Network management configuration method and device, electronic equipment and storage medium

By configuring address pools and gateway IP addresses for non-central point dedicated lines and generating packet filtering access control lists, the problem of non-central point dedicated lines being unable to be isolated in a star network is solved. Communication isolation of all non-central point dedicated lines and intercommunication between central point dedicated lines are achieved, improving the automation and efficiency of network management configuration.

CN119484026BActive Publication Date: 2025-10-10CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411472211.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-21
Publication Date
2025-10-10
Estimated Expiration
2044-10-21

AI Technical Summary

Technical Problem

The existing MPLS VPN star network management configuration method cannot achieve communication isolation between all non-central point dedicated lines, cannot meet user security isolation requirements, and the automatic construction of interconnection between central point dedicated lines is complex.

Method used

By configuring address pools and gateway IP addresses for non-central point dedicated lines, generating packet filtering access control lists, and prohibiting access between non-central point dedicated lines, communication isolation of all non-central point dedicated lines is achieved, and intercommunication between central point dedicated lines is achieved through address pool planning.

Benefits of technology

It achieves communication isolation between all non-central point dedicated lines, simplifies the interconnection process between central point dedicated lines, reduces manual configuration workload, and improves dedicated line construction efficiency and accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119484026B_ABST
    Figure CN119484026B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a network management configuration method and device, electronic equipment and storage medium. The network management configuration method comprises: obtaining demand parameter information of a to-be-processed private line of a virtual private network; obtaining address pool configuration information of the to-be-processed private line according to the demand parameter information, and generating gateway network protocol IP address configuration information of the to-be-processed private line according to the address pool configuration information; when the to-be-processed private line is a non-central point private line, generating a packet filtering access control list in the direction of a sub-interface of the to-be-processed private line based on the address pool configuration information and the gateway IP address configuration information, the packet filtering access control list being used to indicate that access between non-central point private lines is prohibited; and performing network management configuration on the to-be-processed private line according to the address pool configuration information, the gateway IP address configuration information and the packet filtering access control list. The embodiments of the present application can realize communication isolation between all non-central point private lines.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network technology, and in particular to a network management configuration method, device, electronic device and storage medium. Background Art

[0002] A star network uses a central point dedicated line to connect the network or device as the central node. All other non-central points are individually connected to the central node. The central node uses a centralized communication control strategy. Non-central points cannot communicate directly with each other through the central node. Therefore, network management configuration for a star network must meet the aforementioned characteristics of the star network.

[0003] In the current traditional MPLS (Multiprotocol Label Switching) VPN (Virtual Private Network) star network management configuration method, by configuring paired Export RT (RouteTarget) values ​​and Import RT values ​​for the VPN instances of the central point dedicated line and the PE (Provider Edge) devices where the non-central point dedicated lines are located, route learning isolation between the PEs where the non-central point dedicated lines are located is achieved, achieving the purpose of communication isolation between the non-central point dedicated lines, thereby realizing star networking.

[0004] However, in the above network management configuration method, communication isolation is achieved through routing learning isolation between PEs. Therefore, communication isolation can only be achieved between non-central point dedicated lines under different PEs, while communication isolation cannot be achieved between non-central point dedicated lines under the same PE. Therefore, communication isolation between all non-central point dedicated lines cannot be achieved, and the user's security isolation needs cannot be met. Summary of the Invention

[0005] In view of the above problems, the embodiments of the present application propose a network management configuration method, device, electronic device and storage medium to solve the problem of being unable to achieve communication isolation between all non-central point dedicated lines.

[0006] According to one aspect of an embodiment of the present application, a network management configuration method is provided, the method comprising:

[0007] Obtaining the required parameter information of the pending dedicated line of the virtual private network;

[0008] Acquire the address pool configuration information of the dedicated line to be processed according to the demand parameter information, and generate the gateway network protocol IP address configuration information of the dedicated line to be processed according to the address pool configuration information;

[0009] When the to-be-processed private line is a non-center-point private line, a packet filtering access control list for an ingress direction of a sub-interface of the to-be-processed private line is generated based on the address pool configuration information and the gateway IP address configuration information, and the packet filtering access control list is used to indicate that access between non-center-point private lines is prohibited.

[0010] The to-be-processed private line is configured for network management according to the address pool configuration information, the gateway IP address configuration information, and the packet filtering access control list.

[0011] Optionally, the requirement parameter information includes a group access number; and the address pool configuration information of the to-be-processed private line is obtained according to the requirement parameter information, including: determining whether the to-be-processed private line is a first private line in the virtual private network according to the group access number; configuring address pool configuration information of the to-be-processed private line when the to-be-processed private line is the first private line; and calling address pool configuration information that has been configured for the virtual private network as the address pool configuration information of the to-be-processed private line when the to-be-processed private line is not the first private line.

[0012] Optionally, the address pool includes a virtual private network address pool, a center-point private line address pool, and a non-center-point private line address pool; and the address pool configuration information of the to-be-processed private line is configured, including: configuring a first segment of the virtual private network address pool as a first segment of a specified public network address segment, and a second segment of the virtual private network address pool as the last N bits of a route distinguisher of the virtual private network, where N is a positive integer; configuring a first segment of the center-point private line address pool as the first segment of the specified public network address segment, a second segment of the center-point private line address pool as the last N bits of the route distinguisher of the virtual private network, and a third segment of the center-point private line address pool as a first value used by a last segment of a network management IP address of a provider edge device; configuring a first segment of the non-center-point private line address pool as the first segment of the specified public network address segment, a second segment of the non-center-point private line address pool as the last N bits of the route distinguisher of the virtual private network, and a third segment of the non-center-point private line address pool as a second value used by the last segment of the network management IP address of the provider edge device; and the first value has a smaller usage frequency than the second value in the last segment of the network management IP address of the provider edge device.

[0013] Optionally, the demand parameter information includes the number of dedicated line IP addresses, and the address pool includes a center point dedicated line address pool and a non-center point dedicated line address pool; the gateway network protocol IP address configuration information of the dedicated line to be processed is generated based on the address pool configuration information, including: when the dedicated line to be processed is a center point dedicated line, obtaining a mask with a number of subnet IP addresses greater than or equal to the number of dedicated line IP addresses as the mask of the dedicated line to be processed, and obtaining the first available IP address in the center point dedicated line address pool as the gateway IP address of the dedicated line to be processed; when the dedicated line to be processed is a non-center point dedicated line, dividing the non-center point dedicated line address pool into multiple subnets according to the set number of IP addresses, calculating the mask of the dedicated line to be processed according to the set IP number, and using the first available IP address of the first subnet as the main gateway IP address of the dedicated line to be processed, and the first available IP addresses of the remaining subnets as the sub-gateway IP addresses of the dedicated line to be processed.

[0014] Optionally, the address pool includes a virtual private network address pool and a central point dedicated line address pool; based on the address pool configuration information and the gateway IP address configuration information, a packet filtering access control list for the incoming direction of the sub-interface of the dedicated line to be processed is generated, including: configuring the rules in the packet filtering access control list in the following order: allowing the IP address to access the central point dedicated line address pool, allowing the IP address to access the gateway IP address of the non-central point dedicated line of the virtual private network, denying the IP address to access the virtual private network address pool, and allowing the IP address to access.

[0015] Optionally, the demand parameter information includes networking mode, gateway configuration mode, network topology type, provider edge device port interconnection IP address / subnet mask, and user edge device port interconnection IP address / subnet mask; obtaining the address pool configuration information of the dedicated line to be processed according to the demand parameter information, and generating the gateway network protocol IP address configuration information of the dedicated line to be processed according to the address pool configuration information, including: when the networking mode is a three-layer virtual private network, the gateway configuration mode is an independent gateway, the network topology type is a full star network, the provider edge device port interconnection IP address / subnet mask is left blank, and the user edge device port interconnection IP address / subnet mask is left blank, obtaining the address pool configuration information of the dedicated line to be processed according to the demand parameter information, and generating the gateway network protocol IP address configuration information of the dedicated line to be processed according to the address pool configuration information.

[0016] Optionally, the demand parameter information includes the network topology type; before the network management configuration of the dedicated line to be processed is performed according to the address pool configuration information, the gateway IP address configuration information and the packet filtering access control list, it also includes: when the network topology type is a complete star network, the import target of the virtual private network and the export target of the virtual private network are both target information, and the target information is the information obtained by adding a set mark after the routing identifier of the virtual private network; the network management configuration of the dedicated line to be processed according to the address pool configuration information, the gateway IP address configuration information and the packet filtering access control list includes: according to the address pool configuration information, the gateway IP address configuration information, the packet filtering access control list, the import target of the virtual private network and the export target of the virtual private network, the network management configuration of the dedicated line to be processed is performed.

[0017] Optionally, when the dedicated line to be processed is a non-central point dedicated line and the demand parameter information includes the intercommunication requirement between the dedicated line to be processed and the target non-central point dedicated line, the packet filtering access control list is also used to indicate that access is allowed between the dedicated line to be processed and the target non-central point dedicated line.

[0018] According to another aspect of an embodiment of the present application, a network management configuration device is provided, the device comprising:

[0019] An acquisition module, used to obtain the demand parameter information of the pending dedicated line of the virtual private network;

[0020] A first generating module is configured to obtain the address pool configuration information of the dedicated line to be processed according to the demand parameter information, and generate the gateway network protocol IP address configuration information of the dedicated line to be processed according to the address pool configuration information;

[0021] A second generating module is used to generate, when the dedicated line to be processed is a non-central point dedicated line, a packet filtering access control list for the inbound direction of the sub-interface of the dedicated line to be processed based on the address pool configuration information and the gateway IP address configuration information, wherein the packet filtering access control list is used to indicate that access between non-central point dedicated lines is prohibited;

[0022] A configuration module is used to perform network management configuration on the dedicated line to be processed according to the address pool configuration information, the gateway IP address configuration information and the packet filtering access control list.

[0023] Optionally, the demand parameter information includes a group access number; the first generation module includes: a judgment unit, used to judge whether the dedicated line to be processed is the first dedicated line in the virtual private network based on the group access number; an address configuration unit, used to configure the address pool configuration information of the dedicated line to be processed when the dedicated line to be processed is the first dedicated line; and a calling unit, used to call the address pool configuration information configured for the virtual private network as the address pool configuration information of the dedicated line to be processed when the dedicated line to be processed is not the first dedicated line.

[0024] Optionally, the address pool includes a virtual private network address pool, a central point dedicated line address pool and a non-central point dedicated line address pool; the address configuration unit is specifically used to: configure the first segment of the virtual private network address pool to be the first segment of the designated public network address segment, the second segment of the virtual private network address pool to be the last N bits of the routing identifier of the virtual private network, and N is a positive integer; configure the first segment of the central point dedicated line address pool to be the first segment of the designated public network address segment, the second segment of the central point dedicated line address pool to be the last N bits of the routing identifier of the virtual private network, and the central point dedicated line address pool to be the first segment of the designated public network address segment, The third segment of the dedicated line address pool is the first value used at the end of the provider edge device network management IP address; the first segment of the non-central point dedicated line address pool is configured as the first segment of the designated public network address segment, the second segment of the non-central point dedicated line address pool is the last N bits of the routing identifier of the virtual private network, and the third segment of the non-central point dedicated line address pool is the second value used at the end of the provider edge device network management IP address; the frequency of use of the first value at the end of the provider edge device network management IP address is less than the frequency of use of the second value at the end of the provider edge device network management IP address.

[0025] Optionally, the demand parameter information includes the number of dedicated line IP addresses, and the address pool includes a center point dedicated line address pool and a non-center point dedicated line address pool; the first generation module includes: a first address generation unit, which is used to obtain a mask with a number of subnet IP addresses greater than or equal to the number of dedicated line IP addresses as the mask of the dedicated line to be processed when the dedicated line to be processed is a center point dedicated line, and obtain the first available IP address in the center point dedicated line address pool as the gateway IP address of the dedicated line to be processed; a second address generation unit, which is used to divide the non-center point dedicated line address pool into multiple subnets according to the set number of IP addresses when the dedicated line to be processed is a non-center point dedicated line, calculate the mask of the dedicated line to be processed according to the set IP number, and use the first available IP address of the first subnet as the main gateway IP address of the dedicated line to be processed, and the first available IP addresses of the remaining subnets as the sub-gateway IP addresses of the dedicated lines to be processed.

[0026] Optionally, the address pool includes a virtual private network address pool and a central point dedicated line address pool; the second generation module is specifically used to configure the rules in the packet filtering access control list in the following order: allow the IP address to access the central point dedicated line address pool, allow the IP address to access the gateway IP address of the non-central point dedicated line of the virtual private network, deny the IP address to access the virtual private network address pool, and allow the IP address to access.

[0027] Optionally, the demand parameter information includes networking mode, gateway configuration mode, network topology type, provider edge device port interconnection IP address / subnet mask, and user edge device port interconnection IP address / subnet mask; the first generation module is specifically used to obtain the address pool configuration information of the dedicated line to be processed according to the demand parameter information when the networking mode is a three-layer virtual private network, the gateway configuration mode is an independent gateway, the network topology type is a full star network, the provider edge device port interconnection IP address / subnet mask is left blank, and the user edge device port interconnection IP address / subnet mask is left blank, and generate the gateway network protocol IP address configuration information of the dedicated line to be processed according to the address pool configuration information.

[0028] Optionally, the demand parameter information includes the network topology type; the device also includes: a third generation module, which is used to configure the import target of the virtual private network and the export target of the virtual private network as target information when the network topology type is a complete star network, and the target information is the information obtained by adding a set mark after the routing specifier of the virtual private network; the configuration module is specifically used to perform network management configuration on the dedicated line to be processed according to the address pool configuration information, the gateway IP address configuration information, the packet filtering access control list, the import target of the virtual private network and the export target of the virtual private network.

[0029] Optionally, when the dedicated line to be processed is a non-central point dedicated line and the demand parameter information includes the intercommunication requirement between the dedicated line to be processed and the target non-central point dedicated line, the packet filtering access control list is also used to indicate that access is allowed between the dedicated line to be processed and the target non-central point dedicated line.

[0030] According to another aspect of an embodiment of the present application, an electronic device is provided, which includes a processor and a computer-readable storage medium, and a computer program is stored on the computer-readable storage medium; when the computer program is executed by the processor, the processor executes the network management configuration method as described in any one of the above items.

[0031] According to another aspect of an embodiment of the present application, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the processor executes the network management configuration method as described in any one of the above items.

[0032] In the embodiment of the present application, the method of configuring paired ExportRT values ​​and Import RT values ​​for the VPN instances of the PE devices where the central point dedicated lines and non-central point dedicated lines are located is no longer adopted. Instead, a packet filtering access control list is configured in the inbound direction of the sub-interface of the non-central point dedicated line based on the address pool configuration information of the dedicated line to be processed and the gateway IP (Internet Protocol) address configuration information of the dedicated line to be processed. The packet filtering access control list is used to indicate that access between non-central point dedicated lines is prohibited. Therefore, it is no longer limited to the communication isolation between non-central point dedicated lines under different PEs, and can achieve communication isolation between all non-central point dedicated lines. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments of the present application. Obviously, the drawings described below are only some drawings of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0034] Figure 1 This is a business processing flow chart of an embodiment of the present application;

[0035] Figure 2 This is a flowchart of the steps of a network management configuration method according to an embodiment of the present application;

[0036] Figure 3 This is a structural block diagram of a network management configuration device according to an embodiment of the present application;

[0037] Figure 4 This is a structural block diagram of an electronic device according to an embodiment of the present application;

[0038] Figure 5 This is a structural block diagram of a computer-readable storage medium in an embodiment of the present application. DETAILED DESCRIPTION

[0039] To make the purposes, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some but not all of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.

[0040] In the current star network network management configuration mode, the communication isolation between all non-central point private lines is achieved by configuring a pair of Export RT value and Import RT value for the VPN instance of the PE device where the central point private line and the non-central point private line are located. However, the network management configuration mode has the following problems:

[0041] (1) Some non-central point private lines cannot be isolated: The traditional star network is isolated by route learning between PEs, so it can only achieve communication isolation between non-central point private lines under different PEs, and cannot achieve communication isolation between non-central point private lines under the same PE. Therefore, it cannot meet the demand of communication isolation between all non-central point private lines, cannot adapt to VPN networking business in the metropolitan area network, and cannot meet the user's demand for security isolation.

[0042] (2) It is difficult to automatically implement the interconnection of multiple central point private lines: When the VPN needs multiple central point private lines, according to the existing specification, a pair of Export RT value and Import RT value is configured, and the central point private lines on different PEs cannot interconnect. To achieve the interconnection between the central point private lines, when the second central point private line is received, the RT configuration needs to be increased on all PEs where the existing central point private lines are located. The network management automatic construction is complex, and if the central point private line is added in the later operation of the VPN, the RT configuration needs to be increased on all existing PEs, which makes it difficult to implement the network management automatic construction.

[0043] In the embodiments of the present application, the demand of communication isolation between all non-central point private lines can be met, the interconnection between the central point private lines can be achieved, the completely star networking can be implemented, the customer's demand for security networking can be met, the market competitiveness can be improved, the IP network management configuration automatic construction can be adapted to, the manual configuration workload can be reduced, the manual input error can be reduced, and the private line construction efficiency and accuracy can be improved. The following will be specifically introduced.

[0044] Referring to Figure 1 , a service processing flowchart of an embodiment of the present application is shown.

[0045] As Figure 1As shown, the overall process includes business acceptance, resource allocation, IP network management construction, and external line construction. After the business acceptance phase is completed, the resource allocation phase begins. If the resource allocation phase is normal, the IP network management construction phase begins after completion. If an exception occurs in the resource allocation phase, the process returns to the business acceptance phase. If the IP network management construction phase is normal, the external line construction phase begins after completion. If an exception occurs in the IP network management construction phase, the process returns to the business acceptance phase. If an exception occurs in the IP network management construction phase, the process returns to the resource allocation phase. If the external line construction phase is normal, the receipt is returned normally after completion. If an exception occurs in the external line construction phase, the process returns to the business acceptance phase. If an exception occurs in the external line construction phase, the process returns to the resource allocation phase.

[0046] During the service acceptance phase, the account manager initiates an MPLS VPN dedicated line service application in the service management system based on the customer's networking requirements and enters the necessary dedicated line networking parameters. After network access resources are allocated in the resource allocation phase, the networking parameters and access resource information are sent to the IP network management system for implementation. During the IP network management implementation phase, the network management automated implementation system automatically logs into the relevant network equipment and configures the dedicated line service. Finally, the application is sent to the external line implementation phase, where installation and maintenance engineers complete on-site service installation and commissioning. Any resource or application anomalies discovered during the IP network management implementation phase or the external line implementation phase are returned to the relevant phase.

[0047] The network management configuration method in the embodiment of the present application is applied to the above-mentioned IP network management construction link.

[0048] Reference Figure 2 , shows a step flow chart of a network management configuration method according to an embodiment of the present application.

[0049] like Figure 2 As shown, the network management configuration method may include the following steps:

[0050] Step 201: Obtain the required parameter information of the dedicated line to be processed in the virtual private network.

[0051] In the embodiment of the present application, the demand parameter information of the dedicated line to be processed may include: the networking parameter information configured for the dedicated line to be processed in the service acceptance stage, and the access resource information allocated to the dedicated line to be processed in the resource allocation stage.

[0052] The networking parameter information configured during the service acceptance phase determines the network management configuration plan for the IP network management construction phase. Some networking parameter information requires conditional judgment and limited selection or formatting. The networking parameter information in the embodiments of this application can refer to the networking parameter information table below. However, in actual applications, the networking parameter information is not limited to these parameters, and this embodiment does not impose any restrictions on this.

[0053] Table 1 Network parameter information table

[0054]

[0055]

[0056]

[0057] A full star network is one in which each node is directly connected to the central node via a separate line. A regular star network is similar to a full star network. In a regular star network, nodes are still directly connected to the central node, but there may be some shared connections or less redundant paths.

[0058] Based on the access resources allocated during the resource allocation phase, relevant information about the PE being constructed can be determined. For example, this access resource information may include, but is not limited to, PE device type, PE network management IP address, PE port number, PVLAN (Private Virtual Local Area Network), CVLAN (Customer Virtual Local Area Network), and so on.

[0059] Step 202: Acquire the address pool configuration information of the dedicated line to be processed according to the demand parameter information, and generate the gateway IP address configuration information of the dedicated line to be processed according to the address pool configuration information.

[0060] Based on the demand parameter information of the dedicated line to be processed, including the networking parameter information configured for the dedicated line to be processed in the business acceptance phase and the access resource information allocated for the dedicated line to be processed in the resource allocation phase, the network management configuration plan for the dedicated line to be processed can be determined.

[0061] In an embodiment of the present application, when the networking mode is a three-layer virtual private network, the gateway configuration mode is an independent gateway, the network topology type is a full star network, the provider edge device port interconnection IP address / subnet mask is left blank, and the user edge device port interconnection IP address / subnet mask is left blank, configuration can be performed according to the network management configuration scheme of the embodiment of the present application. In this case, the address pool configuration information of the dedicated line to be processed is obtained according to the demand parameter information, and the gateway network protocol IP address configuration information of the dedicated line to be processed is generated according to the address pool configuration information.

[0062] In the embodiment of the present application, the address pool configuration information of the dedicated line to be processed may be obtained first based on the demand parameter information of the dedicated line to be processed.

[0063] In an optional embodiment, the process of obtaining the address pool configuration information of the dedicated line to be processed based on the demand parameter information may include: judging whether the dedicated line to be processed is the first dedicated line in the VPN based on the group access number; when the dedicated line to be processed is the first dedicated line, configuring the address pool configuration information of the dedicated line to be processed; when the dedicated line to be processed is not the first dedicated line, retrieving the address pool configuration information configured for the VPN as the address pool configuration information of the dedicated line to be processed. In this method, when the dedicated line to be processed is not the first dedicated line, it indicates that the address pool configuration information has been configured for the VPN, so there is no need to repeatedly configure the address pool, thereby avoiding unnecessary processing and saving processing resources.

[0064] Since one VPN corresponds to one group access number, the process of determining whether the dedicated line to be processed is the first dedicated line in the VPN based on the group access number includes: if the group access number of the dedicated line to be processed exists in the group access numbers of the configured VPN, determining that the dedicated line to be processed is the first dedicated line in the VPN; otherwise, determining that the dedicated line to be processed is not the first dedicated line in the VPN.

[0065] Exemplarily, the address pool includes a VPN address pool, a central point dedicated line address pool, and a non-central point dedicated line address pool, wherein the central point dedicated line and the non-central point dedicated line are located in the VPN.

[0066] Exemplarily, the process of configuring the address pool configuration information of the dedicated line to be processed may include:

[0067] The first segment of the VPN address pool is configured to be the first segment of the designated public network address segment, and the second segment of the VPN address pool is configured to be the last N bits of the routing distinguisher of the virtual private network, where N is a positive integer;

[0068] The first segment of the central point dedicated line address pool is configured to be the first segment of the designated public network address segment, the second segment of the central point dedicated line address pool is configured to be the last N bits of the VPN route distinguisher, and the third segment of the central point dedicated line address pool is configured to be the first value used for the last segment of the PE network management IP address;

[0069] The first segment of the non-central point dedicated line address pool is configured as the first segment of the designated public network address segment, the second segment of the non-central point dedicated line address pool is configured as the last N bits of the VPN routing identifier, and the third segment of the non-central point dedicated line address pool is configured as the second value used at the end of the PE network management IP address.

[0070] In the embodiment of the present application, in order to avoid conflicts between the dedicated line IP address and the customer's intranet and potential future network connection conflicts, the VPN address pool is not allocated with common private IP address segments, such as 10.0.0.0 / 8, 172.16.0.0 / 20, 192.168.0.0 / 16, etc. Instead, a designated public network address segment is allocated. The designated public network address segment is an uncommon public network address segment. Therefore, the first segment of the VPN address pool can be the first segment of the designated public network address segment. The specific information of the designated public network address segment is not limited in this embodiment.

[0071] In the embodiment of the present application, the second segment of the VPN address pool is the last N digits of the route distinguisher of the VPN. The specific value of N can be set according to actual needs, and this embodiment does not impose any restrictions on this. For example, N can be 2, 3, and so on. According to this rule, the address pool planning scale is 7 digits for the route distinguisher, but the first digits of each branch are fixed values. Therefore, configuring a VPN address pool that is regularly associated with the route distinguisher and the access device can reduce the amount of memory required for manual maintenance, which is beneficial for network maintenance and troubleshooting by network administrators.

[0072] In the embodiment of the present application, the first segment and the second segment of the central point dedicated line address pool are the same as the first segment and the second segment of the VPN address pool, and the third segment of the central point dedicated line address pool is the first value used at the end of the PE network management IP address. The first segment and the second segment of the non-central point dedicated line address pool are the same as the first segment and the second segment of the VPN address pool, and the third segment of the non-central point dedicated line address pool is the second value used at the end of the PE network management IP address. Among them, the frequency of use of the first value at the end of the PE network management IP address is less than the frequency of use of the second value at the end of the PE network management IP address. Therefore, the first value that is not frequently used in the end of the PE network management IP address can be used as the third segment of the central point dedicated line address pool, so that the network segment of the central point dedicated line address pool can be allowed to pass in the packet filtering access control list generated subsequently.

[0073] For example, the first segment of the VPN address pool is assigned the first segment of a Class B network segment starting with 100. The second segment of the VPN address pool is derived from the last N bits of the VPN's route distinguisher. The third segment of each dedicated line is assigned the third segment of a Class C network segment within that Class B network segment, with the third segment of that Class C network segment derived from the last segment of the PE network management IP address. For example, the VPN address pool is 100.X.0.0 / 16, and the address pool for each dedicated line is 100.XY0 / 24, where X is the last N bits of the VPN's route distinguisher and Y is the last segment of the PE network management IP address. The first segment of the Class B network segment starting with 101 is planned as a backup address pool segment, following the same allocation rules as above.

[0074] For example, since PE network management IP addresses generally do not end with 0 or 1, the two Class C network segments Y = 0 and Y = 1 are fixed as the address pool segments for each central point dedicated line. The address segments at the end of the remaining PE network management IP addresses are used as the address pool segments for non-central point dedicated lines.

[0075] The address pool configuration information in this embodiment can be referred to in the following address pool configuration information table.

[0076] Table 2 Address pool configuration information

[0077]

[0078] In the embodiment of the present application, the gateway IP address configuration information of the dedicated line to be processed is generated according to the address pool configuration information.

[0079] In an optional implementation, the process of generating the gateway network protocol IP address configuration information of the dedicated line to be processed according to the address pool configuration information may include:

[0080] When the dedicated line to be processed is a central point dedicated line, obtain a mask whose number of subnet IP addresses is greater than or equal to the number of dedicated line IP addresses as the mask of the dedicated line to be processed, and obtain the first available IP address in the central point dedicated line address pool as the gateway IP address of the dedicated line to be processed;

[0081] When the dedicated line to be processed is a non-central point dedicated line, the address pool of the non-central point dedicated line is divided into multiple subnets according to the set number of IP addresses, the mask of the dedicated line to be processed is calculated according to the set number of IP addresses, and the first available IP address of the first subnet is used as the main gateway IP address of the dedicated line to be processed, and the first available IP addresses of the remaining subnets are used as the sub-gateway (sub gateway) IP addresses of the dedicated line to be processed.

[0082] The number of dedicated IP addresses is configured in the networking parameter information. There is a corresponding relationship between the number of subnet IP addresses and the mask. Specifically, the number of subnet IP addresses = 2 m, m = 32 - the number of "1" bits in the mask, so a mask can be calculated in which the number of subnet IP addresses is greater than or equal to the number of dedicated line IP addresses. The number of subnet IP addresses can be equal to or greater than the number of dedicated line IP addresses.

[0083] The set number of IP addresses can be determined based on the number of dedicated line IP addresses. For example, when the number of dedicated line IP addresses is a multiple of 8, the set number of IP addresses can be 8, and so on. The specific number can be set according to actual needs. Similarly, based on the above-mentioned correspondence between the number of subnet IP addresses and the mask, the mask of the dedicated line to be processed can be calculated based on the set number of IP addresses.

[0084] Step 203, when the dedicated line to be processed is a non-central point dedicated line, a packet filtering access control list for the incoming sub-interface of the dedicated line to be processed is generated based on the address pool configuration information and the gateway IP address configuration information, and the packet filtering access control list is used to indicate that access between non-central point dedicated lines is prohibited.

[0085] The "Is it a center point dedicated line" parameter in the requirement parameters can be used to determine whether the dedicated line to be processed is a center point dedicated line.

[0086] In order to achieve communication isolation between all non-central point dedicated lines and intercommunication between different central point dedicated lines, when the dedicated line to be processed is a non-central point dedicated line, a packet filter (PacketFilter) access control list (ACL) for the inbound direction of the sub-interface of the dedicated line to be processed can be generated based on the address pool configuration information and the gateway IP address configuration information. The packet filter access control list is used to indicate that access between non-central point dedicated lines is prohibited, thereby achieving communication isolation between all non-central point dedicated lines, and the packet filter access control list is not configured for the central point dedicated line, so that the communication between the central point dedicated lines will not be isolated, thereby achieving intercommunication between different central point dedicated lines.

[0087] Packet filtering access control lists can be used on network devices or firewalls to filter and control the flow and access rights of data packets. They consist of a series of rules that define which network traffic is allowed or denied through a specific network device. When a data packet passes through a network device configured with an ACL, the device checks the data packet according to the rules defined in the ACL. If a data packet matches a rule in the ACL, the device will perform the action specified by the rule, that is, allow or deny the transmission of the data packet. ACL rules are usually executed in ascending order of rule number. Once a data packet matches a rule, subsequent rules will no longer be checked.

[0088] Exemplarily, the process of generating a packet filtering access control list for the incoming direction of the sub-interface of the dedicated line to be processed based on the address pool configuration information and the gateway IP address configuration information includes: configuring the rules in the packet filtering access control list in the following order: allowing the IP address to access the central point dedicated line address pool, allowing the IP address to access the gateway IP address of the non-central point dedicated line of the virtual private network, denying the IP address to access the virtual private network address pool, and allowing the IP address to access.

[0089] For example, a packet filtering access control list can be named "ACL-group access number" and configured as an advanced access control list. The rules in a packet filtering access control list can be as shown in the following table.

[0090] Table 3 Rules table

[0091]

[0092] In the embodiment of the present application, according to the VPN address pool planning rules described above, the IP addresses of the central point dedicated lines are 100.X.0.0 / 23 and 101.X.0.0 / 23, so the wildcard 1.0.1.255 can match the IP address of the central point dedicated line; the gateway IP addresses of all non-central point dedicated lines are multiples of 8 plus 1, so the wildcard 1.0.255.248 can match the gateway IP address of the VPN non-central point dedicated line. Each non-central point dedicated line needs to configure this policy in the inbound (in) direction of the sub-interface to achieve communication isolation between all non-central point dedicated lines; the central point dedicated line does not need to configure this policy.

[0093] When a non-central point dedicated line accesses a central point dedicated line, the messages generated will match rule number 1 and be allowed to be forwarded; when a non-central point dedicated line needs to test gateway connectivity, the messages sent will match rule number 2 and be allowed to be forwarded; when non-central point dedicated lines access each other, the messages sent will match rule number 100 and be discarded; when a non-central point dedicated line accesses a network segment outside the VPN address pool, the messages sent will match rule number 101 and be allowed to be forwarded.

[0094] Exemplarily, considering that there may be intercommunication requirements between individual non-central point private lines, when the to-be-processed private line is a non-central point private line and the requirement parameter information contains intercommunication requirements between the to-be-processed private line and a target non-central point private line, the packet filtering access control list is further used to indicate that access between the to-be-processed private line and the target non-central point private line is allowed. For example, corresponding rules can be inserted between packet filtering access control list serial numbers 2 and 100 of the PE where the relevant non-central point private line is located, and the IP address of the relevant non-central point private line is allowed. For specific processes, actual requirement processing can be performed, and the embodiment will not be discussed in detail here. In this way, the complex problem of needing to modify all access PEs of the existing non-central point private line according to the traditional configuration mode can be solved.

[0095] In step 204, the to-be-processed private line is automatically configured according to the address pool configuration information, the gateway IP address configuration information and the packet filtering access control list.

[0096] In step 204, the to-be-processed private line is automatically configured according to the address pool configuration information, the gateway IP address configuration information and the packet filtering access control list.

[0097] In implementation, first, a PE configuration script can be generated according to the above configuration rules, which contains commands to configure the PE to the required state. Then, a secure connection with the PE can be established by logging in using the SSH (Secure Shell) protocol, which is an encrypted network protocol used to securely transmit data over insecure networks. Next, interactive configuration can be performed using device line commands. Once the SSH connection is established, the system sends the commands in the previously generated configuration script through the command line interface of the PE. These commands are executed in order to configure the PE to the required state. After configuration is completed, configuration verification can be performed to ensure that the PE has been configured as expected, which can include checking the syntax of configuration files, testing network connections, verifying routing policies, etc. If the configuration is successful, the system can generate a confirmation report or status update to notify the requester or service provider that the configuration has been completed. If the configuration fails, the system can generate an error report indicating the problem and providing possible solutions. The entire process realizes the automation of network configuration, reduces errors and delays caused by manual configuration, and improves the efficiency of network deployment and management.

[0098] In the embodiment of the application, in addition to the address pool configuration information, the gateway IP address configuration information and the packet filtering access control list described above, some other parameters can also be configured.

[0099] For example, before performing network management configuration on the dedicated line to be processed based on the address pool configuration information, the gateway IP address configuration information, and the packet filtering access control list, the following also includes: when the network topology type is a complete star network, configuring the import target of the virtual private network and the export target of the virtual private network are both target information, and the target information is the information obtained by adding a set mark after the routing identifier of the virtual private network. This method eliminates the need to configure import targets and export targets to achieve communication isolation between non-central point dedicated lines, simplifying the configuration process of import targets and export targets.

[0100] Correspondingly, the network management configuration of the dedicated line to be processed is performed according to the address pool configuration information, the gateway IP address configuration information and the packet filtering access control list, including: network management configuration of the dedicated line to be processed according to the address pool configuration information, the gateway IP address configuration information, the packet filtering access control list, the import target of the virtual private network and the export target of the virtual private network.

[0101] In some possible scenarios, the configuration information may be as shown in the following configuration information table.

[0102] Table 4 Configuration information table

[0103]

[0104]

[0105]

[0106]

[0107] Let's use a specific example. The VPN group access number is GVPN123456, with one central point dedicated line and ten non-central point dedicated lines. After each dedicated line is accepted through the service acceptance system, the network management automatic construction system, upon receiving the first order, allocates an address pool of 100.23.0.0 / 16 and a backup address pool of 101.23.0.0 / 16 for this VPN. The gateway automatic construction system allocates the corresponding free IP addresses from the VPN address pool based on the order in which the dedicated line orders arrive, and logs into the corresponding PEs for configuration and construction.

[0108] The configured dedicated line IP addresses are shown in the following dedicated line IP address table:

[0109] Table 5 Dedicated Line IP Address Table

[0110]

[0111] The configured isolation policy is shown in the following packet filtering access control list:

[0112] Table 6 Packet filtering access control list

[0113]

[0114]

[0115] In the embodiments of the present application, based on the VPN center point private line and non-center private line address pool planning, and in the non-center private line sub-interface direction, a packet filtering access control list is configured, so as to solve the problem that the non-center private lines under the same PE cannot be isolated in the traditional configuration mode. Different from the traditional star network, the star network configuration scheme proposed in the embodiments of the present application is based on the full-mesh interconnected VPN, therefore, the VPN can increase other center point private lines at any time, realizes the intercommunication of double center point private lines and the intercommunication with non-center point private lines, and does not need to change the configuration of the PE where the existing private line is located.

[0116] With reference to Figure 3 , a structural block diagram of a network management configuration device according to an embodiment of the present application is shown.

[0117] As shown in Figure 3 , the network management configuration device can include the following modules:

[0118] The obtaining module 301 is configured to obtain the demand parameter information of a to-be-processed private line of a virtual private network.

[0119] The first generating module 302 is configured to obtain the address pool configuration information of the to-be-processed private line according to the demand parameter information, and generate the gateway IP address configuration information of the to-be-processed private line according to the address pool configuration information.

[0120] The second generating module 303 is configured to, when the to-be-processed private line is a non-center point private line, generate a packet filtering access control list of the sub-interface direction of the to-be-processed private line based on the address pool configuration information and the gateway IP address configuration information, and the packet filtering access control list is used to indicate that the access between non-center point private lines is prohibited.

[0121] The configuration module 304 is configured to perform network management configuration on the to-be-processed private line according to the address pool configuration information, the gateway IP address configuration information and the packet filtering access control list.

[0122] Optionally, the demand parameter information includes a group access number; the first generation module 302 includes: a judgment unit, used to judge whether the dedicated line to be processed is the first dedicated line in the virtual private network based on the group access number; an address configuration unit, used to configure the address pool configuration information of the dedicated line to be processed when the dedicated line to be processed is the first dedicated line; and a calling unit, used to call the address pool configuration information configured for the virtual private network as the address pool configuration information of the dedicated line to be processed when the dedicated line to be processed is not the first dedicated line.

[0123] Optionally, the address pool includes a virtual private network address pool, a central point dedicated line address pool and a non-central point dedicated line address pool; the address configuration unit is specifically used to: configure the first segment of the virtual private network address pool to be the first segment of the designated public network address segment, the second segment of the virtual private network address pool to be the last N bits of the routing identifier of the virtual private network, N is a positive integer; configure the first segment of the central point dedicated line address pool to be the first segment of the designated public network address segment, the second segment of the central point dedicated line address pool to be the last N bits of the routing identifier of the virtual private network, the central point dedicated line address pool The third segment of the address pool is the first value used at the end of the provider edge device network management IP address; the first segment of the non-central point dedicated line address pool is configured as the first segment of the designated public network address segment, the second segment of the non-central point dedicated line address pool is the last N bits of the routing identifier of the virtual private network, and the third segment of the non-central point dedicated line address pool is the second value used at the end of the provider edge device network management IP address; the frequency of use of the first value at the end of the provider edge device network management IP address is less than the frequency of use of the second value at the end of the provider edge device network management IP address.

[0124] Optionally, the demand parameter information includes the number of dedicated line IP addresses, and the address pool includes a center point dedicated line address pool and a non-center point dedicated line address pool; the first generation module 302 includes: a first address generation unit, which is used to obtain a mask with a number of subnet IP addresses greater than or equal to the number of dedicated line IP addresses as the mask of the dedicated line to be processed when the dedicated line to be processed is a center point dedicated line, and obtain the first available IP address in the center point dedicated line address pool as the gateway IP address of the dedicated line to be processed; a second address generation unit, which is used to divide the non-center point dedicated line address pool into multiple subnets according to the set number of IP addresses when the dedicated line to be processed is a non-center point dedicated line, calculate the mask of the dedicated line to be processed according to the set IP number, and use the first available IP address of the first subnet as the main gateway IP address of the dedicated line to be processed, and the first available IP addresses of the remaining subnets as the sub-gateway IP addresses of the dedicated lines to be processed.

[0125] Optionally, the address pool includes a virtual private network address pool and a central point dedicated line address pool; the second generation module 303 is specifically used to configure the rules in the packet filtering access control list in the following order: allow the IP address to access the central point dedicated line address pool, allow the IP address to access the gateway IP address of the non-central point dedicated line of the virtual private network, deny the IP address to access the virtual private network address pool, and allow the IP address to access.

[0126] Optionally, the demand parameter information includes networking mode, gateway configuration mode, network topology type, provider edge device port interconnection IP address / subnet mask, and user edge device port interconnection IP address / subnet mask; the first generation module 302 is specifically used to obtain the address pool configuration information of the dedicated line to be processed according to the demand parameter information when the networking mode is a three-layer virtual private network, the gateway configuration mode is an independent gateway, the network topology type is a full star network, the provider edge device port interconnection IP address / subnet mask is left blank, and the user edge device port interconnection IP address / subnet mask is left blank, and generate the gateway network protocol IP address configuration information of the dedicated line to be processed according to the address pool configuration information.

[0127] Optionally, the demand parameter information includes the network topology type; the device also includes: a third generation module, which is used to configure the import target of the virtual private network and the export target of the virtual private network as target information when the network topology type is a complete star network, and the target information is the information obtained by adding a set mark after the routing specifier of the virtual private network; the configuration module 304 is specifically used to perform network management configuration on the dedicated line to be processed according to the address pool configuration information, the gateway IP address configuration information, the packet filtering access control list, the import target of the virtual private network and the export target of the virtual private network.

[0128] Optionally, when the dedicated line to be processed is a non-central point dedicated line and the demand parameter information includes the intercommunication requirement between the dedicated line to be processed and the target non-central point dedicated line, the packet filtering access control list is also used to indicate that access is allowed between the dedicated line to be processed and the target non-central point dedicated line.

[0129] In the embodiment of the present application, the method of configuring paired ExportRT values ​​and Import RT values ​​for the VPN instances of the PE devices where the central point dedicated lines and non-central point dedicated lines are located is no longer adopted. Instead, a packet filtering access control list is configured in the inbound direction of the sub-interface of the non-central point dedicated line based on the address pool configuration information of the dedicated line to be processed and the gateway IP address configuration information of the dedicated line to be processed. The packet filtering access control list is used to indicate that access between non-central point dedicated lines is prohibited. Therefore, it is no longer limited to the communication isolation between non-central point dedicated lines under different PEs, and can achieve communication isolation between all non-central point dedicated lines.

[0130] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0131] In an embodiment of the present application, an electronic device is further provided. The electronic device may include a processor and a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program; when the computer program is executed by the processor, the processor executes the network management configuration method of any of the above embodiments.

[0132] Reference Figure 4 , shows a structural block diagram of an electronic device according to an embodiment of the present application. Figure 4 As shown, the electronic device 40 includes a processor 401 and a computer-readable storage medium 402 , on which a computer program 4021 is stored.

[0133] Processor 401 is used to execute the computer program 4021 stored on the computer-readable storage medium 402. When executing the computer program 4021, the processor 401 implements the network management configuration method of any of the above embodiments and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0134] The processor 401 mentioned above may include but is not limited to: a central processing unit (CPU), a network processor (NP), a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0135] The computer readable storage medium 402 mentioned above can include, but is not limited to, Read Only Memory (ROM), Random Access Memory (RAM), Compact Disc Read Only Memory (CD-ROM), Electronic Erasable Programmable Read Only Memory (EEPROM), hard disk, floppy disk, flash memory, etc.

[0136] In the embodiments of the present application, a computer readable storage medium is also provided, and the computer readable storage medium stores a computer program, the computer program can be executed by a processor of an electronic device, and when the computer program is executed by the processor, the processor executes the network management configuration method according to any one of the above embodiments.

[0137] Reference Figure 5 is a structural block diagram of a computer readable storage medium according to an embodiment of the present application. As shown in Figure 5 , the computer readable storage medium 50 stores a computer program 501, and when the computer program 501 is executed by a processor, the processor executes the network management configuration method according to any one of the above embodiments and achieves the same technical effects. To avoid repetition, details are not described here.

[0138] Each of the embodiments in the present specification is associated with each other, and each of the embodiments is described in a progressive manner, and each embodiment mainly explains the difference from other embodiments, and the same and similar parts between each embodiment are referred to each other.

[0139] It should be pointed out that all the actions of acquiring signals, information or data in the present application are performed under the premise of complying with the corresponding data protection regulations and policies of the place, and with the authorization given by the owner of the corresponding device.

[0140] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprises" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or terminal device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or terminal device. In the absence of further restrictions, an element defined by the sentence "comprises a..." does not exclude the presence of other identical elements in the process, method, article or terminal device that includes the element.

[0141] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application.

[0142] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.

[0143] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed in the embodiments of this application can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0144] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0145] In the embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0146] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0147] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included in the scope of protection of the present application. In summary, the contents of this specification should not be construed as limiting the present application.

Claims

1. A network management configuration method, characterized in that: The method comprises: Obtaining the required parameter information of the pending dedicated line of the virtual private network; Acquire the address pool configuration information of the dedicated line to be processed according to the demand parameter information, and generate the gateway network protocol IP address configuration information of the dedicated line to be processed according to the address pool configuration information; When the dedicated line to be processed is a non-central point dedicated line, generating a packet filtering access control list for the inbound direction of the sub-interface of the dedicated line to be processed based on the address pool configuration information and the gateway IP address configuration information, wherein the packet filtering access control list is used to indicate that access between non-central point dedicated lines is prohibited; Performing network management configuration on the dedicated line to be processed according to the address pool configuration information, the gateway IP address configuration information and the packet filtering access control list; Among them, the address pool includes a virtual private network address pool and a central point dedicated line address pool; based on the address pool configuration information and the gateway IP address configuration information, a packet filtering access control list for the incoming direction of the sub-interface of the dedicated line to be processed is generated, including: configuring the rules in the packet filtering access control list in the following order: allowing the IP address to access the central point dedicated line address pool, allowing the IP address to access the gateway IP address of the non-central point dedicated line of the virtual private network, denying the IP address to access the virtual private network address pool, and allowing the IP address to access.

2. The method according to claim 1, characterized in that The demand parameter information includes a group access number; and obtaining the address pool configuration information of the dedicated line to be processed according to the demand parameter information includes: Determining whether the dedicated line to be processed is the first dedicated line in the virtual private network according to the group access number; When the dedicated line to be processed is the first dedicated line, configuring address pool configuration information of the dedicated line to be processed; When the dedicated line to be processed is not the first dedicated line, the address pool configuration information configured for the virtual private network is retrieved as the address pool configuration information of the dedicated line to be processed.

3. The method according to claim 2, characterized in that The address pool includes a virtual private network address pool, a central point dedicated line address pool, and a non-central point dedicated line address pool; the address pool configuration information for configuring the dedicated line to be processed includes: The first segment of the virtual private network address pool is configured to be the first segment of the designated public network address segment, and the second segment of the virtual private network address pool is configured to be the last N bits of the routing distinguisher of the virtual private network, where N is a positive integer; The first segment of the central point dedicated line address pool is configured to be the first segment of the designated public network address segment, the second segment of the central point dedicated line address pool is configured to be the last N digits of the routing distinguisher of the virtual private network, and the third segment of the central point dedicated line address pool is configured to be the first value used for the last segment of the provider edge device network management IP address; The first segment of the non-central point dedicated line address pool is configured to be the first segment of the designated public network address segment, the second segment of the non-central point dedicated line address pool is configured to be the last N bits of the routing distinguisher of the virtual private network, and the third segment of the non-central point dedicated line address pool is configured to be the second value used for the last segment of the provider edge device network management IP address; The usage frequency of the first value at the end of the provider edge device network management IP address is less than the usage frequency of the second value at the end of the provider edge device network management IP address.

4. The method according to claim 1, wherein The demand parameter information includes the number of dedicated line IP addresses, and the address pool includes a central point dedicated line address pool and a non-central point dedicated line address pool; and the gateway network protocol IP address configuration information of the dedicated line to be processed is generated according to the address pool configuration information, including: When the dedicated line to be processed is a central point dedicated line, obtain a mask whose number of subnet IP addresses is greater than or equal to the number of dedicated line IP addresses as the mask of the dedicated line to be processed, and obtain the first available IP address in the central point dedicated line address pool as the gateway IP address of the dedicated line to be processed; When the dedicated line to be processed is a non-central point dedicated line, the address pool of the non-central point dedicated line is divided into multiple subnets according to the set number of IP addresses, the mask of the dedicated line to be processed is calculated according to the set number of IP addresses, and the first available IP address of the first subnet is used as the main gateway IP address of the dedicated line to be processed, and the first available IP addresses of the remaining subnets are used as the sub-gateway IP addresses of the dedicated lines to be processed.

5. The method according to claim 1, wherein The demand parameter information includes a networking mode, a gateway configuration mode, a network topology type, an IP address / subnet mask for interconnection of a provider edge device port, and an IP address / subnet mask for interconnection of a user edge device port; the step of obtaining the address pool configuration information of the dedicated line to be processed based on the demand parameter information, and generating the gateway network protocol IP address configuration information of the dedicated line to be processed based on the address pool configuration information includes: When the networking mode is a three-layer virtual private network, the gateway configuration mode is an independent gateway, the network topology type is a full star network, the provider edge device port interconnection IP address / subnet mask is left blank, and the user edge device port interconnection IP address / subnet mask is left blank, the address pool configuration information of the dedicated line to be processed is obtained according to the demand parameter information, and the gateway network protocol IP address configuration information of the dedicated line to be processed is generated according to the address pool configuration information.

6. The method according to claim 1, characterized in that The demand parameter information includes the network topology type; Before performing network management configuration on the dedicated line to be processed based on the address pool configuration information, the gateway IP address configuration information, and the packet filtering access control list, the method further includes: when the network topology type is a full star network, configuring the import target of the virtual private network and the export target of the virtual private network to be target information, wherein the target information is information obtained by adding a setting tag after the routing identifier of the virtual private network; The network management configuration of the dedicated line to be processed is performed according to the address pool configuration information, the gateway IP address configuration information and the packet filtering access control list, including: network management configuration of the dedicated line to be processed is performed according to the address pool configuration information, the gateway IP address configuration information, the packet filtering access control list, the import target of the virtual private network and the export target of the virtual private network.

7. The method according to claim 1, characterized in that When the dedicated line to be processed is a non-central point dedicated line and the demand parameter information includes the intercommunication requirement between the dedicated line to be processed and the target non-central point dedicated line, the packet filtering access control list is further used to indicate that access between the dedicated line to be processed and the target non-central point dedicated line is allowed.

8. A network management configuration device, characterized in that: The device comprises: An acquisition module is used to obtain the demand parameter information of the dedicated line to be processed of the virtual private network; A first generating module is configured to obtain the address pool configuration information of the dedicated line to be processed according to the demand parameter information, and generate the gateway network protocol IP address configuration information of the dedicated line to be processed according to the address pool configuration information; A second generating module is used to generate, when the dedicated line to be processed is a non-central point dedicated line, a packet filtering access control list for the inbound direction of the sub-interface of the dedicated line to be processed based on the address pool configuration information and the gateway IP address configuration information, wherein the packet filtering access control list is used to indicate that access between non-central point dedicated lines is prohibited; A configuration module, configured to perform network management configuration on the dedicated line to be processed according to the address pool configuration information, the gateway IP address configuration information and the packet filtering access control list; Among them, the address pool includes a virtual private network address pool and a central point dedicated line address pool; the second generation module is specifically used to configure the rules in the packet filtering access control list in the following order: allow the IP address to access the central point dedicated line address pool, allow the IP address to access the gateway IP address of the non-central point dedicated line of the virtual private network, deny the IP address to access the virtual private network address pool, and allow the IP address to access.

9. An electronic device, characterized in that: The electronic device includes a processor and a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program; when the computer program is executed by the processor, the processor executes the network management configuration method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the processor executes the network management configuration method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Configuration issuing method and device and computer equipment

    CN113328942A

  • Network topology generation method and device, cloud platform and readable storage medium

    CN118041795A