Backup method, device, electronic device and storage medium

By establishing a wireless RBM channel between firewall devices and pairing them using virtual interfaces and backup keys, the problems of device resource occupation and wiring complexity in existing technologies are solved, and efficient and reliable data transmission is achieved.

CN119210995BActive Publication Date: 2025-10-03NEW H3C SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411342734.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-23
Publication Date
2025-10-03
Estimated Expiration
2044-09-23

AI Technical Summary

Technical Problem

In the prior art, the Remote Backup Management (RBM) channel of firewall devices is mainly implemented by multiple physical connections and interfaces, which takes up device resources, is easily damaged, affects transmission efficiency, and increases wiring complexity.

Method used

By establishing wireless transmission RBM channels between firewall devices and pairing them using virtual interfaces and backup keys, key configuration information, service table information, and RBM system status information can be synchronized, reducing the use of device interface resources and minimizing the impact of physical connection damage.

Benefits of technology

It achieves data transmission reliability and security between firewall devices, reduces the complexity of device wiring, and reduces the impact of physical connections on transmission efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119210995B_ABST
    Figure CN119210995B_ABST
Patent Text Reader

Abstract

The present application provides a backup method, apparatus, electronic device, and storage medium. The method is applied to a first firewall device serving as the primary device in a backup group, which also includes a second firewall device serving as the backup device. The method comprises: generating a pairing request message and broadcasting the pairing request message within the current subnet; upon receiving a pairing response message returned by the second firewall device, establishing an RBM channel between the first firewall device and the second firewall device; and synchronizing key configuration information, service table information, and RBM system status information based on the RBM channel. The method implements an RBM channel between the two firewall devices using wireless transmission technology, reducing the occupation of device interface resources and minimizing the impact of actual physical connection damage on transmission efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a backup method, device, electronic device, and storage medium. Background Art

[0002] Firewalls are a critical component of modern network security systems. To ensure high availability, two firewalls are typically deployed at key network locations to serve as backup devices. Remote Backup Management (RBM) technology enables hot standby between two devices. RBM provides an RBM channel for information synchronization between the two devices. However, this implementation currently relies on multiple physical cables and interfaces between the two devices. This approach consumes device interface resources, is susceptible to damage, and can affect channel transmission efficiency. It also increases the complexity of device wiring. Summary of the Invention

[0003] To overcome the problems existing in the related art, the present application provides a backup method, device, electronic device and storage medium.

[0004] According to a first aspect of an embodiment of the present application, a backup method is provided. The method is applied to a first firewall device serving as a primary device in a backup group, wherein the backup group also includes a second firewall device serving as a backup device. The method includes:

[0005] Generate a pairing request message including a backup key and a first address, and broadcast the pairing request message in the current subnet, where the first address is the IP address of the virtual interface of the first firewall device;

[0006] Upon receiving the pairing response message, determining whether the backup key and IP address included in the pairing response message are identical to the locally recorded backup key and second address, wherein the second address is the IP address of the virtual interface of the second firewall device, the first address and the second address belong to the same subnet segment, and the pairing response message is generated and sent by the second firewall device to the first firewall device after determining that the backup key and IP address included in the pairing request message are identical to the backup key and first IP address recorded by the second firewall device;

[0007] If the judgment result is yes, creating a remote backup management RBM channel between the first firewall device and the second firewall device according to the first address and the second address;

[0008] Based on the RBM channel, key configuration information, service entry information, and RBM system status information are synchronized between the first firewall device and the second firewall device.

[0009] According to a second aspect of an embodiment of the present application, a backup device is provided. The device is applied to a first firewall device serving as a primary device in a backup group, the backup group also including a second firewall device serving as a backup device. The device includes:

[0010] a pairing request module, configured to generate a pairing request message including a backup key and a first address, and broadcast the pairing request message in a current subnet, wherein the first address is the IP address of the virtual interface of the first firewall device;

[0011] a determination module, configured to, upon receiving a pairing response message, determine whether a backup key and an IP address included in the pairing response message are identical to a locally recorded backup key and a second address, wherein the second address is the IP address of a virtual interface of the second firewall device, the first address and the second address belong to the same subnet segment, and the pairing response message is generated and sent by the second firewall device to the first firewall device after determining that the backup key and the IP address included in the pairing request message are identical to the backup key and the first IP address recorded by the second firewall device;

[0012] a creation module configured to, when the judgment result is yes, create a remote backup management (RBM) channel between the first firewall device and the second firewall device according to the first address and the second address;

[0013] A synchronization module is used to synchronize key configuration information, service table information, and RBM system status information between the first firewall device and the second firewall device based on the RBM channel.

[0014] According to a third aspect of an embodiment of the present application, an electronic device is provided, comprising a processor and a machine-readable storage medium, wherein the machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor is prompted by the machine-executable instructions to implement the steps of the backup method described above.

[0015] According to a fourth aspect of an embodiment of the present application, a computer-readable storage medium is provided, wherein a computer program is stored in the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the backup method described above are implemented.

[0016] The technical solutions provided by the embodiments of the present application may have the following beneficial effects:

[0017] In an embodiment of the present application, an RBM channel is implemented by applying wireless transmission technology between two firewall devices. Based on the RBM channel, synchronization of key configuration information, service table information, and RBM system status information between the two firewall devices is achieved, thereby reducing the occupation of device interface resources to a certain extent, reducing the impact of actual physical connection damage on transmission efficiency, ensuring the reliability and security of data transmission, and reducing the complexity of device wiring.

[0018] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0020] Figure 1 A first flow chart of a backup method provided in an embodiment of the present application;

[0021] Figure 2 A schematic diagram of a backup method according to an embodiment of the present invention;

[0022] Figure 3 A second flow chart of a backup method provided in an embodiment of the present application;

[0023] Figure 4 A schematic diagram of a backup device provided in an embodiment of the present application;

[0024] Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0025] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.

[0026] The terms used in this application are for the purpose of describing specific embodiments only and are not intended to limit this application. As used in this application and the appended claims, the singular forms "a," "an," "the," and "the" are intended to include the plural forms, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.

[0027] It should be understood that although the terms first, second, third, etc. may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the words "if" or "if" as used herein may be interpreted as "when" or "when".

[0028] To ensure high availability, modern network security systems typically deploy two devices at key network locations. This reduces the risk of network outages due to single points of failure and improves network reliability. For traditional network devices (such as switches and routers), Layer 2 redundancy and routing table backups are sufficient to ensure uninterrupted service delivery. However, for devices that require stateful packet inspection and policy processing (such as firewalls, intrusion prevention systems, web firewalls, and online behavior auditing), these devices perform a validation check on the first packet of a flow. If the check passes, a session is established. Subsequent packets in the flow are not subject to validation checks and are forwarded only if they match the session; otherwise, the packet is discarded. Therefore, when deploying these devices for reliability, consistency in service table information and key configuration information between the two devices is crucial to ensuring uninterrupted service delivery.

[0029] RBM technology can address these issues, ensuring consistency in configuration and service entry information between the primary and backup devices. RBM provides an RBM channel to transmit RBM system status information, key configuration information, and service entry information between the two devices. However, this channel is currently implemented primarily through multiple physical cables and interfaces between the two devices.

[0030] Next, the embodiments of the present application are described in detail.

[0031] The embodiment of the present application provides a backup method, which is applied to a first firewall device as a primary device in a backup group, and the backup group also includes a second firewall device as a backup device. Figure 1 As shown, the method may include the following steps:

[0032] Step 110: Generate a pairing request message including a backup key and a first address, and broadcast the pairing request message in the current subnet;

[0033] The first address mentioned above refers to the IP address of the virtual interface of the first firewall device.

[0034] Step 120: Upon receiving the pairing response message, determine whether the backup key and IP address included in the pairing response message are the same as the locally recorded backup key and second address; if so, proceed to the next step; otherwise, do nothing;

[0035] The second address is the IP address of the virtual interface of the second firewall device. It should be noted that the first address and the second address belong to the same subnet segment.

[0036] The pairing response message is generated and sent to the first firewall device by the second firewall device after determining that the backup key and IP address included in the pairing request message are the same as the backup key and first IP address recorded by the second firewall device.

[0037] Step 130: Create a remote backup management (RBM) channel between the first firewall device and the second firewall device according to the first address and the second address.

[0038] Step 140: Synchronize key configuration information, service entry information, and RBM system status information between the first firewall device and the second firewall device based on the RBM channel.

[0039] To create an RBM channel, the embodiment of the present application creates a virtual interface on each of the two firewall devices and configures the IP address of the virtual interface so that the virtual interfaces of the two firewall devices are in the same subnet. Specifically, the embodiment of the present application pre-creates a virtual interface on the first firewall device and configures the IP address of the virtual interface to obtain a first address, and then creates a virtual interface on the second firewall device and configures the IP address of the virtual interface to obtain a second address. The first address and the second address are in the same subnet segment. For example, the virtual interface IP of the first firewall device is configured to 192.168.1.1 / 30, and the virtual interface IP of the second firewall device is configured to 192.168.1.2 / 30.

[0040] For the first firewall device, the first address is the local address of the RBM channel to be created. Therefore, in this embodiment of the present application, the remote address of the RBM channel to be created is also specified as the second address on the first firewall device, that is, the IP address of the virtual interface of the second firewall device is specified on the first firewall device. Similarly, for the second firewall device, the second address is the local address of the RBM channel to be created. In this embodiment of the present application, the remote address of the RBM channel to be created is also specified as the first address on the second firewall device, that is, the IP address of the virtual interface of the first firewall device is specified on the second firewall device.

[0041] In addition, this embodiment of the present application also configures backup keys on both firewall devices. The backup key on the first firewall device is identical to the backup key on the second firewall device. The backup key is used for pairing the two firewall devices and for encrypting synchronization data between the two firewall devices, ensuring that synchronization data is transmitted only between the two firewall devices connected by the RBM channel. Specifically, the pairing key can be a 64-bit key.

[0042] Finally, the embodiment of the present application also specifies the roles of the two firewall devices in the backup group, that is, specifies whether each firewall device is a primary device or a backup device in the backup group. The embodiment of the present application is described with the first firewall device as the primary device.

[0043] After the above configuration, if Figure 2 As shown, the first firewall device generates a pairing request message including a backup key and a first address. Using wireless technology, it broadcasts the pairing request message within the current subnet to locate the device at the second address. Upon receiving the pairing request message, the second firewall device verifies that the backup key and IP address included in the pairing request message match the backup key and first IP address recorded by the second firewall device. Pairing is permitted only if the backup key and IP address are identical. Specifically, if they are identical, a pairing response message including the backup key and second address is generated and sent to the first firewall device. If they are not identical, no action is taken.

[0044] like Figure 2 As shown, after receiving the pairing response message, the first firewall device first verifies whether the backup key and IP address included in the pairing response message are identical to the locally recorded backup key and second address. Pairing is allowed only if both the backup key and IP address are identical. Specifically, if the verification result is yes, a remote backup management (RBM) channel is established between the first and second firewall devices based on the first and second addresses. Otherwise, no action is taken.

[0045] At this point, the RBM channel is created. The first firewall device synchronizes key configuration information, service entry information, and RBM system status information between the first firewall device and the second firewall device based on the RBM channel.

[0046] This embodiment of the present application uses an RBM channel to synchronize service table information from the primary device to the backup device to ensure that service is not interrupted after a primary-backup switchover. Specifically, in this embodiment of the present application, the service table information synchronized between the first firewall device and the second firewall device may include the following: session table entries, session association table entries, load balancing persistence table entries, proximity table entries, and domain name system table entries.

[0047] In an embodiment of the present application, the key configuration information on the first firewall device as the primary device is backed up to the second firewall device as the backup device based on the RBM channel, and the corresponding configuration information on the second firewall device as the backup device is overwritten to ensure that the key configuration information is completely consistent on the primary and backup devices, thereby avoiding the service interruption problem caused by the lack of corresponding configuration information on the new primary device during the primary-backup switching. Specifically, in an embodiment of the present application, the key configuration information synchronized between the first firewall device and the second firewall device may include the following: firewall default policy, log function parameters, firewall mode (such as routing mode, transparent mode, hybrid mode, etc.), firewall interface configuration, network address translation configuration, VPN configuration, high availability settings, attack protection settings, etc.

[0048] To ensure reliability, as a preferred implementation, after establishing the RBM channel, the first firewall device also creates a backup RBM channel, achieving dual-channel redundancy. Data transmission between the primary and backup RBM channels is backed up to prevent data transmission interruptions or anomalies between the two firewall devices if an RBM channel anomaly occurs. If an RBM channel anomaly occurs, the backup RBM channel takes over the transmission task. Alternatively, the two RBM channels can simultaneously serve as backups for each other, improving transmission efficiency.

[0049] As a specific implementation method, Figure 3 As shown, the first firewall device can also implement the following steps:

[0050] Step 310: Create an RBM backup channel between the first firewall device and the second firewall device according to the first address and the second address;

[0051] Step 320: When the RBM channel is abnormal, key configuration information, service entry information, and RBM system status information are synchronized between the first firewall device and the second firewall device based on the RBM backup channel.

[0052] In order to ensure the integrity of data transmission during the data transmission process, as a preferred implementation method, the second firewall device locally generates an integrity check value for the synchronized data at intervals of a certain time period or at transmissions of a certain size of data, and compares the generated integrity check value with the received integrity check value. If the comparison is consistent, it indicates that the synchronized data is complete and normal, otherwise it is abnormal. If the verification result is abnormal, the second firewall device sends a message to the first firewall device to retransmit the data.

[0053] As a specific implementation, the second firewall device performs integrity check on the synchronization data when preset conditions are met, where the preset conditions are that the synchronization data size reaches a preset size, the synchronization duration reaches a preset duration, or an integrity check command is received.

[0054] As a specific implementation method, the process of creating an RBM channel specifically includes the following steps: the first firewall device sends a TCP connection request and a channel detection message to the second firewall device based on the first address and the second address; after receiving the TCP connection request and the channel detection message, the second firewall device determines that the channel between the two has been created and performs a channel detection to detect whether the channel is normal, and then generates a detection response message and sends it to the first firewall device; after receiving the detection response message, the first firewall device determines that the remote backup management RBM channel between the first firewall device and the second firewall device has been successfully created.

[0055] As a specific implementation method, the first firewall device determines its role in the backup group in the following manner: when the first address is smaller than the second address, the first firewall device determines its role in the backup group as the active device, and determines the role of the second firewall device in the backup group as the backup device; or, based on the role configuration information, the first firewall device determines its role in the backup group as the active device, and determines the role of the second firewall device in the backup group as the backup device.

[0056] As a specific implementation method, the process of synchronizing information based on the RBM channel specifically includes: using the backup key as the data stream prefix, encapsulating key configuration information, service table item information and RBM system status information into a data stream; transmitting the data stream to the second firewall device through the RBM channel, so that the second firewall device performs a data synchronization operation according to the data stream after determining that the data stream prefix of the data stream is the same as the backup key recorded by the second firewall device, thereby realizing synchronization of key configuration information, service table item information and RBM system status information between the first firewall device and the second firewall device.

[0057] It can be seen from the above technical solution that the embodiment of the present application uses wireless transmission technology between two firewall devices to realize the RBM channel, and based on the RBM channel, the synchronization of key configuration information, service table information and RBM system status information between the two firewall devices is realized. Compared with the wired implementation solution of the RBM channel, this wireless implementation solution of the RBM channel reduces the occupation of device interface resources, reduces the impact of actual physical connection damage on transmission efficiency, and reduces the complexity of device wiring.

[0058] Based on the same inventive concept, the present application also provides a backup device, which is applied to a first firewall device serving as a primary device in a backup group, and the backup group also includes a second firewall device serving as a backup device.

[0059] like Figure 4 As shown, the backup device of the embodiment of the present application specifically includes:

[0060] a pairing request module 410 configured to generate a pairing request message including a backup key and a first address, and broadcast the pairing request message within the current subnet, wherein the first address is the IP address of the virtual interface of the first firewall device;

[0061] a determination module 420 configured to, upon receiving a pairing response message, determine whether a backup key and an IP address included in the pairing response message are identical to a locally recorded backup key and a second address, wherein the second address is the IP address of a virtual interface of the second firewall device, the first address and the second address belong to the same subnet segment, and the pairing response message is generated and sent to the first firewall device by the second firewall device after determining that the backup key and the IP address included in the pairing request message are identical to the backup key and the first IP address recorded by the second firewall device;

[0062] A creation module 430 is configured to, when the judgment result is yes, create a remote backup management (RBM) channel between the first firewall device and the second firewall device according to the first address and the second address;

[0063] The synchronization module 440 is configured to synchronize key configuration information, service entry information, and RBM system status information between the first firewall device and the second firewall device based on the RBM channel.

[0064] As a specific embodiment, the device further includes:

[0065] A first configuration module is used to create a virtual interface and configure an IP address of the virtual interface to obtain a first address;

[0066] A second configuration module is used to obtain the IP address of the virtual interface of the second firewall device to obtain a second address;

[0067] The third configuration module is used to configure the backup key.

[0068] As a specific embodiment, the device further includes:

[0069] a redundancy creation module, configured to create an RBM backup channel between the first firewall device and the second firewall device according to the first address and the second address;

[0070] A redundant synchronization module is used to synchronize key configuration information, service table information, and RBM system status information between the first firewall device and the second firewall device based on the RBM backup channel when the RBM channel is abnormal.

[0071] As a specific implementation, the creation module 430 specifically includes:

[0072] A first creating unit, configured to send a TCP connection request and a channel detection message to the second firewall device according to the first address and the second address;

[0073] The second creating unit is configured to determine that the remote backup management (RBM) channel between the first firewall device and the second firewall device is successfully created after receiving the detection response message returned by the second firewall device.

[0074] As a specific embodiment, the device further includes:

[0075] A role determination module is used to determine its own role in the backup group in the following manner: when the first address is smaller than the second address, determining its own role in the backup group as the active device, and determining the role of the second firewall device in the backup group as the backup device; or, based on role configuration information, determining its own role in the backup group as the active device, and determining the role of the second firewall device in the backup group as the backup device.

[0076] As a specific implementation, the synchronization module 440 specifically includes:

[0077] A first synchronization unit, configured to encapsulate key configuration information, service entry information, and RBM system status information into a data stream using the backup key as a data stream prefix;

[0078] a second synchronization unit, configured to transmit the data stream to the second firewall device through the RBM channel, so that the second firewall device performs a data synchronization operation according to the data stream after determining that the data stream prefix of the data stream is the same as the backup key recorded by the second firewall device, thereby achieving synchronization of key configuration information, service table item information, and RBM system status information between the first firewall device and the second firewall device.

[0079] The present application also provides an electronic device, such as Figure 5 As shown, it includes a processor 510 and a machine-readable storage medium 520, wherein the machine-readable storage medium 520 stores machine-executable instructions that can be executed by the processor 510, and the processor 510 is prompted by the machine-executable instructions to implement the steps of any of the above backup methods.

[0080] The machine-readable storage medium may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Alternatively, the machine-readable storage medium may be at least one storage device located remote from the processor.

[0081] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components.

[0082] In another embodiment provided by the present application, a computer-readable storage medium is further provided, in which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above backup methods are implemented.

[0083] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A backup method, characterized in that: The method is applied to a first firewall device serving as a primary device in a backup group, wherein the backup group also includes a second firewall device serving as a backup device, and the method includes: Generate a pairing request message including a backup key and a first address, and broadcast the pairing request message in the current subnet, where the first address is the IP address of the virtual interface of the first firewall device; Upon receiving the pairing response message, determining whether the backup key and IP address included in the pairing response message are identical to the locally recorded backup key and second address, wherein the second address is the IP address of the virtual interface of the second firewall device, the first address and the second address belong to the same subnet segment, and the pairing response message is generated and sent by the second firewall device to the first firewall device after determining that the backup key and IP address included in the pairing request message are identical to the backup key and first IP address recorded by the second firewall device; If the judgment result is yes, creating a remote backup management RBM channel between the first firewall device and the second firewall device according to the first address and the second address; Based on the RBM channel, key configuration information, service entry information, and RBM system status information are synchronized between the first firewall device and the second firewall device.

2. The method according to claim 1, characterized in that Before generating the pairing request message including the backup key and the first address, the method further includes: Creating a virtual interface and configuring an IP address for the virtual interface to obtain a first address; Obtaining the IP address of the virtual interface of the second firewall device to obtain a second address; Configure the backup key.

3. The method according to claim 1, characterized in that After creating a remote backup management (RBM) channel between the first firewall device and the second firewall device according to the first address and the second address, the method further includes: Creating an RBM backup channel between the first firewall device and the second firewall device according to the first address and the second address; When the RBM channel is abnormal, key configuration information, service entry information, and RBM system status information are synchronized between the first firewall device and the second firewall device based on the RBM backup channel.

4. The method according to claim 1, wherein The step of establishing a remote backup management (RBM) channel between the first firewall device and the second firewall device according to the first address and the second address specifically includes: Sending a TCP connection request and a channel detection message to the second firewall device according to the first address and the second address; After receiving the detection response message returned by the second firewall device, it is determined that the remote backup management RBM channel between the first firewall device and the second firewall device is successfully established.

5. The method according to claim 1, wherein The method further comprises: The role of the backup group is determined by: When the first address is smaller than the second address, the firewall device determines its own role in the backup group as a master device, and determines the role of the second firewall device in the backup group as a backup device; or According to the role configuration information, the role of the firewall device itself in the backup group is determined to be a master device, and the role of the second firewall device in the backup group is determined to be a backup device.

6. The method according to claim 1, characterized in that Synchronizing key configuration information, service entry information, and RBM system status information between the first firewall device and the second firewall device based on the RBM channel, specifically including: Using the backup key as a data stream prefix, key configuration information, service table information, and RBM system status information are encapsulated into a data stream; The data stream is transmitted to the second firewall device through the RBM channel, so that the second firewall device performs a data synchronization operation according to the data stream after determining that the data stream prefix of the data stream is the same as the backup key recorded by the second firewall device, so as to achieve synchronization of key configuration information, service table item information and RBM system status information between the first firewall device and the second firewall device.

7. A backup device, characterized in that: The device is applied to a first firewall device as a primary device in a backup group, wherein the backup group also includes a second firewall device as a backup device, and the device includes: a pairing request module, configured to generate a pairing request message including a backup key and a first address, and broadcast the pairing request message in a current subnet, wherein the first address is the IP address of the virtual interface of the first firewall device; a determination module, configured to, upon receiving a pairing response message, determine whether a backup key and an IP address included in the pairing response message are identical to a locally recorded backup key and a second address, wherein the second address is the IP address of a virtual interface of the second firewall device, the first address and the second address belong to the same subnet segment, and the pairing response message is generated and sent by the second firewall device to the first firewall device after determining that the backup key and the IP address included in the pairing request message are identical to the backup key and the first IP address recorded by the second firewall device; a creation module configured to, when the judgment result is yes, create a remote backup management (RBM) channel between the first firewall device and the second firewall device according to the first address and the second address; A synchronization module is used to synchronize key configuration information, service table information, and RBM system status information between the first firewall device and the second firewall device based on the RBM channel.

8. The device according to claim 7, characterized in that The device further comprises: a redundancy creation module, configured to create an RBM backup channel between the first firewall device and the second firewall device according to the first address and the second address; A redundant synchronization module is used to synchronize key configuration information, service table information, and RBM system status information between the first firewall device and the second firewall device based on the RBM backup channel when the RBM channel is abnormal.

9. An electronic device, characterized in that: The method comprises a processor and a machine-readable storage medium, wherein the machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor is prompted by the machine-executable instructions to implement the method steps according to any one of claims 1 to 6.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Method and device for updating ARP (Address Resolution Protocol) information table

    CN102904818A

  • Backup information sending method and device

    CN105591810A