Management Method and Device of Network Device, Electronic Device and Storage Medium

By introducing a preset cluster management center into the network management system, receiving the cluster status inquiry request of network equipment and returning the address of the optimal device manager, the problem that the network management system cannot effectively manage when the number of firewall devices is rapidly expanded, and timely adaptation and effective management of network equipment are achieved.

CN115988065BActive Publication Date: 2025-06-13HILLSTONE NETWORKS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211502470.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-28
Publication Date
2025-06-13
Estimated Expiration
2042-11-28

AI Technical Summary

Technical Problem

In the prior art, when the number of firewall devices is rapidly expanded, the network management system cannot effectively manage network devices, resulting in confusion in status and unbalanced load.

Method used

In the preset cluster management center of the network management system, the cluster status inquiry request of the target network device is received, and the address of the optimal device manager is queried and returned, so that the target network device can be registered with the optimal device manager and realize effective management.

Benefits of technology

Through the intervention of the preset cluster management center, the network management system can be adapted in a timely manner when the number of network devices is rapidly expanded, and effective management of network devices can be achieved, avoiding state chaos and load imbalance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115988065B_ABST
    Figure CN115988065B_ABST
Patent Text Reader

Abstract

The present invention discloses a management method and apparatus for a network device, an electronic device, and a storage medium. The management method includes: receiving a cluster status inquiry request initiated by a target network device, in response to the cluster status inquiry request, querying to obtain a target device manager, and returning the device manager address of the target device manager to the target network device indicated by the target device identifier. The target network device initiates a registration request to the target device manager based on the device manager address. The present invention solves the technical problem that the network management system in the related art cannot effectively manage network devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and in particular, to a management method and device for a network device, an electronic device, and a storage medium. Background Art

[0002] Firewall technology is a technology that helps build a relatively isolated protection barrier between the internal and external networks of a computer network by combining various software and hardware devices for security management and screening, so as to protect the security of user data and information.

[0003] The functions of firewall technology mainly lie in timely discovering and handling potential security risks, data transmission and other problems that may exist during the operation of a computer network. Among them, the handling measures include isolation and protection. At the same time, records and detections can be implemented for various operations in computer network security to ensure the security of computer network operation, guarantee the integrity of user data and information, and provide users with a better and more secure computer network usage experience.

[0004] With the development of the times, users' computer networks are becoming larger and larger, and the traditional single-machine management method has become increasingly powerless. The horizontal expansion function of the network management system has become increasingly important for the current user network. As the user network continues to expand, the network management system also needs to flexibly support the expansion of firewall devices by expanding server nodes.

[0005] Figure 1 It is a schematic diagram of an optional firewall management method in the related art. As Figure 1 shown, the management method of the firewall in the related art is often: the user creates a configuration by logging in to the UI interface (such as Figure 1 schematic Apache (WebUI)), and transfers the tcp packet (such as Figure 1 schematic tcp: 9999) to the firewall proxy module (such as Figure 1 schematic Agent) in the way of the netconf protocol, and finally realizes the configuration of the firewall (such as Figure 1 schematic Firewall Core).

[0006] After the centralized network management system appears, the firewall device establishes a tcp long connection with the network management system, configures centrally on the network management, and sends the xml file conforming to the netconf protocol to the firewall through the tcp long connection, so as to achieve the purpose of centralized configuration of a batch of firewall devices.

[0007] Figure 2 It is a schematic diagram of an optional communication architecture between a network management system and a firewall in the related art. As Figure 2As shown in the figure, the network management system includes: a device adapter (such as Figure 2 the Device Adapter shown in the figure), which establishes a connection with the firewall through a TCP long connection (such as Figure 2 the 9091 long connection shown in the figure), and sends an xml file conforming to the netconf protocol to the firewall through the egress network management. After that, the user creates a configuration through the login UI interface (such as Figure 2 the Apache (WebUI) shown in the figure), and transfers a TCP message (such as Figure 2 the tcp9999 shown in the figure) to the firewall proxy module (such as Figure 2 the Agent shown in the figure) in the netconf protocol manner, and finally realizes the configuration of the firewall (such as Figure 2 the Firewall Core shown in the figure).

[0008] Figure 3 is a schematic diagram of an optional description of the long connection between the network management system and the firewall in the related art. As Figure 3 shown in the figure, multiple TCP long connections can be established between the firewall (abbreviated as FW) and the device manager (abbreviated as DM) in the network management system, such as TCP long connections through the control channel, data channel 1, data channel 2, data channel 3, etc.

[0009] In the related art, the registration requests of the firewall are often forwarded through load balancing components such as Nginx to achieve the purpose of horizontal expansion. Figure 4 is a schematic diagram of an optional horizontal expansion solution in the related art. As Figure 4 shown in the figure, the network management system provides multiple device manager DM services. Among them, load balancers / api / gateways and other nginx connect to configuration managers (such as CM1, CM2), the configuration managers connect to device managers (such as DM1, DM2), and a reverse proxy service (such as the load balancer nginx) is set in front of the device manager DM. When the firewall devices (such as FW1, FW2, FW3, FW4) register to the network management system, the registration requests are forwarded through proxy forwarding at the TCP layer by nginx to different DMs to achieve the purpose of horizontal expansion.

[0010] However, the horizontal expansion solution in the related art has the following problems: (1) There are multiple management channels (TCP long connections) between the firewall and the network management system (such as Figure 4Among the 4 items in (), if load forwarding is performed according to the polling scheme, the connections of the same firewall will be forwarded to different DMs, resulting in a chaotic state. If load is performed in the ip / hash (i.e., IP address hashing) manner, it will cause uneven load on the firewall device due to the snat environment (a firewall environment); (2) For the proxy at the tcp layer, the requests received on the DM come from nginx, and all the firewall ips it identifies are the ip addresses of nginx, resulting in the loss of the firewall device ip.

[0011] For the above problems, no effective solution has been proposed yet. Summary of the Invention

[0012] Embodiments of the present invention provide a method and apparatus for managing network devices, an electronic device, and a storage medium, so as to at least solve the technical problem that the network management system in the related art cannot effectively manage network devices.

[0013] According to one aspect of the embodiments of the present invention, a method for managing network devices is provided, which is applied to a preset cluster management center of a network management system. The management method includes: receiving a cluster status inquiry request initiated by a target network device, where the cluster status inquiry request at least includes: a target device identifier; in response to the cluster status inquiry request, querying to obtain a target device manager, where N device managers are deployed in the network management system, and N is a positive integer greater than or equal to 1; returning the device manager address of the target device manager to the target network device indicated by the target device identifier, where the target network device initiates a registration request to the target device manager based on the device manager address.

[0014] Optionally, before receiving the cluster status inquiry request initiated by the target network device, it further includes: establishing a preset communication connection with each network device; based on the preset communication connection, managing the device status of all the network devices connected; and / or, based on the preset communication connection, listening for the cluster status inquiry request initiated by the connected network device.

[0015] Optionally, the steps of querying to obtain the target device manager in response to the cluster status query request include: sending a resource status query request to each of the device managers and receiving a resource heartbeat packet returned by the device manager, where the resource heartbeat packet at least includes resource parameters characterizing the resource status, and the resource parameters at least include: the number of managed network devices, the resource status, and the response time, and corresponding weights are set for the number of managed network devices, the resource status, and the response time respectively; calculating the resource value of each device manager based on the resource parameters and the weights corresponding to the resource parameters; sorting all the resource values and determining the device manager indicated by the maximum resource value as the target device manager.

[0016] Optionally, it further includes: in the case of adding a network device, adding the device manager and configuring resource parameters for the added device manager; updating the resource value of each device manager based on the resource parameters of the added device manager and the resource parameters of other device managers.

[0017] Optionally, it further includes: querying the health status of each device manager to obtain a query result; in the case where the query result indicates that the device manager fails, registering the network device connected to the device manager on other device managers.

[0018] Optionally, the network management system further includes: a configuration manager, and further includes: receiving a network device information request initiated by the configuration manager, where the network device information request at least includes: a device identifier; sending the device information of the network device indicated by the device identifier to the configuration manager, where the device information at least includes: the registered device manager address, and the configuration manager forwards the configuration management request for the network device to the device manager indicated by the device manager address.

[0019] Optionally, the network device includes at least one of the following: a firewall device, a network traffic security device, a network data forwarding device, a network traffic analysis device, and a network traffic management device.

[0020] According to another aspect of the embodiments of the present invention, there is also provided a management device for a network device, which is applied to a preset cluster management center of a network management system. The management device includes: a receiving unit, configured to receive a cluster status inquiry request initiated by a target network device, where the cluster status inquiry request at least includes: a target device identifier; a query unit, configured to respond to the cluster status inquiry request and query a target device manager, where N device managers are deployed in the network management system, and N is a positive integer greater than or equal to 1; a return unit, configured to return the device manager address of the target device manager to the target network device indicated by the target device identifier, where the target network device initiates a registration request to the target device manager based on the device manager address.

[0021] Optionally, the management device further includes: a first establishment module, configured to establish a preset communication connection with each network device before receiving a cluster status inquiry request initiated by a target network device; a first management module, configured to manage the device status of all the network devices connected based on the preset communication connection; a first monitoring module, configured to monitor the cluster status inquiry request initiated by the connected network devices based on the preset communication connection.

[0022] Optionally, the query unit includes: a first initiation module, configured to initiate a resource status inquiry request to each device manager and receive a resource heartbeat packet returned by the device manager, where the resource heartbeat packet at least includes resource parameters representing resource status, and the resource parameters at least include: the number of network devices managed, resource status, response time, and corresponding weights are set for the number of network devices managed, the resource status, and the response time respectively; a first calculation module, configured to calculate the resource value of each device manager based on the resource parameters and the weights corresponding to the resource parameters; a first determination module, configured to sort all the resource values and determine the device manager indicated by the maximum resource value as the target device manager.

[0023] Optionally, the management device further includes: a first configuration module, configured to add the device manager and configure resource parameters for the added device manager in the case of adding a network device; a first update module, configured to update the resource value of each device manager based on the resource parameters of the added device manager and the resource parameters of other device managers.

[0024] Optionally, the management device further includes: a first query module, configured to query the health status of each device manager to obtain a query result; a first registration module, configured to register the network device connected to the device manager to another device manager when the query result indicates that the device manager fails.

[0025] Optionally, the network management system further includes: a configuration manager, and the management device further includes: a first receiving module, configured to receive a network device information request initiated by the configuration manager, where the network device information request at least includes: a device identifier; a first sending module, configured to send the device information of the network device indicated by the device identifier to the configuration manager, where the device information at least includes: the registered device manager address, and the configuration manager forwards the configuration management request for the network device to the device manager indicated by the device manager address.

[0026] Optionally, the network device includes at least one of the following: a firewall device, a network traffic security device, a network data forwarding device, a network traffic analysis device, and a network traffic management device.

[0027] On the other hand, according to an embodiment of the present invention, there is also provided a computer-readable storage medium, where the computer-readable storage medium includes a stored computer program, and when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the above-mentioned network device management method.

[0028] On the other hand, according to an embodiment of the present invention, there is also provided an electronic device, including one or more processors and a memory, where the memory is used to store one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the above-mentioned network device management method.

[0029] In the present disclosure, a cluster status inquiry request initiated by a target network device is received, the cluster status inquiry request is responded to, a target device manager is queried, and the device manager address of the target device manager is returned to the target network device indicated by the target device identifier. The target network device initiates a registration request to the target device manager based on the device manager address. In the present disclosure, a preset cluster management center can be pre-deployed in the network management system, and then the cluster status inquiry request of the network device is received through the preset cluster management center, and the device manager address of the optimal device manager is returned to the network device, facilitating the network device to initiate a registration request to the device manager for registration. Even if the number of network devices expands rapidly, the network management system can be adapted in time to effectively manage the network devices, thereby solving the technical problem that the network management system in the related art cannot effectively manage network devices. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] The drawings described herein are used to provide a further understanding of the present invention and form a part of this application. The illustrative embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0031] Figure 1 is a schematic diagram of an optional firewall management method in the related art;

[0032] Figure 2 is a schematic diagram of an optional communication architecture between a network management system and a firewall in the related art;

[0033] Figure 3 is a schematic diagram of an optional description of a long connection between a network management system and a firewall in the related art;

[0034] Figure 4 is a schematic diagram of an optional horizontal expansion scheme in the related art;

[0035] Figure 5 is a flowchart of an optional method for managing a network device according to an embodiment of the present invention;

[0036] Figure 6 is a schematic diagram of an optional addition of a cluster management center in a network management system according to an embodiment of the present invention;

[0037] Figure 7 is a schematic diagram of an optional extended cluster state of FW4 according to an embodiment of the present invention;

[0038] Figure 8 is a schematic diagram of an optional cluster state after a failure of device manager DM1 according to an embodiment of the present invention;

[0039] Figure 9 is a schematic diagram of an optional management device for a network device according to an embodiment of the present invention;

[0040] Figure 10 is a hardware structure block diagram of an electronic device (or mobile device) for a method of managing a network device according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0041] To enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0042] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned accompanying drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order different from those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0043] To facilitate the understanding of the present invention by those skilled in the art, the following explanations are made for some terms or nouns involved in the embodiments of the present invention:

[0044] Server node: Traditional network management systems are mostly based on third-party servers, on which an operating system and application software are built, and management services are provided to the outside in the form of an all-in-one machine. The server node in the present invention refers to a single device manager in the network management system.

[0045] Netconf protocol: It is a set of mechanisms for managing network devices. Users can use this set of mechanisms to add, modify, and delete the configurations of network devices, and obtain the configuration and status information of network devices. Through the Netconf protocol, network devices can provide a complete set of standardized APIs (Application Programming Interfaces), and application programs can directly use these APIs to send and obtain configurations to and from network devices.

[0046] Apache: It is an open-source web server that can run on most computer operating systems. Due to its multi-platform and security features, it is widely used and is one of the most popular web server software. The present invention can use Apache to replace a general web application server.

[0047] CM: That is, the Configuration Management, which is a component in the network management system and is responsible for managing the firewall configuration.

[0048] DM: That is, the Device Management, which is a component in the network management system and is responsible for maintaining the online status of the firewall and data transmission work.

[0049] Nginx (engine x): It is a high-performance HTTP (Hyper Text Transfer Protocol) and reverse proxy web server. At the same time, it also provides IMAP (Internet Mail Access Protocol) / POP3 (Post Office Protocol 3) / SMTP (Simple Mail Transfer Protocol) services. The Nginx server is an intermediary between the client and the server. Through its reverse proxy function, the requests sent by the client first pass through Nginx, and then Nginx distributes the requests to the corresponding services or servers according to the corresponding rules.

[0050] Transmission Control Protocol (TCP for short): It is a connection-oriented, reliable, byte-stream-based transport layer communication protocol.

[0051] TCP long connection: It means that multiple data packets can be continuously sent on a TCP connection. During the period when the TCP connection is maintained, if no data packets are sent, both parties need to send detection packets to maintain this connection.

[0052] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties. For example, there is an interface between this system and relevant users or institutions. Before obtaining relevant information, a request for acquisition needs to be sent to the aforementioned users or institutions through the interface, and after receiving the consent information feedback from the aforementioned users or institutions, the relevant information can be obtained.

[0053] The present invention effectively combines a network management system and firewall devices, achieving the purpose of flexible expansion of network management products to effectively manage them when the number of firewalls expands. The present invention proposes a horizontal expansion cluster solution in the case of multiple TCP long connections. Through the cooperation of the network management system and firewall devices, an efficient and feasible architecture can be realized, effectively solving the problem that the number of firewall devices expands rapidly while a single-machine network management system cannot adapt.

[0054] The present invention will be described in detail below in conjunction with various embodiments.

[0055] Embodiment 1

[0056] According to an embodiment of the present invention, an embodiment of a method for managing network devices is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0057] Figure 5 is a flowchart of an optional method for managing network devices according to an embodiment of the present invention. As Figure 5 shown, the method includes the following steps:

[0058] Step S501, receiving a cluster status inquiry request initiated by a target network device, where the cluster status inquiry request at least includes: a target device identifier.

[0059] Step S502, in response to the cluster status inquiry request, querying to obtain a target device manager, where N device managers are deployed in the network management system, and N is a positive integer greater than or equal to 1.

[0060] Step S503, returning the device manager address of the target device manager to the target network device indicated by the target device identifier, where the target network device initiates a registration request to the target device manager based on the device manager address.

[0061] Through the above steps, a cluster status inquiry request initiated by a target network device can be received, the cluster status inquiry request can be responded to, the target device manager can be queried and obtained, and the device manager address of the target device manager can be returned to the target network device indicated by the target device identifier. Among them, based on the device manager address, the target network device initiates a registration request to the target device manager. In the embodiment of the present invention, a preset cluster management center can be pre-deployed in the network management system, and then the cluster status inquiry request of the network device can be received through the preset cluster management center, and the device manager address of the optimal device manager can be returned to the network device, facilitating the network device to initiate a registration request to the device manager for registration. Even if the number of network devices expands rapidly, the network management system can be adapted in a timely manner to effectively manage the network devices, thereby solving the technical problem that the network management system in the related art cannot effectively manage network devices.

[0062] The embodiments of the present invention will be described in detail below in combination with the above steps. The following steps can be applied to the preset cluster management center of the network management system.

[0063] In the embodiment of the present invention, a service arbitration function can be added to the network management system, that is, a preset cluster management center is deployed in the network management system.

[0064] Figure 6 is a schematic diagram of an optional addition of a cluster management center in the network management system according to an embodiment of the present invention. As Figure 6 shown, the network management system includes: nginx such as a load balancer / api / gateway, configuration managers (such as CM1, CM2), device managers (such as DM1, DM2), and a cluster management center. Among them, nginx such as the load balancer / api / gateway is connected to the configuration managers (such as CM1, CM2), the configuration managers are connected to the device managers (such as DM1, DM2), the cluster management center has connections with the configuration managers and the device managers, and firewall devices (such as FW1, FW2, FW3) have connections with the cluster management center and the device managers (such as DM1, DM2).

[0065] Optionally, before receiving the cluster status inquiry request initiated by the target network device, it further includes: establishing a preset communication connection with each network device; managing the device status of all connected network devices based on the preset communication connection; and / or listening for the cluster status inquiry request initiated by the connected network device based on the preset communication connection.

[0066] In an embodiment of the present invention, a preset cluster management center and each network device are pre-established with a preset communication connection (i.e., a TCP long connection). The preset cluster management center can manage the device status of all connected network devices based on the preset communication connection, and can listen for cluster status inquiry requests initiated by the connected network devices based on the preset communication connection.

[0067] In an embodiment of the present invention, the cluster management center can maintain the health status of all DM nodes (i.e., server nodes of device managers) in the network management system and the device conditions of the managed network devices.

[0068] Optionally, the network device includes at least one of the following: a firewall device, a network traffic security device, a network data forwarding device, a network traffic analysis device, and a network traffic management device.

[0069] In an embodiment of the present invention, it can be applied to the scenario of a centralized network management system managing network devices. The network devices include, but are not limited to: firewall devices, network traffic security devices, network data forwarding devices, network traffic analysis devices, network traffic management devices, etc.

[0070] Step S501: Receive a cluster status inquiry request initiated by a target network device, where the cluster status inquiry request includes at least: a target device identifier.

[0071] In an embodiment of the present invention, before the network device initiates a registration request, it can first initiate a cluster status inquiry request. The preset cluster management center can receive the cluster status inquiry request initiated by the target network device (used to inquire which device manager is the optimal device manager currently for the preset cluster management center). The cluster status inquiry request includes at least: a target device identifier, etc.

[0072] Step S502: Respond to the cluster status inquiry request and query to obtain a target device manager, where N device managers are deployed in the network management system, and N is a positive integer greater than or equal to 1.

[0073] Optionally, the step of responding to the cluster status inquiry request and querying to obtain a target device manager includes: sending a resource status inquiry request to each device manager and receiving a resource heartbeat packet returned by the device manager, where the resource heartbeat packet contains at least resource parameters representing the resource status. The resource parameters include at least: the number of managed network devices, the resource status, and the response time. The number of managed network devices, the resource status, and the response time are respectively set with corresponding weights; calculating the resource value of each device manager based on the resource parameters and the weights corresponding to the resource parameters; sorting all the resource values and determining the device manager indicated by the maximum resource value as the target device manager.

[0074] In an embodiment of the present invention, a preset cluster management center may respond to a cluster status query request to query and obtain a target device manager (i.e., the optimal device manager). Specifically, the cluster management center may initiate a resource status query request to each device manager in the network management system cluster and receive a resource heartbeat packet returned by the device manager. The resource heartbeat packet at least includes resource parameters representing the resource status. The resource parameters at least include: the number of network devices managed (i.e., the number of devices managed by the server node of the current device manager), the resource status (i.e., the server resource status of the server node of the current device manager, for example, the memory status), and the response time (i.e., the server response time of the server node of the current device manager). Then, corresponding weights may be set for the number of network devices managed, the resource status, and the response time respectively. After that, the resource value of each device manager may be calculated according to the resource parameters and the weights corresponding to the resource parameters, and then all the resource values may be sorted, and the device manager indicated by the maximum resource value may be determined as the target device manager (i.e., the optimal device manager).

[0075] In an embodiment of the present invention, N device managers are deployed in the network management system, where N is a positive integer greater than or equal to 1.

[0076] Optionally, in the case of adding network devices, a device manager is added, and resource parameters are configured for the added device manager; based on the resource parameters of the added device manager and the resource parameters of other device managers, the resource value of each device manager is updated.

[0077] In an embodiment of the present invention, when expanding network device nodes, the network management system may flexibly add server node data (i.e., configure resource parameters for the device manager) and automatically perform server node allocation. Specifically, if network devices are added, a device manager may be added, and resource parameters may be configured for the added device manager. After that, according to the resource parameters of the added device manager and the resource parameters of other device managers, the resource value of each device manager is updated, and based on the updated resource value, the optimal device manager is allocated to the newly added network device.

[0078] Figure 7 It is a schematic diagram of an optionally extended cluster status of FW4 according to an embodiment of the present invention, as Figure 7As shown in the figure, the network management system includes: nginx such as a load balancer / api gateway, configuration managers (such as CM1, CM2), device managers (such as DM1, DM2, DM3), and a cluster management center. Among them, nginx such as the load balancer / api gateway is connected to the configuration managers (such as CM1, CM2), the configuration managers are connected to the device managers (such as DM1, DM2, DM3), the cluster management center has connections with the configuration managers and the device managers, and firewall devices (such as FW1, FW2, FW3, FW4) have connections with the cluster management center and the device managers (such as DM1, DM2, DM3). When the firewall device is extended with FW4, the network management system can flexibly extend the device manager DM3, which not only achieves the purpose of horizontal expansion of the network management system but also does not require changes to the original device manager (DM) architecture, ensuring the sustainable development of the product.

[0079] Optionally, query the health status of each device manager to obtain a query result; in the case where the query result indicates that the device manager has a fault, register the network device connected to the device manager on other device managers.

[0080] In the embodiment of the present invention, the preset cluster management center can regularly query the health status of each device manager to obtain a query result. If the query result indicates that the device manager has a fault, register the network device connected to the device manager on other device managers (that is, when a server node fails, the cluster will automatically register the device connected to the server node on a healthy server node).

[0081] Figure 8 is a schematic diagram of the cluster state after a fault of an optional device manager DM1 according to an embodiment of the present invention, as Figure 8 As shown in the figure, the network management system includes: nginx such as a load balancer / api gateway, configuration managers (such as CM1, CM2), device managers (such as DM1, DM2, DM3), and a cluster management center. Among them, nginx such as the load balancer / api gateway is connected to the configuration managers (such as CM1, CM2), the configuration managers are connected to the device managers (such as DM1, DM2, DM3), the cluster management center has connections with the configuration managers and the device managers, and firewall devices (such as FW1, FW2, FW3, FW4) have connections with the cluster management center and the device managers (such as DM1, DM2, DM3). When the server node of DM1 fails, FW1 and FW2 connected to DM1 can be registered on a healthy server node.

[0082] Step S503: Return the device manager address of the target device manager to the target network device indicated by the target device identifier. The target network device initiates a registration request to the target device manager based on the device manager address.

[0083] In an embodiment of the present invention, after the preset cluster management center returns the device manager address of the target device manager to the target network device indicated by the target device identifier, the target network device can initiate a registration request to the target device manager based on the device manager address to achieve registration in the network management system, facilitating inclusion in the management of the network management system.

[0084] Optionally, the network management system further includes: a configuration manager, which further includes: receiving a network device information request initiated by the configuration manager, where the network device information request at least includes: a device identifier; sending the device information of the network device indicated by the device identifier to the configuration manager, where the device information at least includes: the registered device manager address, and the configuration manager forwards the configuration management request for the network device to the device manager indicated by the device manager address.

[0085] In an embodiment of the present invention, when an upper-layer application (such as a configuration manager) in the network management system configures a network device, it can first obtain the information of the corresponding device from the cluster management center. For example, if FW1 is registered on DM2, then the configuration management request for FW1 will be directly forwarded to DM2 to complete. Specifically, the preset cluster management center can receive the network device information request initiated by the configuration manager (the network device information request at least includes: a device identifier), and then send the device information of the network device indicated by the device identifier to the configuration manager. The device information at least includes: the registered device manager address, etc. After that, the configuration manager can forward the configuration management request for the network device to the device manager indicated by the device manager address, and the device manager completes the configuration of the network device.

[0086] Thus, the purpose of expanding the management capability level of the network management system is achieved.

[0087] In an embodiment of the present invention, in the case where there are multiple long connections between the network management system and the network device, it can be ensured that multiple connection requests of the same network device are forwarded to the same server node, achieving the purpose of horizontal expansion of the network management system without changing the original device manager architecture, ensuring the sustainable development of the product. Moreover, adding a cluster management center to the network management system can also control the registration behavior of a large number of network devices, effectively avoiding the network management system from crashing due to too many requests and being unable to process them in time.

[0088] The following is a detailed description in combination with another embodiment.

[0089] Embodiment 2

[0090] A management device for a network device provided in this embodiment includes multiple implementation units, and each implementation unit corresponds to each implementation step in the first embodiment above.

[0091] Figure 9 It is a schematic diagram of an optional management device for a network device according to an embodiment of the present invention. As Figure 9 shown, the management device may include: a receiving unit 90, a query unit 91, and a returning unit 92. Among them,

[0092] The receiving unit 90 is used to receive a cluster status inquiry request initiated by a target network device. Among them, the cluster status inquiry request at least includes: a target device identifier;

[0093] The query unit 91 is used to respond to the cluster status inquiry request and query to obtain a target device manager. Among them, N device managers are deployed in the network management system, and N is a positive integer greater than or equal to 1;

[0094] The returning unit 92 is used to return the device manager address of the target device manager to the target network device indicated by the target device identifier. Among them, the target network device initiates a registration request to the target device manager based on the device manager address.

[0095] The above management device can receive a cluster status inquiry request initiated by a target network device through the receiving unit 90, respond to the cluster status inquiry request through the query unit 91 to query and obtain a target device manager, and return the device manager address of the target device manager to the target network device indicated by the target device identifier through the returning unit 92. Among them, the target network device initiates a registration request to the target device manager based on the device manager address. In the embodiment of the present invention, a preset cluster management center can be pre-deployed in the network management system, and then the preset cluster management center receives the cluster status inquiry request of the network device and returns the device manager address of the optimal device manager to the network device, facilitating the network device to initiate a registration request to the device manager for registration. Even if the number of network devices expands rapidly, the network management system can be adapted in a timely manner to achieve effective management of the network devices, thereby solving the technical problem that the network management system in the related art cannot effectively manage network devices.

[0096] Optionally, the management device further includes: a first establishment module, configured to establish a preset communication connection with each network device before receiving a cluster status inquiry request initiated by the target network device; a first management module, configured to manage the device status of all connected network devices based on the preset communication connection; a first listening module, configured to listen for a cluster status inquiry request initiated by the connected network device based on the preset communication connection.

[0097] In an embodiment of the present invention, a service arbitration function can be added to the network management system, that is, a preset cluster management center is deployed in the network management system.

[0098] In an embodiment of the present invention, a preset communication connection (i.e., a TCP long connection) is pre-established between the preset cluster management center and each network device. The preset cluster management center can manage the device status of all connected network devices based on the preset communication connection, and can listen for cluster status inquiry requests initiated by the connected network devices based on the preset communication connection.

[0099] In an embodiment of the present invention, the cluster management center can maintain the health status of all DM nodes (i.e., server nodes of the device manager) in the network management system and the device conditions of the managed network devices.

[0100] Optionally, the query unit includes: a first initiation module, configured to initiate a resource status inquiry request to each device manager and receive a resource heartbeat packet returned by the device manager, where the resource heartbeat packet at least includes resource parameters representing the resource status, and the resource parameters at least include: the number of managed network devices, the resource status, the response time, and corresponding weights are set for the number of managed network devices, the resource status, and the response time respectively; a first calculation module, configured to calculate the resource value of each device manager based on the resource parameters and the weights corresponding to the resource parameters; a first determination module, configured to sort all the resource values and determine the device manager indicated by the maximum resource value as the target device manager.

[0101] In an embodiment of the present invention, the preset cluster management center can respond to the cluster status inquiry request to obtain the target device manager (i.e., the optimal device manager). Specifically, the cluster management center can initiate a resource status inquiry request to each device manager in the network management system cluster and receive a resource heartbeat packet returned by the device manager. The resource heartbeat packet at least includes resource parameters representing the resource status, and the resource parameters at least include: the number of managed network devices (i.e., the number of devices managed by the server node of the current device manager), the resource status (i.e., the server resource condition of the server node of the current device manager, for example, the memory status), the response time (i.e., the server response time of the server node of the current device manager). Then, corresponding weights can be set for the number of managed network devices, the resource status, and the response time respectively. After that, the resource value of each device manager can be calculated according to the resource parameters and the weights corresponding to the resource parameters, and then all the resource values are sorted, and the device manager indicated by the maximum resource value is determined as the target device manager (i.e., the optimal device manager).

[0102] Optionally, the management device further includes: a first configuration module, configured to add a device manager when adding a network device, and configure resource parameters for the added device manager; a first update module, configured to update the resource value of each device manager based on the resource parameters of the added device manager and the resource parameters of other device managers.

[0103] In the embodiment of the present invention, when expanding network device nodes, the network management system can flexibly add server node data (i.e., configure resource parameters for the device manager), and automatically allocate server nodes. Specifically, if a network device is added, a device manager can be added, and resource parameters can be configured for the added device manager. Then, based on the resource parameters of the added device manager and the resource parameters of other device managers, the resource value of each device manager is updated. According to the updated resource value, the optimal device manager is allocated to the newly added network device.

[0104] Optionally, the management device further includes: a first query module, configured to query the health status of each device manager to obtain a query result; a first registration module, configured to register the network device connected to the device manager to other device managers when the query result indicates that the device manager fails.

[0105] In the embodiment of the present invention, the preset cluster management center can regularly query the health status of each device manager to obtain a query result. If the query result indicates that the device manager fails, the network device connected to the device manager is registered to other device managers (i.e., when a server node fails, the cluster will automatically register the device connected to the server node to a healthy server node).

[0106] Optionally, the network management system further includes: a configuration manager, and the management device further includes: a first receiving module, configured to receive a network device information request initiated by the configuration manager, where the network device information request at least includes: a device identifier; a first sending module, configured to send the device information of the network device indicated by the device identifier to the configuration manager, where the device information at least includes: the registered device manager address, and the configuration manager forwards the configuration management request for the network device to the device manager indicated by the device manager address.

[0107] In an embodiment of the present invention, when an upper-layer application (such as a configuration manager) in a network management system configures a network device, it can first obtain information of the corresponding device from the cluster management center. For example, if FW1 is registered on DM2, then the configuration management request for FW1 will be directly forwarded to DM2 to complete. Specifically, the preset cluster management center can receive a network device information request initiated by the configuration manager (the network device information request at least includes: device identifier), and then send the device information of the network device indicated by the device identifier to the configuration manager. The device information at least includes: the registered device manager address, etc. After that, the configuration manager can forward the configuration management request for the network device to the device manager indicated by the device manager address, and the device manager will complete the configuration of the network device.

[0108] Optionally, the network device includes at least one of the following: firewall device, network traffic security device, network data forwarding device, network traffic analysis device, network traffic management device.

[0109] In an embodiment of the present invention, it can be applied to the scenario of a centralized network management system managing network devices. The network devices include, but are not limited to: firewall devices, network traffic security devices, network data forwarding devices, network traffic analysis devices, network traffic management devices, etc.

[0110] The above management device may further include a processor and a memory. The above receiving unit 90, querying unit 91, returning unit 92, etc. are all stored in the memory as program units, and the processor executes the above program units stored in the memory to implement corresponding functions.

[0111] The above processor includes a kernel, and the kernel retrieves the corresponding program unit from the memory. One or more kernels can be set, and by adjusting the kernel parameters, the device manager address of the target device manager is returned to the target network device indicated by the target device identifier.

[0112] The above memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one storage chip.

[0113] The present application also provides a computer program product, which, when executed on a data processing device, is adapted to execute a program initialized with the following method steps: receiving a cluster status query request initiated by a target network device, responding to the cluster status query request, querying to obtain a target device manager, and returning the device manager address of the target device manager to the target network device indicated by the target device identifier, wherein the target network device initiates a registration request to the target device manager based on the device manager address.

[0114] According to another aspect of the embodiments of the present invention, there is also provided a computer-readable storage medium, which includes a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the above-mentioned management method of the network device.

[0115] According to another aspect of the embodiments of the present invention, there is also provided an electronic device, which includes one or more processors and a memory. The memory is used to store one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the above-mentioned management method of the network device.

[0116] Figure 10 is a hardware structure block diagram of an electronic device (or mobile device) for a management method of a network device according to an embodiment of the present invention. As Figure 10 shown, the electronic device may include one or more (shown as 1002a, 1002b,..., 1002n in the figure) processors 1002 (the processor 1002 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA), and a memory 1004 for storing data. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the I / O interface), a network interface, a keyboard, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 10 the structure shown is only schematic and does not limit the structure of the above-mentioned electronic device. For example, the electronic device may further include more or fewer components than Figure 10 shown, or have a different configuration from Figure 10 shown.

[0117] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.

[0118] In the above embodiments of the present invention, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0119] In several embodiments provided in the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of the units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings or direct couplings or communication connections shown or discussed with each other can be through some interfaces. The indirect couplings or communication connections of units or modules can be in electrical or other forms.

[0120] The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0121] In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.

[0122] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present invention. The foregoing storage medium includes: various media such as USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs that can store program codes.

[0123] The above is only the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A management method for a network device, characterized in that, it is applied to a preset cluster management center of a network management system, and the management method includes: Receiving a cluster status inquiry request initiated by a target network device, where the cluster status inquiry request at least includes: a target device identifier; Responding to the cluster status inquiry request, querying to obtain a target device manager, where N device managers are deployed in the network management system, and N is a positive integer greater than or equal to 1; sending a resource status inquiry request to each device manager and receiving a resource heartbeat packet returned by the device manager, where the resource heartbeat packet at least contains resource parameters representing the resource status, and the resource parameters at least include: the number of network devices managed, the resource status, and the response time, and corresponding weights are set for the number of network devices managed, the resource status, and the response time respectively; calculating the resource value of each device manager based on the resource parameters and the weights corresponding to the resource parameters; sorting all the resource values and determining the device manager indicated by the maximum resource value as the target device manager; Returning the device manager address of the target device manager to the target network device indicated by the target device identifier, where the target network device initiates a registration request to the target device manager based on the device manager address.

2. The management method according to claim 1, characterized in that, before receiving the cluster status inquiry request initiated by the target network device, it further includes: Establishing a preset communication connection with each network device; Based on the preset communication connection, managing the device status of all the network devices connected; and / or, Based on the preset communication connection, listening for the cluster status inquiry request initiated by the connected network device.

3. The management method according to claim 1, characterized in that, it further includes: In the case of adding a network device, adding the device manager and configuring resource parameters for the added device manager; Updating the resource value of each device manager based on the resource parameters of the added device manager and the resource parameters of other device managers.

4. The management method according to claim 1, characterized in that, it further includes: Querying the health status of each device manager to obtain a query result; In the case where the query result indicates that the device manager fails, registering the network device connected to the device manager to other device managers.

5. The management method according to claim 1, characterized in that, the network management system further includes: a configuration manager, and further includes: Receiving a network device information request initiated by the configuration manager, where the network device information request at least includes: a device identifier; Sending the device information of the network device indicated by the device identifier to the configuration manager, where the device information at least includes: the registered device manager address, and the configuration manager forwards the configuration management request for the network device to the device manager indicated by the device manager address.

6. The management method according to claim 2, wherein, the network device includes at least one of the following: a firewall device, a network traffic security device, a network data forwarding device, a network traffic analysis device, and a network traffic management device.

7. A management apparatus for a network device, wherein, it is applied to a preset cluster management center of a network management system, and the management apparatus includes: a receiving unit, configured to receive a cluster status inquiry request initiated by a target network device, where the cluster status inquiry request at least includes: a target device identifier; a query unit, configured to respond to the cluster status inquiry request and query to obtain a target device manager, where N device managers are deployed in the network management system, and N is a positive integer greater than or equal to 1; a returning unit, configured to return the device manager address of the target device manager to the target network device indicated by the target device identifier, where the target network device initiates a registration request to the target device manager based on the device manager address; the query unit includes: a first initiating module, configured to initiate a resource status inquiry request to each of the device managers and receive a resource heartbeat packet returned by the device manager, where the resource heartbeat packet at least includes resource parameters representing a resource status, and the resource parameters at least include: the number of network devices managed, a resource status, and a response time, and corresponding weights are set for the number of network devices managed, the resource status, and the response time respectively; a first calculating module, configured to calculate a resource value of each of the device managers based on the resource parameters and the weights corresponding to the resource parameters; a first determining module, configured to sort all the resource values and determine the device manager indicated by the maximum resource value as the target device manager.

8. A computer-readable storage medium, wherein, the computer-readable storage medium includes a stored computer program, wherein when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the network device management method according to any one of claims 1 to 6.

9. An electronic device, wherein, it includes one or more processors and a memory, and the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the network device management method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Concentrated network equipment managing method

    CN1441569A

  • Network equipment management method and network management system

    CN1744521A