Method, device, equipment and storage medium for changing firewall instance capacity
By synchronizing business configuration data and using idle tags and routing rules, the data security problem during the capacity change of firewall instances is solved, and a secure expansion operation is achieved.
Patent Information
- Application Number
- CN202211623914.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-16
- Publication Date
- 2025-08-12
- Estimated Expiration
- 2042-12-16
AI Technical Summary
Data security cannot be guaranteed during the process of changing the capacity of the firewall instance.
By determining the instance identifier of the new firewall instance, synchronize the business configuration data of the running firewall instance into the new firewall instance, and determine whether there is an idle mark. If it exists, determine the target mark from the idle mark, and determine the routing rules and packet mark set of the new firewall instance based on the target mark and the new instance identifier, and filter out the same tag data packets from the target packet mark set and sent to the new firewall instance.
It realizes that the firewall instances are expanded securely without cutting off the traffic path of the existing firewall instance to ensure data security.
Smart Images

Figure CN116032575B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a method, device, equipment and storage medium for changing the capacity of a firewall instance. Background Art
[0002] With the continuous development of information technology, data security has become increasingly important. Firewall technology uses various software and hardware devices for security management and screening to help computer networks build a relatively isolated protective barrier between their internal and external networks, thereby protecting user data and information security.
[0003] Currently, firewall instances (virtual hosts with firewalls installed) often require expansion to improve their protection capabilities. Typically, the steps for expanding or shrinking a firewall instance include: first, disconnecting the firewall instance's traffic flow path to enable direct communication between the internal and external networks; then, shutting down the firewall instance and directly expanding or shrinking the firewall instance's capacity, such as by expanding or shrinking its CPU and memory; then, restarting the firewall instance and reconnecting its traffic flow path to restore its data security capabilities.
[0004] However, the traditional method of changing the capacity of a firewall instance takes a long time to execute. During this time, production services are not protected by the firewall, and data security cannot be guaranteed. Summary of the Invention
[0005] The present invention provides a method, apparatus, device and storage medium for changing the capacity of a firewall instance, so as to solve the problem that the security of data cannot be guaranteed when the capacity of the firewall instance is changed.
[0006] In a first aspect, the present invention provides a method for changing the capacity of a firewall instance, comprising:
[0007] Determine a new instance identifier of a new firewall instance, and synchronize service configuration data stored in the running first firewall instance to the new firewall instance;
[0008] Determining whether there is an idle tag; if so, determining a target tag from the idle tags, determining a first routing rule for the newly added firewall instance based on the target tag and the newly added instance identifier, and determining a target packet tag set based on the target tag, wherein the idle tag is a packet tag corresponding to a firewall instance that has been deleted and was previously in an intermediate position in a firewall instance link, the firewall instance link includes multiple firewall instances arranged in a preset order, the packet tag is determined based on a source address and a destination address of an untagged packet, and the target packet tag set includes a packet tag corresponding to the first firewall instance and the target tag;
[0009] From the target data packet tag set, a data packet tag that is the same as the target tag in the first routing rule is determined as a first target data packet tag, and the data packet corresponding to the first target data packet tag is sent to the newly added firewall instance to achieve expansion of the firewall instance.
[0010] In a second aspect, the present invention provides a device for changing the capacity of a firewall instance, comprising:
[0011] An instance identification determination module, configured to determine a new instance identification of a new firewall instance and synchronize the service configuration data stored in the running first firewall instance to the new firewall instance;
[0012] a tag set determination module, configured to determine whether there are idle tags; if so, determine a target tag from the idle tags; determine a first routing rule for the newly added firewall instance based on the target tag and the newly added instance identifier; and determine a target packet tag set based on the target tag, wherein the idle tag is a packet tag corresponding to a firewall instance that has been deleted and was previously in an intermediate position in a firewall instance chain, the firewall instance chain comprising multiple firewall instances arranged in a preset order; the packet tag is determined based on the source address and destination address of the untagged packet; and the target packet tag set comprises the packet tag corresponding to the first firewall instance and the target tag;
[0013] The first data packet sending module determines, from the target data packet tag set, a data packet tag that is identical to the target tag in the first routing rule as a first target data packet tag, and sends the data packet corresponding to the first target data packet tag to the newly added firewall instance to achieve capacity expansion of the firewall instance.
[0014] In a third aspect, the present invention provides an electronic device, comprising:
[0015] at least one processor;
[0016] and a memory communicatively coupled to the at least one processor;
[0017] The memory stores a computer program that can be executed by at least one processor. The computer program is executed by at least one processor to enable the at least one processor to perform the method for changing the capacity of a firewall instance in the first aspect.
[0018] In a fourth aspect, the present invention provides a computer-readable storage medium storing computer instructions, which are used to enable a processor to implement the method for changing the capacity of a firewall instance according to the first aspect when executed.
[0019] The present invention provides a solution for changing the capacity of a firewall instance. The solution determines a newly added instance identifier of a newly added firewall instance, synchronizes service configuration data stored in a running first firewall instance to the newly added firewall instance, determines whether an idle tag exists, and if so, determines a target tag from the idle tag. A first routing rule for the newly added firewall instance is determined based on the target tag and the newly added instance identifier, and a target packet tag set is determined based on the target tag. The idle tag is a packet tag corresponding to a firewall instance that has been deleted and was previously in an intermediate position in a firewall instance link. The firewall instance link includes multiple firewall instances arranged in a preset order. The packet tag is determined based on the source address and destination address of an untagged packet. The target packet tag set includes the packet tag corresponding to the first firewall instance and the target tag. A packet tag that is identical to the target tag in the first routing rule is selected from the target packet tag set and determined as a first target packet tag. The packet corresponding to the first target packet tag is then sent to the newly added firewall instance, thereby expanding the capacity of the firewall instance. By adopting the above technical solution, the service configuration data stored in the running first firewall instance is first synchronized to the newly added firewall instance. Then, if there is an idle tag, the target tag is determined from the idle tags. Based on the target tag and the newly added instance identifier, the first routing rule and the target data packet tag set of the newly added firewall instance are determined. Finally, based on the first routing rule, the first target data packet tag is filtered from the target data packet tag set, and the data packet corresponding to the tag is sent to the newly added firewall instance. When a new firewall instance is needed, there is no need to disconnect the traffic traction path of the existing firewall instance or disable the traffic traction function. Instead, the target tag is determined from the idle tags, and a routing rule is created for the newly added firewall instance based on the tag. The data packet is then sent to the newly added firewall instance according to the routing rule. This completes the expansion of the firewall instance. This solves the problem of data security not being guaranteed during the process of changing the capacity of the firewall instance.
[0020] It should be understood that the content described in this section is not intended to identify the key or important features of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0022] Figure 1 This is a flowchart of a method for changing the capacity of a firewall instance provided in accordance with the first embodiment of the present invention;
[0023] Figure 2 This is a flowchart of a method for changing the capacity of a firewall instance provided in accordance with the second embodiment of the present invention;
[0024] Figure 3 This is a schematic diagram of expanding and shrinking a firewall instance according to the second embodiment of the present invention;
[0025] Figure 4 1 is a schematic diagram of the structure of a device for changing the capacity of a firewall instance according to a third embodiment of the present invention;
[0026] Figure 5 It is a structural diagram of an electronic device provided according to the fourth embodiment of the present invention. DETAILED DESCRIPTION
[0027] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0028] It should be noted that the terms "first," "second," and the like in the specification and claims of the present invention and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than that illustrated or described herein. In the description of the present invention, unless otherwise specified, "plurality" refers to two or more. "And / or" describes an association relationship between associated objects, indicating that three relationships can exist. For example, "A and / or B" can mean: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally indicates that the associated objects are in an "or" relationship. In addition, the terms "including" and "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or device that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to such process, method, product, or device.
[0029] Example 1
[0030] Figure 1 A flowchart of a method for changing the capacity of a firewall instance is provided for the first embodiment of the present invention. This embodiment is applicable to situations where the capacity of a firewall instance is changed. The method can be performed by an apparatus for changing the capacity of a firewall instance. The apparatus for changing the capacity of a firewall instance can be implemented in the form of hardware and / or software. The apparatus for changing the capacity of a firewall instance can be configured in an electronic device, such as a cloud host, which can be composed of two or more physical entities or a single physical entity.
[0031] like Figure 1 As shown, the method for changing the capacity of a firewall instance provided in the first embodiment of the present invention specifically includes the following steps:
[0032] S101: Determine a new instance identifier of a new firewall instance, and synchronize service configuration data stored in a running first firewall instance to the new firewall instance.
[0033] In this embodiment, a firewall instance typically runs on a cloud host. A virtual machine gateway running on the cloud platform can obtain the firewall instance identifier, such as ngfw-vm1, which serves as the instance identifier. Furthermore, service configuration data, such as blacklist data, stored in the running firewall instance can be written to the newly added firewall instance.
[0034] S102. Determine whether there is an idle tag. If so, determine a target tag from the idle tag, determine a first routing rule for the newly added firewall instance based on the target tag and the newly added instance identifier, and determine a target data packet tag set based on the target tag.
[0035] The idle mark is a packet mark corresponding to a firewall instance that has been deleted and was once in the middle position in the firewall instance link. The firewall instance link includes multiple firewall instances arranged according to preset order requirements. The packet mark is determined based on the source address and destination address of the untagged packet. The target packet mark set includes the packet mark corresponding to the first firewall instance and the target mark.
[0036] In this embodiment, it can be determined whether there are free tags. If so, a target tag can be selected from the free tags. The target tag can be selected by random selection with equal probability, and the number of target tags is consistent with the number of newly added firewall instances. A correspondence between the target tags and the newly added instance identifiers is established. Alternatively, the target tags can be subjected to preset data processing, and a correspondence between the processed result and the newly added instance identifier is established. This correspondence constitutes the first routing rule. Finally, all target tags and the packet tags corresponding to the first firewall instance can be stored together in a target packet tag set. The packet tag can be determined by processing the source address and destination address, such as performing a modulo operation on the two. The preset data processing can include converting the representation of the target tag, such as converting letters to numbers. The preset order requirement can be based on the order of firewall instance operation time or the order of firewall instance capacity, etc., without limitation.
[0037] S103. From the target data packet tag set, determine the data packet tag that is the same as the target tag in the first routing rule as the first target data packet tag, and send the data packet corresponding to the first target data packet tag to the newly added firewall instance to achieve capacity expansion of the firewall instance.
[0038] In this embodiment, if the first routing rule includes a newly added instance identifier 1 corresponding to target tag 1, and a newly added instance identifier 2 corresponding to target tag 2, then according to the first routing rule, target tags 1 and 2 can be filtered out from the target packet tag set, and these target tags 1 and 2 are the first target packet tags. Based on the correspondence contained in the first routing rule, the data packets corresponding to the first target packet tag can be sent to the newly added firewall instance, that is, the data packets corresponding to the same data packet tag as target tag 1 are sent to the newly added instance identifier 1, and the data packets corresponding to the same data packet tag as target tag 2 are sent to the newly added instance identifier 2.
[0039] A method for changing the capacity of a firewall instance provided by an embodiment of the present invention includes determining a new instance identifier of a new firewall instance, synchronizing service configuration data stored in a running first firewall instance to the new firewall instance, determining whether an idle tag exists, and if so, determining a target tag from the idle tag. A first routing rule for the new firewall instance is determined based on the target tag and the new instance identifier, and a target packet tag set is determined based on the target tag. The idle tag is a packet tag corresponding to a firewall instance that has been deleted and was previously in an intermediate position in a firewall instance link. The firewall instance link includes multiple firewall instances arranged in a preset order. The packet tag is determined based on the source address and destination address of an untagged packet. The target packet tag set includes the packet tag corresponding to the first firewall instance and the target tag. A packet tag that is identical to the target tag in the first routing rule is selected from the target packet tag set and determined as a first target packet tag. The packet corresponding to the first target packet tag is sent to the new firewall instance to achieve capacity expansion of the firewall instance. The technical solution of the embodiment of the present invention first synchronizes the service configuration data stored in the running first firewall instance to the newly added firewall instance. Then, if there is an idle tag, the target tag is determined from the idle tags, and the first routing rule and target data packet tag set of the newly added firewall instance are determined based on the target tag and the newly added instance identifier. Finally, the first target data packet tag is filtered from the target data packet tag set based on the first routing rule, and the data packet corresponding to the tag is sent to the newly added firewall instance. When a new firewall instance is needed, there is no need to cut off the traffic traction path of the existing firewall instance or disable the traffic traction function. Instead, the target tag needs to be determined from the idle tags, and a routing rule for the newly added firewall instance is newly created based on the tag. Then, the data packet is sent to the newly added firewall instance in accordance with the routing rule. This completes the expansion of the firewall instance. This solves the problem of data security not being guaranteed during the process of changing the capacity of the firewall instance.
[0040] Example 2
[0041] Figure 2 This is a flowchart of a method for changing the capacity of a firewall instance provided in the second embodiment of the present invention. The technical solution of the embodiment of the present invention is further optimized based on the above optional technical solutions, and provides a specific method for changing the capacity of a firewall instance.
[0042] Optionally, after determining whether an idle tag exists, the method further includes: if not, calculating the sum of the current modulus and the number of newly added firewall instances, and determining the sum as a first target modulus, wherein the current modulus is consistent with the number of the first firewall instances; performing a hash operation on the source address and destination address of the untagged packet using the first target modulus, a preset base, and a preset offset to obtain a second hash tag value, determining the second hash tag value as a first packet tag of the untagged packet, and determining a packet tag different from the packet tag corresponding to the first firewall instance among the plurality of first packet tags as a newly added tag; determining a second routing rule for the newly added firewall instance based on the newly added tag and the newly added instance identifier; determining a packet tag among the plurality of first packet tags that is the same as the newly added tag in the second routing rule as a second target packet tag, and sending the packet corresponding to the second target packet tag to the newly added firewall instance to achieve expansion of the firewall instance. The advantage of this configuration is that the newly added tag can be determined by updating the modulus, and the second routing rule of the newly added firewall instance is created based on the newly added tag, so that even if an idle tag does not exist, packets can still be sent to the newly added firewall instance in an orderly manner.
[0043] Optionally, determining a target tag from the idle tags and determining a first routing rule for the newly added firewall instance based on the target tag and the newly added instance identifier includes: if there are multiple idle tags, determining a target tag from the multiple idle tags based on a preset policy, wherein the number of target tags is consistent with the number of newly added firewall instances; establishing a correspondence between the target tag and the newly added instance identifier, and determining the correspondence as the first routing rule for the newly added firewall instance. This configuration has the advantage of using a preset policy to determine a target tag from multiple idle tags, thereby orderly determining the correspondence between multiple target tags and multiple newly added firewall instances.
[0044] like Figure 2 As shown, a method for changing the capacity of a firewall instance provided in the second embodiment of the present invention specifically includes the following steps:
[0045] S201: Determine a new instance identifier of a new firewall instance, and synchronize service configuration data stored in a running first firewall instance to the new firewall instance.
[0046] Optionally, the method for determining the packet tag corresponding to the first firewall instance includes: calculating the sum of the number of the first firewall instances and the number of the idle tags to obtain a modulus; performing a hash operation on the source address and destination address of the untagged packet based on the modulus, a preset base, and a preset offset to obtain a first hash tag value; and determining the packet tag corresponding to the first firewall instance from multiple first hash tag values based on the idle tag, wherein the packet tag corresponding to the first firewall instance does not include the idle tag. The advantage of this configuration is that, by utilizing a hash operation, the flow of data packets can be more evenly distributed to the running first firewall instance.
[0047] Specifically, after the newly added firewall instance is actually running, the packet marking method for the newly added firewall instance can also be determined in the same way as the packet marking method for the first firewall instance. The purpose of the hash operation can be understood as breaking up the traffic distribution of untagged packets, thereby evenly distributing packets to the running firewall instances. The hash operation includes modulus and exclusive-or operations. The modulus is used for the modulus operation, and a preset base, such as 0xf4243, is used for the exclusive-or operation. The preset offset is usually greater than 0.
[0048] For example, if the number of first firewall instances is 2 and the number of idle tags is 1, the modulus is 3. If the source address of the untagged data packet is 192.168.255.123 and the destination addresses are 172.19.255.3, 172.19.255.4, and 172.19.255.4, respectively, a hash function can be used to perform hash operations on 192.168.255.123 and 172.19.255.3, 192.168.255.123 and 172.19.255.4, and 192.168.255.123 and 172.19.255.5 to obtain first hash tag values 1, 2, and 3. If the idle tag is 2, the data packet tags corresponding to the first firewall instance can be determined to be 1 and 3 from the first hash tag value.
[0049] Optionally, a hash operation may be performed on the source port, destination port and transport layer protocol of the untagged data packet based on the modulus, a preset base and a preset offset to obtain a first hash tag value.
[0050] Optionally, a marking rule for the idle mark may be preset to process the first hash mark value corresponding to the idle mark. If the preset marking rule is to subtract 1 from the first hash mark value corresponding to the idle mark, the first hash mark value only includes 1 and 3.
[0051] Optionally, the method further includes: determining a firewall instance to be deleted from the first firewall instance, and determining an instance identifier of the firewall instance to be deleted; if the firewall instance to be deleted is located in the middle of the firewall instance link, determining a third hash tag value corresponding to the instance identifier to be deleted as the idle tag; deleting the firewall instance to be deleted from the firewall instance link, and deleting a third routing rule corresponding to the instance identifier to be deleted. The advantage of this arrangement is that by determining the idle tag, the hash tag value and data packet tag corresponding to the running firewall instance can be guaranteed not to change, thereby reducing the impact on the running firewall instance and saving the computing power corresponding to the hash operation.
[0052] Specifically, if it is necessary to delete a firewall instance from a running firewall instance (the first firewall), that is, to scale down the firewall instance, the firewall instance to be deleted and its instance identifier to be deleted can be first determined. The position of the firewall instance to be deleted in the firewall instance link is determined. If the position is in the middle, the hash tag value corresponding to the instance identifier to be deleted (the third hash tag value) can be determined as an idle tag. The firewall instance to be deleted is deleted from the firewall instance link, and the third routing rule corresponding to the instance identifier to be deleted is deleted.
[0053] Optionally, the reason for deleting a firewall instance from a running firewall instance may be that the firewall instance to be deleted has failed. The failed firewall instance to be deleted may be marked as "failed." Running firewall instances may be periodically inspected, and failed instances recorded. The inspection method and location may be preset based on actual business conditions, such as using network diagnostic tools to inspect the link layer and inspecting the internetworking protocols and application programming interfaces on the business side. The inspection period for running firewall instances may be preset based on business scenarios, such as performing a inspection every 5 seconds with a 1-second timeout for each inspection. A firewall instance that fails a preset number of consecutive inspections within a preset period may be identified as a failed instance. For example, five consecutive inspection failures within one minute may be considered a failed instance. For business scenarios with high data security requirements, the number of consecutive failures may be reduced, such as two consecutive inspection failures as a failure. Alternatively, the criteria for determining whether a failed firewall instance has recovered may be preset based on business scenarios. If there is no normal firewall instance, the data packet can be sent directly to the destination address, that is, the network address of the target business cloud host.
[0054] Optionally, it also includes: if the position of the firewall instance to be deleted in the firewall instance link is the end position, deleting the third hash tag value corresponding to the instance identifier to be deleted, deleting the fourth routing rule corresponding to the instance identifier to be deleted, and deleting the firewall instance to be deleted from the firewall instance link; calculating the difference between the current modulus and the number of the firewall instances to be deleted, and determining the difference as the second target modulus, wherein the current modulus is consistent with the number of the second firewall instances that are running; determining the second packet tag of the untagged data packet based on the second target modulus, the preset base, and the preset offset, and sending the data packet to the running second firewall instance based on the second packet tag and the fifth routing rule of the second firewall instance. The advantage of this setting is that by adjusting the modulus, the hash tag value corresponding to the firewall instance to be deleted can be deleted in time, so that the data packet is no longer sent to the firewall instance to be deleted, thereby achieving the reduction of the firewall instance.
[0055] Specifically, if the position of the firewall instance to be deleted in the firewall instance link is the end position, the hash tag value (third hash tag value) corresponding to the instance identifier to be deleted can be deleted. Delete the firewall instance to be deleted from the firewall instance link, and delete the fourth routing rule corresponding to the instance identifier to be deleted. Exemplarily, if the current modulus is 5 and the number of firewall instances to be deleted is 2, the second target modulus is 3. As described above, using the second target modulus, the preset base and the preset offset, the second data packet tags 1, 2 and 3 can be obtained accordingly. According to the routing rule (fifth routing rule) of the second firewall instance that is running, the data packet can be sent to the second firewall instance corresponding to the data packet tag, such as sending the data packet corresponding to the data packet tag 1 to the firewall instance with the running instance identifier 1.
[0056] Furthermore, before deleting the firewall instance to be deleted from the firewall instance link, the method further includes: deleting a connection record corresponding to the firewall instance to be deleted to disconnect the firewall instance to be deleted from the virtual machine gateway. This configuration has the advantage that deleting the connection record automatically disconnects the firewall instance to be deleted from the virtual machine gateway.
[0057] Specifically, the packet tag corresponding to the running firewall instance can be written to the connection record. This allows untagged packets with the same source and destination addresses to directly determine the packet tag based on the connection record, saving computing power consumed by hash operations. By deleting the connection record as described above, the firewall instance to be deleted can be disconnected from the virtual machine gateway.
[0058] S202: Determine whether there is an idle mark. If yes, execute step 203; if no, execute step 204.
[0059] S203 : If there are multiple idle markers, determine a target marker from the multiple idle markers according to a preset strategy, and execute step 208 .
[0060] The number of the target tags is consistent with the number of the newly added firewall instances.
[0061] Specifically, the preset strategy may be equal probability selection, or the target tag may be determined according to the numerical values of the idle tags, such as determining the idle tag with the largest numerical value as the target tag.
[0062] S204: Calculate the sum of the current modulus and the number of newly added firewall instances, and determine the sum as the first target modulus.
[0063] The current module is consistent with the number of the first firewall instances.
[0064] For example, if the current modulus is 3 and the number of newly added firewall instances is 3, the first target modulus is 6.
[0065] S205. Use the first target modulus, the preset base, and the preset offset to perform a hash operation on the source address and the destination address of the untagged data packet to obtain a second hash tag value, and determine the second hash tag value as the first data packet tag of the untagged data packet. Among the multiple first data packet tags, a data packet tag that is different from the data packet tag corresponding to the first firewall instance is determined as a new tag.
[0066] For example, if the first target modulus is 6, the preset base is 0xf4243, and the preset offset is 1, the source and destination addresses of the untagged packet are hashed to obtain second hash tag values of 1, 2, 3, 4, 5, and 6, which are also the first packet tags. If the first firewall instance (i.e., the running firewall instance before the newly added firewall instance) has corresponding packet tags of 1, 2, and 3, then the newly added tags are 4, 5, and 6.
[0067] S206: Determine a second routing rule for the newly added firewall instance according to the newly added mark and the newly added instance identifier.
[0068] For example, if the newly added instances are identified as ngfw vm21, ngfw vm22, and ngfw vm23, a correspondence between ngfw vm21 and the newly added tag 4, a correspondence between ngfw vm22 and the newly added tag 5, and a correspondence between ngfw vm23 and the newly added tag 6 can be established. These correspondences are all second routing rules.
[0069] S207. Determine a packet tag among the multiple first packet tags that is the same as the newly added tag in the second routing rule as a second target packet tag, and send the packet corresponding to the second target packet tag to the newly added firewall instance to achieve capacity expansion of the firewall instance.
[0070] For example, as described in the above example, if the first data packet is marked as 1, 2, 3, 4, 5 and 6, the second routing rule can be used to filter out the second target data packet marks 4, 5 and 6, and then the data packet corresponding to data packet mark 4 is sent to the newly added firewall instance corresponding to ngfw vm21, the data packet corresponding to data packet mark 5 is sent to the newly added firewall instance corresponding to ngfw vm22, and the data packet corresponding to data packet mark 6 is sent to the newly added firewall instance corresponding to ngfw vm23.
[0071] S208: Establish a correspondence between the target tag and the newly added instance identifier, determine the correspondence as a first routing rule of the newly added firewall instance, and determine a target data packet tag set according to the target tag.
[0072] S209. From the target data packet tag set, determine the data packet tag that is the same as the target tag in the first routing rule as the first target data packet tag, and send the data packet corresponding to the first target data packet tag to the newly added firewall instance to achieve expansion of the firewall instance.
[0073] Specifically, Figure 3 This is a schematic diagram of scaling up and down a firewall instance. NGFW vmX represents the firewall instance ID. Figure 3 As shown, NGFW vm1 represents instance ID 1 of firewall instance 1. The vertical order of the firewall instance IDs corresponds to the order of the firewall instances in the firewall instance link. The first arrow indicates that, when there are no idle tags, firewall instance 4 is added to the three running firewall instances. The second arrow indicates that, among the four running firewall instances, firewall instance 1 is deleted, thereby reducing the capacity of the existing firewall instances. The third arrow indicates that, although firewall instance 1 is deleted, its hash tag value is retained. This hash tag value is the idle tag, and firewall instance 1 remains inactive, meaning it does not send packets to firewall instance 1. The fourth arrow indicates that firewall instance 5 is added, and firewall instance 5 will occupy the idle tag, that is, the hash tag value of firewall instance 1. The fifth arrow indicates that firewall instance 4 is deleted. However, since firewall instance 4 is at the end, its hash tag value does not need to be retained.
[0074] The method for changing the capacity of a firewall instance provided by an embodiment of the present invention first synchronizes service configuration data to a newly added firewall instance. Then, if an idle tag exists, a target tag is determined from the idle tags, and a first routing rule for the newly added firewall instance is determined. If no idle tag exists, the packet tag is updated and a second routing rule is determined. Finally, according to the routing rule, a packet corresponding to a packet tag identical to the target tag or the newly added tag is sent to the newly added firewall instance. When a new firewall instance is required, the hash tag value and packet tag corresponding to the currently running firewall instance are ensured to remain unchanged, thereby reducing the impact on the currently running firewall instance. The capacity of the firewall instance can be expanded without affecting existing connections. In addition, the hash operation can be used to distribute packet traffic more evenly to different virtual machine instances.
[0075] Example 3
[0076] Figure 4 This is a schematic diagram of the structure of a device for changing the capacity of a firewall instance provided by the third embodiment of the present invention. Figure 4 As shown, the apparatus includes: an instance identifier determination module 301, a tag set determination module 302, and a first data packet sending module 303, wherein:
[0077] An instance identification determination module, configured to determine a new instance identification of a new firewall instance and synchronize the service configuration data stored in the running first firewall instance to the new firewall instance;
[0078] a tag set determination module, configured to determine whether there are idle tags; if so, determine a target tag from the idle tags; determine a first routing rule for the newly added firewall instance based on the target tag and the newly added instance identifier; and determine a target packet tag set based on the target tag, wherein the idle tag is a packet tag corresponding to a firewall instance that has been deleted and was previously in an intermediate position in a firewall instance chain, the firewall instance chain comprising multiple firewall instances arranged in a preset order; the packet tag is determined based on the source address and destination address of the untagged packet; and the target packet tag set comprises the packet tag corresponding to the first firewall instance and the target tag;
[0079] The first data packet sending module determines, from the target data packet tag set, a data packet tag that is identical to the target tag in the first routing rule as a first target data packet tag, and sends the data packet corresponding to the first target data packet tag to the newly added firewall instance to achieve capacity expansion of the firewall instance.
[0080] An apparatus for changing the capacity of a firewall instance provided by an embodiment of the present invention first synchronizes service configuration data stored in a running first firewall instance with a newly added firewall instance. Then, if there are idle tags, a target tag is determined from the idle tags. Based on the target tag and the newly added instance identifier, a first routing rule and a target packet tag set for the newly added firewall instance are determined. Finally, based on the first routing rule, a first target packet tag is filtered from the target packet tag set, and a packet corresponding to the tag is sent to the newly added firewall instance. When a new firewall instance is needed, there is no need to disconnect the traffic traction path of the existing firewall instance or disable the traffic traction function. Instead, the target tag is determined from the idle tags, a routing rule for the newly added firewall instance is created based on the tag, and the packet is sent to the newly added firewall instance in accordance with the routing rule. This completes the expansion of the firewall instance. This solves the problem of data security not being guaranteed during the process of changing the capacity of the firewall instance.
[0081] Optionally, the method for determining the data packet tag corresponding to the first firewall instance includes: calculating the sum of the number of the first firewall instances and the number of the idle tags to obtain a modulus; based on the modulus, a preset base, and a preset offset, performing a hash operation on the source address and the destination address of the untagged data packet to obtain a first hash tag value, and according to the idle tag, determining the data packet tag corresponding to the first firewall instance from multiple first hash tag values, wherein the data packet tag corresponding to the first firewall instance does not include the idle tag.
[0082] Optionally, the device further includes:
[0083] a first target modulus determination module configured to, after determining whether an idle flag exists, calculate a sum of a current modulus and the number of newly added firewall instances if the idle flag does not exist, and determine the sum as a first target modulus, wherein the current modulus is consistent with the number of the first firewall instances;
[0084] a newly added tag determining module, configured to perform a hash operation on the source address and the destination address of the untagged data packet using the first target modulus, a preset base, and a preset offset to obtain a second hash tag value, determine the second hash tag value as a first data packet tag of the untagged data packet, and determine, from the plurality of first data packet tags, a data packet tag that is different from the data packet tag corresponding to the first firewall instance as a newly added tag;
[0085] a routing rule determination module, configured to determine a second routing rule for the newly added firewall instance based on the newly added tag and the newly added instance identifier;
[0086] The second data packet sending module is used to determine the data packet tag that is the same as the newly added tag in the second routing rule among the multiple first data packet tags as the second target data packet tag, and send the data packet corresponding to the second target data packet tag to the newly added firewall instance to achieve expansion of the firewall instance.
[0087] Optionally, the tag set determination module includes:
[0088] a target tag determining unit, configured to determine a target tag from the plurality of idle tags according to a preset policy if there are multiple idle tags, wherein the number of the target tags is consistent with the number of the newly added firewall instances;
[0089] The routing rule determining unit is configured to establish a correspondence between the target tag and the newly added instance identifier, and determine the correspondence as a first routing rule of the newly added firewall instance.
[0090] Optionally, the device further includes:
[0091] An instance and identifier determination module, configured to determine a firewall instance to be deleted from the first firewall instance, and determine an instance identifier to be deleted of the firewall instance to be deleted;
[0092] an idle tag determining module, configured to determine, if the position of the firewall instance to be deleted is an intermediate position in the firewall instance link, a third hash tag value corresponding to the identifier of the instance to be deleted as the idle tag;
[0093] The first deleting module is configured to delete the firewall instance to be deleted from the firewall instance link, and delete the third routing rule corresponding to the instance identifier to be deleted.
[0094] Optionally, the device further includes:
[0095] a second deleting module, configured to, if the position of the firewall instance to be deleted is at the end in the firewall instance link, delete the third hash tag value corresponding to the instance identifier to be deleted, delete the fourth routing rule corresponding to the instance identifier to be deleted, and delete the firewall instance to be deleted from the firewall instance link;
[0096] a second target modulus determination module, configured to calculate a difference between a current modulus and the number of the to-be-deleted firewall instances, and determine the difference as a second target modulus, wherein the current modulus is consistent with the number of the running second firewall instances;
[0097] a second data packet sending module, configured to determine a second data packet tag for the untagged data packet based on the second target modulus, the preset base, and the preset offset, and to send the data packet to the running second firewall instance based on the second data packet tag and the fifth routing rule of the second firewall instance.
[0098] Optionally, the device further includes:
[0099] A record deletion module is used to delete the connection record corresponding to the firewall instance to be deleted before deleting the firewall instance to be deleted from the firewall instance link, so as to disconnect the connection between the firewall instance to be deleted and the virtual machine gateway
[0100] The apparatus for changing the capacity of a firewall instance provided in an embodiment of the present invention can execute the method for changing the capacity of a firewall instance provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0101] Example 4
[0102] Figure 5 A schematic diagram of the structure of an electronic device 40 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0103] like Figure 5 As shown, the electronic device 40 includes at least one processor 41 and a memory, such as a read-only memory (ROM) 42, a random access memory (RAM) 43, etc., which is communicatively connected to the at least one processor 41. The memory stores a computer program that can be executed by the at least one processor, and the processor 41 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 42 or the computer program loaded from the storage unit 48 into the random access memory (RAM) 43. Various programs and data required for the operation of the electronic device 40 can also be stored in the RAM 43. The processor 41, ROM 42, and RAM 43 are connected to each other via a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.
[0104] Multiple components in the electronic device 40 are connected to the I / O interface 45, including an input unit 46, such as a keyboard, a mouse, etc.; an output unit 47, such as various types of displays, speakers, etc.; a storage unit 48, such as a magnetic disk, an optical disk, etc.; and a communication unit 49, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 49 allows the electronic device 40 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0105] Processor 41 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of processor 41 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any other suitable processors, controllers, microcontrollers, etc. Processor 41 executes the various methods and processes described above, such as the method for changing the capacity of a firewall instance.
[0106] In some embodiments, the method for changing the capacity of a firewall instance can be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as storage unit 48. In some embodiments, part or all of the computer program can be loaded and / or installed on electronic device 40 via ROM 42 and / or communication unit 49. When the computer program is loaded into RAM 43 and executed by processor 41, one or more steps of the method for changing the capacity of a firewall instance described above can be performed. Alternatively, in other embodiments, processor 41 can be configured to perform the method for changing the capacity of a firewall instance in any other suitable manner (e.g., via firmware).
[0107] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0108] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0109] The computer device provided above can be used to execute the method for changing the capacity of a firewall instance provided in any of the above embodiments, and has corresponding functions and beneficial effects.
[0110] Example 5
[0111] In the context of the present invention, a computer-readable storage medium may be a tangible medium having computer-executable instructions for performing, when executed by a computer processor, a method for changing the capacity of a firewall instance, the method comprising:
[0112] Determine a new instance identifier of a new firewall instance, and synchronize service configuration data stored in the running first firewall instance to the new firewall instance;
[0113] Determining whether there is an idle tag; if so, determining a target tag from the idle tags, determining a first routing rule for the newly added firewall instance based on the target tag and the newly added instance identifier, and determining a target packet tag set based on the target tag, wherein the idle tag is a packet tag corresponding to a firewall instance that has been deleted and was previously in an intermediate position in a firewall instance link, the firewall instance link includes multiple firewall instances arranged in a preset order, the packet tag is determined based on a source address and a destination address of an untagged packet, and the target packet tag set includes a packet tag corresponding to the first firewall instance and the target tag;
[0114] From the target data packet tag set, a data packet tag that is the same as the target tag in the first routing rule is determined as a first target data packet tag, and the data packet corresponding to the first target data packet tag is sent to the newly added firewall instance to achieve expansion of the firewall instance.
[0115] In the context of the present invention, computer-readable storage medium can be a tangible medium that can contain or store a computer program for use with an instruction execution system, device or equipment or used in conjunction with an instruction execution system, device or equipment. Computer-readable storage medium can include but is not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage medium can be a machine-readable signal medium. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0116] The computer device provided above can be used to execute the method for changing the capacity of a firewall instance provided in any of the above embodiments, and has corresponding functions and beneficial effects.
[0117] It is worth noting that in the above-mentioned embodiment of the device for changing the capacity of a firewall instance, the various units and modules included are only divided according to functional logic, but are not limited to the above-mentioned division, as long as the corresponding functions can be achieved; in addition, the specific names of the various functional units are only for the convenience of distinguishing each other and are not used to limit the scope of protection of the present invention.
[0118] Note that the above are only preferred embodiments of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and that various obvious changes, readjustments, and substitutions can be made by those skilled in the art without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments and may include many other equivalent embodiments without departing from the concept of the present invention. The scope of the present invention is determined by the scope of the appended claims.
Claims
1. A method for changing the capacity of a firewall instance, characterized in that: include: Determine a new instance identifier of a new firewall instance, and synchronize service configuration data stored in the running first firewall instance to the new firewall instance; Determining whether there is an idle tag; if so, determining a target tag from the idle tags, determining a first routing rule for the newly added firewall instance based on the target tag and the newly added instance identifier, and determining a target packet tag set based on the target tag, wherein the idle tag is a packet tag corresponding to a firewall instance that has been deleted and was previously in an intermediate position in a firewall instance link, the firewall instance link includes multiple firewall instances arranged in a preset order, the packet tag is determined based on a source address and a destination address of an untagged packet, and the target packet tag set includes a packet tag corresponding to the first firewall instance and the target tag; From the target data packet tag set, a data packet tag that is the same as the target tag in the first routing rule is determined as a first target data packet tag, and the data packet corresponding to the first target data packet tag is sent to the newly added firewall instance to achieve expansion of the firewall instance.
2. The method according to claim 1, characterized in that The method for determining the data packet mark corresponding to the first firewall instance includes: Calculating a sum of the number of the first firewall instances and the number of the idle markers to obtain a modulus; Based on the modulus, the preset base, and the preset offset, a hash operation is performed on the source address and the destination address of the untagged data packet to obtain a first hash tag value, and according to the idle tag, a data packet tag corresponding to the first firewall instance is determined from multiple first hash tag values, wherein the data packet tag corresponding to the first firewall instance does not include the idle tag.
3. The method according to claim 1, characterized in that After determining whether there is an idle mark, the method further includes: If not, calculate the sum of the current modulus and the number of newly added firewall instances, and determine the sum as the first target modulus, wherein the current modulus is consistent with the number of the first firewall instances; performing a hash operation on the source address and the destination address of the untagged data packet using the first target modulus, a preset base, and a preset offset to obtain a second hash tag value, determining the second hash tag value as a first data packet tag of the untagged data packet, and determining, among the plurality of first data packet tags, a data packet tag that is different from the data packet tag corresponding to the first firewall instance as a newly added tag; Determining a second routing rule for the newly added firewall instance according to the newly added mark and the newly added instance identifier; The packet tag among the multiple first packet tags that is the same as the newly added tag in the second routing rule is determined as the second target packet tag, and the packet corresponding to the second target packet tag is sent to the newly added firewall instance to achieve expansion of the firewall instance.
4. The method according to any one of claims 1 to 3, characterized in that The determining of a target tag from the idle tag, and determining a first routing rule of the newly added firewall instance according to the target tag and the newly added instance identifier, includes: If there are multiple idle tags, determine a target tag from the multiple idle tags according to a preset strategy, wherein the number of the target tags is consistent with the number of the newly added firewall instances; A correspondence between the target tag and the newly added instance identifier is established, and the correspondence is determined as a first routing rule of the newly added firewall instance.
5. The method according to claim 2, characterized in that Also includes: Determining a firewall instance to be deleted from the first firewall instance, and determining an instance identifier to be deleted of the firewall instance to be deleted; If the position of the firewall instance to be deleted in the firewall instance link is in the middle, determining the third hash tag value corresponding to the identifier of the instance to be deleted as the idle tag; The firewall instance to be deleted is deleted from the firewall instance link, and the third routing rule corresponding to the instance identifier to be deleted is deleted.
6. The method according to claim 5, characterized in that Also includes: If the position of the firewall instance to be deleted is at the end in the firewall instance link, deleting the third hash tag value corresponding to the instance identifier to be deleted, deleting the fourth routing rule corresponding to the instance identifier to be deleted, and deleting the firewall instance to be deleted from the firewall instance link; Calculating a difference between a current modulus and the number of the to-be-deleted firewall instances, and determining the difference as a second target modulus, wherein the current modulus is consistent with the number of the running second firewall instances; Determine a second packet tag for the untagged data packet based on the second target modulus, the preset base, and the preset offset, and send the data packet to the running second firewall instance based on the second packet tag and the fifth routing rule of the second firewall instance.
7. The method according to any one of claims 5 to 6, characterized in that Before deleting the to-be-deleted firewall instance from the firewall instance link, the method further includes: Delete the connection record corresponding to the firewall instance to be deleted to disconnect the connection between the firewall instance to be deleted and the virtual machine gateway.
8. A device for changing the capacity of a firewall instance, characterized in that: include: An instance identification determination module, configured to determine a new instance identification of a new firewall instance and synchronize the service configuration data stored in the running first firewall instance to the new firewall instance; a tag set determination module, configured to determine whether there are idle tags; if so, determine a target tag from the idle tags; determine a first routing rule for the newly added firewall instance based on the target tag and the newly added instance identifier; and determine a target packet tag set based on the target tag, wherein the idle tag is a packet tag corresponding to a firewall instance that has been deleted and was previously in an intermediate position in a firewall instance chain, the firewall instance chain comprising multiple firewall instances arranged in a preset order; the packet tag is determined based on the source address and destination address of the untagged packet; and the target packet tag set comprises the packet tag corresponding to the first firewall instance and the target tag; The first data packet sending module determines, from the target data packet tag set, a data packet tag that is identical to the target tag in the first routing rule as a first target data packet tag, and sends the data packet corresponding to the first target data packet tag to the newly added firewall instance to achieve capacity expansion of the firewall instance.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor. The computer program is executed by the at least one processor to enable the at least one processor to perform the method for changing the capacity of a firewall instance according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the method for changing the capacity of a firewall instance according to any one of claims 1 to 7 when executed.
Citation Information
Patent Citations
Fire wall system and data processing method based on fire wall system
CN102404339A
Method and device for managing firewall
CN115001964A