ACL rule effective method, electronic equipment and storage medium

By taking effect and compatible ACL rules on their own in network devices, the problem of only one ACL rule in the prior art is solved, and the coordinated application and rapid recovery function of multiple ACL rules are realized.

CN120075046APending Publication Date: 2025-05-30ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311636899.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-30
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing network devices can only select one ACL rule according to priority sorting for effective purposes, resulting in the functions of many other ACL rules being unable to be used normally.

Method used

By determining all candidate ACL rules on the target object that matches the target message and finding compatible target ACL rules from them, these target ACL rules will be effective on the target object by themselves.

Benefits of technology

On the premise of avoiding logical conflicts in packet processing, more ACL rules functions can be implemented as much as possible, support multiple application scenarios, and quickly restore the original ACL rules to take effect after the device restarts.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120075046A_ABST
    Figure CN120075046A_ABST
Patent Text Reader

Abstract

The invention provides an ACL rule effective method, electronic equipment and a storage medium. The method comprises the following steps: determining all candidate ACL rules matched with a target message on a target object; all target ACL rules are determined from all the candidate ACL rules; wherein any two target ACL rules are compatible with each other. All the target ACL rules take effect on the target object; wherein the target ACL rule is used for guiding the target object to process the target message. According to the method and the device, the problem that the functions of many other ACL rules cannot be normally used due to the fact that existing network equipment can only select one ACL rule to take effect according to priority ranking is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a method for ACL rule activation, an electronic device, and a storage medium. Background Art

[0002] An access control list (ACL) is a commonly used access control technology that can be used in network devices such as routers, switches, and firewalls. In related technologies, to avoid conflicts in packet processing logic, usually only one ACL rule can be selected for activation in a certain priority order. This activation method is too conservative, resulting in the inability to normally utilize the functions of many other ACL rules. Summary of the Invention

[0003] The purpose of this application is to provide a method for ACL rule activation, an electronic device, and a storage medium, to solve the problem that existing network devices can only select one ACL rule for activation according to the priority order, thereby causing the functions of many other ACL rules to be unable to be normally utilized.

[0004] To achieve the above purpose, the embodiments of this application are implemented as follows:

[0005] In a first aspect, a method for ACL rule activation is provided, including:

[0006] Determine all candidate ACL rules that match the target packet on the target object;

[0007] Determine all target ACL rules from all the candidate ACL rules; where any two of the target ACL rules are compatible with each other;

[0008] Activate all the target ACL rules on the target object; where the target ACL rules are used to guide the target object to process the target packet.

[0009] In a second aspect, an embodiment of this application provides an electronic device, including: a processor; and a memory configured to store computer-executable instructions, where the computer-executable instructions, when executed, cause the processor to execute the method described in the first aspect.

[0010] In a third aspect, a computer-readable storage medium is provided, where the computer-readable storage medium is used to store computer-executable instructions, and the computer-executable instructions, when executed by a processor, implement the method described in the first aspect.

[0011] Based on the solution of the embodiments of the present application, when the target object receives the target message, it first queries all the ACL rules in the local that match the target message as candidate ACL rules. Then, all the target ACL rules that are compatible with each other are found among all the candidate ACL rules, and all the target ACL rules are made effective, so as to realize the functions of more ACL rules as much as possible on the premise of avoiding conflicts in message processing logic to serve different scenarios. In addition, since it is a solution for the target object to make the ACL rules effective by itself, when the physical device of the target object is restarted, there is no need to wait for the upper layer to reissue the ACL rules, and most of the previously effective ACL rules can be quickly restored, and this restoration is determinable and will not bring unexpected changes to the overall function. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0013] Figure 1 It is a schematic flowchart of the method for making the ACL rules effective in the embodiments of the present application.

[0014] Figure 2 It is a schematic flowchart of the process for matching the ACL rules to be made effective in the embodiments of the present application.

[0015] Figure 3 It is a schematic structural diagram of the device for making the ACL rules effective in the embodiments of the present application.

[0016] Figure 4 It is a schematic structural diagram of the electronic device in the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0017] As mentioned above, with the evolution of network technology, the functions of the ACL rules configured on network devices are becoming more and more complex, and more and more dimensions are considered. Different dimensions have different starting points for the processing logic of data messages, which results in some ACL rules that may not be compatible with each other being configured for the same message on network devices.

[0018] Here, the ACL rules in the dimension of network security are simply taken as an example. From the perspective of the ports of network devices, the ACL rules set for the target packets are Permit operations. However, from the perspective of the entire Virtual Local Area Network (VLAN), the ACL rules set for the target packets may be Deny operations. For network devices, both the Permit in the port dimension and the Deny in the VLAN dimension are ACL rules set for the target packets, but obviously, Permit and Deny are not compatible with each other.

[0019] The above is only an example of a scenario where the processing logics of ACL rules conflict with each other in one dimension. In actual applications, the scenarios where ACL rules intersect and exclude each other are more complex. There are ACL rules set for QoS speed limiting, and there are also ACL rules set for route matching, and so on. Currently, in order to avoid conflicts in the packet processing logic, network devices can only select one ACL rule to take effect according to a certain priority order, which results in the inability to normally utilize the functions of many other ACL rules, imposing great limitations on network devices.

[0020] In addition, after the network device restarts, the effective ACL rules need to be reset. Generally, the upper layer issues the ACL rules that need to take effect to the network device. Therefore, which ACL rules take effect on the network device depends on the issuing order, with great uncertainty.

[0021] In view of this, the present application aims to propose a technical solution that enables a network device to simultaneously take effect multiple ACL rules by itself.

[0022] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of this specification.

[0023] An embodiment of the present application proposes a method for an ACL rule to take effect, which can be applied to network devices such as routers and layer-3 switches, or a certain port of a network device, or the entire VLAN. Figure 1 The following is a schematic flowchart of the method for this embodiment to take effect, including:

[0024] S102, determine all candidate ACL rules that match the target packets on the target object.

[0025] In this embodiment, the target object may refer to network devices, ports on network devices, VLANs, etc., which are not specifically limited herein; all candidate ACL rules matching the target packet refer to all ACL rules configured for the target text on the target object, and may include, but are not limited to, ACL rules in at least one of the port control dimension, QoS control dimension, and VLAN control dimension.

[0026] Specifically, all configured ACL rules of the target object are stored in the local chip. When the target packet is received, a table lookup can be performed in the local chip to find all candidate ACL rules matching the target packet.

[0027] S104. Determine all target ACL rules from all candidate ACL rules; where any two target ACL rules are compatible with each other.

[0028] Specifically, in this embodiment, all ACL rules are divided into at least one group according to the effective conflict relationship among all ACL rules on the target object. Among them, an ACL rule is divided into one group, and all ACL rules in each group are compatible with each other, that is, the target object can take effect all ACL rules in one group, so as to distinguish the effective relationship in the form of a group.

[0029] As an exemplary introduction, all ACL rules on the target object can be classified into fully compatible types and non-fully compatible types. As the name implies, the ACL rules of the fully compatible type are compatible with any other ACL rules on the target object; the ACL rules of the non-fully compatible type are not compatible with at least one other ACL rule on the target object.

[0030] On the one hand, in this embodiment, all fully compatible type ACL rules are divided into the first type of group.

[0031] For example, ACL rules such as statistics, mirroring, enabling or disabling differentiated services code point (DSCP), and QoS rate limiting do not conflict with any other ACL rules, so the ACL rules of the statistics type, mirroring type, DSCP type, and QoS type are divided into the first type of group.

[0032] Among them, if the first type of group contains candidate ACL rules matching the target packet, then all candidate ACL rules corresponding to the first type of group are determined as target ACL rules.

[0033] On the other hand, in this embodiment, all non-full-compatible ACL rules are divided into at least two second-type groups. Among them, any two non-full-compatible ACL rules that are incompatible are divided into different second-type groups, and each ACL rule in the second-type group is incompatible with at least some of the ACL rules in other second-type groups that conflict with its effectiveness.

[0034] For example, the ACL rules of Drop and Deny are incompatible with the ACL rules of Permit and Redirect. Then, Drop and Deny are divided into one second-type group, and Permit and Redirect are divided into another second-type group.

[0035] Among them, if the candidate ACL rules matching the target packet are included in both of the second-type groups that conflict with each other in effectiveness, only all the candidate ACL rules corresponding to one of the second-type groups are determined as the target ACL rules, and the other second-type groups are not considered. For example, in the case where the second-type group of "Drop" and "Deny" and the second-type group of "Permit" and "Redirect" both include candidate ACL rules matching the target packet, if all the candidate ACL rules in the second-type group of "Drop" and "Deny" are determined as the target ACL rules, then the determination of the target ACL rules in the second-type group of "Permit" and "Redirect" is no longer considered.

[0036] In addition, in some embodiments, among the second-type groups that conflict with each other in effectiveness, the one with the largest number of candidate ACL rules can be determined as the target second-type group, and all the candidate ACL rules in the target second-type group are determined as the target ACL rules to maximize the number of target ACL rules; or, according to actual requirements, group priorities can be pre-configured for each of the second-type groups that conflict with each other in effectiveness, and the second-type group with the highest group priority among the second-type groups corresponding to the candidate ACL rules is determined as the target second-type group, and then all the candidate ACL rules in the target second-type group are determined as the target ACL rules.

[0037] S106, all the target ACL rules take effect on the target object; among them, the target ACL rules are used to guide the target object to forward the target packet.

[0038] In this embodiment, there is no incompatibility problem among all target ACL rules. Therefore, all target ACL rules can take effect on the target object simultaneously. It should be understood that once these target ACL rules take effect on the target object, it is equivalent to controlling the target object to process the target packet according to the operations indicated by the target ACL rules, which can be but is not limited to the allow or deny operations, QOS rate limiting operations, DSCP start / stop operations, etc. mentioned above.

[0039] Suppose the target ACL rules for functions such as QOS rate limiting, network security, and DSCP take effect simultaneously. Then the target object can apply functions such as QOS rate limiting, network security, and DSCP simultaneously. Compared with the traditional scheme of selecting one ACL rule to take effect preferentially, the application scenario is enriched.

[0040] Based on the method of this embodiment, when the target object receives a target packet, it first queries all local ACL rules that match the target packet as candidate ACL rules. Then, all mutually compatible target ACL rules are found among all candidate ACL rules, and all target ACL rules are made to take effect. Thus, on the premise of avoiding conflicts in packet processing logic, the functions of as many ACL rules as possible are realized as much as possible to serve different scenarios. In addition, since it is a scheme in which the target object itself makes the ACL rules take effect, after the physical device of the target object is restarted, there is no need to wait for the upper layer to reissue the ACL rules, and most of the originally effective ACL rules can be quickly restored, and this restoration is determinable and will not bring unexpected changes to the overall function.

[0041] The method of this embodiment will be introduced in detail below in combination with an actual application scenario.

[0042] In this application scenario, the target object is a port, and the ACL rules include: Permit, Drop, Deny, statistics, Mirror, Redirect, Set DSCP, and QOS rate limiting operation.

[0043] Reference Figure 2 As shown, the following groupings are made for these ACL rules in advance:

[0044] Operations such as statistics, Mirror, Redirect, Set DSCP, and QOS rate limiting do not conflict with other ACL rules. Therefore, statistics, Mirror, Redirect, Set DSCP, and QOS rate limiting are classified into the first type of group.

[0045] Drop and Deny are compatible with each other, and Permit and Redirect are compatible with each other. However, "Drop, Deny" and "Permit, Redirect" are not compatible. Therefore, Drop and Deny are classified into a second type of group, and Permit and Redirect are classified into another second type of group.

[0046] It should be understood that the groups divided above can be applied as prior knowledge.

[0047] After that, after the target object receives the target message, the following steps are executed:

[0048] 1. Based on the information of the target message, look up the ACL rules in the local chip to determine all candidate ACL rules applicable to the target message.

[0049] 2. Find all ACL entries related to the port of this target message. Assume that candidate ACL rules 1 / 2 / 3 / 4 are found.

[0050] 3. Match the ACL rules 1 / 2 / 3 / 4 with the divided groups.

[0051] Here, assume that ACL rule 1 is in the first type of group, ACL rules 2 and 3 are in the second type of group of "Drop, Deny", and ACL rule 4 is in the second type of group of "Permit, Redirect".

[0052] It should be noted that ACL rule 1 belonging to the first type of group means that ACL rule 1 is one of "Statistics, Mirror, Redirect, Set DSCP, and QoS rate limiting". Similarly, ACL rules 2 and 3 belonging to the second type of group of "Drop, Deny" means that ACL rules 2 and 3 belong to one of "Drop, Deny" respectively, which will not be elaborated here.

[0053] According to the matching relationship between the ACL rules 1 / 2 / 3 / 4 and the current first type of group and the second type of group, it can be determined that:

[0054] ACL rule 1 is compatible with any other ACL rule. Therefore, directly determine ACL rule 1 as the target ACL rule that will take effect later.

[0055] ACL rules 2, 3 and ACL rule 4 conflict with each other. Since there are two ACL rules related to the target packet in the second type group of "Drop, Deny", while there is only one ACL rule related to the target packet in the second type group of "Permit, Redirect", under the strategy of making as many ACL rules effective as possible, ACL rules 2 and 3 are determined as the target ACL rules to be effective subsequently, and ACL rule 4 is directly ignored.

[0056] Or, if the group priority of the second type group of "Permit, Redirect" is preset to be higher than that of the second type group of "Drop, Deny", ACL rule 4 can also be determined as the target ACL rule to be effective subsequently, and ACL rules 2 and 3 are directly ignored.

[0057] 4. On the target object, all the determined target ACL rules in ACL rules 1 / 2 / 3 / 4 are made effective simultaneously.

[0058] It should be noted that the above solution can make the target object run ACL rules in different dimensions simultaneously. Here, taking the ACL rules in the port dimension and the ACL rules in the QOS dimension as examples, the following scenarios can be achieved:

[0059] A. Effective simultaneously when the ACL rules do not conflict: The ACL rules in the port dimension, such as Permit and statistics, do not conflict with all the ACL rules in the QOS dimension, so they can be made effective simultaneously.

[0060] B. There is Drop in the ACL rules in the QOS dimension, and the ACL rules in the port dimension are Permit and statistics. When there is Permit in the ACL rules in the port dimension, the packet is either Drop or Permit, and the statistics are made effective simultaneously.

[0061] C. There is Deny in the ACL rules in the port dimension, and the ACL rules in the QOS dimension are Mirror and statistics, then the packet is denied, and Mirror and statistics are made effective simultaneously.

[0062] D. There is Deny in the ACL rules in the port dimension, and the ACL rules in the QOS dimension are Redirect and Set DSCP, etc., then the packet is either Deny or Redirect, and Set DSCP is made effective simultaneously.

[0063] E. There is Deny in the ACL rules in the port dimension, and the ACL rules in the QOS dimension are speed limit actions such as Police cir, then Deny and Police cir of the packet are made effective simultaneously, and it can be Police cir first and then Deny.

[0064] In summary, the method of this embodiment can improve the application scope of the network device for ACL rules, especially for the scenario of multi-dimensional ACL rule intersection, and has good application effects.

[0065] In addition, another embodiment of the present application proposes an ACL rule activation device, which can be applied to network devices such as routers and layer-3 switches, or a certain port of a network device, or the entire VLAN. Figure 3 FIG. 3 is a schematic structural diagram of the activation device 300, including:

[0066] A rule matching module 310, configured to determine all candidate ACL rules that match the target packet on the target object.

[0067] A rule screening module 320, configured to determine all target ACL rules from all the candidate ACL rules; wherein, any two of the target ACL rules are compatible with each other.

[0068] A rule activation module 330, configured to activate all the target ACL rules on the target object; wherein, the target ACL rules are used to guide the target object to process the target packet.

[0069] Based on the device of the embodiment of the present application, when the target object receives the target packet, it first queries all the ACL rules that match the target packet locally as candidate ACL rules. Then, all the target ACL rules that are compatible with each other are found from all the candidate ACL rules, and all the target ACL rules are activated, so as to realize the functions of as many ACL rules as possible on the premise of avoiding packet processing logic conflicts to serve different scenarios. In addition, since it is a solution for the target object to activate the ACL rules by itself, after the physical device of the target object is restarted, it is not necessary to wait for the upper layer to reissue the ACL rules, and most of the originally activated ACL rules can be quickly restored, and this restoration is determinable and will not bring unexpected changes to the overall function.

[0070] Optionally, the rule screening module 320 determines all target ACL rules from all the candidate ACL rules, including: determining at least one group corresponding to all the candidate ACL rules; the at least one group is obtained by pre-dividing all the ACL rules on the target object, one ACL rule corresponds to one group, and all the ACL rules in each group are compatible with each other; based on the at least one group, all the target ACL rules are determined.

[0071] Optionally, the rule screening module 320 determines all the target ACL rules based on the at least one group, including: when the at least one group includes a first type of group, determining all the candidate ACL rules corresponding to the first type of group as the target ACL rules; wherein, each ACL rule in the first type of group is compatible with other ACL rules on the target object. And, when the at least one group includes at least two second type of groups with conflicting effects, determining all the candidate ACL rules corresponding to one of the second type of groups as the target ACL rules based on a preset rule; wherein, each ACL rule in the second type of group is not compatible with at least some of the ACL rules in other second type of groups with which it has a conflicting effect.

[0072] Optionally, before determining the at least one group corresponding to all the candidate ACL rules, the rule screening module 320 also divides all the ACL rules into the at least one group according to the conflicting effect relationship between all the ACL rules on the target object.

[0073] Optionally, dividing all the ACL rules into the at least one group according to the conflicting effect relationship between all the ACL rules on the target object includes: determining all the fully compatible type of ACL rules from all the ACL rules on the target object; wherein, the fully compatible type of ACL rules are compatible with other ACL rules on the target object; dividing all the fully compatible type of ACL rules into the first type of group.

[0074] Optionally, dividing all the ACL rules into the at least one group according to the conflicting effect relationship between all the ACL rules on the target object includes: determining all the non-fully compatible type of ACL rules from all the ACL rules on the target object; wherein, the non-fully compatible type of ACL rules are not compatible with at least one other ACL rule on the target object; dividing all the non-fully compatible type of ACL rules into at least two second type of groups; wherein, any two non-fully compatible type of ACL rules that are not compatible are divided into different second type of groups.

[0075] Optionally, for non-fully compatible types of ACL rules corresponding to operations of drop, deny, permit, and redirect operations, the non-fully compatible types of ACL rules corresponding to the drop operation and the deny operation are divided into one of the second type groups, and the non-fully compatible types of ACL rules corresponding to the permit operation and the redirect operation are divided into another second type group.

[0076] Optionally, the rule screening module 320 determines all the candidate ACL rules in one of the second type groups as target ACL rules based on a preset rule, including: among all the second type groups, determining the one with the largest number of candidate ACL rules included as the target second type group, or determining the second type group with the highest group priority as the target second type group; and determining all the candidate ACL rules corresponding to the target second type group as the target ACL rules.

[0077] Optionally, the target object includes at least one of a port of a communication device and a virtual network. Among them, there are ACL rules corresponding to at least one of a port surface control dimension, a quality of service surface control dimension, and a virtual network surface control dimension on the target object.

[0078] It should be noted that the effective device of the ACL rules in this embodiment is Figure 1 the execution subject of the method shown, and thus can implement Figure 1 the steps and functions in the method shown.

[0079] Figure 4 It is a schematic structural diagram of an electronic device according to an embodiment of this specification. Please refer to Figure 4 , at the hardware level, the electronic device includes a processor, and optionally also includes an internal bus, a network interface, and a memory. Among them, the memory may include a memory, such as a high-speed random access memory (RAM), and may also include a non-volatile memory, such as at least one disk memory, etc. Of course, the electronic device may also include other hardware required for other services.

[0080] The processor, network interface, and memory can be interconnected via an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, an EISA (Extended Industry Standard Architecture) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 4 only a bidirectional arrow is used in the figure, but it does not mean that there is only one bus or one type of bus.

[0081] A memory for storing programs. Specifically, the program can include program code, and the program code includes computer operation instructions. The memory can include a memory and a non-volatile memory, and provide instructions and data to the processor. Among them, the processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it. Correspondingly, the processor executes the program stored in the memory and is specifically used to perform the following operations:

[0082] Determine all candidate ACL rules that match the target message on the target object.

[0083] Determine all target ACL rules from all the candidate ACL rules; among them, any two of the target ACL rules are compatible with each other.

[0084] Effectuate all the target ACL rules on the target object; among them, the target ACL rules are used to guide the target object to process the target message.

[0085] Based on the electronic device of this embodiment, when the target object receives the target message, it first queries all the ACL rules that match the target message locally as candidate ACL rules. Then, find all the target ACL rules that are compatible with each other among all the candidate ACL rules and effectuate all the target ACL rules, so as to achieve the functions of more ACL rules as much as possible on the premise of avoiding message processing logic conflicts to serve different scenarios. In addition, since it is a solution for the target object to effectuate the ACL rules by itself, when the physical device of the target object is restarted, there is no need to wait for the upper layer to reissue the ACL rules, and most of the previously effectuated ACL rules can be quickly restored, and this restoration is determinable and will not bring unexpected changes to the overall function.

[0086] The method for enabling ACL rules disclosed in the embodiments as shown in this specification can be applied to a processor and implemented by the processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, the steps of the above method can be completed through the integrated logic circuit of the hardware in the processor or instructions in software form. The above-mentioned processor may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of this application can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by a combination of the hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method.

[0087] Of course, in addition to the software implementation method, the electronic device in this specification does not exclude other implementation methods, such as a logic device or a combination of software and hardware, etc. That is to say, the execution subject of the following processing flow is not limited to each logic unit, and can also be hardware or a logic device.

[0088] In addition, the embodiments of this application also propose a computer-readable storage medium that stores one or more programs, and the one or more programs include instructions. When the above instructions are executed by a portable electronic device including multiple application programs, the portable electronic device can be enabled to execute Figure 1 the steps of the method shown, including:

[0089] Determine all candidate ACL rules that match the target packet on the target object.

[0090] Determine all target ACL rules from all the candidate ACL rules; among them, any two of the target ACL rules are compatible with each other.

[0091] Effect all the target ACL rules on the target object; wherein, the target ACL rules are used to guide the target object to process the target message.

[0092] Those skilled in the art should understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, this specification can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0093] The above describes specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the specific order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0094] The above are only embodiments of this specification and are not used to limit this specification. For those skilled in the art, this specification can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of this specification shall be included within the scope of the claims of this specification. In addition, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this document.

Claims

1. A method for the effectiveness of access control list (ACL) rules, including: Determining all candidate ACL rules that match the target packet on the target object; Determining all target ACL rules from all the candidate ACL rules; wherein, any two of the target ACL rules are compatible with each other; Making all the target ACL rules effective on the target object; wherein, the target ACL rules are used to guide the target object to process the target packet.

2. The method according to claim 1, Determining all target ACL rules from all the candidate ACL rules, including: Determining at least one group corresponding to all the candidate ACL rules; The at least one group is obtained by pre-dividing all ACL rules on the target object, and one ACL rule is divided into one of the groups, and all ACL rules in each group are compatible with each other; Based on the at least one group, determining all the target ACL rules.

3. The method according to claim 2, Based on the at least one group, determining all the target ACL rules, including: When the at least one group includes a first type of group, determining all the candidate ACL rules corresponding to the first type of group as the target ACL rules; wherein, each ACL rule in the first type of group is compatible with other ACL rules on the target object.

4. The method according to claim 2, Based on the at least one group, determining all the target ACL rules, including: When the at least one group includes at least two second type of groups with conflicting effectiveness, based on a preset rule, determining all the candidate ACL rules corresponding to one of the second type of groups as the target ACL rules; wherein, each ACL rule in the second type of group is not compatible with at least some of the ACL rules in other second type of groups with which it has a conflicting effectiveness.

5. The method according to claim 4, Based on a preset rule, determining all the candidate ACL rules corresponding to one of the second type of groups as the target ACL rules, including: Among all the second type of groups, determining the one with the largest number of candidate ACL rules included as the target second type of group, or determining the second type of group with the highest group priority as the target second type of group; Determining all the candidate ACL rules corresponding to the target second type of group as the target ACL rules.

6. The method according to claim 2, Before determining at least one group corresponding to all the candidate ACL rules, the method further includes: Dividing all the ACL rules into the at least one group according to the effectiveness conflict relationship among all the ACL rules on the target object.

7. The method according to claim 6, Dividing all the ACL rules into the at least one group according to the effectiveness conflict relationship among all the ACL rules on the target object, including: Determine all ACL rules of the fully compatible type from all the ACL rules on the target object; wherein, the ACL rules of the fully compatible type are compatible with other ACL rules on the target object; Divide all the ACL rules of the fully compatible type into a first type group.

8. The method according to claim 6, Divide all the ACL rules into the at least one group according to the effective conflict relationship among all the ACL rules on the target object, including: Determine all the ACL rules of the non-fully compatible type from all the ACL rules on the target object; wherein, the ACL rules of the non-fully compatible type are not compatible with at least one other ACL rule on the target object; Divide all the ACL rules of the non-fully compatible type into at least two second type groups; wherein, any two incompatible ACL rules of the non-fully compatible type are divided into different second type groups.

9. The method according to claim 8, For the ACL rules of the non-fully compatible type corresponding to the operations of drop, deny, permit, and redirect operations, the ACL rules of the non-fully compatible type corresponding to the drop operation and the deny operation are divided into one second type group, and the ACL rules of the non-fully compatible type corresponding to the permit operation and the redirect operation are divided into another second type group.

10. The method according to any one of claims 1 to 9, The target object includes at least one of a port of a communication device and a virtual network.

11. The method according to claim 10, There are ACL rules corresponding to at least one of a port plane control dimension, a quality of service plane control dimension, and a virtual network plane control dimension on the target object.

12. An electronic device, comprising a processor; and a memory configured to store computer-executable instructions, the computer-executable instructions, when executed, cause the processor to execute the method according to any one of claims 1-11.

13. A computer-readable storage medium, the computer-readable storage medium is used to store computer-executable instructions, the computer-executable instructions, when executed by a processor, implement the method according to any one of claims 1-11.