Sd-wan policy management method, apparatus, device, and storage medium
Patent Information
- Application Number
- CN202311405557.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-26
- Publication Date
- 2026-08-21
- Estimated Expiration
- 2043-10-26
AI Technical Summary
[0003]但是,目前的SD-WAN策略集中管理方案只支持中央控制器对设备的策略进行集中配置,忽略了设备对自身策略进行个性化配置的需求,导致SD-WAN策略管理的灵活性不高
[0008]在本申请实施例中,通过对网络设备提供自行修改策略的功能并由集中控制器进行生效判定,在集中控制器判定设备修改策略可以生效则对集中管理策略进行同步更新,从而满足了设备的个性化配置策略的需求,提高了SD-WAN策略管理的灵活性。
Smart Images

Figure CN117459413B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of policy management technology, and more specifically, to an SD-WAN policy management method, apparatus, device, and storage medium. Background Technology
[0002] SD-WAN (Software Defined Wide Area Network) is a network technology that decouples network control from traditional hardware routers, centralizing network control and management in a single controller. This centralized management approach allows enterprises to set up policies for address translation, access control, network traffic routing, QoS (Quality of Service) policies, and security controls on a unified platform, thereby achieving easier network configuration, management, and optimization.
[0003] However, current centralized SD-WAN policy management solutions only support centralized configuration of device policies by the central controller, ignoring the need for devices to customize their own policies, resulting in low flexibility in SD-WAN policy management. Summary of the Invention
[0004] The purpose of this application is to provide an SD-WAN policy management method, apparatus, device, and storage medium to improve the flexibility of SD-WAN policy management.
[0005] In a first aspect, embodiments of this application provide an SD-WAN policy management method, executed by a centralized controller, comprising:
[0006] In response to a policy modification request from a target network device, the device policy to be modified by the target network device is obtained from the policy modification request.
[0007] If it is determined that the policy of the device to be activated meets the preset activation conditions, the locally configured centralized management policy is synchronously updated based on the policy of the device to be activated.
[0008] In this embodiment, by providing network devices with the function of modifying their own policies and having the central controller determine the effectiveness, the central controller synchronously updates the centralized management policy when it determines that the modified policy of the device can take effect, thereby meeting the needs of personalized configuration policies of the devices and improving the flexibility of SD-WAN policy management.
[0009] In some possible embodiments, the SD-WAN policy management method further includes:
[0010] If it is determined that the device policy to be activated does not meet the preset activation conditions, then the target device policy corresponding to the target network device is obtained based on the locally configured centralized management policy, and the target device policy is sent to the target network device.
[0011] In this embodiment, when it is determined that the policy requested by the device will not take effect, the corresponding policy configured locally by the central controller is obtained and sent to the device to avoid the situation where the device has no policy to load, thereby further improving the flexibility of SD-WAN policy management.
[0012] In some possible embodiments, the SD-WAN policy management method further includes:
[0013] Based on the connection channel established with the target network device, the currently configured local default policy of the target network device is retrieved;
[0014] The local default policy is compared with the centralized management policy, and an incremental policy is determined based on the comparison results.
[0015] The incremental policy is sent to the target network device so that the target network device can update its currently configured local default policy based on the incremental policy.
[0016] In this embodiment of the application, when the device is connected to the centralized controller, the centralized controller can retrieve the device's local default policy and compare it with the centralized management policy, thereby updating the device's local default policy according to the incremental policy, which further improves the flexibility of SD-WAN policy management.
[0017] In some possible embodiments, the step of retrieving the currently configured local default policy of the target network device based on the connection channel established with the target network device specifically includes:
[0018] When it is determined that the centralized management policy configured locally for the target network device has changed, the local default policy currently configured for the target network device is retrieved based on the connection channel established with the target network device.
[0019] In this embodiment, when the centralized controller determines that the management policy corresponding to the target network device has changed, it immediately pulls the device's local policy and compares it with the centralized management policy and issues an incremental policy, thereby further improving the flexibility of SD-WAN policy management.
[0020] In some possible embodiments, if it is determined that the policy of the device to be activated meets the preset activation conditions, then the locally configured centralized management policy is synchronously updated based on the policy of the device to be activated, specifically as follows:
[0021] If it is determined that the policy of the device to be activated meets the preset activation conditions, the policy activation instruction is fed back to the target network device, and the locally configured centralized management policy is synchronously updated based on the policy of the device to be activated.
[0022] In this embodiment of the application, when it is determined that the policy requested by the device meets the conditions for effectiveness, a policy effectiveness instruction is fed back to enable the device to load the modified policy, thereby further improving the flexibility of SD-WAN policy management.
[0023] In some possible embodiments, determining that the device policy to be activated meets preset activation conditions includes:
[0024] Determine the modification type of the policy modification request, and determine whether the modification type belongs to a preset allowed modification type;
[0025] If so, then the policy for the device to be activated is determined to meet the activation conditions;
[0026] If not, the device policy to be implemented is determined to not meet the conditions for implementation.
[0027] In this embodiment, the reliability of SD-WAN policy management is improved by determining whether the modification type of the policy modification request belongs to the allowed modification type.
[0028] In some possible embodiments, determining that the device policy to be activated meets preset activation conditions includes:
[0029] Determine whether the policy for the device to be activated conflicts with the locally configured centralized management policy;
[0030] If so, then the policy for the device to be activated is determined not to meet the activation conditions;
[0031] If not, then the policy for the device to be activated is determined to meet the activation conditions.
[0032] In this embodiment of the application, the reliability of SD-WAN policy management is improved by determining whether the policy modified by the device conflicts with the centralized management policy configured locally by the centralized controller.
[0033] Secondly, embodiments of this application provide an SD-WAN policy management device applied to a centralized controller, comprising:
[0034] The modification response module is used to respond to the policy modification request of the target network device and obtain the device policy to be modified from the policy modification request.
[0035] The effectiveness determination module is used to synchronously update the locally configured centralized management policy based on the policy of the device to be effective if it is determined that the policy of the device to be effective meets the preset effectiveness conditions.
[0036] Thirdly, embodiments of this application provide a computer-readable storage medium storing a computer program, which, when executed by a processor, can implement the method described in any embodiment of the first aspect.
[0037] Fourthly, embodiments of this application provide a computer program product, which includes a computer program, wherein the computer program, when executed by a processor, can implement the method described in any embodiment of the first aspect.
[0038] Fifthly, embodiments of this application provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, can implement the method described in any embodiment of the first aspect. Attached Figure Description
[0039] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0040] Figure 1 A flowchart illustrating an SD-WAN policy management method provided in an embodiment of this application;
[0041] Figure 2 A flowchart illustrating the local modification policy of a network device provided in an embodiment of this application;
[0042] Figure 3 This is a schematic diagram illustrating the process of the centralized controller incrementally distributing policies to network devices according to an embodiment of this application.
[0043] Figure 4 This is a schematic diagram of the structure of an SD-WAN policy management device provided in an embodiment of this application;
[0044] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0045] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.
[0046] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0047] It should be noted that SD-WAN (Software-Defined Wide Area Network) is a way to build, deploy, and operate enterprise wide area networks. Compared with traditional WAN (Wide Area Network), the network hardware in SD-WAN is virtualized. By separating the network hardware from its control mechanism, the management and operation of the wide area network are simplified, resulting in higher link flexibility and reliability, while also being lower in cost and higher in performance.
[0048] However, current centralized SD-WAN policy management solutions all rely on the management policies of the centralized controller and do not support personalized configuration of network devices according to their own needs. In addition, network devices do not retain policy configurations locally and need to retrieve the full configuration from the centralized controller every time they are powered on, which consumes a lot of transmission resources. Furthermore, when the network device fails to connect to the computer, the network device will not be able to load the relevant policy configuration, resulting in low reliability of network management.
[0049] In view of the problems existing in the above-mentioned prior art, such as Figure 1 As shown, this application embodiment provides an SD-WAN policy management method, executed by a centralized controller, which may include the following steps:
[0050] S1. Respond to the policy modification request from the target network device and obtain the device policy to be modified from the policy modification request.
[0051] It should be noted that the centralized controller is used to centrally manage policies on one or more network devices. Specifically, the centralized controller can configure policies for resource objects (including addresses, zones, times, services, applications, domain names, certificates, etc.), address translation, access control, traffic control, security control, SD-WAN links, link health checks, and SD-WAN routing.
[0052] In this embodiment, each network device can modify its own device policy. After modifying the policy locally, the network device sends a policy modification request to the central controller. The policy modification request contains the modified policy content (the device policy to be effective). In response to the policy modification request of the target network device, the central controller extracts the device policy to be effective and uses it to determine whether the modified policy is allowed to take effect.
[0053] S2. If it is determined that the policy of the device to be activated meets the preset activation conditions, the centralized management policy configured locally will be updated synchronously based on the policy of the device to be activated.
[0054] In some possible embodiments, determining that the device policy to be implemented meets preset activation conditions may include:
[0055] Determine the modification type of the policy modification request and check if the modification type belongs to the preset allowed modification type; if yes, determine that the policy of the device to be implemented meets the conditions for implementation; if no, determine that the policy of the device to be implemented does not meet the conditions for implementation.
[0056] In some possible embodiments, determining that the device policy to be implemented meets preset activation conditions may include:
[0057] Determine whether the policy to be implemented on the device conflicts with the locally configured centralized management policy; if so, determine that the policy to be implemented on the device does not meet the conditions for implementation; otherwise, determine that the policy to be implemented on the device meets the conditions for implementation.
[0058] It should be noted that the centralized controller can pre-configure the conditions for the policy to take effect, which serves as the basis for determining whether the policy modifications made by the device are effective.
[0059] In one embodiment, it can be determined whether the modification type of the policy modification request in this response belongs to a preset allowed modification type, which serves as the basis for determining whether the policy modification by the device is effective. Specifically, the policy modification types include resource object modification, access control modification, address translation modification, and flow control modification, etc. Among them, resource object modification, access control modification, and address translation modification, etc., do not have a substantial impact on network services or traffic, so these modification types are set as allowed modification types. When it is determined that the modification type of the policy modification request belongs to one of these allowed modification types, it is determined that the policy to be implemented meets the conditions for effectiveness, and the policy modification by the device is allowed to take effect.
[0060] In one embodiment, it can also be determined whether the policy of the device to be implemented conflicts with the locally configured centralized management policy, as a basis for determining whether the policy modified by the device is effective. For example, if the whitelist in the policy modified by the network device overlaps with the blacklist in the centralized management policy, it indicates that the policy of the device to be implemented conflicts with the centralized management policy configured locally by the centralized controller, and therefore will not be effective.
[0061] It should be noted that when determining that the policy of the device to be activated meets the activation conditions, the centralized management policy configured locally on the centralized controller needs to be updated synchronously according to the policy of the device to be activated, so as to achieve consistent policy management and ensure the security and reliability of centralized management of device policies.
[0062] Understandably, network devices can configure and save policies locally, eliminating the need to retrieve all policies from the central controller each time the device boots up. Once a network device modifies a policy locally and the central controller determines that it is effective, the network device can load and manage the policy according to its locally configured settings. The network device can confirm the central controller's approval of the policy modification either through a command from the central controller agreeing to the policy's effectiveness, or by setting a waiting time. If no command is received from the central controller rejecting the policy's effectiveness within the waiting time, the network device is assumed to have agreed to the policy's effectiveness.
[0063] Based on this, by providing network devices with the ability to modify their own policies and having the central controller determine whether the policy changes are effective, the central management policy is updated synchronously when the central controller determines that the modified policy is effective. This satisfies the need for personalized configuration policies of devices and improves the flexibility of SD-WAN policy management.
[0064] In some possible embodiments, the SD-WAN policy management method further includes:
[0065] If it is determined that the policy of the device to be activated does not meet the preset activation conditions, the target device policy corresponding to the target network device is obtained based on the locally configured centralized management policy, and the target device policy is sent to the target network device.
[0066] It should be noted that when a network device's self-modified policy does not meet the preset activation conditions, the policy needs to be reissued to override the network device's modified policy. This ensures consistency between the network device's policy and the policy on the central controller and prevents security issues. Specifically, the central controller can retrieve the target device policy corresponding to the target network device from the locally configured centralized management policy based on the target network device's ID, and then reissue the target device policy to the target network device, allowing the target network device to override its local configuration based on the target device policy.
[0067] It should be noted that after receiving the target device policy, the target network device can directly replace the locally saved default policy (the policy modified by the network device itself) with the target device policy, or it can compare the target device policy with the locally saved default policy and modify the locally saved default policy according to the target device policy.
[0068] Based on this, when it is determined that the policy requested by the device will not take effect, the corresponding policy configured locally by the central controller is obtained and sent to the device to avoid the situation where the device has no policy to load. At the same time, it ensures that the policies of the central controller and the network devices are consistent, thereby improving the security and reliability of policy management and further enhancing the flexibility of SD-WAN policy management.
[0069] As an example, the process of modifying policies locally on a network device is as follows: Figure 2 As shown, the main steps are as follows:
[0070] 1. After modifying the policy configuration locally, the network device sends a policy modification request to the central controller and synchronously sends the modified device policy to be effective to the central controller.
[0071] 2. The centralized controller determines whether to apply the policy to the device to be affected based on the preset effective conditions;
[0072] 3. If the policy of the device to be activated is determined to meet the activation conditions, the locally configured centralized management policy will be updated synchronously according to the policy of the device to be activated to ensure the consistency of policies between the centralized controller and the network devices.
[0073] 4. If it is determined that the policy of the device to be activated does not meet the activation conditions, the policy of the target device corresponding to the target network device is obtained from the local machine and sent to the target network device.
[0074] 5. If the network device confirms that the central controller agrees to the policy modification, it will directly load the modified policy; if it receives a target device policy from the central controller, it will update the locally configured default policy based on the target device policy.
[0075] In some possible embodiments, the SD-WAN policy management method may further include:
[0076] The local default policy currently configured on the target network device is retrieved based on the connection channel established with the target network device;
[0077] The local default policy is compared with the centralized management policy, and the incremental policy is determined based on the comparison results.
[0078] The incremental policy is sent to the target network device so that the target network device can update the currently configured local default policy based on the incremental policy.
[0079] It should be noted that network devices can connect to the centralized controller upon startup. After establishing the connection, the centralized controller can retrieve the currently configured local default policies of each network device. Then, the centralized controller compares the local default policies of the network devices with the centralized management policies. If there is an inconsistency between the local default policies and the centralized management policies, an incremental policy can be determined for each network device based on the comparison results. The incremental policy is then distributed to the corresponding network devices so that they can update their currently configured local default policies based on the incremental policy.
[0080] It should be noted that after a network device updates its current local default policy based on an incremental policy, the updated policy can be temporarily not loaded. Instead, the original default policy (which is backed up when the policy is updated) can be loaded. The updated policy will be loaded when the network device is powered on or restarted, thus not affecting the services that the network device was originally running.
[0081] Based on this, when a device is connected to a centralized controller, the centralized controller can retrieve the device's local default policy and compare it with the centralized management policy, thereby updating the device's local default policy according to the incremental policy, further improving the flexibility of SD-WAN policy management.
[0082] As an example, the process of the central controller incrementally distributing policies to network devices is as follows: Figure 3 As shown, the main steps are as follows:
[0083] 1. Configure policies through the configuration page of the centralized controller to generate centralized management policies;
[0084] 2. After the network device is powered on, it establishes a connection with the centralized controller and goes online to the centralized controller;
[0085] 3. The centralized controller retrieves the currently configured local default policies of the network devices through the connection channel, compares them with the centralized management policies, and then sends the incremental policies to the corresponding network devices.
[0086] 4. The network device updates the currently configured local default policy based on the received incremental policy, and can immediately execute the updated policy.
[0087] It should be noted that after a policy is generated in the centralized controller, if the network device is online, the policy will be immediately synchronized to the corresponding network device; if the network device is offline, the policy will be automatically distributed and synchronized to the corresponding network device after the network device comes online.
[0088] In some possible embodiments, the currently configured local default policy of the target network device is retrieved based on the connection channel established with the target network device, specifically:
[0089] When it is determined that the centralized management policy configured locally for the target network device has changed, the local default policy currently configured for the target network device is retrieved based on the connection channel established with the target network device.
[0090] Understandably, a centralized manager typically connects to and manages the policies of multiple network devices. Therefore, excessively fetching the currently configured local default policy from the target network device would waste network resources. Furthermore, when neither the centralized controller nor the network device's policy has changed, it is unnecessary to fetch the other's policy for comparison every time a connection is established.
[0091] It should be noted that after the network device is connected to the central controller, the local default policy currently configured for the target network device can be temporarily not retrieved. When it is determined that the central management policy configured locally by the central manager for the target network device has changed, the local default policy for the target network device is retrieved and compared to obtain the incremental policy. This avoids unnecessary policy retrieval and comparison, saves the computing resources of the central controller, and further improves the flexibility of SD-WAN policy management.
[0092] In some possible embodiments, if it is determined that the policy of the device to be activated meets the preset activation conditions, the locally configured centralized management policy is synchronously updated based on the policy of the device to be activated, specifically as follows:
[0093] If the policy of the device to be activated is determined to meet the preset activation conditions, the policy activation instruction is fed back to the target network device, and the locally configured centralized management policy is synchronously updated based on the policy of the device to be activated.
[0094] It should be noted that after determining that the policy to be implemented meets the conditions for implementation, the central controller can send a policy implementation instruction to the corresponding target network device, so that the target network device can update the local policy and load the updated policy based on the received policy implementation instruction.
[0095] In addition, in some embodiments, the network device can be configured such that if it does not receive a policy non-effective instruction from the central controller within a preset time after issuing a policy modification request, the policy to be effective is deemed to have met the effective conditions, and the network device automatically updates its local configuration and loads the updated policy.
[0096] Please refer to Figure 4 , Figure 4 This application provides block diagrams illustrating the composition of an SD-WAN policy management device according to some embodiments. It should be understood that this SD-WAN policy management device is similar to the one described above. Figure 1Corresponding to the method embodiments, it can execute the various steps involved in the above method embodiments. The specific functions of the SD-WAN policy management device can be found in the description above. To avoid repetition, detailed descriptions are appropriately omitted here.
[0097] Figure 4 The SD-WAN policy management device includes at least one software function module that can be stored in memory or embedded in the SD-WAN policy management device in the form of software or firmware. The SD-WAN policy management device is used in a centralized controller and includes:
[0098] The modification response module 410 is used to respond to the policy modification request of the target network device and obtain the device policy to be modified from the policy modification request.
[0099] The effectiveness determination module 420 is used to synchronously update the locally configured centralized management policy based on the policy of the device to be effective if it is determined that the policy of the device to be effective meets the preset effectiveness conditions.
[0100] In some possible embodiments, the effectiveness determination module 420 is further configured to:
[0101] If it is determined that the policy of the device to be activated does not meet the preset activation conditions, the target device policy corresponding to the target network device is obtained based on the locally configured centralized management policy, and the target device policy is sent to the target network device.
[0102] In some possible embodiments, the SD-WAN policy management device further includes an incremental distribution module, which is used for:
[0103] The local default policy currently configured on the target network device is retrieved based on the connection channel established with the target network device;
[0104] The local default policy is compared with the centralized management policy, and the incremental policy is determined based on the comparison results.
[0105] The incremental policy is sent to the target network device so that the target network device can update the currently configured local default policy based on the incremental policy.
[0106] In some possible embodiments, the incremental delivery module is specifically used for:
[0107] When it is determined that the centralized management policy configured locally for the target network device has changed, the local default policy currently configured for the target network device is retrieved based on the connection channel established with the target network device.
[0108] In some possible embodiments, the effectiveness determination module 420 is specifically used for:
[0109] If the policy of the device to be activated is determined to meet the preset activation conditions, the policy activation instruction is fed back to the target network device, and the locally configured centralized management policy is synchronously updated based on the policy of the device to be activated.
[0110] In some possible embodiments, the effectiveness determination module 420 is specifically used for:
[0111] Determine the modification type of the policy modification request and determine whether the modification type belongs to the preset allowed modification type;
[0112] If so, the policy for the device to be activated is determined to meet the activation conditions.
[0113] If not, the policy for the device to be activated is determined to not meet the activation conditions.
[0114] In some possible embodiments, the effectiveness determination module 420 is specifically used for:
[0115] Determine whether the policy for the device to be implemented conflicts with the locally configured centralized management policy;
[0116] If so, the policy for the device to be activated is determined not to meet the activation conditions;
[0117] If not, then the policy for the device to be activated is determined to meet the activation conditions.
[0118] It is understood that the above-described device embodiments correspond to the method embodiments of the present invention. The SD-WAN policy management device provided by the embodiments of the present invention can implement the SD-WAN policy management method provided by any one of the method embodiments of the present invention.
[0119] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working process of the device described above can be referred to the corresponding process in the aforementioned method, and will not be elaborated further here.
[0120] like Figure 5 As shown, some embodiments of this application provide an electronic device 500, which includes: a memory 510, a processor 520, and a computer program stored on the memory 510 and executable on the processor 520. When the processor 520 reads the program from the memory 510 via a bus 530 and executes the program, it can implement the methods of any of the embodiments included in the above-described SD-WAN policy management method.
[0121] Processor 520 can process digital signals and can include various computing architectures. For example, it can be a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements multiple instruction set combinations. In some examples, processor 520 can be a microprocessor.
[0122] The memory 510 can be used to store instructions executed by the processor 520 or data related to the execution of instructions. These instructions and / or data may include code for implementing some or all of the functions of one or more modules described in the embodiments of this application. The processor 520 of this disclosure embodiment can be used to execute the instructions in the memory 510 to implement the methods shown above. The memory 510 includes dynamic random access memory, static random access memory, flash memory, optical memory, or other memories well known to those skilled in the art.
[0123] Some embodiments of this application also provide a computer-readable storage medium storing a computer program that, when executed by a processor, describes the method described in the method embodiments.
[0124] Some embodiments of this application also provide a computer program product that, when run on a computer, causes the computer to perform the methods described in the method embodiments.
[0125] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For apparatus embodiments, since they are basically similar to method embodiments, the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0126] It should be understood, in the several embodiments provided in this application, that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative; for example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.
[0127] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0128] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0129] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application. It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.
[0130] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0131] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
Claims
1. An SD-WAN policy management method, characterized in that, Performed by the central controller, including: In response to a policy modification request from a target network device, the device policy to be modified by the target network device is obtained from the policy modification request. If it is determined that the policy of the device to be activated meets the preset activation conditions, the locally configured centralized management policy is synchronously updated based on the policy of the device to be activated. The determination that the policy of the device to be activated meets the preset activation conditions includes: Determine the modification type of the policy modification request, and determine whether the modification type belongs to a preset allowed modification type; If so, then the policy for the device to be activated is determined to meet the activation conditions; If not, the device policy to be implemented is determined to not meet the conditions for implementation.
2. The SD-WAN policy management method according to claim 1, characterized in that, Also includes: If it is determined that the device policy to be activated does not meet the preset activation conditions, then the target device policy corresponding to the target network device is obtained based on the locally configured centralized management policy, and the target device policy is sent to the target network device.
3. The SD-WAN policy management method according to claim 1, characterized in that, Also includes: Based on the connection channel established with the target network device, the currently configured local default policy of the target network device is retrieved; The local default policy is compared with the centralized management policy, and an incremental policy is determined based on the comparison results. The incremental policy is sent to the target network device so that the target network device can update its currently configured local default policy based on the incremental policy.
4. The SD-WAN policy management method according to claim 3, characterized in that, The step of retrieving the currently configured local default policy of the target network device based on the connection channel established with the target network device specifically involves: When it is determined that the centralized management policy configured locally for the target network device has changed, the local default policy currently configured for the target network device is retrieved based on the connection channel established with the target network device.
5. The SD-WAN policy management method according to claim 1, characterized in that, If it is determined that the policy of the device to be activated meets the preset activation conditions, then the locally configured centralized management policy is synchronously updated based on the policy of the device to be activated, specifically as follows: If it is determined that the policy of the device to be activated meets the preset activation conditions, the policy activation instruction is fed back to the target network device, and the locally configured centralized management policy is synchronously updated based on the policy of the device to be activated.
6. The SD-WAN policy management method according to claim 1, characterized in that, The determination that the policy of the device to be activated meets the preset activation conditions includes: Determine whether the policy for the device to be activated conflicts with the locally configured centralized management policy; If so, then the policy for the device to be activated is determined not to meet the activation conditions; If not, then the policy for the device to be activated is determined to meet the activation conditions.
7. An SD-WAN policy management device, characterized in that, Applications in centralized controllers include: The modification response module is used to respond to the policy modification request of the target network device and obtain the device policy to be modified from the policy modification request. The effectiveness determination module is used to synchronously update the locally configured centralized management policy based on the policy of the device to be effective if it is determined that the policy of the device to be effective meets the preset effectiveness conditions. The effectiveness determination module is specifically used for: Determine the modification type of the policy modification request, and determine whether the modification type belongs to a preset allowed modification type; If so, then the policy for the device to be activated is determined to meet the activation conditions; If not, the device policy to be implemented is determined to not meet the conditions for implementation.
8. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, it can implement the SD-WAN policy management method according to any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which, when executed by a processor, performs the SD-WAN policy management method as described in any one of claims 1-6.
Citation Information
Patent Citations
Configuration updating method and device, computer equipment and readable storage medium
CN111654398A
Network feedback in software-defined networks
US20130311675A1