verify the second message by the target firewall, and if the verification passes, it indicates that the second long connection between the second device manager and the target firewall has been established.
[0099] Specifically, the target firewall sends a first message to the second device manager. After the second device manager receives the first message, it processes the first message to obtain a second message, and sends the second message to the target firewall. The target firewall verifies the second message. If the verification passes, it indicates that the second long connection between the second device manager and the target firewall has been established. The stability of the long connection between the target firewall and the device manager can be effectively guaranteed through the three-way handshake connection.
[0100] Optionally, in the processing device of the firewall provided in the embodiments of the present application, the device further includes: before receiving the second long connection request of the target firewall, receiving the first long connection request of the target firewall; a second receiving unit, configured to select a first device manager from multiple device managers through a load balancer, and establish a first long connection between the target firewall and the first device manager; a storage unit, configured to store the target data information in a Redis database after the first long connection is established.
[0101] Specifically, after receiving the first long connection request of the target firewall (the target firewall SN is sn01), select a first device manager from multiple device managers through a load balancer, and establish a first long connection between the target firewall and the first device manager. After the first long connection is established, store the target data information of the target firewall in the Redis database, so that when establishing other long connections later, the long connection status of the target firewall can be accurately read.
[0102] Optionally, in the processing device of the firewall provided in the embodiments of the present application, the establishment unit includes: an update module, configured to update the connection status of the long connection to the second long connection being connected; an addition module, configured to add the identification information of the second device manager corresponding to the second long connection to the target data information.
[0103] Specifically, after the second-longest connection is established, it is necessary to update the target data information of the target firewall in the Redis database, mainly including updating the connection status of the long connection to the second-longest connection has been connected, and adding the identification information of the second device manager corresponding to the second-longest connection to the target data information as well, so that if there is a third-longest connection request for the target firewall, the connection status of the second-longest connection can be accurately read to ensure the accurate establishment of the third-longest connection.
[0104] Optionally, in the processing device of the firewall provided in the embodiment of the present application, the device further includes: a judgment unit, configured to judge whether there are other long connection requests for the target firewall after updating the target data information in the Redis database; a first determination unit, configured to represent that the long connection of the target firewall is completed if there are no other long connection requests for the target firewall.
[0105] Specifically, after the second-longest connection is established and the target data information in the Redis database is updated, it is also necessary to judge whether there are other long connection requests for the target firewall. If there are other long connection requests, other long connections are established, and the establishment method is the same as that of the second-longest connection. If there are no other long connection requests for the target firewall, it represents that the long connection of the target firewall is completed. The target firewall communicates with the network management system through these long connections.
[0106] Optionally, in the processing device of the firewall provided in the embodiment of the present application, the device further includes: a second determination unit, configured to determine the target device manager corresponding to the operation instruction if an operation instruction for the target firewall is received after the long connection of the target firewall is completed; a sending unit, configured to send the operation instruction to the target device manager, so as to send the operation instruction to the target firewall through the target device manager.
[0107] Optionally, in the processing device of the firewall provided in the embodiment of the present application, the second determination unit includes: a first determination module, configured to determine the operation type according to the operation instruction; a second determination module, configured to determine the target long connection from the multiple long connections corresponding to the target firewall according to the operation type; a third determination module, configured to determine the target device manager corresponding to the target long connection from the target data information stored in the Redis database according to the target long connection and the identification information of the target firewall.
[0108] Specifically, after the long connection of the target firewall is completed, if an operation instruction for the target firewall is received, the operation type is determined according to the operation instruction, then the target long connection is determined from multiple long connections corresponding to the target firewall according to the operation type, and according to the target long connection and the identification information of the target firewall, the target device manager corresponding to the target long connection is determined from the target data information stored in the Redis database. Finally, the operation instruction is sent to the target firewall through the target device manager.
[0109] In an optional embodiment, it is assumed that four long connections are established between the target firewall and the network management system. The four long connections transmit different data and correspond to different service types. Assume that the first long connection carries type A services, the second long connection carries type B services, the third long connection undertakes type C services, and the fourth long connection carries type D services. When the CM receives a user instruction to perform a type A operation on the firewall, it will first query from Redis on which DM the first long connection is established, and then send the corresponding command to that DM to complete the communication with the firewall. When the CM receives a user instruction to perform a type B operation on the firewall, it will query from Redis on which DM the second long connection is established, and then send the corresponding command to that DM to complete the communication with the firewall through that DM.
[0110] In an optional embodiment, a high-performance key-value database Redis is added to the network management system, as Figure 5 shown. Redis is used to record the current status of each firewall and on which DM each connection is maintained.
[0111] After the network management system receives a registration request from a firewall (the firewall SN is sn01), it randomly forwards the request to a DM node through a load balancer. For example, at this time, it is forwarded to the DM1 node. DM1 interacts with the firewall normally like a single machine and completes the establishment of the control channel. At this time, the DM1 node needs to write the current information into Redis and wait for the firewall to initiate a request for the next connection. The Redis information is shown in Table 1:
[0112] Table 1
[0113] SN Current Status Connection Status sn01 The first long connection has been established The first long connection: DM1
[0114] The network management system continues to receive long connection requests from other channels of the firewall. At this time, it is necessary to obtain the long connection status of the current firewall from Redis according to the sn of the firewall. In the case where the first long connection has been established, the second long connection is established, and the latest status and connection information are stored in Redis, as shown in Table 2.
[0115] Table 2
[0116]
[0117] Continue to establish connections until all long connections are established, as shown in Table 3.
[0118] Table 3
[0119]
[0120] At this point, four connections have been successfully established between the firewall and the network management system for communication. For ease of maintenance, the services that the four connections can undertake are generally different. We assume that the first connection carries type A services, the second connection carries type B services, the third connection undertakes type C services, and the fourth connection carries type D services. When the CM receives a user instruction to perform a type A operation on the firewall, it will first query in Redis which DM node the first connection is established on, and then send the corresponding command to that DM to complete the communication with the firewall, as Figure 6 shown.
[0121] It should be noted that the first receiving unit 701 in this embodiment can be used to execute step S401 in the embodiment of the present application, the reading unit 702 in this embodiment can be used to execute step S402 in the embodiment of the present application, the selection unit 703 in this embodiment can be used to execute step S403 in the embodiment of the present application, and the establishment unit 704 in this embodiment can be used to execute step S404 in the embodiment of the present application. The examples and application scenarios implemented by the above modules and the corresponding steps are the same, but are not limited to the content disclosed in the above embodiments.
[0122] The processing device of the firewall includes a processor and a memory. The above first receiving unit 701, reading unit 702, selection unit 703, and establishment unit 704 are all stored in the memory as program units, and the processor executes the above program units stored in the memory to implement corresponding functions.
[0123] The processor contains a kernel, and the kernel retrieves the corresponding program unit from the memory. One or more kernels can be set, and by adjusting the kernel parameters, the processing of the connection requests of the firewall can be achieved.
[0124] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one storage chip.
[0125] The embodiment of the present invention provides a computer-readable storage medium, on which a program is stored, and when the program is executed by a processor, it implements the processing method of the firewall.
[0126] An embodiment of the present invention provides a processor for running a program, wherein when the program runs, it executes a processing method of a firewall.
[0127] As Figure 8 shown, an embodiment of the present invention provides an electronic device. The device includes a processor, a memory, and a program stored on the memory and executable on the processor. When the processor executes the program, the following steps are implemented: receiving a second long connection request of a target firewall, where the second long connection request at least includes identification information of the target firewall; reading the connection status of the long connection of the target firewall from a Redis database according to the identification information of the target firewall, where the Redis database stores target data information of the target firewall, and the target data information at least includes: identification information of the target firewall, the connection status of the long connection, and identification information of a first device manager corresponding to a first long connection, and the first long connection is a long connection between the first device manager and the target firewall; if the connection status of the long connection is that the first long connection is already connected, selecting a second device manager from multiple device managers through a load balancer; establishing a second long connection between the second device manager and the target firewall according to the second long connection request, and after the second long connection is established, performing an update process on the target data information in the Redis database.
[0128] Optionally, selecting a second device manager from multiple device managers through a load balancer includes: obtaining the current load condition of each device manager; the load balancer selects the second device manager from multiple device managers according to the load condition.
[0129] Optionally, establishing a second long connection between the second device manager and the target firewall according to the second long connection request includes: the target firewall sending a first message to the second device manager; after receiving the first message, the second device manager processes the first message to obtain a second message and sends the second message to the target firewall; the target firewall verifies the second message, and if the verification passes, it indicates that the second long connection between the second device manager and the target firewall has been established.
[0130] Optionally, before receiving the second long connection request of the target firewall, the method further includes: receiving a first long connection request of the target firewall; selecting a first device manager from multiple device managers through a load balancer and establishing a first long connection between the target firewall and the first device manager; after the first long connection is established, storing the target data information in the Redis database.
[0131] Optionally, the update process for the target data information in the Redis database includes: updating the connection status of the long connection to the second long connection being connected; adding the identification information of the second device manager corresponding to the second long connection to the target data information.
[0132] Optionally, after the update process for the target data information in the Redis database, the method further includes: determining whether there are any other long connection requests for the target firewall; if there are no other long connection requests for the target firewall, it indicates that the long connection of the target firewall is completed.
[0133] Optionally, after the long connection of the target firewall is completed, the method further includes: if an operation instruction for the target firewall is received, determining the target device manager corresponding to the operation instruction; sending the operation instruction to the target device manager, so that the operation instruction is sent to the target firewall through the target device manager.
[0134] Optionally, determining the target device manager corresponding to the operation instruction includes: determining the operation type according to the operation instruction; determining the target long connection from the multiple long connections corresponding to the target firewall according to the operation type; determining the target device manager corresponding to the target long connection from the target data information stored in the Redis database according to the target long connection and the identification information of the target firewall.
[0135] The devices in this article can be servers, PCs, PADs, mobile phones, etc.
[0136] This application also provides a computer program product, which when executed on a data processing device, is suitable for executing a program initialized with the following method steps: receiving a second long connection request of a target firewall, where the second long connection request at least includes the identification information of the target firewall; reading the connection status of the long connection of the target firewall from the Redis database according to the identification information of the target firewall, where the target data information of the target firewall is stored in the Redis database, and the target data information at least includes: the identification information of the target firewall, the connection status of the long connection, and the identification information of the first device manager corresponding to the first long connection, and the first long connection is the long connection between the first device manager and the target firewall; if the connection status of the long connection is the first long connection being connected, selecting a second device manager from multiple device managers through a load balancer; establishing a second long connection between the second device manager and the target firewall according to the second long connection request, and after the second long connection is established, performing an update process on the target data information in the Redis database.
[0137] Optionally, selecting a second device manager from multiple device managers through a load balancer includes: obtaining the current load conditions of each device manager; and the load balancer selecting the second device manager from the multiple device managers according to the load conditions.
[0138] Optionally, establishing a second long connection between the second device manager and the target firewall according to the second long connection request includes: the target firewall sending a first message to the second device manager; after receiving the first message, the second device manager processes the first message to obtain a second message, and sends the second message to the target firewall; the target firewall verifies the second message, and if the verification passes, it indicates that the second long connection between the second device manager and the target firewall has been established.
[0139] Optionally, before receiving the second long connection request from the target firewall, the method further includes: receiving a first long connection request from the target firewall; selecting a first device manager from multiple device managers through a load balancer, and establishing a first long connection between the target firewall and the first device manager; after the first long connection is established, storing the target data information in a Redis database.
[0140] Optionally, performing an update process on the target data information in the Redis database includes: updating the connection status of the long connection to indicate that the second long connection is connected; and adding the identification information of the second device manager corresponding to the second long connection to the target data information.
[0141] Optionally, after performing the update process on the target data information in the Redis database, the method further includes: determining whether there are any other long connection requests from the target firewall; if there are no other long connection requests from the target firewall, it indicates that the long connection of the target firewall has been completed.
[0142] Optionally, after the long connection of the target firewall has been completed, the method further includes: if an operation instruction for the target firewall is received, determining the target device manager corresponding to the operation instruction; and sending the operation instruction to the target device manager, so that the target device manager sends the operation instruction to the target firewall.
[0143] Optionally, determining the target device manager corresponding to the operation instruction includes: determining the operation type according to the operation instruction; determining the target long connection from the multiple long connections corresponding to the target firewall according to the operation type; and determining the target device manager corresponding to the target long connection from the target data information stored in the Redis database according to the target long connection and the identification information of the target firewall.
[0144] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0145] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0146] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0147] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0148] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0149] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.
[0150] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0151] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0152] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0153] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.
Claims
1. A processing method for a firewall, characterized in that, it includes: Receiving a second long connection request of the target firewall, where the second long connection request at least includes the identification information of the target firewall; Reading the connection status of the long connection of the target firewall from the Redis database according to the identification information of the target firewall, where the target data information is stored in the Redis database, and the target data information at least includes: the identification information of the target firewall, the connection status of the long connection, and the identification information of the first device manager corresponding to the first long connection, and the first long connection is the long connection between the first device manager and the target firewall; If the connection status of the long connection is that the first long connection is connected, then select a second device manager from multiple device managers through a load balancer; Establish a second long connection between the second device manager and the target firewall according to the second long connection request, and after the second long connection is established, perform an update process on the target data information in the Redis database; Wherein, selecting a second device manager from multiple device managers through a load balancer includes: Obtaining the current load situation of each device manager; The load balancer selects a second device manager from multiple device managers according to the load situation.
2. The method according to claim 1, characterized in that, Establishing a second long connection between the second device manager and the target firewall according to the second long connection request includes: The target firewall sends a first message to the second device manager; After receiving the first message, the second device manager processes the first message to obtain a second message, and sends the second message to the target firewall; The target firewall verifies the second message, and if the verification passes, it indicates that the second long connection between the second device manager and the target firewall has been established.
3. The method according to claim 1, characterized in that, Before receiving the second long connection request of the target firewall, the method further includes: Receiving the first long connection request of the target firewall; Selecting the first device manager from multiple device managers through the load balancer, and establishing a first long connection between the target firewall and the first device manager; After the first long connection is established, storing the target data information in the Redis database.
4. The method according to claim 1, characterized in that, Performing an update process on the target data information in the Redis database includes: Updating the connection status of the long connection to that the second long connection is connected; Adding the identification information of the second device manager corresponding to the second long connection to the target data information.
5. The method according to claim 1, characterized in that, After performing an update process on the target data information in the Redis database, the method further includes: Judging whether there are other long connection requests for the target firewall; If there are no other long connection requests for the target firewall, it indicates that the long connection of the target firewall has been completed.
6. The method according to claim 5, wherein, after the long connection of the target firewall has been completed, the method further includes: if an operation instruction for the target firewall is received, determining a target device manager corresponding to the operation instruction; sending the operation instruction to the target device manager, so as to send the operation instruction to the target firewall through the target device manager.
7. The method according to claim 6, wherein, determining a target device manager corresponding to the operation instruction includes: determining an operation type according to the operation instruction; determining a target long connection from multiple long connections corresponding to the target firewall according to the operation type; determining the target device manager corresponding to the target long connection from the target data information stored in the Redis database according to the target long connection and the identification information of the target firewall.
8. A processing device for a firewall, wherein, it includes: a first receiving unit, configured to receive a second long connection request of a target firewall, where the second long connection request at least includes the identification information of the target firewall; a reading unit, configured to read the connection status of the long connection of the target firewall from a Redis database according to the identification information of the target firewall, where the target data information is stored in the Redis database, and the target data information at least includes: the identification information of the target firewall, the connection status of the long connection, and the identification information of a first device manager corresponding to a first long connection, and the first long connection is a long connection between the first device manager and the target firewall; a selection unit, configured to, if the connection status of the long connection is that the first long connection has been connected, select a second device manager from multiple device managers through a load balancer; a establishing unit, configured to establish a second long connection between the second device manager and the target firewall according to the second long connection request, and perform an update process on the target data information in the Redis database after the second long connection is established; wherein, the selection unit includes: an obtaining module, configured to obtain the current load condition of each device manager; a selection module, configured to the load balancer selects a second device manager from multiple device managers according to the load condition.
9. A processor, wherein, the processor is used to run a program, and when the program runs, it executes the processing method of the firewall according to any one of claims 1 to 7.
Citation Information
Patent Citations
Configuration file management method and system
CN106603281A
Business processing method and device, storage medium and electronic device
CN114760348A