MLAG channel protection method, equipment and medium
By performing dynamic binding and channel protection locks implemented by state machines in the MLAG communication channel, the MLAG channel protection problem lacking dynamic perception and self-protection in the prior art is solved, and network stability and security are improved.
Patent Information
- Application Number
- CN202510184535.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-19
- Publication Date
- 2025-05-27
AI Technical Summary
The existing technology lacks an MLAG channel protection mechanism that can achieve dynamic perception, self-protection and does not rely on additional hardware resources, resulting in operation and maintenance complexity and security protection lag problems in the face of large-scale network attacks and dynamic cloud network environments.
The channel protection lock implemented by the state machine is activated by establishing an MLAG communication channel between the two switches to be protected and performing a dynamic binding operation after the channel is successfully established. The lock includes a lock status identification bit and a verification logic unit. Through the verification logic unit, the binding feature verification of the received MLAG protocol packets is determined to determine whether the processing of MLAG protocol packets is allowed.
Dynamic protection of MLAG channels is realized, preventing the failure of MLAG connection establishment caused by IP conflicts and other problems, ensuring network stability and security, reducing security risks caused by information leakage or tampering, and improving the network's self-healing ability and fault handling efficiency.
Smart Images

Figure CN120050248A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical fields of network communication and information security, and particularly to an MLAG channel protection method, device, and medium. Background Art
[0002] In the field of Ethernet switch networking technology, the Multi-Chassis Link Aggregation Group (MLAG) technology, as a key technology for realizing network device redundancy and load balancing, is widely used in data centers and various enterprise network architectures. With the continuous expansion of the network scale, the efficient management and security protection of IP address resources in a complex networking environment have become important challenges for the reliable operation of the network.
[0003] In the traditional MLAG connection establishment mechanism, when multiple groups of MLAG devices use the same IP address for protocol communication and there is no effective VLAN or VRF isolation at the upstream and downstream levels, it is extremely easy to cause IP address conflict problems. Such conflicts will directly lead to abnormal interruption of the MLAG protocol connection, and then cause a large-scale paralysis of network services. The typical solutions of the existing technologies mainly rely on access control lists (ACLs) to filter illegal protocol packets, and static rules are configured on network devices to filter protocol packets with conflicting IPs to ensure the establishment of legal TCP / UDP connections.
[0004] However, the existing technical solutions have significant defects: First, in the face of large-scale network attack scenarios (such as multiple ports concurrently sending protocol packets with the same source IP but abnormal MACs), the ACL rules need to cover all possible attacked ports, resulting in rapid exhaustion of switch hardware resources (such as TCAM entries), and instead forming a new resource bottleneck; Second, the existing filtering mechanism lacks dynamic perception ability, and network administrators must manually maintain the ACL rule set to cope with topological changes, which is extremely easy to cause configuration errors in a complex networking environment; Third, the traditional solution only filters packets based on the IP dimension and cannot defend against man-in-the-middle attacks with legal IP addresses but abnormal MAC addresses, presenting security risks.
[0005] It is particularly worth noting that in a dynamic cloud network environment, the change in the terminal location brought about by virtual machine migration makes the pre-configured static filtering rules difficult to adapt to rapid topological changes, resulting in significant operation and maintenance complexity and security protection lag problems in the actual deployment of existing solutions. Therefore, the industry urgently needs an MLAG channel protection mechanism that can achieve dynamic perception, self-protection, and does not rely on additional hardware resources. Summary of the Invention
[0006] The embodiments of the present application provide an MLAG channel protection method, device and medium, which are used to solve the following technical problems: the prior art lacks an MLAG channel protection mechanism that can achieve dynamic perception, self-protection and does not rely on additional hardware resources.
[0007] In a first aspect, the embodiments of the present application provide an MLAG channel protection method, the method includes: establishing an MLAG communication channel between two switches to be protected, and after the MLAG communication channel is successfully established, performing a dynamic binding operation; activating a channel protection lock implemented by a state machine to lock the MLAG communication channel; wherein, the channel protection lock includes a lock status identification bit and a verification logic unit; when the peer switch sends an MLAG protocol message through the MLAG communication channel, the received MLAG protocol message is verified by the verification logic unit for binding characteristics to determine whether to allow processing of the MLAG protocol message.
[0008] In an implementation manner of the present application, performing the dynamic binding operation specifically includes: obtaining a set of binding characteristic information of the peer device; wherein, the set of binding characteristic information at least includes an IP address, a MAC address and a physical port identifier; persisting the set of binding characteristic information to a local non-volatile memory.
[0009] In an implementation manner of the present application, obtaining the set of binding characteristic information of the peer device specifically includes: using the MLAG communication channel to extract the IP address of the peer device through MLAG protocol interaction messages; parsing the MAC address of the peer device from the layer 2 protocol message; determining the physical port identifier of the message ingress port based on the port forwarding table of the switch.
[0010] In an implementation manner of the present application, after persisting the set of binding characteristic information to the local non-volatile memory, the method further includes: encrypting the set of binding characteristic information using the AES-256 algorithm, and binding and storing the encrypted data with the device hardware fingerprint; establishing a CRC checksum for data integrity verification.
[0011] In an implementation manner of the present application, after activating the channel protection lock implemented by the state machine to lock the MLAG communication channel, the method further includes: starting a timing maintenance mechanism to periodically send a verification request message to the peer device; if a response message that conforms to the set of binding characteristic information is not received within a preset time, generating an alarm log and maintaining the locked state; when the number of consecutive verification failures exceeds a threshold, automatically triggering an unlocking operation of the locked state.
[0012] In one implementation of the present application, the lock status release operation specifically includes: sending an unlock reminder to the user, and receiving an unlock instruction sent by the user through the CLI or API interface; verifying the user's operation authority based on the unlock instruction; if the verification passes, clearing the stored binding feature information set, and disabling the channel protection lock function to allow the switch to enter the reconnection state.
[0013] In one implementation of the present application, the method also includes: after sending an unlock reminder to the user, determining whether both administrators have passed the unlock authorization authentication; before clearing the stored binding feature information set, generating an audit log and recording the operation timestamp and operation user information; after executing the lock status unlock operation, forcibly refreshing the ARP table entry of the switch.
[0014] In one implementation of the present application, the method also includes: automatically triggering the MAC address update process when a network card replacement event of the peer device is detected; obtaining new MAC address verification information through an out-of-band management channel while maintaining a locked state; and updating the binding feature information set after verifying the legitimacy of the new MAC address through a digital certificate.
[0015] In a second aspect, an embodiment of the present application also provides an MLAG channel protection device, the device comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute an MLAG channel protection method such as any one of the above items.
[0016] In a third aspect, an embodiment of the present application further provides a non-volatile computer storage medium for MLAG channel protection, which stores computer executable instructions. When the computer executable instructions are executed, an MLAG channel protection method such as any one of the above is implemented.
[0017] The embodiments of the present application provide a MLAG channel protection method, device, and medium, which have the following features:
[0018] Beneficial effects:
[0019] Strengthen network stability: After the MLAG communication channel is successfully established, dynamic binding is performed and the channel protection lock is activated, which can effectively prevent MLAG connection failures caused by IP conflicts and other problems. This avoids the situation where the entire network service is affected due to interference from the same IP, greatly guarantees the normal operation of the network, ensures the stability and continuity of data transmission, reduces the risk of network failures, and ensures the stable development of services.
[0020] Optimized resource management: Different from the traditional method of using ACL to filter illegal packets with the same IP protocol, the present invention does not require a large amount of ACL resources. Channel protection is achieved through a unique binding and verification mechanism, saving the resource overhead of network devices, enabling the devices to invest more resources in other key network tasks, and improving the overall operating efficiency of network devices.
[0021] Enhanced security: The set of bound feature information is encrypted using the AES-256 algorithm and stored in binding with the device hardware fingerprint. At the same time, a CRC checksum is established for data integrity verification. These multiple encryption and verification means effectively prevent the bound information from being stolen or tampered with, ensuring the accuracy and security of the identity recognition of both communication parties, enhancing the security and anti-attack ability of the network, and reducing the security risks brought by information leakage or tampering.
[0022] Intelligent maintenance and fault handling: Start a timed maintenance mechanism to periodically send verification request messages to the peer device, which can timely detect link anomalies. If a response message that conforms to the set of bound feature information is not received, an alarm log is generated and the locked state is maintained. When the number of consecutive verification failures exceeds the threshold, the locked state release operation is automatically triggered. This series of measures realizes the real-time monitoring and intelligent maintenance of the MLAG channel, facilitating network administrators to timely discover and handle potential problems, and improving the self-healing ability and fault handling efficiency of the network.
[0023] Flexible management and permission control: When unlocking, a reminder is sent to the user and an unlocking instruction sent through the CLI or API interface is received, while the user operation permission is verified. This not only ensures the flexibility of network management, facilitating administrators to operate according to actual needs, but also through a strict permission verification mechanism, prevents network security problems caused by illegal operations, and ensures the security and standardization of network management.
[0024] Operation auditing and recording: An audit log is generated during the unlocking process, recording the operation timestamp and operator information, which helps network administrators trace and audit network operations. By viewing the audit log, the network configuration change situation can be clearly understood, potential security problems and operation mistakes can be timely discovered, and the transparency and traceability of network management are improved.
[0025] Efficient address update mechanism: When a network card replacement event of the peer device is detected, the MAC address update process is automatically triggered. The new MAC address verification information is obtained through the out-of-band management channel, and the bound feature information set is updated after verifying its legality through a digital certificate. This mechanism ensures that when the device hardware changes, the MLAG channel protection mechanism can quickly adapt, maintain normal network communication, and improve the adaptability and compatibility of the network to device changes. Brief Description of the Drawings
[0026] The accompanying drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:
[0027] Figure 1 It is a flowchart of an MLAG channel protection method provided by an embodiment of the present application;
[0028] Figure 2 It is a schematic internal structure diagram of an MLAG channel protection device provided by an embodiment of the present application. Detailed implementation manners
[0029] To make the objectives, technical solutions, and advantages of the present application clearer, the technical solutions of the present application will be clearly and completely described below in conjunction with the specific embodiments of the present application and the corresponding accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0030] The embodiments of the present application provide an MLAG channel protection method, device, and medium, which are used to solve the following technical problems: The prior art lacks an MLAG channel protection mechanism that can achieve dynamic perception, self-protection, and does not rely on additional hardware resources.
[0031] The technical solutions proposed by the embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0032] Figure 1 It is a flowchart of an MLAG channel protection method provided by an embodiment of the present application. As Figure 1 shown, an MLAG channel protection method provided by an embodiment of the present application specifically includes the following steps:
[0033] Step 101: Establish an MLAG communication channel between two switches to be protected, and after the MLAG communication channel is successfully established, perform a dynamic binding operation.
[0034] In one embodiment, to implement MLAG channel protection, the administrator first configures MLAG-related parameters on the two switches to be protected according to the network topology planning, including determining the MLAG group ID, selecting the physical ports participating in MLAG, etc. After the configuration is completed, the two switches perform information interaction through the link to negotiate and establish an MLAG communication channel. During this process, the switches will send and receive MLAG protocol messages to confirm whether the configuration parameters of each other match, such as port rate, duplex mode, etc. Only when the parameters of both sides match and the handshake is successful, the MLAG communication channel is considered to be successfully established.
[0035] Furthermore, perform dynamic binding operations.
[0036] Specifically, obtain the binding feature information set of the peer device; wherein, the binding feature information set at least includes an IP address, a MAC address, and a physical port identifier; and persistently store the binding feature information set in the local non-volatile memory.
[0037] In an embodiment of the present application, obtaining the binding feature information set of the peer device specifically includes: using the MLAG communication channel to extract the IP address of the peer device by parsing the MLAG protocol interaction message; parsing the MAC address of the peer device from the layer 2 protocol message; and determining the physical port identifier of the message ingress port based on the port forwarding table of the switch.
[0038] In an embodiment, after the MLAG communication channel is successfully established, the switch starts to obtain the binding feature information set of the peer device. Using the MLAG communication channel, the switch parses the MLAG protocol interaction message and extracts the IP address of the peer device from the message. At the same time, the switch listens to the layer 2 protocol message and parses the MAC address of the peer device from the message through a specific parsing algorithm. For the determination of the physical port identifier, the switch queries its own port forwarding table and finds the corresponding physical port identifier in the port forwarding table according to the ingress port information of the received message.
[0039] In an embodiment, after obtaining the binding feature information set (IP address, MAC address, and physical port identifier), the switch persistently stores this information in the local non-volatile memory. This ensures that even if the switch restarts or loses power, these key information will not be lost. When storing, it will be organized according to a specific data structure. For example, in the form of key-value pairs, the identifier of the peer device is used as the key, and the binding feature information set is used as the value for storage, which is convenient for subsequent quick query and use.
[0040] In an embodiment of the present application, after persistently storing the binding feature information set in the local non-volatile memory, the method further includes: encrypting the binding feature information set using the AES-256 algorithm and binding and storing the encrypted data with the device hardware fingerprint; and establishing a CRC checksum for data integrity verification.
[0041] In one embodiment, after the set of bound feature information is persistently stored in the local non-volatile memory, the switch encrypts this information using the AES-256 algorithm. The AES-256 algorithm is a symmetric encryption algorithm with relatively high security. It uses a 256-bit key to encrypt the set of bound feature information and converts the plaintext information into ciphertext. During the encryption process, the switch needs to generate or obtain a secure encryption key and store it properly. The encrypted data is bound and stored with the device hardware fingerprint. The device hardware fingerprint is a unique identifier generated based on the hardware characteristics of the switch, such as the MAC address of the network card, the serial number of the CPU, etc. By binding the encrypted data with the hardware fingerprint, the security of the data can be further enhanced. When storing, the encrypted data and the hardware fingerprint can be stored in a specific area of the non-volatile memory in a specific format. For example, a new data block is created, and the encrypted data and the hardware fingerprint are stored in this data block in sequence. To ensure the integrity of the stored data, the switch establishes a CRC checksum. Before storing the set of bound feature information, the CRC checksum of this information set is calculated and stored together with the encrypted data and the hardware fingerprint. When reading the data, the CRC checksum of the read data is calculated again and compared with the stored CRC checksum. If the two are consistent, it indicates that the data has not been in error or tampered with during storage; if they are inconsistent, it indicates that the data may have problems and corresponding processing is required, such as re-obtaining the set of bound feature information.
[0042] Step 102, activate the channel protection lock implemented by the state machine to lock the MLAG communication channel.
[0043] In an embodiment of the present application, the channel protection lock includes a lock status flag bit and a verification logic unit.
[0044] In one embodiment, the channel protection lock is implemented by a state machine. The state machine includes different states, such as an initial unlocked state, a locked state, etc. When the channel protection lock needs to be activated, the state machine transitions from the initial unlocked state to the locked state and sets the lock status flag bit at the same time. This flag bit is used to indicate whether the current MLAG communication channel is in the locked state, which is convenient for each module inside the switch to make a judgment.
[0045] In one embodiment, the verification logic unit is one of the core components of the channel protection lock. In the locked state, when the peer switch sends an MLAG protocol packet through the MLAG communication channel, the verification logic unit starts to work. It verifies the received MLAG protocol packet according to the set of bound feature information stored locally. During the verification process, the IP address, MAC address, and port information carried in the packet are extracted and compared one by one with the bound feature information stored locally.
[0046] In one embodiment of the present application, after activating the channel protection lock implemented by the state machine to lock the MLAG communication channel, the method also includes: starting a scheduled maintenance mechanism to periodically send a verification request message to the peer device; if no response message that meets the binding feature information set is received within a preset time, an alarm log is generated and the locked state is maintained; when the number of consecutive verification failures exceeds a threshold, the lock state release operation is automatically triggered.
[0047] Among them, the lock status release operation specifically includes: sending a lock release reminder to the user, and receiving the unlock command sent by the user through the CLI or API interface; verifying the user's operation authority based on the unlock command; if the verification is successful, clearing the stored binding feature information set, and disabling the channel protection lock function to enable the switch to enter the reconnection state.
[0048] In one embodiment, after activating the channel protection lock and locking the MLAG communication channel, the switch starts the timed maintenance mechanism. By setting a timer, a verification request message is periodically sent to the peer device. For example, the timer can be set to send a verification request message every certain time (such as 5 minutes). The verification request message contains some specific identification information so that the peer device can identify and respond correctly. After receiving the verification request message, the peer device will generate a response message according to the binding feature information set stored in itself and return it to the sender. After receiving the response message, the sender switch verifies the response message through the verification logic unit. If the response message meets the binding feature information set, it means that the link is normal; if a response message that meets the requirements is not received within the preset time, the switch generates an alarm log to record the situation that no response is received, and maintains the current lock state and continues to wait for a response. When the number of consecutive verification failures exceeds the threshold (such as no response message that meets the requirements is received for 3 consecutive times), the switch automatically triggers the lock state release operation. This is to prevent the network from being unable to be used normally due to long-term abnormality of the link. By releasing the lock state, the switch can try to reconnect.
[0049] In one embodiment, the switch sends an unlock reminder to the user, and the reminder method can be a message pop-up window, email notification, etc. through the network management system. After receiving the reminder, the user sends an unlock instruction through the CLI (command line interface) or API (application programming interface) interface. For example, in the CLI interface, the user enters a specific unlock command and enters relevant parameters as prompted; in the API interface, the user calls the corresponding unlock interface function by writing a program and passes the necessary parameters. After receiving the unlock instruction, the switch verifies the user's operation authority based on the instruction. During the verification process, the local user authority database will be queried to compare the information entered by the user (such as user name, password, authority level, etc.) with the records in the database. Subsequent operations are allowed only after the user authority verification is passed. If the authority verification is passed, the switch clears the stored binding feature information set and releases the occupied storage space. At the same time, the channel protection lock function is disabled, so that the state machine is converted to the initial unlocked state. At this time, the switch enters the re-establishment state, waiting for the administrator to reconfigure the MLAG parameters and establish a new MLAG communication channel with other devices.
[0050] In one embodiment of the present application, the method also includes: after sending an unlock reminder to the user, determining whether both administrators have passed the unlock authorization authentication; before clearing the stored binding feature information set, generating an audit log and recording the operation timestamp and operation user information; after executing the lock status unlock operation, forcibly refreshing the ARP table entry of the switch.
[0051] In one embodiment, after sending the unlock reminder to the user, the switch determines whether both administrators have passed the unlock authorization authentication. If the system is set up with a dual administrator mechanism, the unlock operation is allowed to continue only when both administrators have passed the unlock authorization authentication. The authentication method can be by entering the respective user names and passwords, or using other security authentication methods, such as fingerprint recognition, digital certificate authentication, etc.
[0052] Before clearing the stored binding feature information set, the switch generates an audit log. The audit log records the operation timestamp, operation user information (such as user name, IP address, etc.) and related operation information for unlocking. These log information can be stored in a local log file or uploaded to a dedicated log server for centralized management to facilitate subsequent auditing and tracing.
[0053] After the lock state is released, the switch is forced to refresh the ARP (Address Resolution Protocol) table entries. The ARP table is used to resolve IP addresses to MAC addresses. Refreshing the ARP table entries can ensure that the switch obtains the latest MAC address information, avoid data forwarding errors caused by outdated ARP table entries, and ensure normal network communication.
[0054] In one embodiment of the present application, the method further includes: when detecting a network card replacement event of the peer device, automatically triggering a MAC address update process; in the maintained locked state, obtaining new MAC address verification information through an out-of-band management channel; and updating the bound feature information set after verifying the legality of the new MAC address through a digital certificate.
[0055] In one embodiment, the switch monitors the status of the peer device in real time. When detecting a network card replacement event of the peer device, it automatically triggers a MAC address update process. The detection method can be by monitoring changes in the network link status or receiving a specific notification message sent by the peer device. In the maintained locked state, the switch obtains new MAC address verification information through an out-of-band management channel. The out-of-band management channel is a management channel independent of the data transmission channel, such as a serial port, a dedicated management network, etc. Through the out-of-band management channel, the switch can safely obtain the new MAC address information of the peer device and avoid transmitting sensitive management information on the data transmission channel. After the switch obtains the new MAC address verification information, it verifies the legality of the new MAC address through a digital certificate. The digital certificate is issued by an authoritative certificate issuing authority and contains content such as the device's identity information and public key. The switch uses the public key in the digital certificate to verify the signature of the new MAC address. If the verification passes, it indicates that the new MAC address is legal. After confirming the legality, the switch updates the MAC address information in the bound feature information set to ensure the accuracy of the bound feature information and maintain normal communication of the MLAG channel.
[0056] Step 103: When the peer switch sends an MLAG protocol message through the MLAG communication channel, the received MLAG protocol message is subjected to bound feature verification by the verification logic unit to determine whether to allow processing of the MLAG protocol message.
[0057] In one embodiment, the verification logic unit verifies the information in the message according to the "AND" relationship. That is, only when the IP address, MAC address, and physical port identifier in the message are all exactly the same as the bound feature information stored locally, the message is determined to be legal, and the switch is allowed to perform subsequent processing on it, such as data forwarding, protocol interaction, etc. If any of the information does not match, the verification logic unit determines that the message is illegal, and the switch will directly discard the message without any processing, thereby preventing illegal messages from interfering with normal MLAG communication.
[0058] The above is the method embodiment proposed by the present application. Based on the same inventive concept, the embodiments of the present application also provide an MLAG channel protection device, and its structure is as Figure 2 shown.
[0059] Figure 2Schematic diagram of the internal structure of an MLAG channel protection device provided by an embodiment of the present application.
[0060] As Figure 2 shown, the device includes:
[0061] At least one processor 201;
[0062] And a memory 202 communicatively connected to the at least one processor;
[0063] Wherein, the memory 202 stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor 201 so that the at least one processor 201 can:
[0064] Establish an MLAG communication channel between two switches to be protected, and perform a dynamic binding operation after the MLAG communication channel is successfully established;
[0065] Activate a channel protection lock implemented by a state machine to lock the MLAG communication channel; wherein, the channel protection lock includes a lock status identification bit and a verification logic unit;
[0066] When the peer switch sends an MLAG protocol message through the MLAG communication channel, perform binding feature verification on the received MLAG protocol message through the verification logic unit to determine whether to allow processing of the MLAG protocol message.
[0067] Some embodiments of the present application provide a non-volatile computer storage medium corresponding to Figure 1 for MLAG channel protection, storing computer-executable instructions, and the computer-executable instructions are set as:
[0068] Establish an MLAG communication channel between two switches to be protected, and perform a dynamic binding operation after the MLAG communication channel is successfully established;
[0069] Activate a channel protection lock implemented by a state machine to lock the MLAG communication channel; wherein, the channel protection lock includes a lock status identification bit and a verification logic unit;
[0070] When the peer switch sends an MLAG protocol message through the MLAG communication channel, perform binding feature verification on the received MLAG protocol message through the verification logic unit to determine whether to allow processing of the MLAG protocol message.
[0071] The embodiments in the present application are all described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other, and the key points of each embodiment are the differences from other embodiments. In particular, for the embodiments of the Internet of Things devices and media, since they are basically similar to the method embodiments, the description is relatively simple, and for the relevant parts, reference can be made to the partial description of the method embodiments.
[0072] The systems and media provided by the embodiments of the present application correspond one-to-one with the methods. Therefore, the systems and media also have beneficial technical effects similar to those of the corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the systems and media will not be elaborated here.
[0073] Those skilled in the art should understand that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0074] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one or more flows or multiple flows and / or blocks Figure 1 one or more blocks or multiple blocks.
[0075] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one or more flows or multiple flows and / or blocks Figure 1 one or more blocks or multiple blocks.
[0076] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 steps of the functions specified in one block or multiple blocks.
[0077] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0078] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM) and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.
[0079] Computer-readable media includes permanent and non-permanent, removable and non-removable media and can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media such as modulated data signals and carrier waves.
[0080] It should also be noted that the term "comprises", "comprising" or any other variation thereof is intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but also other elements not expressly listed, or elements that are inherent to such process, method, article, or apparatus. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that comprises the element.
[0081] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. A MLAG channel protection method, characterized in that: The method comprises: Establishing an MLAG communication channel between two switches to be protected, and performing a dynamic binding operation after the MLAG communication channel is successfully established; Activate a channel protection lock implemented by a state machine to lock the MLAG communication channel; wherein the channel protection lock includes a lock state identification bit and a verification logic unit; When the opposite switch sends an MLAG protocol message through the MLAG communication channel, the verification logic unit performs binding feature verification on the received MLAG protocol message to determine whether to allow processing of the MLAG protocol message.
2. The MLAG channel protection method according to claim 1, characterized in that: Perform dynamic binding operations, including: Obtaining a binding feature information set of a peer device; wherein the binding feature information set includes at least an IP address, a MAC address, and a physical port identifier; The binding feature information set is persistently stored in a local non-volatile memory.
3. The MLAG channel protection method according to claim 2, characterized in that: Get the binding feature information set of the peer device, including: Utilizing the MLAG communication channel, extracting the IP address of the peer device through MLAG protocol interaction messages; Parse the MAC address of the peer device from the Layer 2 protocol message; The physical port identifier of the message inbound port is determined based on the port forwarding table of the switch.
4. The MLAG channel protection method according to claim 2, characterized in that: After persistently storing the binding feature information set in a local non-volatile memory, the method further includes: Encrypt the binding feature information set using the AES-256 algorithm, and bind the encrypted data to the device hardware fingerprint for storage; Create a CRC checksum to verify data integrity.
5. The MLAG channel protection method according to claim 1, characterized in that: After activating the channel protection lock implemented by the state machine to lock the MLAG communication channel, the method further includes: Start the scheduled maintenance mechanism and periodically send verification request messages to the peer device; If no response message that meets the binding feature information set is received within the preset time, an alarm log is generated and remains locked; When the number of consecutive verification failures exceeds the threshold, the lock status release operation is automatically triggered.
6. The MLAG channel protection method according to claim 5, characterized in that: The lock state release operation includes: Send unlock reminders to users and receive unlock instructions sent by users through the CLI or API interface; Verifying the user's operating authority based on the unlock instruction; If the verification is successful, the stored binding feature information set is cleared and the channel protection lock function is disabled to enable the switch to enter the reconnection state.
7. The MLAG channel protection method according to claim 6, characterized in that: The method further comprises: After sending the unlock reminder to the user, determine whether both administrators have passed the unlock authorization authentication; Before clearing the stored binding feature information set, an audit log is generated and the operation timestamp and operation user information are recorded; After the lock state is released, the ARP table of the switch is refreshed forcibly.
8. The MLAG channel protection method according to claim 1, characterized in that: The method further comprises: When the network card of the peer device is replaced, the MAC address update process is automatically triggered; While maintaining the locked state, obtain new MAC address verification information through the out-of-band management channel; After verifying the legitimacy of the new MAC address through the digital certificate, the binding feature information set is updated.
9. An MLAG channel protection device, characterized in that: The device comprises: at least one processor; and, a memory communicatively coupled to the at least one processor; The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the MLAG channel protection method as described in any one of claims 1-8.
10. A non-volatile computer storage medium for MLAG channel protection, storing computer executable instructions, characterized in that: When the computer executable instructions are executed, an MLAG channel protection method as described in any one of claims 1 to 8 is implemented.