Cloud network planning method, device, electronic device and storage medium

By dividing the cloud network into multiple zones and performing refined deployment and planning, the problem that traditional cloud network planning architecture cannot meet the overall needs of tenants is solved, and a network architecture with high availability, security, reliability and flexible expansion is achieved.

CN115988032BActive Publication Date: 2025-09-02CHINA CONSTRUCTION BANK
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202211665470.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-23
Publication Date
2025-09-02
Estimated Expiration
2042-12-23

AI Technical Summary

Technical Problem

The traditional cloud network planning architecture is single, and it is impossible to uniformly allocate network resources involving all requirements to specific tenants, and cannot meet the overall needs of tenants for high availability, security, reliability, flexible deployment and elastic expansion of cloud networks.

Method used

The cloud network is divided into open zones, Internet zones, third-party outreach zones and private cloud outreach zones, and connect each zone through peer-to-peer connections and routing tables, deploy physical subsystems to meet different needs, use security group rules and load balancing for traffic filtering and control, and plan subnets to achieve high availability and security.

Benefits of technology

A network architecture with clear structure, safe and reliable, easy to expand and maintain is formed to meet the overall needs of tenants for high availability, security, reliability, flexible deployment and elastic expansion.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115988032B_ABST
    Figure CN115988032B_ABST
Patent Text Reader

Abstract

The present application provides a cloud network planning method, device, electronic device and storage medium. Among them, in the cloud network planning method, the cloud network is divided into an open area, an Internet area, a third-party external area, and a private cloud external area. The physical subsystem that carries the application is deployed in the open area, wherein the physical subsystem is a service cluster that can independently provide a certain application or function. The physical subsystem that needs to interact with a third party, a private cloud and the Internet is deployed in the third-party external area, the private cloud external area and the Internet area. Finally, subnet planning is performed for the open area and the Internet area. It can be seen that by using the method of the present application, the cloud network product and the tenant's overall needs for high network availability, security, reliability, flexible deployment and elastic expansion are fully integrated to form a network architecture with a clear structure, security, reliability, easy expansion and easy maintenance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet technology, and in particular to a cloud network planning method, device, electronic device and storage medium. Background Art

[0002] In recent years, cloud computing, as an internet infrastructure, has entered an era of rapid development. Deploying applications in the cloud has become the choice of an increasing number of enterprises. Cloud service providers build infrastructure, integrate resources, construct virtual resource pools, and allocate them to multiple tenants as needed.

[0003] Traditional cloud network planning architecture is single and cannot uniformly allocate network resources covering all needs to specific tenants, and cannot meet tenants' overall needs for high availability, security, reliability, flexible deployment and elastic expansion of cloud networks. Summary of the Invention

[0004] In view of this, the present application provides a cloud network planning method, device, electronic device and storage medium to solve the problem that the traditional cloud network planning architecture is single, cannot uniformly allocate network resources involving all needs to specific tenants, and cannot meet the tenants' overall needs for high availability, security, reliability, flexible deployment and elastic expansion of the cloud network.

[0005] To achieve the above objectives, this application provides the following technical solutions:

[0006] In a first aspect, the present application discloses a cloud network planning method, comprising:

[0007] Divide the cloud network into an open area, an Internet area, a third-party external area, and a private cloud external area, wherein the open area is connected to the Internet area, the third-party external area, and the private cloud external area respectively through peer-to-peer connections; the Internet area, the third-party external area, and the private cloud external area are connected to each other through routing tables;

[0008] Deploying a physical subsystem carrying an application in the open area, wherein the physical subsystem is a service cluster capable of independently providing a certain application or function;

[0009] Deploy physical subsystems that need to interact with third parties, private clouds, and the Internet in the third-party external connection area, the private cloud external connection area, and the Internet area;

[0010] Subnet planning is performed for the open area and the Internet area.

[0011] Optionally, in the above method, deploying the physical subsystem that needs to interact with a third party, a private cloud, and the Internet in the third-party external zone, the private cloud external zone, and the Internet zone includes:

[0012] The security group rules are used to filter the external business traffic of the physical subsystems of the third-party external zone, the private cloud external zone, and the Internet zone.

[0013] Optionally, in the above method, deploying the physical subsystem that needs to interact with a third party, a private cloud, and the Internet in the third-party external zone, the private cloud external zone, and the Internet zone includes:

[0014] Each physical subsystem in the Internet zone is respectively planned to have a public network load balancing for Internet access and a network address translation gateway for Internet access.

[0015] Optionally, the above method, performing subnet planning for the open zone and the Internet zone, includes:

[0016] For the Internet zone, divide the inbound subnet and the outbound subnet;

[0017] The open area is divided into application subnet and isolation subnet.

[0018] A second aspect of the present application discloses a cloud network planning device, comprising:

[0019] a partitioning unit, configured to partition the cloud network into an open zone, an Internet zone, a third-party external zone, and a private cloud external zone, wherein the open zone is connected to the Internet zone, the third-party external zone, and the private cloud external zone respectively through a peer-to-peer connection; and the Internet zone, the third-party external zone, and the private cloud external zone are connected to each other through a routing table;

[0020] A first deployment unit is configured to deploy a physical subsystem carrying an application in the open area, wherein the physical subsystem is a service cluster capable of independently providing a certain application or function;

[0021] A second deployment unit is configured to deploy a physical subsystem that needs to interact with a third party, a private cloud, and the Internet in the third-party external connection zone, the private cloud external connection zone, and the Internet zone;

[0022] A planning unit is used to perform subnet planning for the open area and the Internet area.

[0023] Optionally, in the above device, the second deployment unit includes:

[0024] The filtering subunit is used to filter the external business traffic of the physical subsystems of the third-party external zone, the private cloud external zone and the Internet zone by using security group rules.

[0025] Optionally, in the above device, the second deployment unit includes:

[0026] The planning subunit is used to plan the public network load balancing for Internet access and the network address translation gateway for Internet access for each physical subsystem in the Internet zone.

[0027] Optionally, in the above-mentioned device, the planning unit includes:

[0028] A first division sub-unit is configured to divide the Internet zone into an inbound subnet and an outbound subnet;

[0029] The second division sub-unit is used to divide the open area into an application subnet and an isolation subnet.

[0030] A third aspect of the present application discloses an electronic device, comprising:

[0031] one or more processors;

[0032] a storage device having one or more programs stored thereon;

[0033] When the one or more programs are executed by the one or more processors, the one or more processors are enabled to implement the method according to any one of the first aspects of the present invention.

[0034] A fourth aspect of the present application discloses a computer storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the method according to any one of the first aspects of the present invention is implemented.

[0035] As can be seen from the above technical solution, in a cloud network planning method provided by this application, the cloud network is divided into an open area, an Internet area, a third-party external area, and a private cloud external area, wherein the open area is connected to the Internet area, the third-party external area, and the private cloud external area respectively through a peer-to-peer connection; the Internet area, the third-party external area, and the private cloud external area are connected to each other through a routing table. The physical subsystem that carries the application is deployed in the open area, wherein the physical subsystem is a service cluster that can independently provide a certain application or function. The physical subsystem that needs to interact with third parties, private clouds, and the Internet is deployed in the third-party external area, the private cloud external area, and the Internet area. Finally, subnet planning is performed for the open area and the Internet area. It can be seen that using the method of this application, the cloud network product and the tenant's overall needs for high network availability, security, reliability, flexible deployment, and elastic expansion are fully integrated to form a network architecture with a clear structure, security, reliability, easy expansion, and easy maintenance. This solves the problem that the traditional cloud network planning architecture in the existing technology is single, unable to uniformly allocate network resources involving all needs to specific tenants, and unable to meet tenants' overall needs for high availability, security, reliability, flexible deployment and elastic expansion of cloud networks. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without any creative work.

[0037] Figure 1 A flowchart of a cloud network planning method disclosed in an embodiment of the present application;

[0038] Figure 2 A schematic diagram of a cloud network architecture disclosed in another embodiment of the present application;

[0039] Figure 3 A schematic diagram of a cloud network planning device disclosed in another embodiment of the present application;

[0040] Figure 4 This is a schematic diagram of an electronic device disclosed in another embodiment of the present application. DETAILED DESCRIPTION

[0041] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0042] In this application, the terms "comprises," "comprising," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not preclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.

[0043] Furthermore, in this document, relational terms such as first and second, etc. are used merely to distinguish one entity or operation from another entity or operation, but do not necessarily require or imply any actual relationship or order between these entities or operations.

[0044] As can be seen from the background technology, the traditional cloud network planning architecture is single and cannot uniformly allocate network resources involving all needs to specific tenants, and cannot meet tenants' overall needs for high availability, security, reliability, flexible deployment and elastic expansion of cloud networks.

[0045] In view of this, the present application provides a cloud network planning method, device, electronic device and storage medium to solve the problem that the traditional cloud network planning architecture is single, cannot uniformly allocate network resources involving all needs to specific tenants, and cannot meet the tenants' overall needs for high availability, security, reliability, flexible deployment and elastic expansion of the cloud network.

[0046] The present application embodiment provides a cloud network planning method, specifically as follows Figure 1 As shown, specifically including:

[0047] S101. Divide the cloud network into an open area, an Internet area, a third-party external area, and a private cloud external area, wherein the open area is connected to the Internet area, the third-party external area, and the private cloud external area respectively through peer-to-peer connections; the Internet area, the third-party external area, and the private cloud external area are connected to each other through a routing table.

[0048] It should be noted that, combined with Figure 2The cloud network architecture shown divides the cloud network into an open area, an Internet area, a third-party external area, and a private cloud external area. The open area is connected to the Internet area, the third-party external area, and the private cloud external area respectively through peer connections; the Internet area, the third-party external area, and the private cloud external area are connected to each other through routing tables.

[0049] S102: Deploy a physical subsystem carrying an application in the open area, wherein the physical subsystem is a service cluster that can independently provide a certain application or function.

[0050] It should be noted that the physical subsystem refers to a service cluster that can independently provide a certain application or function. The physical subsystem that carries the application (such as cloud host, cloud hard disk, database, bare metal, etc.) is deployed in the open area.

[0051] S103: Deploy the physical subsystems that need to interact with third parties, private clouds, and the Internet in the third-party external connection area, the private cloud external connection area, and the Internet area.

[0052] It should be noted that the physical subsystems (such as load balancing, front-end processors, etc.) that need to interact with third parties, private clouds, and the Internet for business purposes are deployed in the third-party external connection area, the private cloud external connection area, and the Internet area as connection areas for the external business traffic of the physical subsystems. By using the load balancing product to bind several front-end processors, jump access for external systems to access tenant application systems is achieved, thus realizing secure interaction. At the same time, since the load balancing product performs health checks on the multiple front-end processors bound to the back-end and only polls hosts with healthy access status, the failure of a single host will not affect business access, and the underlying virtualization design of the load balancing product itself is also highly reliable, thus avoiding single point failures. The number of hosts under load can also be flexibly expanded according to the business access volume to provide stable and reliable business guarantees.

[0053] Optionally, in another embodiment of the present application, an implementation of step S103 may include:

[0054] The security group rules are used to filter the external business traffic of the physical subsystems of the third-party external zone, the private cloud external zone, and the Internet zone.

[0055] It should be noted that after the physical subsystems (such as load balancing, front-end processors, etc.) that need to interact with third parties, private clouds, and the Internet are deployed in the third-party external zone, the private cloud external zone, and the Internet zone, the external business traffic of the physical subsystems is redirected and accessed by each external device. Therefore, security group rules are used to filter the external business traffic of the physical subsystems in the third-party external zone, the private cloud external zone, and the Internet zone, that is, the business traffic is filtered by matching the source (inbound) and destination (outbound) IP addresses and protocol port numbers of the data packets to ensure the security and reliability of the traffic and avoid the security risks brought by direct external access of the application system.

[0056] Optionally, in another embodiment of the present application, an implementation of step S103 may include:

[0057] Each physical subsystem in the Internet zone is respectively planned to have a public network load balancing for Internet access and a network address translation gateway for Internet access.

[0058] It's important to note that the Internet zone is designed as an independent VPC (Virtual Private Cloud). For each physical subsystem, a public network Cloud Load Balancer (CLB) for inbound Internet access and a NAT (Network Address Translation) gateway for outbound Internet access are separately planned. For example, if an application requires both outbound Internet access and inbound Internet client access during business interactions, two subnets can be created for this subsystem in the Internet VPC: inbound and outbound. Hosts requiring outbound access are placed in the outbound subnet, bound to a NAT gateway, and associated with an outbound security group. This allows for both isolation of the intranet through the NAT gateway and granular control of outbound IP addresses and ports through security group outbound rules. Hosts requiring inbound access are placed in the inbound subnet, a public network Cloud Load Balancer (CLB) is created, bound to a cloud host, and an inbound security group is associated with the cloud host. Inbound security group rules can be used to granularly control inbound IP addresses and ports. This allows for separate control of inbound and outbound traffic, avoiding the security risks associated with direct Internet access from the open zone while enabling granular traffic control.

[0059] S104: Perform subnet planning for the open area and the Internet area.

[0060] It should be noted that subnet planning is performed for the open zone and the internet zone, with different physical subsystems assigned to different subnets. Each subnet contains only one physical subsystem. Each subnet corresponds to one security group, with intra-subnet connectivity and inter-subnet connectivity enabled on demand. Each subnet corresponds to one routing table, named after the physical subsystem. This design clarifies business traffic flow, reduces unnecessary communication traffic, improves bandwidth utilization, and enhances visibility, facilitating future maintenance and expansion.

[0061] Optionally, in another embodiment of the present application, an implementation of step S104 may include:

[0062] The Internet zone is divided into an inbound subnet and an outbound subnet.

[0063] The open area is divided into application subnet and isolation subnet.

[0064] It should be noted that for the Internet zone, the interconnected zone is divided into two subnets for each system, one subnet contains inbound traffic devices, and the other subnet contains outbound traffic devices. For the open zone, application subnets and isolation subnets are divided. The AP (Application) that needs to interact with the Internet in the open zone is deployed in the AP isolation subnet, and each system independently uses an isolated AP subnet to control access. The interconnected zone security group and the isolation subnet security group respectively carry out detailed control of access rules for Internet access to the isolation subnet and isolation subnet access to the corresponding physical subsystem. While effectively controlling the security risks brought by Internet access, it also makes the security rules more organized, clear and easy to maintain.

[0065] In a cloud network planning method provided in an embodiment of the present application, the cloud network is divided into an open area, an Internet area, a third-party external area, and a private cloud external area, wherein the open area is connected to the Internet area, the third-party external area, and the private cloud external area respectively by means of peer-to-peer connection; the Internet area, the third-party external area, and the private cloud external area are connected to each other by means of a routing table. The physical subsystem that carries the application is deployed in the open area, wherein the physical subsystem is a service cluster that can independently provide a certain application or function. The physical subsystem that needs to interact with a third party, a private cloud, and the Internet for business is deployed in the third-party external area, the private cloud external area, and the Internet area. Finally, subnet planning is performed for the open area and the Internet area. It can be seen that by using the method of the present application, the cloud network product and the tenant's overall needs for high network availability, security, reliability, flexible deployment, and elastic expansion are fully integrated to form a network architecture with a clear structure, security, reliability, easy expansion, and easy maintenance. This solves the problem that the traditional cloud network planning architecture in the existing technology is single, unable to uniformly allocate network resources involving all needs to specific tenants, and unable to meet tenants' overall needs for high availability, security, reliability, flexible deployment and elastic expansion of cloud networks.

[0066] Another embodiment of the present application also discloses a cloud network planning device, such as Figure 3 As shown, specifically including:

[0067] The division unit 301 is used to divide the cloud network into an open area, an Internet area, a third-party external area, and a private cloud external area, wherein the open area is connected to the Internet area, the third-party external area, and the private cloud external area respectively through a peer-to-peer connection; the Internet area, the third-party external area, and the private cloud external area are connected to each other through a routing table.

[0068] The first deployment unit 302 is configured to deploy a physical subsystem carrying an application in the open area, wherein the physical subsystem is a service cluster that can independently provide a certain application or function.

[0069] The second deployment unit 303 is configured to deploy a physical subsystem that needs to interact with a third party, a private cloud, and the Internet in the third party external zone, the private cloud external zone, and the Internet zone.

[0070] The planning unit 304 is configured to perform subnet planning for the open area and the Internet area.

[0071] In this embodiment, the specific execution process of the division unit 301, the first deployment unit 302, the second deployment unit 303, and the planning unit 304 can be found in the corresponding Figure 1The content of the method embodiment will not be repeated here.

[0072] In a cloud network planning method provided in an embodiment of the present application, a partitioning unit 301 divides the cloud network into an open zone, an internet zone, a third-party external zone, and a private cloud external zone, wherein the open zone is connected to the internet zone, the third-party external zone, and the private cloud external zone respectively via peer-to-peer connections; the internet zone, the third-party external zone, and the private cloud external zone are connected to each other via routing tables. A first deployment unit 302 deploys a physical subsystem that carries an application in the open zone, wherein the physical subsystem is a service cluster that can independently provide a certain application or function. A second deployment unit 303 deploys a physical subsystem that needs to interact with third parties, private clouds, and the internet in the third-party external zone, the private cloud external zone, and the internet zone. Finally, a planning unit 304 performs subnet planning for the open zone and the internet zone. Thus, the method of the present application fully integrates cloud network products with tenants' overall requirements for high network availability, security, reliability, flexible deployment, and elastic expansion, forming a network architecture with a clear structure, security, reliability, easy expansion, and easy maintenance. This solves the problem that the traditional cloud network planning architecture in the existing technology is single, unable to uniformly allocate network resources involving all needs to specific tenants, and unable to meet tenants' overall needs for high availability, security, reliability, flexible deployment and elastic expansion of cloud networks.

[0073] Optionally, in another embodiment of the present application, an implementation of the second deployment unit 303 includes:

[0074] The filtering subunit is used to filter the external business traffic of the physical subsystems of the third-party external zone, the private cloud external zone and the Internet zone by using security group rules.

[0075] In this embodiment, the specific execution process of the filtering subunit can be found in the corresponding method embodiment above, and will not be repeated here.

[0076] Optionally, in another embodiment of the present application, an implementation of the second deployment unit 303 includes:

[0077] The planning subunit is used to plan the public network load balancing for Internet access and the network address translation gateway for Internet access for each physical subsystem in the Internet zone.

[0078] In this embodiment, the specific execution process of the planning subunit can be found in the corresponding method embodiment described above and will not be repeated here.

[0079] Optionally, in another embodiment of the present application, an implementation of the planning unit 304 includes:

[0080] The first division sub-unit is used to divide the Internet zone into an incoming subnet and an outgoing subnet.

[0081] The second division sub-unit is used to divide the open area into an application subnet and an isolation subnet.

[0082] In this embodiment, the specific execution process of the first division subunit and the second division subunit can be found in the corresponding method embodiment above, and will not be repeated here.

[0083] Another embodiment of the present application further provides an electronic device, such as Figure 4 As shown, specifically including:

[0084] One or more processors 401 .

[0085] The storage device 402 stores one or more programs.

[0086] When one or more programs are executed by one or more processors 401 , the one or more processors 401 implement any one of the methods in the above embodiments.

[0087] Another embodiment of the present application further provides a computer storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, any one of the methods in the above embodiments is implemented.

[0088] Each embodiment in this specification is described in a progressive manner. The same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for system or system embodiments, since they are basically similar to method embodiments, the description is relatively simple. For relevant parts, refer to the partial description of the method embodiment. The system and system embodiments described above are merely schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without expending creative work.

[0089] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.

[0090] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments shown herein, but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A cloud network planning method, characterized in that: include: Divide the cloud network into an open area, an Internet area, a third-party external area, and a private cloud external area, wherein the open area is connected to the Internet area, the third-party external area, and the private cloud external area respectively through peer-to-peer connections; the Internet area, the third-party external area, and the private cloud external area are connected to each other through routing tables; Deploying a physical subsystem carrying an application in the open area, wherein the physical subsystem is a service cluster capable of independently providing a certain application or function; Deploy physical subsystems that need to interact with third parties, private clouds, and the Internet in the third-party external connection area, the private cloud external connection area, and the Internet area; Performing subnet planning for the open area and the Internet area; The physical subsystems that need to interact with third parties, private clouds, and the Internet are deployed in the third-party external connection area, the private cloud external connection area, and the Internet area, including: The security group rules are used to filter the external business traffic of the physical subsystems of the third-party external zone, the private cloud external zone, and the Internet zone.

2. The method according to claim 1, characterized in that The physical subsystem that needs to interact with a third party, a private cloud, and the Internet is deployed in the third-party external zone, the private cloud external zone, and the Internet zone, including: Each physical subsystem in the Internet zone is respectively planned to have a public network load balancing for Internet access and a network address translation gateway for Internet access.

3. The method according to claim 1, characterized in that The subnet planning for the open area and the Internet area includes: For the Internet zone, divide the inbound subnet and the outbound subnet; The open area is divided into application subnet and isolation subnet.

4. A cloud network planning device, characterized in that: include: a partitioning unit, configured to partition the cloud network into an open zone, an Internet zone, a third-party external zone, and a private cloud external zone, wherein the open zone is connected to the Internet zone, the third-party external zone, and the private cloud external zone respectively through a peer-to-peer connection; and the Internet zone, the third-party external zone, and the private cloud external zone are connected to each other through a routing table; A first deployment unit is configured to deploy a physical subsystem carrying an application in the open area, wherein the physical subsystem is a service cluster capable of independently providing a certain application or function; A second deployment unit is configured to deploy a physical subsystem that needs to interact with a third party, a private cloud, and the Internet in the third-party external connection area, the private cloud external connection area, and the Internet area; a planning unit, configured to perform subnet planning for the open area and the Internet area; The second deployment unit includes: The filtering subunit is used to filter the external business traffic of the physical subsystems of the third-party external zone, the private cloud external zone and the Internet zone by using security group rules.

5. The device according to claim 4, characterized in that The second deployment unit includes: The planning subunit is used to plan the public network load balancing for Internet access and the network address translation gateway for Internet access for each physical subsystem in the Internet zone.

6. The device according to claim 4, characterized in that The planning unit includes: A first division sub-unit is configured to divide the Internet zone into an inbound subnet and an outbound subnet; The second division sub-unit is used to divide the open area into an application subnet and an isolation subnet.

7. An electronic device, characterized in that: include: one or more processors; a storage device having one or more programs stored thereon; When the one or more programs are executed by the one or more processors, the one or more processors are enabled to implement the method according to any one of claims 1 to 3.

8. A computer storage medium, characterized in that A computer program is stored thereon, wherein when the computer program is executed by a processor, the method according to any one of claims 1 to 3 is implemented.