Multi-level distributed iptables control method
By building a multi-level distributed iptables control architecture and using intelligent agents to dynamically generate iptables rules, the problems of low efficiency and high maintenance costs in traditional methods are solved, and efficient and secure iptables rule management is achieved.
Patent Information
- Application Number
- CN202510879538.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-09-16
AI Technical Summary
Traditional iptables rule management is inefficient and has high maintenance costs in large-scale data center networks, and is prone to configuration errors and security vulnerabilities.
Build a multi-level distributed control architecture based on server IP segments, use intelligent agents to dynamically generate iptables rules, and implement cross-level propagation and management of policy data through multi-level control end nodes and independent storage components.
It improves processing efficiency, reduces maintenance costs, enhances the system's dynamic adaptability and security, and reduces the possibility of human operational errors.
Smart Images

Figure CN120658603A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer processing technology, and in particular to a multi-level distributed iptables control method. Background Art
[0002] iptables is an IP packet filtering system, a command-line tool for configuring the Linux kernel firewall. With the prevalence of cloud computing, enterprise network environments have become significantly more dynamic and complex, and enterprise networks are growing larger and larger. Traditionally, iptables rules are configured on every server, requiring polling of all servers. This makes it difficult to adapt to frequently changing business access requirements. In data center network environments containing tens of thousands or more servers, this approach suffers from low processing efficiency, high maintenance costs, and is prone to configuration errors or security vulnerabilities.
[0003] Chinese patent publication number CN116962069A discloses a method and device for controlling the effective time of a distributed firewall. By matching target firewall rules to corresponding effective time periods, the method can control the time when the target firewall rules are sent to each host machine and the time when the target firewall rules are retrieved from each host machine according to the effective time range of the effective time period. This allows each host machine to turn on the firewall during the effective time period and turn off the firewall outside the effective time period. This allows the target firewall rules to take effect on the host machine within a preset effective time range, thereby controlling the firewall rules to take effect within a preset time period, thus meeting user requirements for firewall rules to take effect in different time periods. However, this method has the following disadvantages: 1. The dynamic management capability is weak, and professional technicians are required to write and maintain iptables rules according to business needs.
[0004] 2. Using the traditional management terminal to issue commands to multiple target servers is inefficient and has a time complexity of O(n).
[0005] 3. To ensure the correctness of iptables, version management and rollback mechanisms are involved. In a data center-level network with tens of thousands of servers, the maintenance cost is immeasurable and increases exponentially. The rollback time complexity is O(n), and the fault tolerance is low.
[0006] Therefore, we propose an iptables control method that has high processing efficiency, low maintenance cost, and can run safely. Summary of the Invention
[0007] The object of the present invention is to provide a multi-level distributed iptables control method, which is used to solve the problems of low processing efficiency and high maintenance cost of traditional methods.
[0008] The present invention is achieved through the following technical solutions: A multi-level distributed iptables control method, specifically comprising: Build a multi-level control architecture based on the server IP network segment. The architecture consists of at least two levels, each of which contains a control end node, which is used to receive policy data. Each control end node is associated with an independent storage component, which is used to store autonomous domain identification data, upstream domain reference data, downstream domain list data and iptables policy parameters of policy data; An intelligent agent is deployed on each server to periodically poll the storage components on the same subnet to obtain their iptables policy parameters. The intelligent agent program dynamically generates iptables rules according to iptables policy parameters.
[0009] Furthermore, the construction of the multi-level control architecture includes: The IP address is divided into subnets according to CIDR (Classless Inter-Domain Routing) with a hierarchical depth N satisfying the following: 3≤N≤6; The reserved IP at the end of each network segment is fixedly allocated to the storage component; The control end nodes establish a logical association through the IP network segment.
[0010] Furthermore, the autonomous domain identification data includes its own network segment range and storage component IP address; the upstream domain reference data includes the upper-level network segment range and storage component IP address; the downstream domain list data includes the sub-network segment range and storage component IP address list; the iptables policy parameters include source IP, destination IP, action type and timestamp.
[0011] Furthermore, the action type in the iptables policy parameter includes at least one of ACCEPT, DROP, REJECT, and LOG; and the iptables policy parameter supports the full-featured functions of iptables through enumeration fields.
[0012] Furthermore, the working mechanism of the intelligent agent program includes: Poll the storage component at a fixed interval T, where T satisfies: 1s ≤ T ≤ 30s; Only the currently effective policy data is retained, and historical version data is not maintained; Dynamically generate iptables rules based on the parameters of the effective policy data; After the rules are generated, the iptables command is called immediately to load them into the kernel.
[0013] Furthermore, the iptables rules include: When the server IP matches the source IP or destination IP in the policy data, a rule is generated directly; When the server IP is included in the policy data IP range, the wildcard is replaced with its own IP to generate a rule.
[0014] Furthermore, after receiving the policy data, the control end node performs cross-level propagation, and the specific steps are as follows: After receiving the policy data, the control end node first verifies the syntax correctness; Determine the upstream and downstream network segments based on the source IP and destination IP in the policy data. The policy data is forwarded once to all associated upstream and downstream control end nodes, and the path mark is carried during forwarding. The receiving end is prohibited from returning the data carrying the mark.
[0015] Furthermore, the method also includes a system recovery mechanism, specifically: Delete data in a specific time period based on the policy data timestamp, and implement time dimension rollback operation with one-click rollback across the entire network; When an upstream storage component fails, the downstream storage components are aggregated to reconstruct the data; when a downstream storage component fails, the spatial dimension recovery operation is performed by extracting the corresponding subnet policy data from the upstream storage component or aggregating the secondary downstream data to reconstruct the data.
[0016] A distributed iptables control system, comprising: Multiple hierarchical control end nodes, each of which is connected to an independent storage component; An intelligent agent deployed on the server communicates with storage components on the same subnet; The storage component includes: an autonomous domain management module for maintaining its own network segment and upstream and downstream association information; Policy data storage engine, used to store iptables policy parameters in key-value format; Cross-layer propagation module, used to implement anti-loop forwarding of policy data.
[0017] Furthermore, the intelligent agent program includes: Rule converter, used to parse policy data into server-specific iptables rules; Policy data synchronizer, used to periodically pull storage component data and trigger rule updates.
[0018] The technical solution of the present invention has at least the following advantages and beneficial effects: This invention discloses a multi-level distributed iptables control method. By dividing the network into multiple levels, and enabling cross-level data transfer between control nodes at each level, this method reduces the need for centralized management of the entire network. An intelligent agent program can retrieve iptables policy parameters from the storage component of its network segment and apply them to iptables rules, avoiding the traditional problem of having to configure each server individually and significantly improving processing efficiency. In addition, due to the hierarchical structure and the ability of the intelligent agent to automatically synchronize the latest iptables policy parameters, the reliance on professional technicians to write and maintain iptables rules is reduced, thereby reducing maintenance costs. In addition, when the control end node receives new policy data, it will perform cross-level propagation to ensure that the new policy data can be quickly and accurately adopted by all relevant servers, enhancing the system's ability to cope with frequently changing business needs. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 A schematic flow chart of a method of the present invention is shown; Figure 2 A schematic diagram of a topological structure; Figure 3 FIG. 4 is a schematic diagram of a multi-level control architecture of the present invention. DETAILED DESCRIPTION
[0020] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings herein can be arranged and designed in various different configurations.
[0021] Example 1 like Figure 1-Figure 2 A multi-level distributed iptables control method is shown, specifically including: Build a multi-level control architecture based on the server IP network segment. This architecture consists of at least two levels, each of which contains control end nodes, which are used to receive policy data. The number of control end nodes in each level varies, but all control end nodes process data relatively independently. Policy data is an externally input access control instruction with a timestamp. With a layered design, control nodes can pass data across layers, effectively reducing the need for centralized management of the entire network. This significantly reduces the time required to update policy data in large-scale data center environments, improving overall processing efficiency. Furthermore, because each control node is relatively independent and has its own storage components to store relevant data, configuration changes or fault recovery only require attention to the affected parts, eliminating the need to adjust the entire network. This significantly reduces maintenance complexity and costs. Furthermore, when business needs change, new iptables policy data is quickly and accurately propagated to all relevant servers through the hierarchical structure. Furthermore, the intelligent agent regularly polls storage components on the same subnet to obtain the latest iptables policy parameters and dynamically generates iptables rules based on these parameters, ensuring the system can quickly respond to changes. By limiting cross-layer data transmission as needed, potential loops are prevented, ensuring the stability and security of policy data propagation. Furthermore, clear hierarchical divisions help isolate different network areas, further enhancing the security of the overall network.
[0022] In addition, the construction of the multi-level control architecture includes: The CIDR subnet of the IP address is divided into layers, with a layer depth N satisfying the following: 3≤N≤6. Each layer represents a different management scope. For example, global manages the entire data center, regional manages a specific geographic or logical partition, and rack manages a smaller group of servers. This means that users can flexibly adjust the number of layers based on the scale and complexity of the network to adapt to different network environments. The reserved IP address at the end of each network segment is fixedly assigned to the storage component. This ensures that the location of the storage component can be accurately identified even when the network structure changes, thereby ensuring data consistency and reliability. Logical associations are established between control end nodes through IP network segments, enabling effective information exchange and policy data dissemination between different levels. This association method not only improves the flexibility of the system, but also facilitates maintenance and expansion.
[0023] Each control end node is associated with an independent storage component, which is used to store autonomous domain identification data, upstream domain reference data, downstream domain list data, and iptables policy parameters of policy data; upstream and downstream refer to the previous and next levels of the current level, and subsequent secondary downstream refers to the next level of the next level; By classifying and storing different types of data in independent storage components, data management and maintenance are simplified. For example, when the iptables rules for a specific area need to be updated, any control-end node containing a certain network segment can be operated, and then the data can be written to the storage component. At the same time, it can be determined whether to transmit it upstream and downstream, and transmitted on demand without traversing the entire network structure. In addition, this architecture allows the system to flexibly adjust the hierarchical structure according to actual needs. Whether adding new subnets or expanding the existing network scale, it can be achieved by adding corresponding storage components without affecting the functions of other parts. Moreover, since each layer has a clearly defined data flow and logical relationship, new policy data can be transmitted from any control-end node to the final target area, and then automatically converted into specific iptables commands for execution by the intelligent agent deployed on the server, greatly shortening the time delay for the policy data to take effect.
[0024] In particular, the autonomous domain identification data includes its own network segment range and storage component IP address. For example, the last IP address of the network segment 10.0.0.0 / 16 (such as 10.0.255.254) may be fixedly assigned to the storage component of this network segment. This helps to clarify the boundaries of each autonomous domain and its corresponding management entity. The upstream domain reference data includes the upper-level network segment range and the storage component IP address. For example, the last IP address in the upstream network segment 10.0.0.0 / 8 (such as 10.255.255.254) is used as the IP address of its storage component. This allows the subnet to know the larger network to which it belongs and request or forward information upstream when necessary; as well as the upstream control end address, as long as the network is reachable, and no restrictions on the address are included; The downstream domain list data includes the subnet segment range and the storage component IP address list. For example, the downstream network segments 10.0.1.0 / 24 and 10.0.10.0 / 24 each have their own storage nodes (such as 10.0.1.254 and 10.0.10.254). This design facilitates data interaction and policy data dissemination between layers. As for the downstream control end address, it only needs to be reachable by the network, and there is no limit on the address to be included.
[0025] The iptables policy parameters include source IP, destination IP, action type, and timestamp. These parameters are the basis for the intelligent agent to generate specific iptables rules. It supports both exact matching and range matching modes to meet the needs of different application scenarios. In addition, the action type in the iptables policy parameter includes at least one of ACCEPT, DROP, REJECT, and LOG; and the iptables policy parameter supports the full-featured functions of iptables through enumeration fields.
[0026] An intelligent agent is deployed on each server to periodically poll the storage components on the same subnet to obtain iptables policy parameters. The intelligent agent is a lightweight agent program. Compared to the traditional server-by-server configuration method, the use of intelligent agents enables each server to proactively pull the latest policy data, greatly reducing the time required for policy data synchronization. This distributed policy data management method can significantly improve efficiency, especially in large-scale data center environments. When the network environment changes, such as adding or deleting certain services or adjusting access control lists, the intelligent agent can quickly adjust iptables rules based on the latest iptables policy parameters, enhancing the system's dynamic adaptability and flexibility. In addition, the working mechanism of the intelligent agent program includes: Poll the storage component at a fixed interval T, where T satisfies: 1s ≤ T ≤ 30s. This ensures that all servers receive the latest security policy data in a timely manner without manual intervention. Only the currently effective policy data is retained, and historical version data is not maintained. This effectively reduces storage requirements and avoids performance degradation caused by processing large amounts of historical data. This greatly simplifies data management and maintenance, eliminating the need to worry about how to handle old versions of data or facing complex version control issues when rollbacks are needed, thus reducing management complexity. After determining the effective policy data, obtain the corresponding policy parameters and then generate the corresponding rules; After the rules are generated, the iptables command is immediately called to load them into the Linux kernel, ensuring that the firewall rules on the server are always consistent with the latest security policy data.
[0027] The intelligent agent dynamically generates iptables rules based on iptables policy parameters. By updating iptables rules in real time, it can more effectively block unauthorized access and protect the enterprise network from potential threats. In addition, by reducing the possibility of human error, it also indirectly improves system security. As needed, the iptables rules include: When the server IP matches the source IP or destination IP in the policy data, a rule is generated directly; When the server IP is included in the policy data IP range, the wildcard is replaced with its own IP generation rule; By supporting both exact match and range match modes, it can more flexibly adapt to different application scenarios. Security policy data for both a single server and an entire subnet can be effectively implemented. Moreover, only the general policy data needs to be defined once, and the intelligent agent can automatically generate specific rules for each relevant server, eliminating the need to manually configure iptables rules for each server, greatly simplifying the configuration process. This mechanism also ensures that even if the network structure changes (such as adding or removing certain servers), new security policy data can be quickly adjusted and applied, thereby enhancing the security of the overall network; However, because rules are dynamically generated based on actual IP addresses, they avoid the performance degradation and security risks associated with unnecessarily broad rules. For example, compared to overly broad subnet range rules, rules that are specific to a single IP address can filter traffic more efficiently and reduce unnecessary processing overhead.
[0028] After receiving the policy data, the control end node performs cross-level propagation, and the specific steps are as follows: After receiving the policy data, the control end node first verifies the syntax correctness to ensure that the policy data to be distributed is in the correct format and logically correct, avoiding security risks or network failures caused by incorrect configuration, and improving the stability of the entire system operation; Based on the source IP and destination IP in the policy data, the upstream and downstream network segments to which they belong are determined, that is, by comparing the IP address with the network segment ranges defined between each layer. For example, if a control end node receives policy data of 10.0.0.0 / 16, the source IP and destination IP of the policy data are determined. If the control end node contains the network segment identifier 10.0.0.0 / 8 of the upstream control end node, that is, it is included by the upstream control end node, then it will be passed to the upstream control end node; if the control end node contains the network segment identifier 10.0.0.0 / 24 of the downstream control end node, then it will be passed to the downstream control end node. Policy data is forwarded once to all associated upstream and downstream control nodes. After determining the network segment to which it belongs, the control node forwards the policy data once to all associated upstream and downstream control nodes. "Once" means that data is sent only once to each associated storage component, rather than repeatedly, to reduce network load and improve efficiency. This can significantly reduce bandwidth usage and improve overall performance, especially in large-scale data center environments. It should be noted that the purpose of this method is to generate iptables rules, which occur in the server unit where each control node is located. After the control node receives the policy data, the subsequent process will continue according to the steps for generating iptables rules.
[0029] The data is forwarded with a path tag, and each time it is forwarded, a control-end tag is added. This control-end tag is used to identify the control-end node that has received the policy data. The receiver is prohibited from returning the data carrying the tag. This tag is used to identify the path that the data has passed. After the receiver (i.e., the upstream and downstream storage components) recognizes the data with this tag, it will not return it to the original sender or other nodes included in the path tag, thus effectively preventing potential data loop problems. In addition, through the clear hierarchical division and path tagging mechanism, the efficient policy data dissemination capability can be maintained even when the network scale continues to expand and the hierarchical structure becomes more complex, supporting the smooth expansion of the system. This step is the step in which the control end node obtains the new policy data and then forwards the policy data to the storage component. Therefore, after the new policy data is forwarded to the storage component, the intelligent agent program will periodically poll the storage components in the same subnet according to the normal steps to obtain the iptables policy parameters of its policy data, and finally dynamically generate iptables rules based on the iptables policy parameters.
[0030] Example 2 As an embodiment, based on embodiment 1, a system recovery mechanism is further included, specifically: Data for a specific time period is deleted based on the policy data timestamp, enabling one-click rollback of the entire network. This means that when a misconfiguration or security incident is detected, incorrect changes can be quickly undone by deleting all policy data since a certain time point, returning the iptables rules of the entire network to their previous secure state. For example, deleting all policy data after the timestamp of 2025-06-25 10:00:00 will roll back the system to the rule state before that time point.
[0031] When an upstream storage component fails, the downstream storage components are aggregated to reconstruct the data, ensuring that even in the event of a key node failure, the complete policy data information can still be restored using the lower-level data; when a downstream storage component fails, the spatial dimension recovery operation of extracting the corresponding subnet policy data from the upstream storage component or aggregating the secondary downstream data to reconstruct the data ensures that local failures will not affect the overall situation while maintaining data consistency and integrity.
[0032] Therefore, whether facing configuration errors or hardware failures, the system can effectively recover to normal operating status through the above mechanism, reducing downtime and the risk of data loss; and clarifying the specific response measures in different failure scenarios, reducing the difficulty of operation and maintenance personnel in handling problems and speeding up the fault response speed.
[0033] In addition, if Figure 3The topology shown here is used as an example. The last IP address in each network segment corresponds to the IP address of the corresponding storage component. The actual hierarchy and network scale can be larger, but the principle remains the same. The example parameters are primarily based on IP addresses, and other features and functions are omitted. The controller identifier is not its own IP address; as long as the network is reachable, it serves primarily as a hierarchical identification.
[0034] It includes a global control terminal and two regional control terminals. One regional control terminal manages two rack control terminals, and the other regional control terminal manages another rack control terminal. Rack 1 and Rack 2 each contain 252 servers, and Rack 3 contains 506 servers.
[0035] 1. In the first step, enter the parameter source IP 10.0.10.2 and destination IP 10.100.0.0 / 24 on the global control terminal. After local judgment and local storage, it is sent to regional control terminals 1 and 2. Regional control terminals 1 and 2 continue the previous step and send it to rack control terminals 2 and 3.
[0036] 2. In the second step, all servers in rack 2 read the storage component data and detect the change. Only server 10.0.10.2 successfully matches the IP address and generates a corresponding rule. Simultaneously, all servers in rack 3 read the storage component data and detect the change. Based on the subnet rules, corresponding rules are generated for 254 servers (10.100.0.2-10.100.0.255). Servers 10.100.1.0-10.100.1.253 determine that the network segment does not match their own IP addresses and take no action. Traditional methods require centrally distributing rules to all 254 servers one by one. However, this method only involves four interactions between the control end and one automatic pull request for each server.
[0037] 3. Alternatively, you can directly enter the parameters for source IP 10.100.1.200 and destination IP 10.0.1.128 / 25 on Regional Control Station 2, which doesn't have a corresponding rack. This will be sent to Rack Control Station 3, with the data flowing sequentially: Global Control Station -> Regional Control Station 1 -> Rack Control Station 1. The corresponding server will generate rules using the same method as in step 2. This method also allows you to enter parameters on the Rack Control Station or any other control station, greatly increasing operational flexibility.
[0038] 4. If the global controller is temporarily unavailable, a temporary controller can be added. Based on IP subnet rules, data from two regional controllers can be sent to the temporary controller's storage components. Alternatively, a larger subnet can be defined upstream of the global controller. In short, upstream and downstream connections can be divided based on subnet ranges.
[0039] Example 3 A distributed iptables control system, comprising: Multiple hierarchical control end nodes, each of which is connected to an independent storage component; An intelligent agent deployed on the server communicates with storage components on the same subnet; The storage component includes: an autonomous domain management module for maintaining its own network segment and upstream and downstream association information; Policy data storage engine, used to store iptables policy parameters in key-value format; Cross-layer propagation module, used to implement anti-loop forwarding of policy data.
[0040] In addition, the intelligent agent program includes: Rule converter, used to parse policy data into server-specific iptables rules; Policy data synchronizer, used to periodically pull storage component data and trigger rule updates.
[0041] As needed, the control end node is deployed at: Rack level: rack switch or independent management blade; Regional level: aggregation switch or dedicated virtual machine cluster; Global level: core network devices or high-availability server clusters; And it is physically isolated from the server.
[0042] In addition, the data reconstruction module of the storage component: When an upstream node failure is detected, data aggregation requests are automatically initiated to all registered downstream nodes; Rebuild the local storage based on the aggregated data and update the topology relationship to adjacent nodes.
[0043] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A multi-level distributed iptables control method, characterized in that: Specifically include: Build a multi-level control architecture based on the server IP segment. The architecture consists of at least two levels. Each level contains a control end node, which is used to receive iptables policy parameters for policy data. Each control end node is associated with an independent storage component, wherein the storage component is used to store autonomous domain identification data, upstream domain reference data, downstream domain list data and policy data; An intelligent agent is deployed on each server to periodically poll the storage components on the same subnet to obtain iptables policy parameters. The intelligent agent program dynamically generates iptables rules according to iptables policy parameters.
2. The multi-level distributed iptables control method according to claim 1, characterized in that: The construction of the multi-level control architecture includes: Divide the hierarchy into levels based on the CIDR subnet of the IP address, and the hierarchy depth N satisfies: 3≤N≤6; The reserved IP at the end of each network segment is fixedly allocated to the storage component; The control end nodes establish a logical association through the IP network segment.
3. The multi-level distributed iptables control method according to claim 1, wherein: The autonomous domain identification data includes its own network segment range and storage component IP address; the upstream domain reference data includes the upper-level network segment range and storage component IP address; the downstream domain list data includes the sub-network segment range and storage component IP address list; the iptables policy parameters include source IP, destination IP, action type and timestamp.
4. The multi-level distributed iptables control method according to claim 3, wherein: The action type in the iptables policy parameter includes: at least one of ACCEPT, DROP, REJECT, and LOG; and the iptables policy parameter supports the full-featured functions of iptables through enumeration fields.
5. The multi-level distributed iptables control method according to claim 3, wherein: The working mechanism of the intelligent agent program includes: Poll the storage component at a fixed interval T, where T satisfies: 1s ≤ T ≤ 30s; Only the currently effective policy data is retained, and historical version data is not maintained; Dynamically generate iptables rules based on the parameters of the effective policy data; After the rules are generated, the iptables command is called immediately to load them into the kernel.
6. The multi-level distributed iptables control method according to claim 5, characterized in that: The iptables rules include: When the server IP matches the source IP or destination IP in the policy data, a rule is generated directly; When the server IP is included in the policy data IP range, the wildcard is replaced with its own IP to generate a rule.
7. The multi-level distributed iptables control method according to claim 6, characterized in that: After receiving the policy data, the control end node performs cross-level propagation, and the specific steps are as follows: After receiving the policy data, the control end node first verifies the syntax correctness; Determine the upstream and downstream network segments based on the source IP and destination IP in the policy data. The policy data is forwarded once to all associated upstream and downstream control end nodes, and the path mark is carried during forwarding. The receiving end is prohibited from returning the data carrying the mark.
8. The multi-level distributed iptables control method according to claim 7, characterized in that: This method also includes a system recovery mechanism, specifically: Delete data in a specific time period based on the policy data timestamp, and implement time dimension rollback operation with one-click rollback across the entire network; When an upstream storage component fails, the downstream storage components are aggregated to reconstruct the data; when a downstream storage component fails, the spatial dimension recovery operation is performed by extracting the corresponding subnet policy data from the upstream storage component or aggregating the secondary downstream data to reconstruct the data.
9. A distributed iptables control system, characterized in that: include: Multiple hierarchical control end nodes, each of which is connected to an independent storage component; An intelligent agent deployed on the server communicates with storage components on the same subnet; The storage component includes: an autonomous domain management module for maintaining its own network segment and upstream and downstream association information; Policy data storage engine, used to store iptables policy parameters in key-value format; Cross-layer propagation module, used to implement anti-loop forwarding of policy data.
10. The multi-level distributed iptables control system according to claim 9, characterized in that: The intelligent agent program includes: Rule converter, used to parse policy data into server-specific iptables rules; Policy data synchronizer, used to periodically pull storage component data and trigger rule updates.
Citation Information
Patent Citations
Effect time control method and device based on distributed firewall
CN116962069A