Configuration fallback method and device, network equipment and program product
By selecting the target network device and archived configuration on the configuration management interface of the network device, and automatically generating and executing fallback commands, the problem of more human intervention in the configuration comparison and fallback process in the prior art is solved, and efficient and automated configuration management is achieved.
Patent Information
- Application Number
- CN202510307689.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-06-24
Smart Images

Figure CN120200914A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer networks, and particularly to a method, apparatus, network device and program product for configuration rollback. Background Art
[0002] A switch is a network device for forwarding electrical (optical) signals. It can provide an exclusive electrical signal path for any two network nodes connected to the switch. Among them, the configuration of the switch is very important to ensure the normal operation of the network.
[0003] The configuration of the switch is generally manually set and debugged by a network administrator. If a configuration error occurs in the switch, a configuration failure occurs, or the configuration has an unexpected result on the network, the network administrator needs to log in to the switch system, retrieve the current configuration and the previously saved configuration, manually compare the differences between the two, and then manually modify the configuration according to these differences.
[0004] In the above method, there are still many intervention operations by network administrators in the comparison and rollback of configurations. Summary of the Invention
[0005] In view of this, the present invention provides a method for configuration rollback to reduce many manual intervention operations still existing in the process of configuration comparison and rollback of network devices, simplify the configuration management process of network devices, and improve the efficiency of configuration management.
[0006] According to the first aspect of the embodiments of the present invention, a method for configuration rollback is provided. The method includes: displaying a configuration management interface of a network device; in response to a selection operation on the network device on the configuration management interface, displaying the selected target network device; in response to a selection operation on the archived configuration of the target network device on the configuration management interface, displaying the selected target configuration; and in response to an operation of rolling back the current configuration of the target network device to the target configuration, generating and executing a rollback command.
[0007] According to the second aspect of the embodiments of the present invention, a device for configuration rollback is provided. The device includes: a display module for displaying a configuration management interface of a network device; the display module for displaying the selected target network device in response to a selection operation on the network device on the configuration management interface; the display module for displaying the selected target configuration in response to a selection operation on the archived configuration of the target network device on the configuration management interface; and an execution module for generating and executing a rollback command in response to an operation of rolling back the current configuration of the target network device to the target configuration.
[0008] According to a third aspect of an embodiment of the present invention, a network device is provided. The network device includes: a processor, a memory, a communication interface, and a communication bus. The processor, the memory, and the communication interface complete communication with each other through the communication bus. The memory is used to store at least one executable instruction, and the executable instruction causes the processor to perform operations corresponding to the method described in the previous aspect.
[0009] According to a fourth aspect of an embodiment of the present invention, a computer program product is provided. The computer program product includes computer instructions, and the computer instructions instruct a computer device to perform operations corresponding to the method described in the first aspect above.
[0010] According to a fifth aspect of an embodiment of the present invention, a computer-readable storage medium is provided. A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the method described in the first aspect above is implemented.
[0011] As can be seen from the above solution, due to the configuration rollback solution provided by the present invention, a target network device is selected on the configuration management interface, and a target configuration is selected from the archived configurations, and then the rollback operation is triggered to automatically generate and execute a rollback command to roll back the current configuration of the target network device to the target configuration. There is no need for a management personnel to manually compare the current configuration with the target configuration, nor is there a need for a management personnel to modify the current configuration to roll back to the target configuration, reducing many manual intervention operations still existing in the process of configuration comparison and rollback, simplifying the configuration management process of the network device, and improving the efficiency of configuration management. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] The following will make the above and other features and advantages of the present invention clearer to those of ordinary skill in the art by describing the preferred embodiments of the present invention in detail with reference to the drawings, in which:
[0013] Figure 1 It is a flowchart of a method for rolling back a configuration provided for an exemplary embodiment of the present invention.
[0014] Figure 2 It is a schematic diagram of a rollback interface for a configuration provided for an exemplary embodiment of the present invention.
[0015] Figure 3 It is a flowchart of a method for comparing configurations provided for an exemplary embodiment of the present invention.
[0016] Figure 4 It is a schematic diagram of a comparison interface for a configuration provided for an exemplary embodiment of the present invention.
[0017] Figure 5 It is a flowchart of a method for archiving a configuration provided for an exemplary embodiment of the present invention.
[0018] Figure 6 Schematic diagram of the archiving interface for the configuration provided for the exemplary embodiment of the present invention.
[0019] Figure 7 Schematic diagram of the management interface of the network device provided for the exemplary embodiment of the present invention.
[0020] Figure 8 Schematic diagram of the configuration management interface provided for the exemplary embodiment of the present invention.
[0021] Figure 9 Schematic diagram of the rollback device for the configuration provided for the exemplary embodiment of the present invention.
[0022] Figure 10 Schematic diagram of the rollback device for the configuration provided for another exemplary embodiment of the present invention.
[0023] Figure 11 Schematic diagram of the structure of the electronic device provided for the exemplary embodiment of the present invention.
[0024] List of reference numerals:
[0025] 100: Rollback method for configuration; 101 - 104: Steps of the rollback method for configuration; 11: First selection control; 12: Second selection control; 13: Selection window for archived configuration; 14: Command generation control; 15: Command execution control; 16: Display area; 200: Comparison method for configuration; 201 - 203: Steps of the comparison method for configuration; 21: Third selection control; 22: Fourth selection control; 23: Comparison control; 24: Configuration comparison result; 300: Archiving method for configuration; 301 - 303: Steps of the archiving method for configuration; 31: Network device selection control; 32: Archiving control; 33: Display area for archived configuration; 41: Editing area for adding a new switch 41; 42: Switch adding control; 43: Display area for existing switches; 44: Operation control for existing switches; 10: Editing area for rollback configuration; 20: Editing area for comparing configuration; 30: Editing area for archiving configuration; 40: Interface for managing devices; 50: Control for managing network devices; 60: Configuration management interface; 400: Rollback device for configuration; 401: Display module; 402: Device selection module; 403: Configuration selection module; 404: Execution module; 405: Comparison module; 406: Archiving module; 407 Login module; 408: Management module; 500: Electronic device (such as a network device); 502: Processor; 504: Communication interface; 506: Memory; 508: Communication bus; 510: Program. Detailed implementation manners
[0026] To make the objectives, technical solutions, and advantages of the present invention clearer, the following examples are given to further elaborate on the present invention in detail.
[0027] Please refer to Figure 1 , which shows a fallback method 100 of a configuration provided by an embodiment of the present invention. The method includes:
[0028] Step 101, display the configuration management interface of the network device.
[0029] A display device and an input device are connected to the network device; the configuration management interface of the network device is displayed on the display device. The display device and the input device may be connected to the network device in an external connection form, or the network device is connected to a computer through a network.
[0030] For example, the network device is a switch, the switch is connected to a computer, the computer's display is used as its own display device, and the computer's input device (such as a keyboard, touchpad, or mouse) is used as its own input device; the computer enters the configuration management interface of the switch and displays the configuration management interface of the switch on the computer's display.
[0031] The configuration management interface of the network device is an interface for editing operations related to the configuration fallback of the network device.
[0032] Step 102, in response to a selection operation on the network device on the configuration management interface, display the selected target network device.
[0033] The configuration management interface includes a first selection control for the network device; in response to a selection operation on the network device on the first selection control, display the selected target network device. Exemplarily, as Figure 2 shown, the configuration management interface includes a first selection control 11 for the network device. In response to a click operation on the first selection control 11, a selection window for candidate network devices is displayed. The selection window includes the device names of one or more network devices; in response to a selection operation on the network device in the selection window, the device name "aa(192.168.222.68)" of the selected target network device is displayed on the first selection control 11.
[0034] Exemplarily, if the computer determines that the optional network device is unique, the computer automatically selects this network device as the target network device and automatically displays the device name of this target network device on the first selection control. For example, in the case where the computer is connected to a network device in an external connection manner.
[0035] Step 103, in response to a selection operation on the archived configuration of the target network device on the configuration management interface, display the selected target configuration.
[0036] The configuration management interface includes a second selection control for the archived configuration; in response to a selection operation on the archived configuration of the target network device on the second selection control, the selected target configuration is displayed. Exemplarily, as Figure 2 shown, the configuration management interface includes a second selection control 12. In response to a click operation on the second selection control 12, a selection window 13 for the archived configuration is displayed. The selection window 13 includes the identification numbers (IDentity, ID) of one or more archived configurations; in response to a selection operation on the archived configuration in the selection window, the identification number "ID: 1-2024-08-06 00:35:29" of the selected target configuration is displayed on the second selection control 12.
[0037] Step 104, in response to an operation of reverting the current configuration of the target network device to the target configuration, a rollback command is generated and executed.
[0038] The configuration management interface also includes a rollback control; in response to a rollback operation triggered on the rollback control, a rollback command is generated and executed.
[0039] Alternatively, in response to a command generation operation on the configuration management interface, a rollback command is generated and displayed; in response to a command execution operation on the configuration management interface, the rollback command is executed. For example, the configuration interface also includes a command generation control and a command execution control; in response to a generation operation triggered on the command generation control, a rollback command is generated; in response to an execution operation triggered on the command execution control, the rollback command is executed. As Figure 2 shown, the configuration management interface also includes a command generation control 14 and a command execution control 15. In response to a click operation on the command generation control 14, a rollback command is generated; in response to a click operation on the command execution control 15, the rollback command is executed. The configuration management interface also includes a display area 16. After the rollback command is generated, the rollback command is displayed in the display area 16.
[0040] Optionally, the displayed rollback command is editable. After the rollback command is generated and displayed and before the rollback command is executed, in response to an editing operation on the rollback command, the edited rollback command is displayed. For example, the rollback command displayed in the display area 16 is editable. In response to an editing operation on the rollback command, the edited rollback command is displayed. Subsequently, in response to a command execution operation on the configuration management interface, the edited rollback command is executed.
[0041] Optionally, the rollback command includes at least one of the following:
[0042] A parameter modification command for instructing to modify the parameter of the first configuration item in the current configuration to the parameter of the first configuration item in the target configuration, where the first configuration item is a configuration item that is configured in both the current configuration and the target configuration but has different configuration parameters;
[0043] Configure an add command to indicate adding a second configuration item to the current configuration and setting the parameters of the second configuration item in the current configuration to the parameters of the second configuration item in the target configuration. The second configuration item is a configuration item that is not configured in the current configuration but is configured in the target configuration.
[0044] Configure a deletion command to indicate deleting a third configuration item from the current configuration. The third configuration item is a configuration item that is configured in the current configuration but is not configured in the target configuration.
[0045] Exemplarily, generating a rollback command further includes: obtaining and comparing the current configuration and the selected target configuration of the target network device to obtain the configuration items with differences between the two; then generating a rollback command based on the configuration items with differences between the two. For example, comparing whether there are differences in the configuration items between the current configuration and the target configuration of the target network device, determining whether the current configuration lacks a certain configuration item compared to the target configuration, whether there is an extra configuration item, and determining whether the parameters corresponding to the configuration items that both the current configuration and the target configuration have are the same. Based on these comparisons, obtain the differences between the two, and then generate at least one of the above parameter modification commands, configuration add commands, and configuration deletion commands according to these differences. Further, execute at least one of the above commands. For example, execute the parameter modification command to modify the parameters of the first configuration item in the current configuration to the parameters of the first configuration item in the target configuration; or execute the configuration add command to add a second configuration item to the current configuration and set the parameters of the added second configuration item in the current configuration to the parameters of the second configuration item in the target configuration; or execute the configuration deletion command to directly delete the third configuration item from the current configuration, and the current configuration can be rolled back to the target configuration.
[0046] In summary, for the configuration rollback method provided in this embodiment, select a target network device on the configuration management interface and select a target configuration from the archived configurations, then trigger the rollback operation, automatically generate and execute the rollback command, and roll back the current configuration of the target network device to the target configuration. There is no need for the administrator to manually compare the current configuration with the target configuration, nor does the administrator need to modify the current configuration to roll back to the target configuration, reducing many manual intervention operations that still exist in the process of configuration comparison and rollback, and can also minimize the errors that may occur in the manual rollback process, ensure the accuracy of the rollback command, and be customized for specific devices and configurations, simplifying the configuration management process of network devices and improving the efficiency of configuration management.
[0047] Secondly, the generated rollback command is editable, enabling the administrator to review and manually adjust the automatically generated rollback command, providing flexibility while maintaining automation.
[0048] Before performing the configuration rollback of network devices, configuration managers may need to understand the differences between the archived configurations. The configuration management of the present invention provides an automatic comparison function for configurations, as Figure 2 shown.
[0049] Please refer to Figure 3 , which shows a configuration comparison method 200 provided by an embodiment of the present invention. The method includes:
[0050] Step 201, display the configuration management interface of the network device.
[0051] A display device and an input device are connected to the network device; the configuration management interface of the network device is displayed on the display device. The display device and the input device may be connected to the network device in an external form, or the network device is connected to a computer through a network.
[0052] For example, the network device is a switch, the switch is connected to a computer, the computer's monitor is used as its own display device, and the computer's input devices (such as a keyboard, touchpad, or mouse) are used as its own input devices; the computer enters the configuration management interface of the switch, and the configuration management interface of the switch is displayed on the computer's monitor.
[0053] The configuration management interface of the network device is also an interface for editing operations related to the configuration comparison of the network device.
[0054] Step 202, in response to a selection operation on the configuration for comparison on the configuration management interface, display the selected first configuration and second configuration.
[0055] As Figure 4 shown, the configuration management interface includes a third selection control 21 and a fourth selection control 22 for the archived configurations; in response to a selection operation on the first configuration on the third selection control, display the selected first configuration, and in response to a selection operation on the second configuration on the third selection control, display the selected second configuration. For example, in response to a click operation on the third selection control 21, display a first selection window, which includes the identification numbers of one or more archived configurations. In response to a selection operation on the first configuration in the first selection window, display the identification number "Configuration ID 1" of the first configuration; in response to a click operation on the fourth selection control 22, display a second selection window, which includes the identification numbers of one or more archived configurations. In response to a selection operation on the second configuration in the second selection window, display the identification number "Configuration ID 2" of the second configuration.
[0056] The identification numbers of the archived configurations displayed in the first selection window and the second selection window are all the same or partially the same. If they are partially the same, the following situation may exist: If the identification number of the first configuration is already displayed on the first selection control, then the identification numbers of the archived configurations displayed in the first selection window include those displayed in the second selection window, and the identification numbers of the archived configurations displayed in the second selection window do not include the identification number of the first configuration.
[0057] Optionally, display the first configuration and the second configuration selected from the archived configurations of the target network device.
[0058] Before comparing the configurations, first select the target network device. Then, the available archived configurations are the archived configurations corresponding to the target network device. Or, when managing the configuration of a single network device, if this network device is the target network device, then there is no need to perform the operation of selecting the target network device, and the available archived configurations are also the archived configurations corresponding to the target network device.
[0059] Step 203: In response to the comparison operation triggered on the configuration management interface, display the configuration comparison result of the first configuration and the second configuration.
[0060] The configuration management interface also includes a comparison control 23. In response to the comparison operation triggered on the comparison control 23, compare the first configuration and the second configuration, and display the configuration comparison result of the first configuration and the second configuration. As Figure 4 shown, the configuration comparison result 24 can be displayed below the identification numbers of the first configuration and the second configuration. Or, the configuration comparison result can also be displayed through a pop-up window ( Figure 4 not shown in the figure).
[0061] In summary, the configuration comparison method provided in this embodiment is to select two groups of configurations on the network configuration interface, then trigger the automatic comparison of the two groups of configurations, and finally display the configuration comparison result. There is no need for the configuration management personnel to manually call out the two groups of configurations and then manually compare the two groups of configurations. Instead, a detailed configuration comparison result can be obtained, which improves the efficiency of configuration comparison, visually shows the differences between the two configuration items, and reduces many manual intervention operations still existing in the process of configuration comparison, simplifies the configuration management process of the network device, and improves the efficiency of configuration management.
[0062] If the configuration of the target network device has changed, it is also possible to obtain and compare the current configuration and the archived configuration of the target network device, so as to determine whether to archive the current configuration. The implementation process can be as Figure 5 shown.
[0063] Please refer to Figure 5, which shows a configuration archiving method 300 provided by an embodiment of the present invention. The method includes:
[0064] Step 301, display the configuration management interface of the network device.
[0065] A display device and an input device are connected to the network device; the configuration management interface of the network device is displayed on the display device. The display device and the input device may be connected to the network device in an external connection form, or the network device is connected to a computer through a network.
[0066] For example, the network device is a switch, the switch is connected to a computer, the computer's display is used as its own display device, and the computer's input device (such as a keyboard, touchpad or mouse) is used as its own input device; the computer enters the configuration management interface of the switch and displays the configuration management interface of the switch on the computer's display.
[0067] The configuration management interface of the network device is also an interface for operations related to the configuration archiving of the network device.
[0068] Step 302, obtain and compare the current configuration of the target network device with the archived configuration to obtain a comparison result.
[0069] Obtain the current configuration and the archived configuration of the target network device, compare the current configuration with the archived configuration one by one, and obtain the comparison result of the current configuration with each archived configuration. Exemplarily, a real-time configuration comparison engine is integrated in the system of the target network device, and the real-time configuration comparison engine is used to compare the current configuration with the archived configuration.
[0070] Optionally, after completing the configuration change of the target network device, if a selection operation on the target network device is received on the configuration management interface, display the comparison result of the archived configuration and the current configuration; or, periodically obtain and compare the archived configuration and the current configuration to obtain a comparison result.
[0071] For example, a configuration manager changes the configuration of the target network device. The configuration management interface includes a network device selection control 31 to be archived, such as Figure 6 shown; in response to the selection operation on the target network device on the network device selection control 31 to be archived, display the selected target network device (such as the device name or identification number) on the network device selection control 31 to be archived, obtain and compare the current configuration of the target network device with the archived configuration, and display the comparison result of the archived configuration and the current configuration.
[0072] There may also be other scenarios of configuration changes. For example, other personnel other than the configuration manager change the configuration of the target network device. For this scenario, periodically obtain and compare the archived configuration and the current configuration to obtain a comparison result.
[0073] Optionally, compare the current configuration of the target network device with the archived configuration, including: comparing the hash values (i.e., hash codes) of the current configuration and the archived configuration of the target network device. Each configuration corresponds to its own unique hash value. If two configurations are the same, the hash values are the same; if two configurations are different, the hash values are different. Correspondingly, the comparison result between the archived configuration and the current configuration includes: the comparison result of the hash values of the archived configuration and the current configuration. For example, the hash values of a certain archived configuration and the current configuration are the same or different.
[0074] Optionally, the hash value can be an MD5 value, which is a cryptographic hash value calculated based on the MD5 Message-Digest Algorithm.
[0075] Step 303, if the comparison result indicates that the current configuration does not exist in the archived configuration, archive the current configuration.
[0076] If the comparison result indicates that each archived configuration is different from the current configuration, archive the current configuration and store the current configuration in the database for managing network devices. For example, archive the switch IP, current configuration, hash value of the configuration, modification time of the configuration, and time stamp at the time of archiving in the database for managing network devices.
[0077] Optionally, if the comparison result indicates that the hash values of the archived configuration and the current configuration are different, archive the current configuration. If the comparison result indicates that the hash values of each archived configuration and the current configuration are different, archive the current configuration.
[0078] Optionally, if the comparison result indicates that the current configuration does not exist in the archived configuration and an archiving operation triggered on the configuration management interface is received, archive the current configuration. Exemplarily, display the comparison result on the configuration management interface; as Figure 6 shown, the configuration management interface further includes an archiving control 32, and in response to the archiving operation on the current configuration on the archiving control 32, archive the current configuration.
[0079] On the configuration management interface, relevant information of the archived configuration is also displayed, and the relevant information may include the ID of the archived configuration, network device IP (such as switch IP), time stamp, etc. As Figure 6 shown, relevant information of multiple archived configurations is displayed in the display area 33 of the archived configuration.
[0080] After archiving the current configuration, relevant information of the current configuration can also be displayed in the display area 33 of the archived configuration, including the ID of the current configuration, network device IP, time stamp, etc.
[0081] In some embodiments, if the comparison result indicates that the current configuration exists in the archived configuration, the archiving operation is not performed.
[0082] In other embodiments, if, after periodically obtaining and comparing the archived configuration with the current configuration, the comparison result is that the current configuration does not exist in the archived configuration, a notification email is automatically triggered and sent to the configured email address. The content of the notification email includes at least: the device name or ID, IP, a prompt message indicating that the configuration has been changed, and the change time of the target network device. The configured email address can be the monitoring email address used by the configuration management personnel. Sending the notification email enables the configuration management personnel to timely learn about the configuration changes of the target network device.
[0083] In other embodiments, after the target network device is selected, the corresponding existing archived configuration of the target network device is also displayed. For example, after the target network device for rollback, comparison, or archiving is selected, the archived configuration corresponding to the target network device is displayed on the display area 33, as Figure 6 shown.
[0084] In summary, for the configuration archiving method provided in this embodiment, after changing the configuration of the target network device, the target network device is selected, and then the search result of whether the changed configuration already exists in the database can be viewed. If the search result is that it does not exist, the archiving operation is performed, avoiding duplicate archiving operations, reducing many manual intervention operations in the configuration archiving process, simplifying the configuration management process of network devices, and improving the efficiency of configuration management.
[0085] In some embodiments, for the search of the changed configuration (i.e., the above-mentioned current configuration) in the archived configuration, it is performed based on the hash value of the configuration. As long as it is searched whether the hash value of the archived configuration contains the changed configuration, it is not necessary to compare all configurations, improving the search efficiency. A real-time configuration comparison engine can also be integrated into the system of the network device, and the comparison between different configurations is implemented through the real-time configuration comparison engine, which can highlight the differences between configurations, reduce the configuration, and also significantly reduce the time spent on configuration management and the complexity of configuration management.
[0086] In some embodiments, if configuration management is to be performed on a target network device, a management account needs to be logged in on the target network device. In the present invention, the management account can be automatically logged in. For example, after selecting the target network device, the login information corresponding to the target network device is obtained from the security database, such as the number sequence and password sequence of the login account, or the user name and password. Based on this login information, the management account is automatically logged in on the target network device. In this method, the automatic login process can be executed in the background and not displayed on the interface; alternatively, after selecting the target network device, a login interface pops up, and the obtained login account and password are displayed on the login interface. After automatic login, the pop-up window is automatically closed.
[0087] Exemplarily, during the execution of the configuration rollback operation, after selecting the target network device and the target configuration, the login information corresponding to the target network device in the security database that records the login information of the network device is automatically called, and the management account is automatically logged in in the SSH (Secure Shell) login mode. SSH is a network protocol used for secure communication on an insecure network. Then, the current configuration of the target network device is obtained by "show run". The current configuration can be a real-time configuration, and it is compared with the target configuration to obtain a configuration comparison result. Then, a rollback command is generated based on this configuration comparison result.
[0088] This method realizes the automatic login of the account during the management process of the network device, enabling the management personnel to automatically log in to the management account safely without manually entering the login information, avoiding editing errors that are prone to occur during manual input, and improving the login efficiency of the account on the network device.
[0089] It is also possible to manage network devices to achieve the automatic login of management accounts on one or more network devices. Exemplarily, an operation to manage network devices on the configuration management interface is received, and an interface for managing network devices is displayed; in response to an edit operation on a newly added network device on the interface for managing network devices, the edited device information and login information are displayed; in response to an addition operation on the newly added network device, the device information of the added newly added network device is displayed, and the device information and login information of the newly added network device are stored in the security database. Such as Figure 7As shown in the figure, taking the network device as a switch as an example, an editing operation for adding a new switch can be performed on the interface 40 of the management device. For example, in the controls of the editing area 41 for "adding a new switch", device information such as the switch name and IP address, as well as login information such as the user name and password, can be edited. After the editing is completed, click the add control 42 of the switch to send the device information and login information of the newly added switch to the security database for storage. The name, IP address, user name, etc. of the newly added switch are also displayed in the display area 43 for "existing switches". Each existing switch in the display area 43 corresponds to its own operation controls 44. The operation controls 44 include an editing control and a deletion control. The editing control can modify the device information and login information of the switch, and the deletion control can directly delete the device information and login information of the existing switch.
[0090] This method can manage the login information of network devices to achieve automatic login of accounts on one or more network devices, thereby enabling automatic login of accounts during the management process of network devices, eliminating the need for administrators to manually enter login information, avoiding editing errors that are prone to occur during manual input, and improving the login efficiency of accounts on network devices.
[0091] Exemplarily, as Figure 8 shown, the editing areas for configuration rollback, comparison, and archiving are located in the same configuration management interface 60, which includes an editing area 10 for rollback configuration, an editing area 20 for comparison configuration, and an editing area 30 for archiving configuration. The configuration management interface 60 also includes a control 50 for managing network devices. Click the control 50 to enter the management interface 40 of the network device, where operations such as adding, editing, and deleting network devices can be performed.
[0092] In some embodiments, for the configuration management of network devices, each network device can be managed separately.
[0093] Alternatively, a local deployment method can be adopted. For example, a local computer can be deployed to manage one or more network devices, and the configuration management system can be integrated into each network device, and the various methods provided in the above embodiments can be executed in the configuration management system of the network device.
[0094] Alternatively, a cloud deployment approach can also be adopted. For example, the configurations of multiple network devices located at different sites are managed on a cloud server. This approach enables centralized management of the configurations of a large number of network devices. Exemplarily, the cloud server can periodically poll network devices to obtain their current configurations, compare them with the archived configurations, and store the results in a database. The configuration rollback process is automated and initiated by the cloud server. The cloud server communicates with the network devices to control the network devices to perform configuration rollback. For example, a configuration management interface of the network devices is displayed on a display device connected to the cloud server; in response to a selection operation on a network device in the configuration management interface, the selected target network device is displayed, and the current configuration is obtained from the target network device, and the archived configuration of the target network device is obtained from the database for configuration management and displayed; in response to a selection operation on the archived configuration of the target network device in the configuration management interface, the selected target configuration is displayed; in response to an operation to roll back the current configuration of the target network device to the target configuration, a rollback command is generated and sent to the target network device, and the target network device executes the rollback command. The generation method of the rollback command can refer to the above embodiments and will not be elaborated here. The cloud server also has functions such as comparing configurations, archiving configurations, and managing network devices. The specific implementation methods can refer to the above embodiments and will not be elaborated here either. Cloud-based configuration management provides greater scalability and reliability, especially for organizations with geographically dispersed networks; it also reduces the need for local hardware.
[0095] Alternatively, a lightweight proxy can also be deployed on the network devices to implement functions such as comparing configurations, archiving configurations, managing network devices, and rolling back configurations as described in the above embodiments. This proxy approach can distribute the processing load to each device, reduce the need for a central server, and also allow for more fine-grained control of individual devices, enabling faster execution of configuration changes and rollbacks.
[0096] In some other embodiments, the login of the management account and the execution of commands can be implemented through an API (Application Programming Interface). For example, a RESTful API for management tasks is used to retrieve the current configuration, compare configurations, and execute rollback commands. API-based management is more secure and easier to automate, allowing for better integration with other management and monitoring systems that already use APIs.
[0097] In some other embodiments, template-based implementation can be adopted for configuration management. For example, predefined configuration setting templates, configuration comparison templates, and templates for generating configuration rollback commands are used to implement functions such as configuring devices, comparing configurations, and rolling back configurations. By ensuring that devices always conform to the standard templates, configuration management is simplified, the complexity of managing custom configurations is reduced, and the likelihood of errors is minimized.
[0098] In summary, the above embodiments provided by the present invention achieve multiple functions such as automated SSH login, real-time configuration comparison, automated rollback command generation, and editable rollback commands. The automation of the login, comparison, and rollback processes significantly improves the efficiency of network device management and reduces the time required for these tasks. By automating key steps such as configuration comparison and rollback command generation, the system reduces the risk of human errors, making network operations more reliable. It also allows for manual adjustment of the automatically generated commands, providing a balance between automation and manual control in complex network environments. The reduction of manual labor and the increase in the speed of configuration management translate into lower operating costs. Integration with a database to store login credentials ensures secure and efficient access management and reduces the administrative overhead associated with manually entering credentials.
[0099] Figure 9 FIG. 7 is a schematic diagram of a configuration rollback device 400 provided by an embodiment of the present invention. The device includes:
[0100] A display module 401, configured to display a configuration management interface of a network device;
[0101] A device selection module 402, configured to display a selected target network device in response to a selection operation on the network device on the configuration management interface;
[0102] A configuration selection module 403, configured to display a selected target configuration in response to a selection operation on the archived configuration of the target network device on the configuration management interface;
[0103] An execution module 404, configured to generate and execute a rollback command in response to an operation of rolling back the current configuration of the target network device to the target configuration.
[0104] In some embodiments, the execution module 404 is configured to generate and display a rollback command in response to a command generation operation on the configuration management interface, and execute the rollback command in response to a command execution operation on the configuration management interface.
[0105] In some embodiments, the execution module 404 is configured to obtain and compare the current configuration and the target configuration, and obtain the configuration items with differences between the two; according to the configuration items with differences between the two, generate a rollback command, where the rollback command includes at least one of the following: a parameter modification command, used to instruct to modify the parameter of the first configuration item in the current configuration to the parameter of the first configuration item in the target configuration, and the first configuration item is a configuration item that exists in both the current configuration and the target configuration but has different configuration parameters; a configuration addition command, used to instruct to add a second configuration item to the current configuration and set the parameter of the second configuration item in the current configuration to the parameter of the second configuration item in the target configuration, and the second configuration item is a configuration item that does not exist in the current configuration but exists in the target configuration; a configuration deletion command, used to instruct to delete the third configuration item in the current configuration, and the third configuration item is a configuration item that exists in the current configuration but does not exist in the target configuration.
[0106] In some embodiments, the execution module 404 is further configured to, in response to a command execution operation on the configuration management interface, before executing the rollback command, in response to an editing operation on the rollback command, display the edited rollback command.
[0107] In some embodiments, the configuration selection module 403 is configured to, in response to a selection operation on the configuration for comparison on the configuration management interface, display the selected first configuration and second configuration; in response to a comparison operation triggered on the configuration management interface, display the configuration comparison result of the first configuration and the second configuration.
[0108] In some embodiments, the configuration selection module 403 is configured to display the selected first configuration and second configuration from the archived configurations, including: displaying the selected first configuration and second configuration from the archived configurations of the target network device.
[0109] In some embodiments, as Figure 10 shown, the device further includes: a comparison module 405 and an archiving module 406;
[0110] The comparison module 405 is configured to obtain and compare the current configuration of the target network device with the archived configuration to obtain a comparison result;
[0111] The archiving module 406 is configured to, if the comparison result indicates that the current configuration does not exist in the archived configuration, archive the current configuration.
[0112] In some embodiments, the archiving module 406 is configured to, after completing the configuration change of the target network device, if receiving a selection operation on the target network device on the configuration management interface, display the comparison result between the archived configuration and the current configuration; or, periodically obtain and compare the archived configuration and the current configuration to obtain a comparison result.
[0113] In some embodiments, the comparison result includes: the comparison result of the hash values of the archived configuration and the current configuration;
[0114] An archiving module 406, configured to archive the current configuration if the comparison result indicates that the hash values of the archived configuration and the current configuration are different.
[0115] In some embodiments, the archiving module 406 is configured to archive the current configuration if the comparison result indicates that the current configuration does not exist in the archived configuration and an archiving operation triggered on the configuration management interface is received.
[0116] In some embodiments, as Figure 10 shown, the apparatus further includes: a login module 407;
[0117] The login module 407 is configured to obtain the login information corresponding to the target network device from the security database after selecting the target network device; and automatically log in to the management account on the target network device based on the login information.
[0118] In some embodiments, as Figure 10 shown, the apparatus further includes: a management module 408;
[0119] The management module 408 is configured to receive an operation of managing a network device on the configuration management interface, and display an interface for managing the network device; in response to an edit operation on a newly added network device on the interface for managing the network device, display the edited device information and login information; in response to an addition operation on the newly added network device, display the device information of the newly added network device after addition, and store the device information and login information of the newly added network device in the security database.
[0120] Figure 11 is a schematic block diagram of an electronic device 500 provided by an embodiment of the present invention. The specific implementation of the electronic device is not limited in the specific embodiments of the present application. Exemplarily, the electronic device 500 may be a network device or other computers (such as a local or cloud server, etc.). As Figure 11 shown, the electronic device 500 may include: a processor 502, a communications interface 504, a memory 506, and a communication bus 508. Wherein:
[0121] The processor 502, the communications interface 504, and the memory 506 communicate with each other through the communication bus 508.
[0122] The communications interface 504 is configured to communicate with other electronic devices or servers.
[0123] A processor 502 is configured to execute a program 510, and specifically, can execute the relevant steps in any of the foregoing embodiments.
[0124] Specifically, the program 510 may include program code, and the program code includes computer operation instructions.
[0125] The processor 502 may be a CPU, or a specific integrated circuit ASIC (Application Specific Integrated Circuit), or one or more integrated circuits configured to implement the embodiments of the present application. One or more processors included in the intelligent device may be of the same type of processor, such as one or more CPUs; or may be of different types of processors, such as one or more CPUs and one or more ASICs.
[0126] RISC-V is an open-source instruction set architecture based on the principle of reduced instruction set (RISC). It can be applied to various aspects such as single-chip microcomputers and FPGA chips, and can be specifically applied in the fields of Internet of Things security, industrial control, mobile phones, personal computers, etc. Moreover, due to the consideration of small size, fast speed, and low power consumption in its design, it is particularly suitable for modern computing devices such as warehouse-scale cloud computers, high-end mobile phones, and tiny embedded systems. With the rise of artificial intelligence Internet of Things (AIoT), the RISC-V instruction set architecture has received more and more attention and support, and is expected to become the next-generation CPU architecture widely used.
[0127] The computer operation instructions in the embodiments of the present application may be computer operation instructions based on the RISC-V instruction set architecture. Correspondingly, the processor 502 may be designed based on the RISC-V instruction set. Specifically, the chip of the processor in the electronic device provided in the embodiments of the present application may be a chip designed with the RISC-V instruction set. The chip can execute executable code based on the configured instructions, thereby implementing the rollback method, comparison method, and archiving method configured in the foregoing embodiments.
[0128] A memory 506 is configured to store the program 510. The memory 506 may include high-speed RAM memory, and may also include non-volatile memory, such as at least one disk memory.
[0129] The program 510 is specifically configured to cause the processor 502 to execute the method in any of the foregoing embodiments.
[0130] For the specific implementation of each step in Program 510, reference may be made to the corresponding steps and descriptions in the corresponding units in any of the foregoing method embodiments, which will not be elaborated herein. Those skilled in the art can clearly understand that, for the sake of convenience and brevity of description, the specific working processes of the above-described devices and modules may refer to the corresponding process descriptions in the foregoing method embodiments, which will not be repeated herein.
[0131] Computer storage medium
[0132] This application also provides a computer-readable storage medium storing instructions for causing a machine to execute the rollback method, comparison method, and archiving method configured as described herein. Specifically, a system or device equipped with a storage medium may be provided, on which software program code for implementing the functions of any one of the foregoing embodiments is stored, and the computer (or CPU or MPU) of the system or device is caused to read and execute the program code stored in the storage medium.
[0133] In this case, the program code read from the storage medium itself can implement the functions of any one of the foregoing embodiments. Therefore, the program code and the storage medium storing the program code constitute a part of this application.
[0134] Embodiments of the storage medium for providing program code include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tapes, non-volatile memory cards, and ROMs. Optionally, the program code may be downloaded from a server computer via a communication network.
[0135] Computer program product
[0136] Embodiments of this application also provide a computer program product including computer instructions that direct a computing device to perform any corresponding operation in the foregoing multiple method embodiments.
[0137] It should be noted that, according to the needs of implementation, the various components / steps described in the embodiments of this application may be split into more components / steps, or two or more components / steps or partial operations of components / steps may be combined into new components / steps to achieve the objectives of the embodiments of this application.
[0138] The method according to the embodiments of the present application can be implemented in hardware, firmware, or be implemented as software or computer code that can be stored in a recording medium (such as a CD ROM, RAM, floppy disk, hard disk, or magneto-optical disk), or be implemented as computer code originally stored in a remote recording medium or a non-transitory machine-readable medium and downloaded through a network and to be stored in a local recording medium, so that the method described herein can be stored as such software processing on a recording medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware (such as an ASIC or FPGA). It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component (such as RAM, ROM, flash memory, etc.) that can store or receive software or computer code, and when the software or computer code is accessed and executed by the computer, the processor, or the hardware, the method described herein is implemented. In addition, when a general-purpose computer accesses the code for implementing the method shown herein, the execution of the code converts the general-purpose computer into a dedicated computer for executing the method shown herein.
[0139] Those of ordinary skill in the art can realize that the units and method steps of each example described in combination with the embodiments disclosed herein can be implemented in electronic hardware, or in a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the embodiments of the present application.
[0140] In this patent application, nouns and pronouns related to people are not limited to a specific gender.
[0141] The above are only the preferred embodiments of the present invention, and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included in the protection scope of the present invention.
Claims
1. A configuration rollback method (100), characterized in that: The method comprises: Display the configuration management interface of network devices; In response to a selection operation on a network device on the configuration management interface, displaying a selected target network device; In response to a selection operation on the archived configuration of the target network device on the configuration management interface, displaying the selected target configuration; In response to an operation of rolling back the current configuration of the target network device to the target configuration, a rollback command is generated and executed.
2. The method according to claim 1, characterized in that In response to the operation of rolling back the current configuration of the target network device to the target configuration, generating and executing a rollback command comprises: In response to a command generation operation on the configuration management interface, generating and displaying the rollback command; In response to a command execution operation on the configuration management interface, the rollback command is executed.
3. The method according to claim 2, characterized in that The generating the rollback command comprises: Acquire and compare the current configuration and the target configuration to obtain configuration items that are different between the two; Generate the rollback command according to the configuration items that differ between the two, wherein the rollback command includes at least one of the following: A parameter modification command, used to instruct to modify a parameter of a first configuration item in the current configuration to a parameter of the first configuration item in the target configuration, wherein the first configuration item is a configuration item that is configured in both the current configuration and the target configuration but has different configuration parameters; A configuration adding command, used to instruct to add a second configuration item in the current configuration, and set the parameters of the second configuration item in the current configuration to the parameters of the second configuration item in the target configuration, where the second configuration item is a configuration item that is not configured in the current configuration but is configured in the target configuration; The configuration deletion command is used to instruct to delete a third configuration item in the current configuration, where the third configuration item is a configuration item that is configured in the current configuration but not configured in the target configuration.
4. The method according to claim 2, characterized in that: The executing operation in response to the command on the configuration management interface, before executing the rollback command, further includes: In response to an editing operation on the back command, the edited back command is displayed.
5. The method according to claim 1, characterized in that The method further comprises: In response to a selection operation on the configuration management interface for comparison, displaying a selected first configuration and a second configuration; In response to a comparison operation triggered on the configuration management interface, a configuration comparison result of the first configuration and the second configuration is displayed.
6. The method according to claim 1, characterized in that The method further comprises: Acquire and compare the current configuration of the target network device with the archived configuration to obtain a comparison result; If the comparison result indicates that the current configuration does not exist in the archived configuration, the current configuration is archived.
7. The method according to claim 6, characterized in that The obtaining and comparing the current configuration of the target network device with the archived configuration to obtain a comparison result includes: After completing the configuration change of the target network device, if a selection operation of the target network device is received on the configuration management interface, displaying the comparison result between the archived configuration and the current configuration; or, The archived configuration and the current configuration are periodically acquired and compared to obtain the comparison result.
8. The method according to claim 6, characterized in that The comparison result includes: a comparison result of the hash value of the archived configuration and the current configuration; If the comparison result indicates that the current configuration does not exist in the archived configuration, archiving the current configuration includes: If the comparison result indicates that the hash values of the archived configuration and the current configuration are different, the current configuration is archived.
9. A configuration retraction device (400), characterized in that: The device comprises: A display module (401), used to display a configuration management interface of a network device; A device selection module (402), configured to display a selected target network device in response to a selection operation on a network device on the configuration management interface; A configuration selection module (403), configured to display a selected target configuration in response to a selection operation on the archived configuration of the target network device on the configuration management interface; The execution module (404) is used to generate and execute a rollback command in response to the operation of rolling back the current configuration of the target network device to the target configuration.
10. A computer program product, characterized in that The computer program product includes computer instructions, and the computer instructions instruct a computer device to perform operations corresponding to the method according to any one of claims 1 to 8.
Citation Information
Cited By
Network equipment configuration management method and device, electronic equipment and storage medium
CN121037218A