Method, device and equipment for updating cloud platform firewall instance capacity and medium

By generating new virtual machines, migrating data, and switching traffic within firewall instances, the data security issues during firewall instance scaling up or down are resolved, achieving secure capacity updates and business continuity.

CN116032572BActive Publication Date: 2026-07-14BEIJING QINGYUN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211622426.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-16
Publication Date
2026-07-14
Estimated Expiration
2042-12-16

AI Technical Summary

Technical Problem

Existing technologies require closing traffic paths during firewall instance scaling up or down, which compromises data security and impacts the security of production operations.

Method used

By generating a new firewall instance virtual machine, a configuration lock is invoked to lock the data of the original firewall instance virtual machine, the data is imported into the new firewall instance virtual machine, traffic is diverted through the virtual gateway, and the original firewall instance virtual machine is shut down after the lock is released.

Benefits of technology

It enables secure updates to firewall instance capacity without impacting existing production operations, ensuring data security and business continuity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116032572B_ABST
    Figure CN116032572B_ABST
Patent Text Reader

Abstract

The method comprises: generating a new firewall instance virtual machine according to new system resource specification information; obtaining an original firewall instance virtual machine to be updated; calling a configuration lock to add the configuration lock to data of the original firewall instance virtual machine; obtaining the data of the original firewall instance virtual machine, importing the data into the new firewall instance virtual machine, and leading traffic to the new firewall instance virtual machine through a virtual gateway; releasing the configuration lock, and closing and recycling the original firewall instance virtual machine. In the method, the data of the original firewall instance virtual machine is obtained, and the data is imported into the new firewall instance virtual machine, so that the update of the firewall instance capacity can be implemented in the security protection of the firewall without closing the original firewall instance virtual machine and affecting existing production services.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of computer technology, and in particular to a method, apparatus, device, and medium for updating the capacity of a cloud platform firewall instance. Background Technology

[0002] With the continuous development of information technology, data security has become increasingly important. Firewall technology is a technology that uses various software and hardware devices for security management and screening to help computer networks build a relatively isolated protective barrier between their internal and external networks, thereby protecting the security of user data and information.

[0003] Currently, firewall instances typically need to be scaled up or down to update their processing capacity. Existing techniques for scaling up or down firewall instances involve: first, disconnecting the firewall instance's traffic routing path to allow direct communication between the internal and external networks; then, shutting down the firewall instance and directly scaling it up or down; finally, restarting the firewall instance and reconnecting its traffic routing path to restore its ability to protect data security.

[0004] Although existing technologies enable direct communication between internal and external networks (internet requests communicate directly with production services), scaling up or down operations take a long time. During this period, production services lack firewall security protection, and data security cannot be guaranteed. Summary of the Invention

[0005] This disclosure provides a method, apparatus, device, and medium for updating the capacity of a cloud platform firewall instance, which can realize the updating of firewall instance capacity in the security protection of the firewall.

[0006] In a first aspect, embodiments of this disclosure provide a method for updating the capacity of a cloud platform firewall instance, comprising: generating a new firewall instance virtual machine based on new system resource specification information; obtaining the original firewall instance virtual machine to be updated; wherein the original firewall instance virtual machine is generated based on the original system resource specification information, and the capacity of the original firewall instance virtual machine and the new firewall instance virtual machine are different; invoking a configuration lock to add the configuration lock to the data of the original firewall instance virtual machine; obtaining the data of the original firewall instance virtual machine, importing the data into the new firewall instance virtual machine, and directing traffic to the new firewall instance virtual machine through a virtual gateway; releasing the configuration lock, and shutting down and reclaiming the original firewall instance virtual machine.

[0007] Secondly, this disclosure also provides a device for updating the capacity of a cloud platform firewall instance, comprising: a new firewall instance virtual machine generation module, used to generate a new firewall instance virtual machine according to new system resource specification information; an original firewall instance virtual machine acquisition module, used to acquire the original firewall instance virtual machine to be updated; wherein the original firewall instance virtual machine is generated based on the original system resource specification information, and the capacity of the original firewall instance virtual machine and the new firewall instance virtual machine are different; a configuration lock invocation module, used to invoke a configuration lock and add the configuration lock to the data of the original firewall instance virtual machine; an import module, used to acquire the data of the original firewall instance virtual machine, import the data into the new firewall instance virtual machine, and guide traffic to the new firewall instance virtual machine through a virtual gateway; and a recycling module, used to release the configuration lock, close and recycle the original firewall instance virtual machine.

[0008] Thirdly, embodiments of this disclosure also provide an electronic device, the electronic device comprising:

[0009] One or more processors;

[0010] Storage device for storing one or more programs.

[0011] When the one or more programs are executed by the one or more processors, the one or more processors implement the cloud platform firewall instance capacity update method as described in the embodiments of this disclosure.

[0012] Fourthly, embodiments of this disclosure also provide a storage medium containing computer-executable instructions, which, when executed by a computer processor, are used to perform the cloud platform firewall instance capacity update method as described in embodiments of this disclosure.

[0013] The technical solution of this disclosure involves generating a new firewall instance virtual machine based on new system resource specification information; obtaining the original firewall instance virtual machine to be updated; wherein the original firewall instance virtual machine is generated based on the original system resource specification information, and the original firewall instance virtual machine and the new firewall instance virtual machine have different capacities; invoking a configuration lock to add the configuration lock to the data of the original firewall instance virtual machine; obtaining the data of the original firewall instance virtual machine, importing the data into the new firewall instance virtual machine, and directing traffic to the new firewall instance virtual machine through a virtual gateway; releasing the configuration lock, and shutting down and reclaiming the original firewall instance virtual machine. This disclosure, without shutting down the original firewall instance virtual machine or affecting existing production operations, achieves firewall instance capacity updates (vertical scaling up or down of firewall instances) within firewall security protection by obtaining the data of the original firewall instance virtual machine, importing the data into the new firewall instance virtual machine, and directing traffic to the new firewall instance virtual machine through a virtual gateway. Attached Figure Description

[0014] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale.

[0015] Figure 1 This is a schematic flowchart illustrating a method for updating the capacity of a cloud platform firewall instance, as provided in an embodiment of this disclosure.

[0016] Figure 2 This is a schematic diagram of another method for updating the capacity of a cloud platform firewall instance provided in this embodiment;

[0017] Figure 3 A schematic diagram of a method for updating the capacity of a cloud platform firewall instance provided in an embodiment of the present invention;

[0018] Figure 4 A schematic diagram of a method for updating the capacity of a cloud platform firewall instance provided in an embodiment of the present invention;

[0019] Figure 5 A schematic diagram of a cloud platform firewall instance capacity update device provided in an embodiment of this disclosure;

[0020] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this disclosure. Detailed Implementation

[0021] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0022] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.

[0023] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". It is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and related provisions.

[0024] Figure 1 This is a schematic flowchart illustrating a method for updating the capacity of a cloud platform firewall instance according to an embodiment of this disclosure. This embodiment is applicable to situations involving expanding or shrinking the capacity of a cloud platform firewall instance. The method can be executed by a cloud platform firewall instance capacity updating device, which can be implemented in software and / or hardware, optionally through an electronic device, such as a mobile terminal, PC, or server. Figure 1 As shown, the method includes:

[0025] S110. Generate a new firewall instance virtual machine based on the new system resource specification information.

[0026] It should be noted that a firewall instance can be understood as a virtual host with a firewall engine (software) installed. Virtual hosts are also called virtual machines or cloud hosts.

[0027] The system resource specifications may include the size of the central processing unit (CPU), memory, hard disk, etc., for example, an 8-core CPU and 16GB of memory. This embodiment does not impose any limitations on this. In this embodiment, a new firewall instance virtual machine can be created based on the new system resource specifications. After the new firewall instance virtual machine is successfully created, its operating system is started.

[0028] S120. Obtain the original firewall instance virtual machine to be updated.

[0029] The original firewall instance virtual machine was generated based on the original system resource specifications, and the capacity of the original firewall instance virtual machine differs from that of the new firewall instance virtual machine. "To be updated" can be understood as "to be expanded" or "to be scaled down".

[0030] It should be noted that the original system resource specifications differ from the new system resource specifications. If the capacity of the original firewall instance virtual machine is expanded (i.e., increased), the original system resource specifications might be 2 CPU cores and 2GB of memory, while the new system resource specifications might be 4 CPU cores and 4GB of memory. Conversely, if the capacity of the original firewall instance virtual machine is reduced (i.e., decreased), the original system resource specifications might be 4 CPU cores and 4GB of memory, while the new system resource specifications might be 2 CPU cores and 2GB of memory.

[0031] Optionally, after obtaining the original firewall instance virtual machine to be updated, the process also includes: adding the new firewall instance virtual machine to the same network as the original firewall instance virtual machine.

[0032] It should be noted that to add a new firewall instance virtual machine to the same network as the original firewall instance virtual machine, it can be done in the following ways: First, specify the network as the same as the original firewall instance virtual machine during the creation of the new firewall instance virtual machine. Alternatively, it can be added to the same network as the original firewall instance virtual machine after the new firewall instance virtual machine is created. Here, "same network" can be understood as being on the same internal network or the same subnet.

[0033] S130. Invoke the configuration lock to add a configuration lock to the data of the original firewall instance virtual machine.

[0034] In this embodiment, a configuration lock can be understood as a lock that locks the data of the original firewall instance virtual machine. This embodiment adds a configuration lock to the data of the original firewall instance virtual machine to ensure that the data remains unchanged during the import process into the new firewall instance virtual machine, thus preventing changes to the data of the original firewall instance virtual machine (see attached image). This embodiment does not limit the specific techniques used to add and release the configuration lock, as long as it ensures that the data of the original firewall instance virtual machine remains unchanged during the import process into the new firewall instance virtual machine.

[0035] S140. Obtain the data from the original firewall instance virtual machine, import the data into the new firewall instance virtual machine, and redirect traffic to the new firewall instance virtual machine through the virtual gateway.

[0036] The data in the original firewall instance virtual machine includes business configuration data.

[0037] In this embodiment, the data of the original firewall instance virtual machine can be imported into the new firewall instance virtual machine by "exporting the service configuration data of the original firewall instance virtual machine" and "backing up the data of the original firewall instance virtual machine", and traffic can be directed to the new firewall instance virtual machine through the virtual gateway to update the firewall instance capacity.

[0038] Optionally, the method for obtaining data from the original firewall instance virtual machine and importing the data into the new firewall instance virtual machine can be: exporting the service configuration data from the original firewall instance virtual machine; or importing the service configuration data into the new firewall instance virtual machine according to the service interface.

[0039] The business configuration data can be understood as the business configuration data related to the production business of the original firewall instance virtual machine. The business interface can be the API (Application Programming Interface) provided by the new firewall instance virtual machine.

[0040] In this embodiment, by exporting the service configuration data of the original firewall instance virtual machine and importing the service configuration data into the new firewall instance virtual machine according to the service interface, the online update of the firewall instance capacity can be achieved without shutting down the original firewall instance virtual machine, thereby ensuring the security of service-related data.

[0041] Optionally, the method for obtaining data from the original firewall instance virtual machine and importing the data into the new firewall instance virtual machine can be: backing up the data from the original firewall instance virtual machine; or copying the backed-up data to the new firewall instance virtual machine.

[0042] The backup data for the original firewall instance virtual machine can be understood as all the data in the original firewall instance virtual machine, that is, it can be a backup of the hard disk data of the original firewall instance virtual machine.

[0043] In this embodiment, by backing up the data of the original firewall instance virtual machine, copying the backed-up data to the new firewall instance virtual machine, and replacing the original data in the new firewall instance virtual machine with the data of the original firewall instance virtual machine (backup data), the online update of the firewall instance capacity can be achieved without shutting down the original firewall instance virtual machine, thereby ensuring the security of business-related data.

[0044] Optionally, after obtaining the data from the original firewall instance virtual machine and importing the data into the new firewall instance virtual machine, the process also includes: diagnosing the network of the new firewall instance virtual machine using the PING command and / or ARP command to obtain feedback information; and verifying the correctness of the network of the new firewall instance virtual machine based on the feedback information.

[0045] In this embodiment, after importing data into the new firewall instance virtual machine, the network of the new firewall instance virtual machine can be diagnosed using the Packet Internet Groper (ping command) and / or Address Resolution Protocol (ARP) commands. If a response message, i.e., feedback information, is received, the network of the new firewall instance virtual machine can be considered to have been verified correctly. This embodiment does not limit the specific feedback information; as long as feedback information is received, it is acceptable.

[0046] Optionally, after obtaining the data from the original firewall instance virtual machine and importing the data into the new firewall instance virtual machine, the process further includes: comparing the data before importing into the new firewall instance virtual machine with the data after importing into the new firewall instance virtual machine; if the data before importing into the new firewall instance virtual machine is consistent with the data after importing into the new firewall instance virtual machine, then the data verification of the new firewall instance virtual machine is correct; if the data before importing into the new firewall instance virtual machine is inconsistent with the data after importing into the new firewall instance virtual machine, then the data verification of the new firewall instance virtual machine fails.

[0047] In this embodiment, after importing data into the new firewall instance virtual machine, the data imported into the new firewall instance virtual machine can be verified before traffic is redirected to it via the virtual gateway. It should be noted that if the data from the original firewall instance virtual machine is backed up and then imported into the new firewall instance virtual machine, verification of the backed-up data is not required. However, if the service configuration data from the original firewall instance virtual machine is exported and then imported into the new firewall instance virtual machine, verification of the service configuration data in the new firewall instance virtual machine is possible.

[0048] In this embodiment, the data before and after importing the new firewall instance virtual machine is compared (e.g., comparing the exported service configuration data of the original firewall instance virtual machine with the service configuration data after importing into the new firewall instance virtual machine). If the data before and after importing the new firewall instance virtual machine are consistent, the new firewall instance virtual machine data verification is successful; if the data before and after importing the new firewall instance virtual machine are inconsistent, the new firewall instance virtual machine data verification fails. This embodiment ensures the correctness of the imported data by verifying the correctness of the new firewall instance virtual machine data, thereby ensuring the correctness of the new firewall instance virtual machine capacity update.

[0049] Optionally, the method for directing traffic to the new firewall instance virtual machine via the virtual gateway can be: configuring routing information through the virtual gateway; disconnecting the traffic directing connection between the virtual gateway and the original firewall instance virtual machine through the virtual gateway; and establishing a traffic directing connection with the new firewall instance virtual machine based on the routing information to direct traffic to the new firewall instance virtual machine.

[0050] The routing information includes the address information of the new firewall instance virtual machine, and may also include routing policies. The address information of the new firewall instance virtual machine can be understood as the IP address information of the new firewall instance virtual machine.

[0051] In this embodiment, after importing the data from the original firewall instance virtual machine into the new firewall instance virtual machine, and after verifying the correctness of the network of the new firewall instance virtual machine and the correctness of the data imported into the new firewall instance virtual machine, routing information is configured through the virtual gateway. The traffic pulling connection between the virtual gateway and the original firewall instance virtual machine is disconnected through the virtual gateway. According to the routing information, the virtual gateway establishes a traffic pulling connection with the new firewall instance virtual machine to pull traffic to the new firewall instance virtual machine, thereby achieving a smooth traffic switching.

[0052] S150. Release the configuration lock, shut down and reclaim the original firewall instance virtual machine.

[0053] In this embodiment, after releasing the configuration lock, the original firewall instance virtual machine is shut down, and the original firewall instance virtual machine is asynchronously processed through a unified garbage collection mechanism to reclaim the original firewall instance virtual machine.

[0054] The technical solution of this disclosure involves generating a new firewall instance virtual machine based on new system resource specifications; obtaining the original firewall instance virtual machine to be updated; wherein the original firewall instance virtual machine is generated based on the original system resource specifications, and the original firewall instance virtual machine and the new firewall instance virtual machine have different capacities; invoking a configuration lock to add a configuration lock to the data of the original firewall instance virtual machine; obtaining the data of the original firewall instance virtual machine, importing the data into the new firewall instance virtual machine, and directing traffic to the new firewall instance virtual machine through a virtual gateway; releasing the configuration lock, shutting down and reclaiming the original firewall instance virtual machine. This disclosure, without shutting down the original firewall instance virtual machine or affecting existing production operations, achieves firewall instance capacity updates (vertical scaling up or down of firewall instances) within firewall security protection by obtaining the data of the original firewall instance virtual machine, importing the data into the new firewall instance virtual machine, and directing traffic to the new firewall instance virtual machine through a virtual gateway.

[0055] Figure 2This embodiment provides a schematic diagram of another method for updating the capacity of a cloud platform firewall instance. The specific steps are as follows:

[0056] S201. Create a new firewall instance virtual machine based on the new system resource specification information, and add the new firewall instance virtual machine to the same network as the original firewall instance virtual machine.

[0057] In this embodiment, the networks of the new firewall instance virtual machine and the original firewall instance virtual machine can be different, but their attributes are the same. For example, the first network card is the management network, and the second network card is the service network.

[0058] S202. Wait for the new firewall instance virtual machine to be created successfully. Determine whether the new firewall instance virtual machine has been created successfully. If the new firewall instance virtual machine has been created successfully, execute S203; otherwise, execute S210.

[0059] S203. Wait for the new firewall instance virtual machine operating system to start. Determine whether the new firewall instance virtual machine operating system has started successfully. If the new firewall instance virtual machine operating system has started successfully, execute S204; otherwise, execute S210.

[0060] S204. Invoke the configuration lock, add a configuration lock to the data of the original firewall instance virtual machine, and determine whether the configuration lock is successfully locked. If the lock is successful, execute S205; otherwise, execute S210.

[0061] S205. Obtain the data from the original firewall instance virtual machine and import the data into the new firewall instance virtual machine.

[0062] S206. Verify the correctness of the new firewall instance virtual machine network and the correctness of the new firewall instance virtual machine data. If the verification of the new firewall instance virtual machine network or the new firewall instance virtual machine data passes, proceed to S207. If the verification of the new firewall instance virtual machine network or the new firewall instance virtual machine data fails, proceed to S210.

[0063] S207. Direct traffic to the new firewall instance virtual machine through the virtual gateway. Determine if the redirection is successful. If successful, proceed to S208; otherwise, proceed to S210.

[0064] In this embodiment, if the pull fails, the original environment of the original firewall instance virtual machine will not be affected, and the new firewall instance virtual machine will be deleted.

[0065] S208, Release configuration lock.

[0066] S209. Set the original firewall instance virtual machine to a disabled state.

[0067] S210. Set the new firewall instance virtual machine to a disabled state.

[0068] S211. Asynchronously reclaim firewall instance virtual machines that are in an unused state.

[0069] Figure 3 This is a schematic flowchart illustrating another method for updating the capacity of a cloud platform firewall instance, provided in an embodiment of the present invention. The specific steps are as follows:

[0070] S310. Generate a new firewall instance virtual machine based on the new system resource specification information.

[0071] S320, Export the business configuration data of the original firewall instance virtual machine.

[0072] S330. Import the business configuration data into the new firewall instance virtual machine according to the business interface.

[0073] S340, redirect traffic to the new firewall instance virtual machine via the virtual gateway.

[0074] S350, shut down and reclaim the original firewall instance virtual machine.

[0075] Figure 4 This is a schematic flowchart illustrating another method for updating the capacity of a cloud platform firewall instance, provided in an embodiment of the present invention. The specific steps are as follows:

[0076] S410. Generate a new firewall instance virtual machine based on the new system resource specification information, and then shut down the new firewall instance virtual machine.

[0077] S420, back up the data of the original firewall instance virtual machine.

[0078] S430. Copy the backed-up data to the new firewall instance virtual machine.

[0079] S440, Start the new firewall instance virtual machine.

[0080] S450: Traffic is redirected to the new firewall instance virtual machine via a virtual gateway.

[0081] S460. Shut down and reclaim the original firewall instance virtual machine.

[0082] It should be noted that if the cloud platform management network uses Dynamic Host Configuration Protocol (DHCP) for IP address allocation, the IP addresses of the firewall instance virtual machine's service network can be bound via MAC addresses, and traffic redirection can be handled automatically without address conflicts. However, if the management network uses planned, statically allocated IP addresses, then the IP addresses need to be modified to ensure that the addresses of the new firewall instance virtual machine and the original firewall instance virtual machine do not conflict.

[0083] Figure 5 This is a schematic diagram of a cloud platform firewall instance capacity update device provided in an embodiment of the present disclosure, as shown below. Figure 5 As shown, the device includes: a new firewall instance virtual machine generation module 510, an original firewall instance virtual machine acquisition module 520, a configuration lock invocation module 530, an import module 540, and a recycling module 550.

[0084] The new firewall instance virtual machine generation module 510 is used to generate a new firewall instance virtual machine based on the new system resource specification information.

[0085] The original firewall instance virtual machine acquisition module 520 is used to acquire the original firewall instance virtual machine to be updated; wherein, the original firewall instance virtual machine is generated based on the original system resource specification information, and the capacity of the original firewall instance virtual machine and the new firewall instance virtual machine are different;

[0086] The configuration lock calling module 530 is used to call the configuration lock and add the configuration lock to the data of the original firewall instance virtual machine;

[0087] Import module 540 is used to obtain data from the original firewall instance virtual machine, import the data into the new firewall instance virtual machine, and redirect traffic to the new firewall instance virtual machine through a virtual gateway;

[0088] The recycling module 550 is used to release the configuration lock, shut down and recycle the original firewall instance virtual machine.

[0089] The technical solution of this embodiment involves generating a new firewall instance virtual machine based on new system resource specifications using a new firewall instance virtual machine generation module; obtaining the original firewall instance virtual machine to be updated using an original firewall instance virtual machine acquisition module; wherein the original firewall instance virtual machine is generated based on the original system resource specifications, and the original firewall instance virtual machine and the new firewall instance virtual machine have different capacities; invoking a configuration lock using a configuration lock invocation module to add the configuration lock to the data of the original firewall instance virtual machine; obtaining the data of the original firewall instance virtual machine using an import module, importing the data into the new firewall instance virtual machine, and directing traffic to the new firewall instance virtual machine through a virtual gateway; and releasing the configuration lock using a recycling module to shut down and recycle the original firewall instance virtual machine. This embodiment, without shutting down the original firewall instance virtual machine or affecting existing production operations, achieves firewall instance capacity updates (vertical scaling up or down of firewall instances) within firewall security protection by obtaining the data of the original firewall instance virtual machine, importing the data into the new firewall instance virtual machine, and directing traffic to the new firewall instance virtual machine through a virtual gateway.

[0090] Optionally, the above device further includes a network joining module, which is used to: join the new firewall instance virtual machine to the same network as the original firewall instance virtual machine.

[0091] Optionally, the data of the original firewall instance virtual machine includes service configuration data.

[0092] Optionally, the import module is specifically used to: export the service configuration data of the original firewall instance virtual machine; and import the service configuration data into the new firewall instance virtual machine according to the service interface.

[0093] Optionally, the import module is also used to: back up the data of the original firewall instance virtual machine; and copy the backed-up data to the new firewall instance virtual machine.

[0094] Optionally, the above apparatus further includes a first verification module, which is specifically used to: diagnose the new firewall instance virtual machine network through PING and / or ARP commands to obtain feedback information; and verify the correctness of the new firewall instance virtual machine network based on the feedback information.

[0095] Optionally, the above device further includes a second verification module, which is specifically used to: compare the data before importing the new firewall instance virtual machine with the data after importing the new firewall instance virtual machine; if the data before importing the new firewall instance virtual machine is consistent with the data after importing the new firewall instance virtual machine, then the new firewall instance virtual machine data verification is correct; if the data before importing the new firewall instance virtual machine is inconsistent with the data after importing the new firewall instance virtual machine, then the new firewall instance virtual machine data verification fails.

[0096] Optionally, the import module is also used to: configure routing information through a virtual gateway; the routing information includes the address information of the new firewall instance virtual machine; disconnect the traffic redirection connection between the virtual gateway and the original firewall instance virtual machine through the virtual gateway; and establish a traffic redirection connection with the new firewall instance virtual machine according to the routing information, so as to redirect traffic to the new firewall instance virtual machine.

[0097] The cloud platform firewall instance capacity update device provided in this disclosure can execute the cloud platform firewall instance capacity update method provided in any embodiment of this disclosure, and has the corresponding functional modules and beneficial effects of the method execution.

[0098] It is worth noting that the various units and modules included in the above-mentioned device are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the protection scope of the embodiments of this disclosure.

[0099] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this disclosure. Reference is made below. Figure 6 It illustrates an electronic device suitable for implementing embodiments of the present disclosure (e.g., Figure 6 The diagram below shows the structure of the terminal device or server 600. The terminal device in this embodiment may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), and vehicle terminals (e.g., vehicle navigation terminals), as well as fixed terminals such as digital TVs and desktop computers. Figure 3 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.

[0100] like Figure 6 As shown, electronic device 600 may include a processing unit (e.g., central processing unit, graphics processor, etc.) 601, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 602 or a program loaded from storage device 608 into random access memory (RAM) 603. RAM 603 also stores various programs and data required for the operation of electronic device 600. Processing unit 601, ROM 602, and RAM 603 are interconnected via bus 604. Edit / output (I / O) interface 606 is also connected to bus 604.

[0101] Typically, the following devices can be connected to I / O interface 606: input devices 606 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 607 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 608 including, for example, magnetic tapes, hard disks, etc.; and communication devices 609. Communication device 609 allows electronic device 600 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 6 An electronic device 600 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.

[0102] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 609, or installed from a storage device 608, or installed from a ROM 602. When the computer program is executed by the processing device 601, it performs the functions defined in the methods of embodiments of this disclosure.

[0103] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.

[0104] The electronic device provided in this embodiment and the cloud platform firewall instance capacity update method provided in the above embodiments belong to the same inventive concept. Technical details not described in detail in this embodiment can be found in the above embodiments, and this embodiment has the same beneficial effects as the above embodiments.

[0105] This disclosure provides a computer storage medium storing a computer program that, when executed by a processor, implements the cloud platform firewall instance capacity update method provided in the above embodiments.

[0106] It should be noted that the computer-readable medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in connection with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0107] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol, such as HTTP (Hypertext Transfer Protocol), and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future-developed networks.

[0108] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.

[0109] The aforementioned computer-readable medium carries one or more programs that, when executed by the electronic device, cause the electronic device to:

[0110] The aforementioned computer-readable medium carries one or more programs. When the aforementioned one or more programs are executed by the electronic device, the electronic device causes the following: a new firewall instance virtual machine to be generated based on new system resource specification information; the original firewall instance virtual machine to be updated to be obtained; wherein the original firewall instance virtual machine is generated based on the original system resource specification information, and the original firewall instance virtual machine and the new firewall instance virtual machine have different capacities; a configuration lock is invoked to add the configuration lock to the data of the original firewall instance virtual machine; the data of the original firewall instance virtual machine is obtained, the data is imported into the new firewall instance virtual machine, and traffic is directed to the new firewall instance virtual machine through a virtual gateway; the configuration lock is released, and the original firewall instance virtual machine is shut down and recycled.

[0111] Computer program code for performing the operations of this disclosure can be written in one or more programming languages ​​or a combination thereof, including but not limited to object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0112] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0113] The units described in the embodiments of this disclosure can be implemented in software or in hardware. The name of a unit does not necessarily limit the unit itself; for example, the first acquisition unit can also be described as "a unit that acquires at least two Internet Protocol addresses".

[0114] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.

[0115] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0116] The above description is merely a preferred embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.

[0117] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0118] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.

Claims

1. A method for updating the capacity of a cloud platform firewall instance, characterized in that, include: A new firewall instance virtual machine is generated based on the new system resource specifications. Obtain the original firewall instance virtual machine to be updated; wherein, the original firewall instance virtual machine is generated based on the original system resource specification information, and the capacity of the original firewall instance virtual machine is different from that of the new firewall instance virtual machine; Invoke the configuration lock to add the configuration lock to the data of the original firewall instance virtual machine; wherein, the data of the original firewall instance virtual machine includes service configuration data; Obtain the data from the original firewall instance virtual machine, import the data into the new firewall instance virtual machine, and redirect traffic to the new firewall instance virtual machine through the virtual gateway; Release the configuration lock, shut down and reclaim the original firewall instance virtual machine; The step of obtaining the data from the original firewall instance virtual machine and importing the data into the new firewall instance virtual machine includes: Export the service configuration data of the original firewall instance virtual machine; Import the service configuration data into the new firewall instance virtual machine according to the service interface; The step of directing traffic to the new firewall instance virtual machine via a virtual gateway includes: Configure routing information through a virtual gateway; the routing information includes the virtual machine address information of the new firewall instance and routing policies. Disconnect the traffic-driving connection between the virtual gateway and the original firewall instance virtual machine through the virtual gateway; A traffic redirection connection is established with the new firewall instance virtual machine based on the routing information to redirect traffic to the new firewall instance virtual machine.

2. The method according to claim 1, characterized in that, After obtaining the original firewall instance virtual machine to be updated, the following is also included: Add the new firewall instance virtual machine to the same network as the original firewall instance virtual machine.

3. The method according to claim 1, characterized in that, Obtaining data from the original firewall instance virtual machine and importing the data into the new firewall instance virtual machine includes: Back up the data of the original firewall instance virtual machine; Copy the backed-up data to the new firewall instance virtual machine.

4. The method according to claim 1, characterized in that, After obtaining the data from the original firewall instance virtual machine and importing the data into the new firewall instance virtual machine, the process further includes: Diagnose the new firewall instance virtual machine network using the PING and / or ARP commands to obtain feedback information; Verify the correctness of the new firewall instance virtual machine network based on the feedback information.

5. The method according to claim 1, characterized in that, After obtaining the data from the original firewall instance virtual machine and importing the data into the new firewall instance virtual machine, the process further includes: Compare the data before importing the new firewall instance virtual machine with the data after importing the new firewall instance virtual machine; If the data before importing the new firewall instance virtual machine is consistent with the data after importing the new firewall instance virtual machine, then the data verification of the new firewall instance virtual machine is correct. If the data before importing the new firewall instance virtual machine is inconsistent with the data after importing the new firewall instance virtual machine, the data verification of the new firewall instance virtual machine will fail.

6. A device for updating the capacity of a cloud platform firewall instance, characterized in that, include: The new firewall instance virtual machine generation module is used to generate new firewall instance virtual machines based on the new system resource specification information. The original firewall instance virtual machine acquisition module is used to acquire the original firewall instance virtual machine to be updated; wherein, the original firewall instance virtual machine is generated based on the original system resource specification information, and the capacity of the original firewall instance virtual machine and the new firewall instance virtual machine are different; The configuration lock invocation module is used to invoke the configuration lock and add the configuration lock to the data of the original firewall instance virtual machine; wherein, the data of the original firewall instance virtual machine includes service configuration data; The import module is used to export the service configuration data of the original firewall instance virtual machine; import the service configuration data into the new firewall instance virtual machine according to the service interface; configure routing information through the virtual gateway; the routing information includes the address information and routing policy of the new firewall instance virtual machine; disconnect the traffic redirection connection between the virtual gateway and the original firewall instance virtual machine through the virtual gateway; and establish a traffic redirection connection with the new firewall instance virtual machine according to the routing information to redirect traffic to the new firewall instance virtual machine. The recycling module is used to release the configuration lock, shut down, and recycle the original firewall instance virtual machine.

7. An electronic device, characterized in that, The electronic device includes: One or more processors; Storage device for storing one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the cloud platform firewall instance capacity update method as described in any one of claims 1-5.

8. A storage medium containing computer-executable instructions, which, when executed by a computer processor, are used to perform the method for updating the capacity of a cloud platform firewall instance as described in any one of claims 1-5.

Citation Information

Patent Citations

  • Virtual machine management system and method

    CN103136030A

  • Method and device for upgrading distributed firewall

    CN113595802A