Address allocation test method, device, equipment and storage medium

CN117714354BActive Publication Date: 2026-09-15BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311660313.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-05
Publication Date
2026-09-15
Estimated Expiration
2043-12-05

AI Technical Summary

Technical Problem

[0005]本申请实施例的目的是提供一种地址分配测试方法、装置、设备及存储介质,用以解决现有的DHCP地址池内IP地址分配测试技术未对IP地址分配是否冲突、续约是否成功进行测试导致测试不充分的技术问题

Benefits of technology

[0040] The address allocation test apparatus as described in the second aspect.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117714354B_ABST
    Figure CN117714354B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of network communication, and discloses an address allocation test method, an address allocation test device, an address allocation test equipment and a storage medium.The address allocation test method comprises the following steps: controlling a client device and a firewall device through a terminal device, collecting and summarizing test data, analyzing test results, testing IP address allocation in a DHCP address pool of the firewall device from multiple aspects and multiple angles, and supplementarily testing multiple test points, such as the correctness and effectiveness of an IP address in the DHCP address pool acquired by different service boards of the firewall device from the client device, the correctness of renewal of the same IP address on different service boards, whether IP addresses allocated by the same service board and different service boards conflict, and the correctness of release of IP addresses by the client device to different service boards, so that the test accuracy and coverage are improved, and the test is more sufficient.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network communication technology, and specifically to an address allocation testing method, apparatus, device, and storage medium. Background Technology

[0002] DHCP (Dynamic Host Configuration Protocol) is a local area network protocol that refers to a server controlling a range of IP (Internet Protocol) addresses. When a client device logs into the server, it can automatically obtain an IP address and subnet mask assigned by the server. Traditional single-board firewall devices use a single service board to handle all DHCP requests from client devices, uniformly assigning IP addresses to client devices and handling renewal requests.

[0003] The existing method for testing IP address allocation within a DHCP address pool is as follows: A secure connection is established between a simulated client device and an SSL (Secure Socket Layer) VPN (Virtual Private Network) server, using the standard SSL protocol to encrypt transmitted data packets; the SSL VPN server assigns an IP address to the client device; it is then determined whether the client device's IP address is within the valid address range configured by the server; if it is, the test passes; otherwise, it fails. The client device releases the IP address, and the server checks whether it reclaims the IP address; if reclamation is successful, the test passes; otherwise, it fails. It can be seen that the existing testing technology focuses on testing the effectiveness of address allocation and the stability of address release, without specifically testing for IP address conflicts or successful renewals. This method is suitable for single-board firewall devices.

[0004] However, unlike traditional single-board firewall devices, distributed firewall devices have multiple relatively independent service boards. Different DHCP request packets from client devices are distributed to different service boards, each handling the client device's DHCP requests independently, and all service boards share the same address pool. Furthermore, distributed firewall devices can perform service backups between different service boards; when one service board goes offline, the renewal requests originally handled by that board will be handled by other service boards. Therefore, existing DHCP address pool-based IP address allocation testing techniques cannot meet the testing requirements of distributed firewall devices, necessitating a suitable testing method for DHCP address pool-based IP address allocation in distributed firewall devices. Summary of the Invention

[0005] The purpose of this application is to provide an address allocation testing method, apparatus, device, and storage medium to solve the technical problem that existing DHCP address pool IP address allocation testing technologies do not test whether IP address allocation conflicts or renewals are successful, resulting in insufficient testing.

[0006] To achieve the above objectives, the first aspect of this application provides an address allocation testing method applied to a terminal device. The address allocation testing method includes:

[0007] The control client device sends a first number of Dynamic Host Configuration Protocol (DHCP) request messages to the firewall device, so that the firewall device allocates Internet Protocol (IP) addresses from its DHCP address pool to the client device according to the first number of DHCP request messages, wherein the first number is the number of service boards included in the firewall device;

[0008] The first test result is determined based on the first IP address information assigned to the client device and the first IP address allocation information recorded by all service boards of the firewall device.

[0009] When any one of the service boards of the firewall device is offline and all IP address leases obtained by the client device have expired, the client device is controlled to send a first number of DHCP renewal request messages to the firewall device, so that the firewall device will allocate IP addresses in the DHCP address pool of the firewall device to the client device according to the first number of DHCP renewal request messages.

[0010] The second test result is determined based on the second IP address information assigned to the client device and the second IP address allocation information recorded by all service boards of the firewall device.

[0011] The control client device sends a second number of DHCP request messages to the firewall device, so that the firewall device assigns IP addresses from its DHCP address pool to the client device based on the second number of DHCP request messages, wherein the second number is greater than the number of IP addresses in the firewall device's DHCP address pool;

[0012] The third test result is determined based on the third IP address information assigned to the client device and the third IP address allocation information recorded by all service boards of the firewall device.

[0013] Control the client device to release a third number of IP addresses, where the third number is the number of IP addresses in the firewall device's DHCP address pool;

[0014] The fourth test result is determined based on the fourth IP address information released by the client device and the fourth IP address allocation information recorded by all service boards of the firewall device.

[0015] The final test result is determined based on the results of the first test, the second test, the third test, and the fourth test.

[0016] In this embodiment of the application, the first test result is determined based on the first IP address information assigned to the client device and the first IP address allocation information recorded by all service boards of the firewall device, including:

[0017] Obtain the IP address from the firewall device's DHCP address pool;

[0018] Obtain the first IP address information assigned to the client device and the first IP address allocation information recorded by all service boards of the firewall device, wherein the first IP address information includes the IP address corresponding to the client device;

[0019] If the client device is successfully assigned an IP address, the IP address is within the range of IP addresses in the DHCP address pool, and the first IP address information corresponds to the first IP address allocation information, then the first test result is determined to be a successful test.

[0020] In this embodiment of the application, the second test result is determined based on the second IP address information assigned to the client device and the second IP address allocation information recorded by all service boards of the firewall device, including:

[0021] Obtain the second IP address information assigned to all client devices and the second IP address allocation information recorded by all service boards of the firewall device. The second IP address information includes the IP address corresponding to the client device.

[0022] If the IP address assigned to the client device remains unchanged, the DHCP renewal request packets originally routed to the offline service board are successfully routed to its corresponding backup service board, the DHCP renewal request packets originally routed to other service boards are still routed to the corresponding service board, and the second IP address information corresponds to the second IP address allocation information, then the second test result is determined to be a successful test.

[0023] In this embodiment of the application, the third test result is determined based on the third IP address information assigned to the client device and the third IP address allocation information recorded by all service boards of the firewall device, including:

[0024] Obtain the IP addresses from the firewall device's DHCP address pool;

[0025] Obtain the third IP address information assigned to the client device and the third IP address allocation information recorded by all service boards of the firewall device. The third IP address information includes the IP address corresponding to the client device, and the third IP address allocation information includes the IP address, number of leases, and number of logs assigned to the client device by each service board.

[0026] If the client device successfully obtains a third number of IP addresses, and these IP addresses are all within the range of IP addresses in the DHCP address pool and are all different from each other, and a fourth number of DHCP request messages fail to obtain a corresponding IP address, and the IP addresses assigned to the client device by each service board are not duplicated, and the IP addresses assigned to the client device by different service boards are not duplicated, and the sum of the number of leases and the sum of the number of logs are equal to the third number, and the third IP address information corresponds to the third IP address allocation information, then the third test result is determined to be a successful test. Here, the third number is the number of IP addresses in the DHCP address pool of the firewall device, and the fourth number is the difference between the second number and the third number.

[0027] In this embodiment of the application, the fourth test result is determined based on the fourth IP address information released by the client device and the fourth IP address allocation information recorded by all service boards of the firewall device, including:

[0028] Obtain the IP address occupancy status within the firewall device's DHCP address pool;

[0029] Obtain the fourth IP address information released by the client device and the fourth IP address allocation information recorded by all service boards of the firewall device. The fourth IP address information includes the IP address corresponding to the client device, and the fourth IP address allocation information includes the IP address, number of leases, and number of logs allocated to the client device by each service board.

[0030] If all IP addresses on the client devices are successfully released, all IP addresses in the firewall device's DHCP address pool are reclaimed, the number of leases on all service boards is zero, and the total number of logs equals the third quantity, then the fourth test result is considered a pass.

[0031] In this embodiment of the application, controlling the client device to release a third number of IP addresses includes:

[0032] Control the client device to send a third number of DHCP release IP address request messages to the firewall device; or

[0033] The third number of IP addresses on the control client device are prevented from sending DHCP renewal request messages to the firewall device after their leases expire.

[0034] In this embodiment of the application, the final test result is determined based on the first test result, the second test result, the third test result, and the fourth test result, including:

[0035] If the first, second, third, and fourth test results are all passed, the final test result is determined to be a pass.

[0036] A second aspect of this application provides an address allocation testing apparatus, comprising:

[0037] The memory is configured to store instructions; and

[0038] The processor is configured to retrieve instructions from memory and, when executing instructions, to implement the address allocation test method as described in the first aspect.

[0039] A third aspect of this application provides a terminal device, comprising:

[0040] The address allocation test apparatus as described in the second aspect.

[0041] A fourth aspect of this application provides a machine-readable storage medium storing instructions that cause a machine to perform the address allocation test method as described in the first aspect.

[0042] The above technical solution enables testing of IP address allocation within the DHCP address pool of firewall devices from multiple perspectives. It supplements the testing with multiple test points, including the correctness and effectiveness of client devices obtaining IP addresses from different service boards of the firewall device, the correctness of renewing the same IP address on different service boards, whether there are conflicts between IP addresses allocated to the same and different service boards, and the correctness of client devices releasing IP addresses to different service boards. This improves the accuracy and coverage of the tests, making the testing more comprehensive.

[0043] Other features and advantages of the embodiments of this application will be described in detail in the following detailed description section. Attached Figure Description

[0044] The accompanying drawings are provided to further illustrate the embodiments of this application and form part of the specification. They are used together with the following detailed description to explain the embodiments of this application, but do not constitute a limitation on the embodiments of this application. In the drawings:

[0045] Figure 1 The illustration shows a flowchart of an address allocation test method according to an embodiment of this application;

[0046] Figure 2A schematic block diagram of a test system according to an embodiment of this application is shown.

[0047] Explanation of reference numerals in the attached figures

[0048] 200 Test System 210 Terminal Equipment

[0049] 220 Client devices 230 Firewall devices Detailed Implementation

[0050] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only for illustration and explanation of the embodiments of this application and are not intended to limit the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0051] It should be noted that if the embodiments of this application involve directional indicators (such as up, down, left, right, front, back, etc.), the directional indicators are only used to explain the relative positional relationship and movement of the components in a certain specific posture (as shown in the figure). If the specific posture changes, the directional indicators will also change accordingly.

[0052] Furthermore, if the embodiments of this application involve descriptions such as "first" or "second," these descriptions are for descriptive purposes only and should not be construed as indicating or implying their relative importance or implicitly specifying the number of technical features indicated. Therefore, features defined with "first" or "second" may explicitly or implicitly include at least one of those features. Additionally, the technical solutions of various embodiments can be combined with each other, but this must be based on the ability of those skilled in the art to implement them. If the combination of technical solutions is contradictory or impossible to implement, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection claimed in this application.

[0053] Figure 1 The illustration shows a flowchart of an address allocation testing method according to an embodiment of this application. Figure 1 As shown in the embodiments of this application, an address allocation test method is provided, which is applied to a terminal device. Further, the terminal device belongs to the test system. Figure 2 A schematic block diagram of a test system according to an embodiment of this application is shown. Figure 2As shown in this embodiment, the test system 200 includes a terminal device 210, a client device 220, and a firewall device 230. The client device 220 and the firewall device 230 are directly connected to enable mutual communication. The client device 220 sends various DHCP request messages to the firewall device 230. The terminal device 210 can control the client device 220 and the firewall device 230, collect and summarize test data, analyze test results, and control the progress of the test. Please refer to... Figure 1 The address allocation test method includes the following steps:

[0054] Step S110: Control the client device to send a first number of Dynamic Host Configuration Protocol (DHCP) request messages to the firewall device, so that the firewall device allocates Internet Protocol (IP) addresses from its DHCP address pool to the client device according to the first number of DHCP request messages, wherein the first number is the number of service boards included in the firewall device.

[0055] Assigning a correct and valid IP address to a client device is the fundamental function of IP address allocation within the DHCP address pool, and it is also the prerequisite for the implementation of all other functions.

[0056] In this embodiment, terminal device 210 controls client device 220 to send a first number of DHCP request messages to firewall device 230. To ensure that all service boards of firewall device 230 are tested, the first number is set to the number of service boards included in the firewall device. This can be understood as simulating a first number of clients sending DHCP request messages to firewall device 230 on one client device 220. Firewall device 230 includes at least one service board. The DHCP request message first arrives at the switching board. The switching board performs hash routing based on the source and destination IP of the message, and routes the DHCP request message to the corresponding service board for processing. Different client requests are routed to different service boards, and each service board allocates IP addresses in the DHCP address pool to each client.

[0057] Specifically, this embodiment of the application illustrates the case where the firewall device 230 includes 4 service boards and has 30 IP addresses in its DHCP address pool. In this case, step S110 involves simulating 4 clients sending DHCP request messages to the firewall device 230 on a client device 220, so that the firewall device 230 allocates IP addresses in its DHCP address pool to the 4 clients based on the 4 DHCP request messages.

[0058] Step S120: Determine the first test result based on the first IP address information assigned to the client device and the first IP address allocation information recorded by all service boards of the firewall device.

[0059] After assigning IP addresses from the DHCP address pool of firewall device 230 to client device 220, the correctness and validity of the address assignment need to be tested to obtain the first test result.

[0060] Specifically, in this embodiment of the application, step S120 includes:

[0061] Step S121: Obtain the IP addresses in the DHCP address pool of the firewall device.

[0062] To determine the validity of the address allocation, that is, to determine whether the IP address assigned to the client device 220 is valid and within the range of IP addresses in the DHCP address pool, it is necessary to first obtain the IP address in the DHCP address pool of the firewall device 230.

[0063] Specifically, in this embodiment of the application, it is necessary to obtain 30 IP addresses in the DHCP address pool. Please refer to Table 1, which schematically shows the IP addresses in the DHCP address pool of the firewall device provided in this embodiment of the application.

[0064] Table 1

[0065] 20.1.1.1 20.1.1.2 20.1.1.3 20.1.1.4 20.1.1.5 20.1.1.6 20.1.1.7 20.1.1.8 20.1.1.9 20.1.1.10 20.1.1.11 20.1.1.12 20.1.1.13 20.1.1.14 20.1.1.15 20.1.1.16 20.1.1.17 20.1.1.18 20.1.1.19 20.1.1.20 20.1.1.21 20.1.1.22 20.1.1.23 20.1.1.24 20.1.1.25 20.1.1.26 20.1.1.27 20.1.1.28 20.1.1.29 20.1.1.30

[0066] Step S122: Obtain the first IP address information assigned to the client device and the first IP address allocation information recorded by all service boards of the firewall device, wherein the first IP address information includes the IP address corresponding to the client device.

[0067] Terminal device 210 needs to collect and summarize test data and analyze test results. The test data refers to the first IP address information assigned to client device 220 and the first IP address allocation information recorded by all service boards of firewall device 230. The first IP address information assigned to client device 220 includes the IP address corresponding to client device 220. The first IP address information and the first IP address allocation information are analyzed in detail in order to obtain the first test result.

[0068] Specifically, in this embodiment, the first IP address information of the four clients simulated by the client device 220 and the first IP address allocation information recorded by the four service boards of the firewall device 230 are obtained. The first IP address information may also include the MAC address corresponding to the client device 220. The first IP address allocation information may include the MAC address, IP address and corresponding lease time assigned to the client device 220 by the firewall device 230. Please refer to Tables 2 and 3. Table 2 schematically shows the first IP address information of the four clients simulated by the client device 220, and Table 3 schematically shows the first IP address allocation information recorded by the four service boards of the firewall device 230.

[0069] Table 2

[0070] Client 1 9C-7B-EF-4D-BC-01 20.1.1.20 Client 2 9C-7B-EF-4D-BC-02 20.1.1.5 Client 3 9C-7B-EF-4D-BC-03 20.1.1.17 Client 4 9C-7B-EF-4D-BC-04 20.1.1.28

[0071] Table 3

[0072]

[0073]

[0074] Furthermore, the correctness and effectiveness of the client device 220 obtaining IP addresses from the DHCP address pool of different service boards of the firewall device 230 after the lease expires and is successfully renewed can be tested. Please refer to Tables 4 and 5. Table 4 schematically shows the first IP address information assigned to the four clients simulated by the client device 220 after the lease expires and is successfully renewed. Table 5 schematically shows the first IP address allocation information recorded by the four service boards of the firewall device 230 after the lease expires and is successfully renewed.

[0075] Table 4

[0076] Client 1 9C-7B-EF-4D-BC-01 20.1.1.20 Client 2 9C-7B-EF-4D-BC-02 20.1.1.5 Client 3 9C-7B-EF-4D-BC-03 20.1.1.17 Client 4 9C-7B-EF-4D-BC-04 20.1.1.28

[0077] Table 5

[0078]

[0079] Step S123: If the client device is successfully assigned an IP address, the IP address is within the range of IP addresses in the DHCP address pool, and the first IP address information corresponds to the first IP address allocation information, then the first test result is determined to be a successful test.

[0080] If client device 220 is successfully assigned an IP address within the range of IP addresses in the DHCP address pool, and the first IP address information corresponds to the first IP address allocation information (that is, the IP address assigned to client device 220 by firewall device 230 corresponds to the IP address actually obtained by client device 220), then the test is considered to have met the prior expectations, and the first test result is considered a pass. It is understandable that if any of the aforementioned conditions are not met, the test is considered to have failed, and the test can be terminated.

[0081] Specifically, in this embodiment of the application, referring to Tables 1, 2 and 3, it can be seen that the four clients simulated by the client device 220 were successfully assigned IP addresses, and the assigned IP addresses were within the range of 30 IP addresses in the DHCP address pool. The first IP address allocation information recorded by the four service boards of the firewall device 230 corresponds to the first IP address information assigned to the four simulated clients. The correspondence between MAC address and IP address is consistent in the first IP address information and the first IP address allocation information, which meets expectations. Therefore, the first test result is determined to be a successful test.

[0082] Furthermore, in this embodiment of the application, referring to Tables 4 and 5, it can be seen that after the lease expires and is successfully renewed, the IP addresses assigned to the four clients simulated by the client device 220 do not change, the first IP address allocation information recorded by the four service boards of the firewall device 230 corresponds to the first IP address information assigned to the four simulated clients, the lease time in the first IP address allocation information is also updated, and the test results after the lease expires and is successfully renewed are as expected, and the first test result is determined to be a successful test.

[0083] Step S130: When any service board of the firewall device is offline and all IP address leases obtained by the client device have expired, control the client device to send a first number of DHCP renewal request messages to the firewall device, so that the firewall device will allocate IP addresses in the DHCP address pool of the firewall device to the client device according to the first number of DHCP renewal request messages.

[0084] It is understandable that distributed firewall devices can perform service backups between different service boards. When a service board goes offline, the services that were originally routed to that service board will be routed to its corresponding backup service board, which will continue to process the requests. This means that when a service board goes offline, the DHCP renewal requests that were originally processed by that service board are prone to failure. Therefore, it is necessary to test whether the IP address renewal is successful.

[0085] Specifically, in this embodiment, after the service board 4 of the firewall device 230 is taken offline and all IP address leases obtained by the client device 220 expire, the terminal device 210 controls the client device 220 to send four DHCP renewal request messages to the firewall device 230. The firewall device 230 continues to allocate IP addresses in its DHCP address pool to the client device 220 according to the four DHCP renewal request messages. The service traffic that was originally diverted to the service board 4 is diverted to its backup service board, namely service board 2.

[0086] Step S140: Determine the second test result based on the second IP address information assigned to the client device and the second IP address allocation information recorded by all service boards of the firewall device.

[0087] After taking any one of the service boards of the firewall device offline and renewing all the IP address leases obtained by the client device 220 upon expiration, it is necessary to test the correctness of renewing the same IP address on different service boards to obtain the second test result.

[0088] Specifically, in this embodiment of the application, step S140 includes:

[0089] Step S141: Obtain the second IP address information assigned to all client devices and the second IP address allocation information recorded by all service boards of the firewall device, wherein the second IP address information includes the IP address corresponding to the client device.

[0090] Terminal device 210 obtains the second IP address information assigned after client device 220 sends a DHCP renewal request message, as well as the second IP address allocation information recorded by all service boards of firewall device 230. The second IP address information includes the IP address corresponding to client device 220. The second IP address information and the second IP address allocation information are analyzed in detail to obtain the second test result.

[0091] Specifically, in this embodiment, the second IP address information of the four clients simulated by the client device 220 after the lease expires and is renewed, and the second IP address allocation information recorded by the three service boards of the firewall device 230 are obtained. The second IP address information may also include the MAC address corresponding to the client device 220. The second IP address allocation information may include the MAC address, IP address and corresponding lease time assigned to the client device 220 by the firewall device 230. Please refer to Tables 6 and 7. Table 6 schematically shows the second IP address information of the four clients simulated by the client device 220 after the lease expires and is renewed, and Table 7 schematically shows the second IP address allocation information recorded by the three service boards of the firewall device 230 after the lease expires and is renewed.

[0092] Table 6

[0093] Client 1 9C-7B-EF-4D-BC-01 20.1.1.20 Client 2 9C-7B-EF-4D-BC-02 20.1.1.5 Client 3 9C-7B-EF-4D-BC-03 20.1.1.17 Client 4 9C-7B-EF-4D-BC-04 20.1.1.28

[0094] Table 7

[0095]

[0096] Step S142: If the IP address assigned to the client device has not changed, the DHCP renewal request message originally diverted to the offline service board is successfully diverted to its corresponding backup service board, the DHCP renewal request message originally diverted to other service boards is still diverted to the corresponding service board, and the second IP address information corresponds to the second IP address allocation information, then the second test result is determined to be a successful test.

[0097] After the lease expires and is renewed, the IP address assigned to client device 220 remains unchanged compared to before the lease expires. DHCP renewal request packets originally routed to the offline service board are successfully routed to its corresponding backup service board. DHCP renewal request packets originally routed to other service boards are still routed to their corresponding service boards. Furthermore, the second IP address information corresponds to the second IP address allocation information. In other words, if the IP address assigned to client device 220 by firewall device 230 corresponds to the IP address actually obtained by client device 220, then the test is considered to have met the prior expectations, and the second test result is considered a pass. It is understandable that if any of the aforementioned conditions are not met, the test is considered to have failed, and the test can be terminated.

[0098] Specifically, in this embodiment, referring to Tables 6 and 7, it can be seen that after the lease expires and is renewed, the IP addresses assigned to the four clients simulated by client device 220 do not change, service board 4 is offline, and the DHCP renewal request packets originally diverted to service board 4 are successfully diverted to its backup service board, i.e., service board 2. The DHCP renewal request packets originally diverted to service board 1, service board 2, and service board 3 are still diverted to their respective service boards. The second IP address allocation information recorded by the three service boards of firewall device 230 corresponds to the second IP address information assigned to the four simulated clients. The correspondence between MAC address and IP address is consistent in the second IP address information and the second IP address allocation information, which meets expectations. Therefore, the second test result is determined to be a successful test.

[0099] Step S150: Control the client device to send a second number of DHCP request messages to the firewall device, so that the firewall device assigns IP addresses in the firewall device's DHCP address pool to the client device according to the second number of DHCP request messages, wherein the second number is greater than the number of IP addresses in the firewall device's DHCP address pool.

[0100] Understandably, unlike traditional single-board firewall devices, distributed firewall devices have multiple relatively independent service boards. These service boards distribute traffic load. In a distributed firewall device, after a client device logs into the server, the switching board performs hash-based traffic splitting based on the source and destination IP addresses of the packets. Different DHCP request packets from the client device are distributed to different service boards. Each service board independently processes different DHCP requests from the client device, and all service boards share the same address pool. This can easily lead to IP address conflicts when the firewall device assigns IP addresses to client devices due to IP address reuse. Therefore, it is necessary to test whether there are conflicts in the IP address allocation within the DHCP address pool.

[0101] Specifically, in this embodiment of the application, in order to test whether there is a conflict in the allocation of IP addresses in the DHCP address pool, the number of DHCP request messages sent by the client device 220, that is, the number of simulated clients, is greater than the number of IP addresses in the DHCP address pool of the firewall device 230. Since the number of IP addresses in the DHCP address pool is 30, the terminal device 210 controls the client device 220 to send 35 DHCP request messages to the firewall device 230. That is, the client device 220 simulates 35 clients sending DHCP request messages to the firewall device 230, so that the firewall device 230 allocates the IP addresses in the DHCP address pool of the firewall device 230 to the 35 clients according to the 35 DHCP request messages.

[0102] It should be noted that there is no restriction on the order of execution of steps S110, S130, S150 and the subsequent step S170. For example, step S150 can be executed first and then step S130 can be executed. Therefore, taking the service board 4 of the firewall device 230 offline in step S130 will not affect step S150. The prerequisite for step S150 can still be the initial condition, that is, none of the four service boards of the firewall device 230 have been taken offline and all are working normally.

[0103] Step S160: Determine the third test result based on the third IP address information assigned to the client device and the third IP address allocation information recorded by all service boards of the firewall device.

[0104] After assigning IP addresses from the DHCP address pool of firewall device 230 to client device 220, it is necessary to test whether there are conflicts between IP addresses assigned to the same service board and different service boards to obtain the third test result.

[0105] Specifically, in this embodiment of the application, step S160 includes:

[0106] Step S161: Obtain the IP addresses in the DHCP address pool of the firewall device.

[0107] To test whether there are conflicts between IP addresses assigned to the same or different service boards, it is also necessary to determine the validity of the address allocation, that is, to determine whether the IP address assigned to the client device 220 is valid and within the range of IP addresses in the DHCP address pool. Therefore, it is also necessary to first obtain the IP address in the DHCP address pool of the firewall device 230.

[0108] This application embodiment always uses the example of firewall device 230 including 4 service boards and 30 IP addresses in DHCP address pool for illustration. Therefore, the IP addresses in DHCP address pool of firewall device 230 can be obtained in this step by referring to Table 1, and will not be repeated here.

[0109] Step S162: Obtain the third IP address information assigned to the client device and the third IP address allocation information recorded by all service boards of the firewall device. The third IP address information includes the IP address corresponding to the client device, and the third IP address allocation information includes the IP address, number of leases, and number of logs assigned to the client device by each service board.

[0110] Terminal device 210 obtains the third IP address information assigned to client device 220 after sending a DHCP request message, as well as the third IP address allocation information recorded by all service boards of firewall device 230. The third IP address information includes the IP address corresponding to client device 220, and the third IP address allocation information includes the IP address, number of leases, and number of logs assigned to client device 220 by each service board. The third IP address information and the third IP address allocation information are analyzed in detail to obtain the third test results.

[0111] Specifically, in this embodiment, the third IP address information of 35 clients simulated by client device 220 and the third IP address allocation information recorded by the four service boards of firewall device 230 are obtained. The third IP address information may also include the MAC address corresponding to client device 220, and the third IP address allocation information may also include the MAC address and lease time assigned to client device 220 by firewall device 230. Please refer to Tables 8 and 9. Table 8 schematically shows the third IP address information of 35 clients simulated by client device 220, and Table 9 schematically shows the third IP address allocation information recorded by the four service boards of firewall device 230.

[0112] Table 8

[0113]

[0114]

[0115]

[0116] Table 9

[0117]

[0118]

[0119]

[0120] Step S163: If the client device successfully obtains a third number of IP addresses, the IP addresses are within the range of IP addresses in the DHCP address pool and are all different, the fourth number of DHCP request messages do not obtain the corresponding IP address, the IP addresses assigned to the client device by each service board are not duplicated, the IP addresses assigned to the client device by different service boards are not duplicated, the sum of the number of leases and the sum of the number of logs are equal to the third number, and the third IP address information corresponds to the third IP address allocation information, then the third test result is determined to be a successful test. Here, the third number is the number of IP addresses in the DHCP address pool of the firewall device, and the fourth number is the difference between the second number and the third number.

[0121] Specifically, in this embodiment, referring to Tables 8 and 9, it can be seen that client device 220 successfully obtained 30 IP addresses. That is, 30 out of the 35 clients simulated by client device 220 were assigned IP addresses. These 30 IP addresses are all within the range of IP addresses in the DHCP address pool and are all different from each other. The number of simulated clients is 5 more than the number of IP addresses in the DHCP address pool of the firewall device. Therefore, 5 clients failed to obtain IP addresses. The IP addresses assigned to client device 220 by each service board are not duplicated. Service board 1, service board 2, and service board 3 are all included in the IP address pool. There is no overlap in the IP addresses assigned to client device 220 between service board 3 and service board 4. The total number of leases and log entries corresponding to the four service boards are both equal to 30, which is the number of IP addresses in the firewall device's DHCP address pool. The third IP address allocation information recorded by the four service boards of firewall device 230 corresponds to the third IP address information assigned to the 30 simulated clients that successfully obtained IP addresses. The correspondence between MAC addresses and IP addresses is consistent in the third IP address information and the third IP address allocation information, which meets expectations. Therefore, the third test result is determined to be a pass. It is understandable that if any of the aforementioned conditions are not met, it is considered not to meet the prior expectations, the third test result is determined to be a fail, and the test can be terminated.

[0122] Step S170: Control the client device to release a third number of IP addresses, where the third number is the number of IP addresses in the firewall device's DHCP address pool.

[0123] Successfully releasing IP addresses by client devices is a basic function of IP address allocation within the DHCP address pool. To facilitate the collection and analysis of test data, we control client devices to release all IP addresses, meaning the number of released IP addresses is equal to the number of IP addresses in the firewall device's DHCP address pool.

[0124] It is understandable that the client device can release its IP address in two ways, and step S170 includes:

[0125] Step S170A: Control the client device to send a third number of DHCP release IP address request messages to the firewall device; or

[0126] Step S170B: Control the third number of IP addresses in the client device to not send DHCP renewal request messages to the firewall device after their leases expire.

[0127] Both steps S170A and S170B can enable the client device to release its IP address. The difference is that step S170A is when the client device actively releases its IP address, while step S170B is when the client device passively releases its IP address.

[0128] Specifically, in this embodiment, step S170A can be understood as the terminal device 210 controlling the client device 220 to send 30 DHCP release IP address request messages to the firewall device 230, that is, all 30 clients simulated by the client device 220 release their IP addresses, and the four service boards no longer allocate IP addresses to the 30 clients; step S170B can be understood as the terminal device 210 controlling the 30 clients simulated by the client device 220 to not send DHCP renewal request messages to the firewall device 230 after the lease expires, similarly, all 30 clients simulated by the client device 220 release their IP addresses, and the four service boards no longer allocate IP addresses to the 30 clients.

[0129] Step S180: Determine the fourth test result based on the fourth IP address information released by the client device and the fourth IP address allocation information recorded by all service boards of the firewall device.

[0130] After controlling the client device 220 to release all IP addresses, it is necessary to test the correctness of the client device 220 in releasing IP addresses to different service boards, and obtain the fourth test result.

[0131] Specifically, in this embodiment of the application, step S180 includes:

[0132] Step S181: Obtain the IP address occupancy status in the DHCP address pool of the firewall device.

[0133] After the service board assigns IP addresses from the DHCP address pool to the client device 220, all IP addresses in the DHCP address pool of the firewall device 230 are in a state of being occupied. When the client device 220 releases all IP addresses, all IP addresses in the DHCP address pool of the firewall device 230 are reclaimed. Obtaining the occupancy status of IP addresses in the DHCP address pool of the firewall device 230 can better help with testing.

[0134] Step S182: Obtain the fourth IP address information released by the client device and the fourth IP address allocation information recorded by all service boards of the firewall device. The fourth IP address information includes the IP address corresponding to the client device, and the fourth IP address allocation information includes the IP address, number of leases, and number of logs allocated to the client device by each service board.

[0135] Terminal device 210 obtains the fourth IP address information released by client device 220 and the fourth IP address allocation information recorded by all service boards of firewall device 230. The fourth IP address information includes the IP address corresponding to client device 220, and the fourth IP address allocation information includes the IP address, number of leases, and number of logs allocated to client device 220 by each service board. The terminal device 210 performs a detailed analysis of the fourth IP address information and the fourth IP address allocation information in order to obtain the fourth test result.

[0136] Specifically, in this embodiment, the fourth IP address information released by 30 clients simulated by client device 220 and the fourth IP address allocation information recorded by the four service boards of firewall device 230 are obtained. The fourth IP address information may also include the MAC address corresponding to client device 220. Please refer to Tables 10 and 11. Table 10 schematically shows the fourth IP address information released by 30 clients simulated by client device 220, and Table 11 schematically shows the fourth IP address allocation information recorded by the four service boards of firewall device 230.

[0137] Table 10

[0138]

[0139]

[0140] Table 11

[0141] Business Board 1 0 8 Business Board 2 0 7 Business Board 3 0 8 Business Board 4 0 7

[0142] Step S183: If all IP addresses of the client devices are successfully released, all IP addresses in the DHCP address pool of the firewall devices are reclaimed, the number of leases for all service boards is zero, and the total number of logs is equal to the third quantity, then the fourth test result is determined to be a successful test.

[0143] Specifically, in this embodiment, referring to Tables 10 and 11, it can be seen that the IP addresses of client device 220 were all successfully released, meaning that the IP addresses of the 30 clients simulated by client device 220 were all successfully released. The number of leases for service boards 1, 2, 3, and 4 is 0, indicating that the service boards did not allocate any IP addresses from the DHCP address pool to client device 220. The total number of log entries for IP address release for service boards 1, 2, 3, and 4 is 30, which is equal to the number of IP addresses in the DHCP address pool of the firewall device. In other words, the service boards successfully released all IP addresses in the DHCP address pool, which meets expectations. Therefore, the fourth test result is determined to be a pass. It is understood that if any of the aforementioned conditions are not met, it is considered not to meet prior expectations, the fourth test result is determined to be a fail, and the test can be terminated.

[0144] Step S190: Determine the final test result based on the first test result, the second test result, the third test result, and the fourth test result.

[0145] After all test points have been tested, the final test result needs to be determined based on the test results of each test point, that is, based on the first test result, the second test result, the third test result, and the fourth test result.

[0146] Specifically, in this embodiment of the application, step S190 includes:

[0147] If the first, second, third, and fourth test results are all passed, the final test result is determined to be a pass.

[0148] Understandably, only when the first, second, third, and fourth test results are all passed can the final test result be determined as a pass. Furthermore, if the test result is a fail in any test step, the entire test process can be terminated directly, saving test time, and the final test result will also be determined as a fail.

[0149] The address allocation testing method provided in this application embodiment can test the IP address allocation in the DHCP address pool of the firewall device from multiple aspects and angles. It supplements the test with multiple test points, such as the correctness and effectiveness of the client device obtaining IP addresses from different service boards of the firewall device in the DHCP address pool, the correctness of renewing the same IP address in different service boards, whether there are conflicts between IP addresses allocated by the same service board and different service boards, and the correctness of the client device releasing IP addresses to different service boards. This improves the accuracy and coverage of the test and makes the test more comprehensive.

[0150] Corresponding to the above method embodiments, this application provides an address allocation testing apparatus, including:

[0151] The memory is configured to store instructions; and

[0152] The processor is configured to retrieve instructions from memory and to implement the address allocation test method described above when executing instructions.

[0153] The address allocation testing device provided in this application embodiment can realize each process of the address allocation testing method in the method embodiment and achieve the same technical effect. To avoid repetition, it will not be described again here.

[0154] This application embodiment also provides a terminal device 210, including:

[0155] Such as the address allocation test device described above.

[0156] This application also provides a machine-readable storage medium storing instructions that cause a machine to perform the address allocation test method described above.

[0157] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0158] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0159] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0160] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0161] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0162] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0163] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0164] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0165] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. An address allocation test method, characterized in that, Applied to a terminal device, the method includes: The control client device sends a first number of Dynamic Host Configuration Protocol (DHCP) request messages to the firewall device, so that the firewall device allocates Internet Protocol (IP) addresses from its DHCP address pool to the client device according to the first number of DHCP request messages, wherein the first number is the number of service boards included in the firewall device; The first test result is determined based on the first IP address information assigned to the client device and the first IP address allocation information recorded by all service boards of the firewall device. When any one of the service boards of the firewall device is offline and all IP address leases obtained by the client device have expired, the client device is controlled to send a first number of DHCP renewal request messages to the firewall device, so that the firewall device allocates IP addresses in the DHCP address pool of the firewall device to the client device according to the first number of DHCP renewal request messages. The second test result is determined based on the second IP address information assigned to the client device and the second IP address allocation information recorded by all service boards of the firewall device. The control client device sends a second number of DHCP request messages to the firewall device, so that the firewall device allocates IP addresses in the DHCP address pool of the firewall device to the client device according to the second number of DHCP request messages, wherein the second number is greater than the number of IP addresses in the DHCP address pool of the firewall device; The third test result is determined based on the third IP address information assigned to the client device and the third IP address allocation information recorded by all service boards of the firewall device. Control the client device to release a third number of IP addresses, wherein the third number is the number of IP addresses in the DHCP address pool of the firewall device; The fourth test result is determined based on the fourth IP address information released by the client device and the fourth IP address allocation information recorded by all service boards of the firewall device. The final test result is determined based on the first test result, the second test result, the third test result, and the fourth test result.

2. The address allocation test method according to claim 1, characterized in that, The step of determining the first test result based on the first IP address information assigned to the client device and the first IP address allocation information recorded by all service boards of the firewall device includes: Obtain the IP address from the DHCP address pool of the firewall device; Obtain the first IP address information assigned to the client device and the first IP address allocation information recorded by all service boards of the firewall device, wherein the first IP address information includes the IP address corresponding to the client device; If the client device is successfully assigned an IP address, the IP address is within the range of IP addresses in the DHCP address pool, and the first IP address information corresponds to the first IP address allocation information, then the first test result is determined to be a successful test.

3. The address allocation test method according to claim 1, characterized in that, The step of determining the second test result based on the second IP address information assigned to the client device and the second IP address allocation information recorded by all service boards of the firewall device includes: Obtain the second IP address information assigned to the client device and the second IP address allocation information recorded by all service boards of the firewall device, wherein the second IP address information includes the IP address corresponding to the client device; If the IP address assigned to the client device has not changed, the DHCP renewal request packets originally diverted to the offline service board are successfully diverted to its corresponding backup service board, the DHCP renewal request packets originally diverted to other service boards are still diverted to their corresponding service boards, and the second IP address information corresponds to the second IP address allocation information, then the second test result is determined to be a successful test.

4. The address allocation test method according to claim 1, characterized in that, The process of determining the third test result based on the third IP address information assigned to the client device and the third IP address allocation information recorded by all service boards of the firewall device includes: Obtain the IP address from the DHCP address pool of the firewall device; Obtain the third IP address information assigned to the client device and the third IP address allocation information recorded by all service boards of the firewall device, wherein the third IP address information includes the IP address corresponding to the client device, and the third IP address allocation information includes the IP address, number of leases, and number of logs assigned to the client device by each service board; If the client device successfully obtains a third number of IP addresses, which are all within the range of IP addresses in the DHCP address pool and are all different, and a fourth number of DHCP request messages fail to obtain a corresponding IP address, and the IP addresses assigned to the client device by each service board are not duplicated, and the IP addresses assigned to the client device by different service boards are not duplicated, and the sum of the number of leases and the sum of the number of logs are both equal to the third number, and the third IP address information corresponds to the third IP address allocation information, then the third test result is determined to be a successful test. Here, the third number is the number of IP addresses in the DHCP address pool of the firewall device, and the fourth number is the difference between the second number and the third number.

5. The address allocation test method according to claim 1, characterized in that, The determination of the fourth test result based on the fourth IP address information released by the client device and the fourth IP address allocation information recorded by all service boards of the firewall device includes: Obtain the IP address occupancy status within the DHCP address pool of the firewall device; Obtain the fourth IP address information released by the client device and the fourth IP address allocation information recorded by all service boards of the firewall device, wherein the fourth IP address information includes the IP address corresponding to the client device, and the fourth IP address allocation information includes the IP address, the number of leases, and the number of logs allocated to the client device by each service board; If all IP addresses of the client devices are successfully released, all IP addresses in the DHCP address pool of the firewall device are reclaimed, the number of leases for all service boards is zero, and the total number of logs equals the third quantity, then the fourth test result is determined to be a successful test.

6. The address allocation test method according to claim 1, characterized in that, The control of the client device to release a third number of IP addresses includes: Control the client device to send a third number of DHCP release IP address request messages to the firewall device; or The system controls a third number of IP addresses in the client device to not send DHCP renewal request messages to the firewall device after their leases expire.

7. The address allocation test method according to claim 1, characterized in that, The step of determining the final test result based on the first test result, the second test result, the third test result, and the fourth test result includes: If the first test result, the second test result, the third test result, and the fourth test result are all passed, the final test result is determined to be passed.

8. An address allocation testing device, characterized in that, include: The memory is configured to store instructions; as well as A processor configured to retrieve the instructions from the memory and, when executing the instructions, to implement the address allocation test method according to any one of claims 1 to 7.

9. A terminal device, characterized in that, include: The address allocation testing device according to claim 8.

10. A machine-readable storage medium, characterized in that, The machine-readable storage medium stores instructions for causing the machine to perform the address allocation test method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Address distributing method, client terminal, server and address distributing system

    CN104410727A

  • Method and system for automatically allocating IP (Internet Protocol) and testing in batch

    CN112804368A