Firewall traffic balancing method and device, electronic equipment and storage medium

CN120034540AActive Publication Date: 2025-05-23ZIGUANG HENGYUE TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510512122.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-23
Publication Date
2025-05-23
Estimated Expiration
2045-04-23

Smart Images

  • Figure CN120034540A_ABST
    Figure CN120034540A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a firewall traffic balancing method and device, electronic equipment and a storage medium. The method comprises the following steps: receiving a service request sent by a client through a preset firewall; determining a first firewall identifier corresponding to the service request according to a port number of a preset firewall, a port number of load balancing equipment and quintuple information corresponding to the service request; obtaining service data corresponding to the service request according to the service request; calculating a second firewall identifier of each port number of the load balancing equipment, and matching the first firewall identifier with the second firewall identifier; in the embodiment of the invention, when the first firewall identifier is matched with the second firewall identifier, the firewall matched with the first firewall identifier is adopted to send the service data, so that the firewall for sending the request and the firewall for returning the data can be ensured to be the same firewall, the balance processing of the firewall flow is realized, and the processing efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technologies, and more particularly, to a method, apparatus, electronic device, and storage medium for balancing firewall traffic. Background Art

[0002] With the continuous development of network technologies, to ensure the security of data transmission, firewalls need to be provided for data transmission devices. Moreover, if there are a large number of concurrent sessions, multiple sessions may use the same firewall for data transmission, while there may also be idle firewalls, resulting in a problem of uneven load. Therefore, how to improve the efficiency of firewall traffic balancing is an urgent problem to be solved currently. Summary of the Invention

[0003] Some embodiments of this application aim to provide a method, apparatus, electronic device, and storage medium for balancing firewall traffic. Through the technical solutions of the embodiments of this application, a load balancing device receives a service request sent by a client through a preset firewall; determines a first firewall identifier corresponding to the service request according to the port number of the preset firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request; obtains service data corresponding to the service request according to the service request; calculates second firewall identifiers for each port number of the load balancing device, and matches the first firewall identifier and the second firewall identifiers; and when the first firewall identifier and the second firewall identifiers match, sends the service data using the firewall that matches the first firewall identifier. In the embodiments of this application, by obtaining the port number of the firewall that receives the service request, and calculating the first firewall identifier corresponding to the service request according to this port number, the port number of the load balancing device, and the five-tuple information corresponding to the service request, then matching the first firewall identifier with the second firewall identifiers in the load balancing device, and when the first firewall identifier and the second firewall identifiers match, sending the service data using the firewall that matches the first firewall identifier, in this way, it can be ensured that the firewall for sending the request and the firewall for returning the data are the same firewall, realizing the balanced processing of firewall traffic and improving the processing efficiency.

[0004] In a first aspect, some embodiments of this application provide a method for balancing firewall traffic, including: Receiving a service request sent by a client through a preset firewall; Determining a first firewall identifier corresponding to the service request according to the port number of the preset firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request; Obtaining service data corresponding to the service request according to the service request; Calculating a second firewall identifier for each port number of the load balancing device, and matching the first firewall identifier with the second firewall identifier; In a case where the first firewall identifier and the second firewall identifier match, the service data is sent using a firewall that matches the first firewall identifier.

[0005] Some embodiments of the present application obtain the port number of the firewall that receives the business request, and calculate the first firewall identifier corresponding to the business request based on the port number, the port number of the load balancing device and the five-tuple information corresponding to the business request, and then match the first firewall identifier with the second firewall identifier in the load balancing device. When the first firewall identifier and the second firewall identifier match, the firewall that matches the first firewall identifier is used to send the business data. In this way, it can be ensured that the firewall that sends the request and the firewall that returns the data are the same firewall, thereby achieving balanced processing of firewall traffic and improving processing efficiency.

[0006] Optionally, determining the first firewall identifier corresponding to the service request according to the port number of the preset firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request includes: Performing a hash calculation on the port number of the preset firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a first hash value; The first hash value is determined as a first firewall identifier corresponding to the service request.

[0007] Some embodiments of the present application perform a hash calculation on the port number of a preset firewall, the port number of a load balancing device, and the five-tuple information corresponding to the service request to obtain a seven-tuple hash value, i.e., a first firewall identifier. The first firewall identifier is used to determine that the forward traffic and the reverse traffic use the same firewall to facilitate load balancing.

[0008] Optionally, calculating the second firewall identifier of each port number of the load balancing device and matching the first firewall identifier with the second firewall identifier includes: After receiving the service data, performing hash calculations on the port numbers of each firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a second hash value; Determine the second Hash value as the second firewall identifier; The first Hash value and the second Hash value are judged.

[0009] Optionally, when the first firewall identifier and the second firewall identifier match, using the firewall matching the first firewall identifier to send the service data includes: If the first hash value and the second hash value are the same, determining the port number of the firewall corresponding to the second hash value as the target firewall port number; The service data is sent using a firewall corresponding to the target firewall port number.

[0010] Some embodiments of the present application match the first hash value with the second hash values ​​of multiple firewalls in the load balancing device. In this way, a firewall that matches the first hash value can be found from multiple firewalls. In this way, it can be ensured that the firewall that sends the request and the firewall that returns the data are the same firewall, thereby achieving balanced processing of firewall traffic and improving processing efficiency.

[0011] Optionally, performing hash calculation on the port number of the preset firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain the first hash value includes: An MD5 calculation is performed on the port number of the preset firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a first MD5 value.

[0012] Some embodiments of the present application ensure the accuracy of data verification by calculating a seven-tuple hash value containing the port number of a preset firewall.

[0013] In a second aspect, some embodiments of the present application provide a firewall traffic balancing device, including: A receiving module, used for receiving a service request sent by a client through a preset firewall; A determination module, configured to determine a first firewall identifier corresponding to the service request according to the port number of the preset firewall, the port number of the load balancing device and the five-tuple information corresponding to the service request; An acquisition module, used to acquire business data corresponding to the business request according to the business request; A calculation module, used for calculating the second firewall identifier of each port number of the load balancing device, and matching the first firewall identifier with the second firewall identifier; A sending module is used to send the business data using the firewall that matches the first firewall identifier when the first firewall identifier matches the second firewall identifier.

[0014] Some embodiments of the present application calculate a first firewall identifier corresponding to a service request by obtaining the port number of a firewall that receives the service request and based on the port number, the port number of a load balancing device, and five-tuple information corresponding to the service request, and then match the first firewall identifier with a second firewall identifier in the load balancing device. When the first firewall identifier and the second firewall identifier match, the firewall that matches the first firewall identifier is used to send the service data. In this way, it can be ensured that the firewall that sends the request and the firewall that returns the data are the same firewall, achieving balanced processing of firewall traffic and improving processing efficiency.

[0015] Optionally, the determining module is configured to: Perform a hash calculation on the port number of the preset firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a first hash value; Determine the first hash value as the first firewall identifier corresponding to the service request.

[0016] Some embodiments of the present application perform a hash calculation on the port number of a preset firewall, the port number of a load balancing device, and five-tuple information corresponding to a service request to obtain a seven-tuple hash value, that is, the first firewall identifier. This first firewall identifier is used to determine that the same firewall is used for forward traffic and reverse traffic, facilitating load balancing.

[0017] Optionally, the calculating module is configured to: After receiving the service data, perform a hash calculation on the port number of each firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a second hash value; Determine the second hash value as the second firewall identifier; Judge the first hash value and the second hash value.

[0018] Optionally, the sending module is configured to: If the first hash value and the second hash value are the same, determine the port number of the firewall corresponding to the second hash value as the target firewall port number; Send the service data using the firewall corresponding to the target firewall port number.

[0019] Some embodiments of the present application match the first hash value with second hash values of multiple firewalls in the load balancing device. In this way, a firewall that matches the first hash value can be found from multiple firewalls. In this way, it can be ensured that the firewall that sends the request and the firewall that returns the data are the same firewall, achieving balanced processing of firewall traffic and improving processing efficiency.

[0020] Optionally, the determining module is used to: An MD5 calculation is performed on the port number of the preset firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a first MD5 value.

[0021] Some embodiments of the present application ensure the accuracy of data verification by calculating a seven-tuple hash value containing the port number of a preset firewall.

[0022] In a third aspect, some embodiments of the present application provide an electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, the firewall traffic balancing method as described in any embodiment of the first aspect can be implemented.

[0023] In a fourth aspect, some embodiments of the present application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, can implement the firewall traffic balancing method as described in any embodiment of the first aspect.

[0024] In a fifth aspect, some embodiments of the present application provide a computer program product, comprising a computer program, wherein the computer program, when executed by a processor, can implement the firewall traffic balancing method as described in any embodiment of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to more clearly illustrate the technical solutions of some embodiments of the present application, the drawings required for use in some embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0026] Figure 1 A flowchart of a method for balancing firewall traffic provided in an embodiment of the present application; Figure 2 A flowchart of another method for balancing firewall traffic provided in an embodiment of the present application; Figure 3 A schematic diagram of the structure of a firewall traffic balancing device provided in an embodiment of the present application; Figure 4 A schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0027] The technical solutions in some embodiments of the present application will be described below in conjunction with the drawings in some embodiments of the present application.

[0028] It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.

[0029] With the continuous development of network technology, for the security of data transmission, it is necessary to provide a firewall for the data transmission device. Moreover, if there are many sessions executed at the same time, multiple sessions will use the same firewall for data transmission, while there will also be idle firewalls, which will cause the problem of load imbalance. Therefore, how to improve the efficiency of firewall traffic balancing is a problem that needs to be solved urgently. In view of this, some embodiments of the present application provide a firewall traffic balancing method, which includes receiving a service request sent by a client through a preset firewall; determining a first firewall identifier corresponding to the service request according to the port number of the preset firewall, the port number of the load balancing device and the five-tuple information corresponding to the service request; obtaining the service data corresponding to the service request according to the service request; calculating the second Firewall identifier, and match the first firewall identifier and the second firewall identifier; when the first firewall identifier and the second firewall identifier match, the firewall matching the first firewall identifier is used to send the business data. In the embodiment of the present application, the port number of the firewall that receives the business request is obtained, and the first firewall identifier corresponding to the business request is calculated according to the port number, the port number of the load balancing device and the five-tuple information corresponding to the business request, and then the first firewall identifier is matched with the second firewall identifier in the load balancing device. When the first firewall identifier and the second firewall identifier match, the firewall matching the first firewall identifier is used to send the business data. In this way, it can be ensured that the firewall sending the request and the firewall returning the data are the same firewall, so that the balanced processing of the firewall traffic is achieved and the processing efficiency is improved.

[0030] like Figure 1 As shown, an embodiment of the present application provides a method for balancing firewall traffic, the method comprising: S101, receiving a service request sent by a client through a preset firewall; Specifically, Figure 2 As shown, the client terminal is connected to the switch, the switch is connected to the load balancing device, the load balancing device is connected to the external network, and a firewall is installed on the load balancing device. The number of firewalls is not specifically limited in the embodiment of the present application.

[0031] The client terminal, namely the client, sends a service request to the switch, and the load balancing device receives the service request, namely the session service, through a preset firewall. Exemplarily, the load balancing device receives the service request through firewall 1.

[0032] S102, determining a first firewall identifier corresponding to the service request according to the port number of the preset firewall, the port number of the load balancing device and the five-tuple information corresponding to the service request; Specifically, the load balancing device obtains the port number of the preset firewall, the port number of the load balancing device, and the five-tuple information of the session corresponding to the service request, wherein the five-tuple information of the session includes the five basic attributes of a network data packet, including the source IP address, the destination IP address, the source port number, the destination port number, and the transport protocol. In network communications, each session data packet contains these five attributes, which together constitute the unique identifier of the session data packet.

[0033] The load balancing device performs a hash operation on the port number of the preset firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a first firewall identifier corresponding to the service request.

[0034] S103. Acquire business data corresponding to the business request according to the business request; Specifically, after obtaining the service request, the load balancing device obtains the service data corresponding to the service request from the external network.

[0035] S104, calculating the second firewall identifier of each port number of the load balancing device, and matching the first firewall identifier with the second firewall identifier; Specifically, the load balancing device calculates the firewall identifier for each firewall respectively to obtain the second firewall identifier, that is, performs a hash operation on the port number of each firewall, the port number of the load balancing device and the five-tuple information corresponding to the service request to obtain the second firewall identifier.

[0036] The load balancing device matches the first firewall identifier and the second firewall identifier, and determines the firewall identifier that matches the first firewall.

[0037] S105: When the first firewall identifier and the second firewall identifier match, the service data is sent using the firewall that matches the first firewall identifier.

[0038] Specifically, the load balancing device searches for a firewall matching the first firewall identifier among multiple second firewall identifiers, and uses the firewall matching the first firewall identifier (that is, one of the second firewall identifiers) to send service data.

[0039] Some embodiments of the present application obtain the port number of the firewall that receives the business request, and calculate the first firewall identifier corresponding to the business request based on the port number, the port number of the load balancing device and the five-tuple information corresponding to the business request, and then match the first firewall identifier with the second firewall identifier in the load balancing device. When the first firewall identifier and the second firewall identifier match, the firewall that matches the first firewall identifier is used to send the business data. In this way, it can be ensured that the firewall that sends the request and the firewall that returns the data are the same firewall, thereby achieving balanced processing of firewall traffic and improving processing efficiency.

[0040] Another embodiment of the present application further supplements the firewall traffic balancing method provided in the above embodiment.

[0041] Optionally, determining a first firewall identifier corresponding to the service request according to a port number of a preset firewall, a port number of a load balancing device, and five-tuple information corresponding to the service request includes: Performing a hash calculation on the port number of the preset firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a first hash value; The first hash value is determined as a first firewall identifier corresponding to the service request.

[0042] Some embodiments of the present application perform a hash calculation on the port number of a preset firewall, the port number of a load balancing device, and the five-tuple information corresponding to the service request to obtain a seven-tuple hash value, i.e., a first firewall identifier. The first firewall identifier is used to determine that the forward traffic and the reverse traffic use the same firewall to facilitate load balancing.

[0043] Optionally, calculating the second firewall identifier of each port number of the load balancing device and matching the first firewall identifier with the second firewall identifier includes: After receiving the service data, hash calculations are performed on the port numbers of each firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a second hash value; Determine the second Hash value as a second firewall identifier; The first Hash value and the second Hash value are judged.

[0044] Optionally, when the first firewall identifier and the second firewall identifier match, using the firewall matching the first firewall identifier to send the service data includes: If the first hash value and the second hash value are the same, the port number of the firewall corresponding to the second hash value is determined as the target firewall port number; Use the firewall corresponding to the target firewall port number to send business data.

[0045] Some embodiments of the present application match the first hash value with the second hash values ​​of multiple firewalls in the load balancing device. In this way, a firewall that matches the first hash value can be found from multiple firewalls. In this way, it can be ensured that the firewall that sends the request and the firewall that returns the data are the same firewall, thereby achieving balanced processing of firewall traffic and improving processing efficiency.

[0046] Optionally, performing a hash calculation on the port number of the preset firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a first hash value includes: An MD5 calculation is performed on the port number of the preset firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a first MD5 value.

[0047] Some embodiments of the present application ensure the accuracy of data verification by calculating a seven-tuple hash value containing the port number of a preset firewall.

[0048] like Figure 2 As shown, another embodiment of the present application provides a method for balancing firewall traffic, including: 1. The PC (client) accesses the internet and sends a service request from firewall 1 to the load balancing device through the switch. The load balancing device obtains the service data corresponding to the service request from the internet and returns it to the switch through firewall 1. The switch sends the obtained data to the PC.

[0049] 2. The load balancing device calculates the seven-tuple hash value, i.e., the first hash value, which is also the first firewall identifier, based on the five-tuple, the port number of firewall 1, and the port number of the load balancing device; 3. Load balancing device The load balancing device calculates the firewall identifier for each firewall respectively to obtain a second firewall identifier, that is, a hash operation is performed on the port number of each firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a second hash value, that is, the second firewall identifier; alternatively, the second firewall identifier can be pre-stored in the load balancing device.

[0050] 4. After receiving the service request through firewall 1, the load balancing device calculates the first hash value according to firewall 1, compares the calculated first hash value with the pre-stored second hash value, determines the corresponding firewall according to the first hash value, and returns the data returned from the external network to the switch through the firewall return value.

[0051] 5. Load balancing equipment distributes traffic to multiple firewalls; among them, the forward traffic of the same session needs to be processed by the same firewall; the reverse traffic of the same session needs to be processed by the same firewall to achieve balanced processing of firewall traffic and improve processing efficiency.

[0052] Exemplarily, two firewalls are installed on the load balancing device. Through the switch, the load balancing device receives the service request sent by the client from firewall 1. After the load balancing device obtains the service data corresponding to the service request from the external network, it is necessary to return the obtained service data to the client terminal. In order to achieve load balancing, the forward traffic and the reverse traffic need to be transmitted from the same firewall. In this way, the traffic of a certain firewall is avoided to be too large. Based on this, the load balancing device calculates a seven-tuple hash value, that is, a first hash value, that is, a first firewall identifier, according to the five-tuple, the port number of firewall 1 and the port number of the load balancer, and then calculates the firewall identifiers for firewall 1 and firewall 2 respectively to obtain a second firewall identifier, that is, the port numbers of firewall 1 and firewall 2, the port number of the load balancing device and the five-tuple information corresponding to the service request are hashed to obtain a second hash value, and the two second hash values ​​are matched with the first hash value respectively, and the firewall with the same first hash value is used as the firewall for reverse traffic, that is, the obtained service data is returned to the switch through firewall 1, and the switch sends the obtained data to the PC.

[0053] It should be noted that each implementable method in this embodiment may be implemented separately, or may be implemented in combination in any combination without conflict, and this application is not limited thereto.

[0054] Another embodiment of the present application provides a firewall traffic balancing device, which is used to execute the firewall traffic balancing method provided in the above embodiment.

[0055] like Figure 3 , which is a schematic diagram of the structure of a firewall traffic balancing device provided in an embodiment of the present application. The firewall traffic balancing device includes a receiving module 301, a determining module 302, an acquiring module 303, a calculating module 304 and a sending module 305, wherein: The receiving module 301 is used to receive the service request sent by the client through the preset firewall; The determination module 302 is used to determine the first firewall identifier corresponding to the service request according to the port number of the preset firewall, the port number of the load balancing device and the five-tuple information corresponding to the service request; The acquisition module 303 is used to acquire the business data corresponding to the business request according to the business request; The calculation module 304 is used to calculate the second firewall identifier of each port number of the load balancing device, and match the first firewall identifier with the second firewall identifier; The sending module 305 is used to send the service data by using the firewall matching the first firewall identifier when the first firewall identifier and the second firewall identifier match.

[0056] Regarding the device in this embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.

[0057] Some embodiments of the present application obtain the port number of the firewall that receives the business request, and calculate the first firewall identifier corresponding to the business request based on the port number, the port number of the load balancing device and the five-tuple information corresponding to the business request, and then match the first firewall identifier with the second firewall identifier in the load balancing device. When the first firewall identifier and the second firewall identifier match, the firewall that matches the first firewall identifier is used to send the business data. In this way, it can be ensured that the firewall that sends the request and the firewall that returns the data are the same firewall, thereby achieving balanced processing of firewall traffic and improving processing efficiency.

[0058] Another embodiment of the present application further supplements the firewall traffic balancing device provided in the above embodiment.

[0059] Optionally, a module is determined to: Performing a hash calculation on the port number of the preset firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a first hash value; The first hash value is determined as a first firewall identifier corresponding to the service request.

[0060] Some embodiments of the present application perform a hash calculation on the port number of a preset firewall, the port number of a load balancing device, and the five-tuple information corresponding to the service request to obtain a seven-tuple hash value, i.e., a first firewall identifier. The first firewall identifier is used to determine that the forward traffic and the reverse traffic use the same firewall to facilitate load balancing.

[0061] Optionally, the computing module is used to: After receiving the service data, hash calculations are performed on the port numbers of each firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a second hash value; Determine the second Hash value as a second firewall identifier; The first Hash value and the second Hash value are judged.

[0062] Optionally, the sending module is used to: If the first hash value and the second hash value are the same, the port number of the firewall corresponding to the second hash value is determined as the target firewall port number; Use the firewall corresponding to the target firewall port number to send business data.

[0063] Some embodiments of the present application match the first hash value with the second hash values ​​of multiple firewalls in the load balancing device. In this way, a firewall that matches the first hash value can be found from multiple firewalls. In this way, it can be ensured that the firewall that sends the request and the firewall that returns the data are the same firewall, thereby achieving balanced processing of firewall traffic and improving processing efficiency.

[0064] Optionally, a module is determined to: An MD5 calculation is performed on the port number of the preset firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a first MD5 value.

[0065] Some embodiments of the present application ensure the accuracy of data verification by calculating a seven-tuple hash value containing the port number of a preset firewall.

[0066] Regarding the device in this embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.

[0067] It should be noted that each implementable method in this embodiment may be implemented separately, or may be implemented in combination in any combination without conflict, and this application is not limited thereto.

[0068] The embodiments of the present application also provide a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the operation of the method corresponding to any embodiment of the firewall traffic balancing method provided in the above embodiments can be implemented.

[0069] An embodiment of the present application further provides a computer program product, wherein the computer program product includes a computer program, wherein when the computer program is executed by a processor, it can implement the operations corresponding to the method of any embodiment of the firewall traffic balancing method provided in the above embodiments.

[0070] like Figure 4 As shown, some embodiments of the present application provide an electronic device 400, which includes: a memory 410, a processor 420, and a computer program stored in the memory 410 and executable on the processor 420, wherein the processor 420 can implement any embodiment of the method of balancing firewall traffic as described above when reading the program from the memory 410 through a bus 430 and executing the program.

[0071] Processor 420 can process digital signals and can include various computing structures, such as complex instruction set computer structure, reduced instruction set computer structure, or a structure that implements a combination of multiple instruction sets. In some examples, processor 420 can be a microprocessor.

[0072] The memory 410 may be used to store instructions executed by the processor 420 or data related to the execution of instructions. These instructions and / or data may include codes for implementing some or all functions of one or more modules described in the embodiments of the present application. The processor 420 of the disclosed embodiment may be used to execute instructions in the memory 410 to implement the method shown above. The memory 410 includes a dynamic random access memory, a static random access memory, a flash memory, an optical memory, or other memory known to those skilled in the art.

[0073] The above are only embodiments of the present application and are not intended to limit the scope of protection of the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings.

[0074] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

[0075] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

Claims

1. A method for balancing firewall traffic, characterized in that: Applied to a load balancing device, the method comprises: Receive the service request sent by the client through the preset firewall; Determine a first firewall identifier corresponding to the service request according to the port number of the preset firewall, the port number of the load balancing device and the five-tuple information corresponding to the service request; According to the business request, obtaining business data corresponding to the business request; Calculating a second firewall identifier for each port number of the load balancing device, and matching the first firewall identifier with the second firewall identifier; In a case where the first firewall identifier and the second firewall identifier match, the service data is sent using a firewall that matches the first firewall identifier.

2. The method for balancing firewall traffic according to claim 1, characterized in that: The determining, according to the port number of the preset firewall, the port number of the load balancing device and the five-tuple information corresponding to the service request, a first firewall identifier corresponding to the service request includes: Performing a hash calculation on the port number of the preset firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a first hash value; The first hash value is determined as a first firewall identifier corresponding to the service request.

3. The method for balancing firewall traffic according to claim 2, characterized in that: The step of calculating the second firewall identifier of each port number of the load balancing device and matching the first firewall identifier with the second firewall identifier includes: After receiving the service data, performing hash calculations on the port numbers of each firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a second hash value; Determine the second Hash value as the second firewall identifier; The first Hash value and the second Hash value are judged.

4. The method for balancing firewall traffic according to claim 3, characterized in that: When the first firewall identifier and the second firewall identifier match, using the firewall matching the first firewall identifier to send the service data includes: If the first hash value and the second hash value are the same, determining the port number of the firewall corresponding to the second hash value as the target firewall port number; The service data is sent using a firewall corresponding to the target firewall port number.

5. The method for balancing firewall traffic according to claim 2, characterized in that: The step of performing hash calculation on the port number of the preset firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a first hash value includes: An MD5 calculation is performed on the port number of the preset firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a first MD5 value.

6. A firewall traffic balancing device, characterized in that: Applied to a load balancing device, the device comprises: A receiving module, used for receiving a service request sent by a client through a preset firewall; A determination module, configured to determine a first firewall identifier corresponding to the service request according to the port number of the preset firewall, the port number of the load balancing device and the five-tuple information corresponding to the service request; An acquisition module, used to acquire business data corresponding to the business request according to the business request; A calculation module, used for calculating the second firewall identifier of each port number of the load balancing device, and matching the first firewall identifier with the second firewall identifier; A sending module is used to send the business data using the firewall that matches the first firewall identifier when the first firewall identifier matches the second firewall identifier.

7. The firewall traffic balancing device according to claim 6, characterized in that: The determining module is used to: Performing a hash calculation on the port number of the preset firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a first hash value; The first hash value is determined as a first firewall identifier corresponding to the service request.

8. The firewall traffic balancing device according to claim 7, characterized in that: The computing module is used for: After receiving the service data, performing hash calculations on the port numbers of each firewall, the port number of the load balancing device, and the five-tuple information corresponding to the service request to obtain a second hash value; Determine the second Hash value as the second firewall identifier; The first Hash value and the second Hash value are judged.

9. An electronic device, characterized in that: The invention comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor can implement the firewall traffic balancing method as described in any one of claims 1 to 5 when executing the program.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein when the program is executed by a processor, the method for balancing firewall traffic as described in any one of claims 1 to 5 can be implemented.

Citation Information

Patent Citations

  • Firewall multi-outlet intelligent route selection method

    CN101753426A

  • Data transmission method, data transmission system, firewall device and storage medium

    CN111181985A

  • Message processing method and device for firewall, and storage medium

    CN118473790A

  • Firewall load balancing using a single physical device

    US20050257256A1

  • Network load balancing method, device and system

    WO2018036173A1