Deployment method and device of network equipment, equipment, storage medium and program product

By writing authentication information into network devices and utilizing the configuration platform's storage space, the server obtains and distributes configuration information, solving the problem of mixed deployment of network devices from different manufacturers and achieving efficient deployment without the need for on-site engineers.

CN121333933APending Publication Date: 2026-01-13SHANGHAI KAIYONG INFORMATION TECHNOLOGY CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202511565817.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-29
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

Network equipment from different manufacturers has significantly different zero-contact configuration schemes, making it difficult to achieve mixed deployment and requiring on-site engineer intervention.

Method used

By writing authentication information into the first device, and using the configuration platform and storage space to store network device information, the server obtains and distributes configuration information, thereby achieving unified configuration of network devices from different manufacturers.

Benefits of technology

It enables the mixed deployment of network equipment from different vendors, reduces the involvement of on-site engineers, and improves deployment efficiency and unified management capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121333933A_ABST
    Figure CN121333933A_ABST
Patent Text Reader

Abstract

The invention discloses a network equipment deployment method and device, equipment, a storage medium and a program product, and relates to the technical field of computers, and the method comprises the steps: obtaining first authentication information associated with a first network from first equipment in the first network; acquiring information of at least one network device in the first network from a configuration platform based on the first authentication information; acquiring configuration information corresponding to the at least one network device from the first storage space based on the information of the at least one network device; receiving a configuration request sent by first network equipment in the first network, wherein the configuration request carries first equipment information of the first network equipment; querying and acquiring first configuration information of the first network device from configuration information corresponding to the at least one network device based on the first device information; and sending the first configuration information to the first network device for configuration. The problem of hybrid deployment of network devices of different manufacturers can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of computer, and particularly relates to a network device deployment method and device, equipment, storage medium and program product. BACKGROUND

[0002] Zero Touch Provisioning (ZTP) is a way of deploying network devices. The zero touch provisioning of network devices is strongly associated with manufacturers, and different manufacturers have different zero touch provisioning schemes. Therefore, it is difficult to implement mixed deployment of network devices of different manufacturers. SUMMARY

[0003] Therefore, the present disclosure provides a network device deployment method and device, equipment, storage medium and program product to solve the problem of mixed deployment of network devices of different manufacturers.

[0004] In a first aspect, the present disclosure provides a network device deployment method, applicable to a first server, and the method comprises the following steps. obtaining first authentication information associated with a first network from a first device in the first network; obtaining information of at least one network device in the first network from a configuration platform based on the first authentication information; obtaining configuration information corresponding to the at least one network device respectively from a first storage space based on the information of the at least one network device; receiving a configuration request sent by a first network device in the first network, the configuration request carrying first device information of the first network device; querying and obtaining first configuration information of the first network device from the configuration information corresponding to the at least one network device respectively based on the first device information; sending the first configuration information to the first network device for configuration.

[0005] In a second aspect, the present disclosure provides a network device deployment device, applicable to a first server, and the device comprises the following modules. a first obtaining module, configured to obtain first authentication information associated with a first network from a first device in the first network; a second obtaining module, configured to obtain information of at least one network device in the first network from a configuration platform based on the first authentication information; a third obtaining module, configured to obtain configuration information corresponding to the at least one network device respectively from a first storage space based on the information of the at least one network device; The request receiving module is configured to receive a configuration request sent by a first network device in the first network, wherein the configuration request carries first device information of the first network device. The data querying module is configured to query and acquire first configuration information of the first network device from the configuration information corresponding to the at least one network device respectively based on the first device information. The first configuration module is configured to send the first configuration information to the first network device for configuration.

[0006] In a third aspect, the present disclosure provides an electronic device, comprising a memory and a processor, which are connected to each other in communication, the memory stores computer instructions, and the processor executes the computer instructions to perform the network device deployment method in the first aspect or any of the corresponding embodiments thereof.

[0007] In a fourth aspect, the present disclosure provides a computer readable storage medium, which stores computer instructions, and the computer instructions are used to make a computer execute the network device deployment method in the first aspect or any of the corresponding embodiments thereof.

[0008] In a fifth aspect, the present disclosure provides a computer program product, which comprises computer instructions, and the computer instructions are used to make a computer execute the network device deployment method in the first aspect or any of the corresponding embodiments thereof.

[0009] The network device deployment method provided by the embodiments of the present disclosure writes first authentication information associated with a first network in a first device of the first network, stores information of at least one network device in the first network in a configuration platform, and stores configuration information corresponding to the at least one network device respectively in a first storage space. Therefore, the first server can acquire the first authentication information associated with the first network from the first device, and acquire the information of the at least one network device in the first network from the configuration platform by using the first authentication information. Further, the configuration information corresponding to the at least one network device in the first network respectively is acquired in the first storage space by using the information of the at least one network device. Thus, even if the network devices in the first network belong to different manufacturers, the configuration information corresponding to the network devices can be uniformly sent by the first server to configure the network devices, so as to realize the mixed deployment of the network devices of different manufacturers.

[0010] The beneficial effects of the network device deployment apparatus, the electronic device, the storage medium, and the program product correspond to those of the network device deployment method, which are not repeated here. BRIEF DESCRIPTION OF DRAWINGS

[0011] In order to more clearly illustrate the technical solutions in the specific embodiments of the present disclosure or the prior art, the following will briefly introduce the drawings needed to be used in the specific embodiments or prior art description. Obviously, the drawings in the following description are some embodiments of the present disclosure, and other drawings can be obtained by those skilled in the art without creative labor under the premise of the drawings.

[0012] Figure 1 is a schematic diagram of an optional application scenario according to an embodiment of the present disclosure; Figure 2 is a flowchart of a deployment method of a network device according to an embodiment of the present disclosure; Figure 3 is a flowchart of another deployment method of a network device according to an embodiment of the present disclosure; Figure 4 is a flowchart of a deployment flow of a switch according to an embodiment of the present disclosure; Figure 5 is a schematic diagram of a target page according to an embodiment of the present disclosure; Figure 6 is a flowchart of yet another deployment method of a network device according to an embodiment of the present disclosure; Figure 7 is a structural block diagram of a deployment device of a network device according to an embodiment of the present disclosure; Figure 8 is a structural block diagram of an electronic device according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0013] In order to make the objects, technical solutions and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be described clearly and completely below with reference to the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are some embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present disclosure.

[0014] It can be understood that, before using the technical solutions disclosed in the embodiments of the present disclosure, the type, use range, use scenario and the like of the personal information involved in the present disclosure should be informed to the user and the authorization of the user should be obtained through appropriate means according to relevant laws and regulations.

[0015] For example, in response to receiving an active request of a user, prompt information is sent to the user to explicitly prompt the user that the operation requested to be performed by the user will require obtaining and using personal information of the user. Thus, the user can autonomously select whether to provide personal information to software or hardware such as an electronic device, an application program, a server, or a storage medium, etc. performing the operation of the technical solution of the present disclosure according to the prompt information.

[0016] As an optional but non-limiting implementation manner, in response to receiving an active request of a user, the manner of sending prompt information to the user may, for example, be a pop-up window manner, in which the prompt information may be presented in a text manner. In addition, the pop-up window may also carry selection controls for the user to select “agree” or “disagree” to provide personal information to the electronic device.

[0017] It can be understood that the above notification and obtaining user authorization process is only illustrative and does not limit the implementation manner of the present disclosure, and other manners meeting relevant laws and regulations can also be applied to the implementation manner of the present disclosure.

[0018] It can be understood that the data (including but not limited to the data itself, the obtaining or use of the data) involved in the technical solution should comply with the requirements of relevant laws and regulations and relevant provisions.

[0019] Zero Touch Provisioning (ZTP) is a way to deploy network devices. At present, the zero touch provisioning scheme of network devices is mainly provided by manufacturers, and the zero touch provisioning schemes of different manufacturers are different.

[0020] The following are examples of zero touch provisioning schemes provided by several different manufacturers: First, the network device initiates a Dynamic Host Configuration Protocol (DHCP) request through a network port after power-on to obtain a network address and related configurations. The configurations in the Option field of the DHCP are parsed, such as an option field for providing a server address of a Trivial File Transfer Protocol (TFTP), an option field carrying a configuration information string, etc. The network device locally runs an automatic configuration boot script to construct a download path of a configuration file, and downloads the configuration file of the switch by using the download path. The network device automatically restarts after applying the configuration file to complete the configuration loading.

[0021] The second, the network device initiates a DHCP request through a network card after being powered on, and obtains a network address and related configurations, such as a server address of TFTP. The network device splices a download path of a configuration file under a root directory of TFTP according to a serial number (SN) of the network device, and downloads the configuration file from the server of TFTP. If the configuration file is successfully downloaded, the network device applies the downloaded configuration file to complete deployment of the network device.

[0022] It can be seen that different manufacturers have different zero-touch configuration schemes, the zero-touch configuration scheme is strongly associated with the manufacturer, and the expansibility is poor. Therefore, for mixed deployment of network devices of different manufacturers, engineers need to be deployed on site, which leads to difficulty in realizing mixed deployment of network devices of different manufacturers.

[0023] Therefore, according to an embodiment of the present disclosure, a network device deployment method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a group of computer executable instructions. Although the logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in a different order.

[0024] As an optional application scenario of the embodiment of the present disclosure, as shown in Figure 1 , the network device deployment scenario includes a configuration platform 10, a first storage space 20, and one or more sites to be deployed, such as Figure 1 site 1 and site 2. Each site to be deployed has a first device 30 (such as a firewall), a first server 40 of ZTP, and a network device 50 in the first network. The network device 50 includes a switch and the like. The user uploads the configuration information (such as a configuration file, a boot file) of each network device 50 in the first network and the information of the network device 50 to the configuration platform 10. The information of the network device 50 includes device information of the network device 50, such as a device identifier of the network device 50, an information identifier of the configuration information corresponding to the network device 50, and the like. The configuration platform 10 packs and uploads the configuration information of the network device 50 and the information of the network device 50 to the first storage space 20 for storage. The configuration platform 10 generates first authentication information for the first network of the site to be deployed, and writes the first authentication information into the first device 30. The first server 40 obtains the network address configuration and the first authentication information from the first device 30 when starting, obtains the information of each network device 50 from the configuration platform 10 according to the first authentication information, and obtains the configuration information of each network device 50 from the first storage space 20 according to the information of the network device 50. The first server 40 deploys each network device 50 by using the network address configuration and the configuration information.

[0025] This embodiment provides a method for deploying a network device, applicable to a first server, in which a ZTP server is deployed. Figure 2 This is a flowchart illustrating a method for deploying a network device according to an embodiment of the present disclosure, as shown below. Figure 2 As shown, the process includes the following steps: Step S201: Obtain first authentication information associated with the first network from the first device in the first network.

[0026] The first network mentioned above is the local area network of the site to be deployed.

[0027] Optionally, the first device deploys a DHCP service. The first device is a firewall; alternatively, it can also be a gateway or other similar device, which is not limited here.

[0028] Specifically, the first device is configured with first authentication information associated with the first network. This first authentication information is generated and distributed to the first device by the configuration platform for the first network. The first server sends a network request for the first network to the first device and receives the first authentication information from the first device in response to the network request. This first authentication information is a token.

[0029] Furthermore, the first server sends a network request to the first device via a DHCP broadcast and receives a DHCP message from the first device in response to the network request. This DHCP message carries first authentication information. The first server extracts the first authentication information from the DHCP message.

[0030] Step S202: Obtain information about at least one network device in the first network from the configuration platform based on the first authentication information.

[0031] Specifically, the configuration platform stores information about at least one network device in the first network, as well as first authentication information associated with the first network. The first server interacts with the configuration platform through the first authentication information to obtain information about at least one network device in the first network.

[0032] The information of at least one network device includes device information such as the device identifier, the information identifier of the corresponding configuration information, and the first address of the network device in the second network. A ZTP client is deployed on the network device.

[0033] In practical applications, users upload information about at least one network device in the first network, along with its corresponding configuration information, through a configuration platform. The configuration platform packages the configuration information for the at least one network device and the information for the at least one network device, uploads them to the first storage space for storage, and then clears the configuration information for the at least one network device stored locally on the configuration platform.

[0034] Optionally, the network devices include switches in the first network, and may also include other devices to be deployed in the first network.

[0035] Step S203: Based on the information of at least one network device, obtain the configuration information corresponding to each of the at least one network device from the first storage space.

[0036] The first storage space can be a cloud storage system (such as a TOS system) or other storage space accessible to the first server. The first storage space stores configuration information for at least one network device and information about at least one network device.

[0037] Specifically, the first server queries the first storage space for the configuration information corresponding to at least one network device based on information from at least one network device. For example, the first server queries the first storage space for configuration information that matches the information identifier of the configuration information corresponding to the network device, thereby obtaining the configuration information corresponding to at least one network device. The first server stores the configuration information corresponding to each network device in a designated location, thus preparing the ZTP environment.

[0038] Optionally, the configuration information corresponding to the network device includes the configuration file and the boot file corresponding to the network device. The boot file is used to guide the network device corresponding to the boot file to download the corresponding configuration file and perform configuration according to the configuration file.

[0039] Furthermore, the information identifier for configuration information includes the file identifier of the configuration file and the file identifier of the boot file. Additionally, the information identifier for configuration information can also be a unique identifier configured specifically for the configuration information; this is not limited here.

[0040] Step S204: Receive a configuration request sent by a first network device in the first network, the configuration request carrying the first device information of the first network device.

[0041] Specifically, after startup, the first network device sends a configuration request in the second network it is in, based on its first device information. The second network is ZTP's Management Network (MGT). The first server receives the configuration request from the first network device through the second network.

[0042] Optionally, the first device information includes one or more of the device identifier, device type, and belonging object (such as the manufacturer to which the first network device belongs). In addition, other device information that can determine the configuration information of the first network device may also be used, which is not limited here.

[0043] Step S205: Based on the first device information, query and obtain the first configuration information of the first network device from the configuration information corresponding to at least one network device.

[0044] Specifically, based on the matching of the first device information with the information (such as device information) of at least one network device, the first configuration information of the first network device is queried and obtained from the configuration information corresponding to each of the at least one network device.

[0045] Step S206: Send the first configuration information to the first network device for configuration.

[0046] Specifically, the first server sends the first configuration information to the first network device so that the first network device can be configured according to the first configuration information, thereby achieving zero-contact deployment of the first network device.

[0047] Furthermore, the first server can send the first configuration information to the first network device for configuration via DHCP service, thereby achieving zero-contact deployment of the first network device.

[0048] The network device deployment method provided in this embodiment involves writing first authentication information associated with the first network into a first device in the first network, storing information about at least one network device in the first network in a configuration platform, and storing configuration information corresponding to each of the at least one network device in a first storage space. Therefore, a first server can obtain the first authentication information associated with the first network from the first device, and then use the first authentication information to obtain information about at least one network device in the first network from the configuration platform. Furthermore, it uses the information of the at least one network device to obtain the configuration information corresponding to each of the at least one network device in the first network from the first storage space. Thus, even if the network devices in the first network belong to different manufacturers, the first server can uniformly distribute the corresponding configuration information for each network device for configuration, thereby achieving mixed deployment of network devices from different manufacturers.

[0049] In some optional implementations, step S202 above, which involves obtaining information about at least one network device in the first network from the configuration platform based on the first authentication information, includes: Step a1: Send an authentication request to the configuration platform based on the authentication information.

[0050] Step a2: Receive the first key returned by the configuration platform if the first authentication information is successfully authenticated.

[0051] Step a3: Obtain information about at least one network device from the configuration platform based on the first key.

[0052] Specifically, the first server sends an authentication request to the configuration platform based on the first authentication information. The configuration platform responds to the authentication request by authenticating the first authentication information sent by the first server. If authentication is successful, the first authentication information is deemed to have passed authentication. If authentication fails, the first authentication information is deemed to have failed authentication. If the first authentication information has passed authentication, the configuration platform sends a first key (i.e., the interaction key between the first server and the configuration platform) back to the first server. The first server uses the first key to obtain information about at least one network device in the first network from the configuration platform.

[0053] The network device deployment method provided in this embodiment utilizes first authentication information to perform authentication at the configuration platform and receives a first key fed back by the configuration platform after successful authentication on the first server. The first key is then used to obtain information about at least one network device in the first network from the configuration platform. Therefore, not only can the correctness of the network device information issued by the configuration platform be ensured using the first authentication information, but the security of the network device information can also be ensured using the first key.

[0054] In some optional implementations, step a3 above, which involves obtaining information about at least one network device from the configuration platform based on the first key, includes: generating a second key based on the first authentication information and the first key; and obtaining information about at least one network device from the configuration platform based on the second key.

[0055] In practical applications, the first authentication information and the first key can be concatenated to obtain the second key. Alternatively, the first authentication information and the first key can be fused using a preset template to obtain the second key. The method of generating the second key is not limited here.

[0056] The network device deployment method provided in this embodiment utilizes a second key generated from the first authentication information and the first key to obtain information about at least one network device from a configuration platform. Therefore, it can further improve the security of information distribution and transmission within the network device.

[0057] In some optional implementations, the information of at least one network device includes a first address of at least one network device in the second network. Receiving the configuration request sent by the first network device in the first network in step S204 above includes: Step b1: Send an address request for the second network to the configuration platform and obtain the second address of the first server in the second network in response to the address request from the configuration platform.

[0058] Step b2: Using the first address, the second address, and the second network, receive the configuration request sent by the first network device.

[0059] Specifically, the first server sends an address request for the second network to the configuration platform, and obtains the second address (i.e., IP address) of the first server in the second network in response to the address request from the configuration platform. This second address is then used to enable relevant services on the second network to support subsequent communication and configuration synchronization. Afterwards, the first server uses the first and second addresses to detect the status of network devices in the first network, waiting for the network devices to initiate configuration requests. These configuration requests can be DHCP or TFTP requests.

[0060] The network device deployment method provided in this embodiment utilizes a first address of the network device in a second network, a second address of the first server in the second network, and the second network to receive configuration requests initiated by the first network device. Therefore, the first address can be used to filter information unrelated to the network device, improving the detection efficiency of configuration requests from the first network device.

[0061] In some optional implementations, step S206 above, sending the first configuration information to the first network device for configuration, includes: Step c1: Obtain the network address configuration associated with the first network from the first device. The network address configuration includes the host address and the address range corresponding to at least one network device.

[0062] Step c2: Set the network address of the first server to the host address, and determine the network address of the first network device according to the address range.

[0063] Step c3: Send the first configuration information, host address, and network address of the first network device to the first network device for configuration.

[0064] Specifically, the network address configuration in the first device is sent to the first device by the configuration platform. The user can configure the network address configuration of the first network on the configuration platform, and then the configuration platform sends the network address configuration to the first device. When the first server sends a network request for the first network to the first device, the first device, in addition to returning the first authentication information, also returns the network address configuration associated with the first network.

[0065] Taking a practical application scenario as an example, assume the first network is the local area network (LAN) of the site to be deployed, and the first device is the firewall within that LAN. The user plans the LAN of the site to be deployed in the configuration platform, enters project information for the site, and configures the network address configuration for the site's local network, such as the host address of the DHCP service and the address range of network devices. Simultaneously, the user can also configure the wiring diagram for the site to be deployed on the configuration platform. Wiring personnel then perform on-site wiring for the first server, firewall, and network devices (such as switches) within the site to establish a zero-contact deployment of the corresponding management network (i.e., the aforementioned second network). The configuration platform generates authentication information for the LAN of the site to be deployed and sends the authentication information and the network address configuration of the LAN to the firewall's control platform for firewall initialization. The firewall connects to the internet and connects to its control platform. The firewall downloads the authentication information and network address configuration from the control platform. Then, the first server sends a DHCP broadcast. After receiving the DHCP broadcast, the firewall sends a DHCP message back to the first server based on the authentication information and network address configuration, so that the first server can extract the authentication information and network address configuration from the DHCP message.

[0066] Furthermore, the aforementioned host addresses are the host addresses of the DHCP and TFTP services in the first network, and the aforementioned address range is the address range provided by the DHCP service for network devices. The first server changes its local network address (i.e., IP address) from its original address to a host address. The first server enables and configures the DHCP service, and determines the network address of the first network device in the first network based on the address range, that is, the network address of the first network device corresponding to the DHCP / TFTP service. The first server sends the host address and the network address of the first network device to the first network device through the DHCP service, so that the first network device configures the host address of the DHCP / TFTP service, and configures its local network address according to the network address of the first network device, ensuring that the server address of the TFTP service and the configuration information corresponding to the network device both point to the network address of the first server, thereby achieving zero-contact deployment of the network device.

[0067] It should be noted that different network devices have different network addresses, and these addresses are different from the host address of the first server.

[0068] The network device deployment method provided in this embodiment sets the network address of the first server as the host address and determines the network address of the first network device based on the address range associated with the first network. Both the host address and the network address of the first network device are sent to the first network device for configuration. Therefore, the host address and the network address of the first network device can be used to support subsequent communication and configuration synchronization between the first network device and the first server.

[0069] In some optional implementations, step c3 above, sending the first configuration information, host address, and network address of the first network device to the first network device for configuration, includes: Step c31: Generate request parameters corresponding to the first configuration information. The request parameters are used by the first network device to request the first configuration information from the first server. Step c32: Send the request parameters, host address, and network address of the first network device to the first network device for configuration.

[0070] Specifically, in step c31 above, the request parameters corresponding to the first configuration information generated based on the DHCP service are DHCP parameters, which determine the configuration information requested by the first network device. The first server sends the request parameters, the host address, and the network address of the first network device to the first network device, so that the first network device configures the host address for the DHCP / TFTP service, configures the local network address according to the network address of the first network device, and obtains the download address of the first configuration information by concatenating the request parameters. Based on the download address, the first server requests the first configuration information from the first network device. In response to the request for the first configuration information from the first network device, the first server sends the first configuration information to the first network device, so that the first network device can configure itself according to the first configuration information, thereby achieving zero-contact deployment of the first network device.

[0071] The network device deployment method provided in this embodiment sends request parameters corresponding to the first configuration information to the first network device, which then requests the first configuration information from the first server based on the request parameters. Therefore, if the transmission of the first configuration information fails, the first network device can use the request parameters to request the first configuration information from the first server again, ensuring that the first network device can successfully receive the first configuration information and thus ensuring the successful deployment of the first network device.

[0072] As one specific application scenario, taking the first network as the local area network of the site to be deployed, the first storage space as the storage space of the cloud storage system, the first device as the firewall in the local area network, and the network device as a switch as an example, see [link to relevant documentation]. Figure 3The network device deployment method disclosed herein mainly includes the following steps: The user uploads the configuration information and switch information of the switches in the first network through a configuration platform. The switch information includes the information identifier of the corresponding configuration information and the device information of the switch. The configuration platform packages the switch configuration information and switch information and uploads them to the cloud storage system. The user configures the host address of the DHCP service of the first network and the address range of the switches through the configuration platform to obtain the network address configuration. The configuration platform packages the network address configuration and sends it to the firewall's control platform. After startup, the firewall in the first network connects to the Internet and connects to the control platform to download the network address configuration. The first server in the first network (hereinafter referred to as the ZTP Server) sends a network request to the firewall, extracting the ZTP Server's authentication information (hereinafter referred to as the Token) and the network address configuration from the firewall's DHCP message. The ZTP Server uses the Token to obtain the switch information from the configuration platform. The ZTP Server uses the switch information to obtain the switch configuration information from the cloud storage system and uses the switch configuration information to achieve zero-contact deployment of the switches.

[0073] In some optional implementations, the device deployment method of this disclosure further includes: detecting the network connectivity between the first network device and the first server using the host address and the network address of the first network device; and determining the deployment status of the first network device based on the network connectivity status.

[0074] As one specific application example, see Figure 4 Taking the first server as the ZTP Server, the first device as the firewall, the network device as the switch, and the second network as the ZTP management network as an example, the deployment process of the switch mainly includes the following stages: 1. ZTP Server Network Connection: The ZTP Server continuously initiates DHCP requests (i.e., the network requests mentioned above) through a preset network port to detect whether the firewall is online and sends a DHCP message containing a token and network address configuration for the DHCP service. If the ZTP Server detects the token field, it considers the firewall ready and enters the zero-touch deployment process.

[0075] 2. ZTP Server Connection to Configuration Platform: The ZTP Server requests and obtains management network information from the configuration platform, such as its address within the management network. The ZTP Server uses the host address in its network address configuration as the host address for both DHCP and TFTP services, and changes its own network address from its original address to the host address in the network address configuration. The ZTP Server enables and configures the DHCP service using the host address and the address range in the network address configuration, ensuring that the switch's TFTP server address and configuration information both point to the aforementioned host address.

[0076] 3. ZTP Server Enables ZTP Capabilities: The ZTP Server enables the management network using the acquired management network information. It detects the status of switches in the first network using its address within the management network. Furthermore, the ZTP Server requests information about the switches in the first network from the configuration platform and downloads their configuration information (such as configuration files, boot files, images, and patches) from the first storage space. The ZTP Server sets the DHCP parameters (i.e., request parameters) corresponding to the switch's configuration information. The ZTP Server waits for the switch to initiate a configuration request, such as a DHCP or TFTP request. It then queries the downloaded switch configuration information for the current switch and sends this information to the switch, achieving zero-contact configuration. The ZTP Server continuously monitors network connectivity with the switches to determine if the switch deployment was successful and collects relevant deployment information to send back to the configuration platform. Figure 5 As shown, the configuration platform displays the device name, network address, device role, and device model of each device (including ZTP Server and switch) in the local area network of the site to be deployed on the target page. Users can interact with the target page to view the configuration information and ZTP logs of each device.

[0077] 4. ZTP Server disables ZTP capabilities: After the switch deployment is complete, the ZTP Server automatically exits while retaining its configuration environment. The ZTP Server enters standby mode for subsequent manual or automatic control operations. Simultaneously, a detection program is started to automatically verify the switch deployment, thus completing the pre-network deployment work for the site.

[0078] For example, see a real-world application scenario. Figure 6The network device deployment method disclosed herein includes the following process: The user maintains basic information for network device deployment at a site on a configuration platform. The user performs network planning for the site to be deployed on the configuration platform, enters project information for the site (e.g., site A and site B), and configures the host address for the DHCP service of the site's local area network and the corresponding address range for the switch to obtain the network address configuration. Simultaneously, the user also configures the wiring table for the devices at the site to be deployed on the configuration platform. Wiring personnel perform on-site wiring for the first server associated with the site's local area network, the firewall in the site, network devices, and other equipment. The configuration platform generates first authentication information for the local area network of the site to be deployed and sends the first authentication information and the site's network address configuration to the firewall's control platform for firewall initialization. The firewall connects to the Internet and connects to the firewall's control platform. The firewall downloads the first authentication information and network address configuration from the control platform. Then, the first server performs zero-contact deployment of the network devices in the site's local area network using the above network device deployment method, collects and displays the zero-contact deployment results, and completes the automatic acceptance of the network device deployment.

[0079] This disclosed network device deployment method provides an automated remote device initialization and deployment solution, supporting ZTP deployment in a mixed environment of multi-vendor network devices. No deployment engineer intervention is required on-site; only wiring personnel are needed to complete the operation. Therefore, it effectively enhances network device deployment capabilities and enables unified management of the entire network device deployment process by the configuration platform. Furthermore, this disclosed network device deployment method leverages the technical capabilities of various network device vendors to build a system that supports the simultaneous commissioning of multi-vendor network devices, encompassing network device configuration synchronization and distribution functions.

[0080] This embodiment also provides a network device deployment apparatus for implementing the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that performs a predetermined function. Although the apparatus described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.

[0081] This embodiment provides a network device deployment apparatus, suitable for a first server, such as... Figure 7 As shown, it includes: The first acquisition module 701 is used to acquire first authentication information associated with the first network from the first device in the first network; The second acquisition module 702 is used to acquire information about at least one network device in the first network from the configuration platform based on the first authentication information; The third acquisition module 703 is used to acquire configuration information corresponding to at least one network device from the first storage space based on the information of at least one network device; The request receiving module 704 is used to receive a configuration request sent by a first network device in the first network, wherein the configuration request carries the first device information of the first network device; The data query module 705 is used to query and obtain the first configuration information of the first network device from the configuration information corresponding to at least one network device based on the first device information. The first configuration module 706 is used to send the first configuration information to the first network device for configuration.

[0082] In some alternative implementations, the second acquisition module 702 includes: The authentication unit is used to send an authentication request to the configuration platform based on the first authentication information. The first receiving unit is used to receive the first key fed back by the configuration platform after the first authentication information is successfully authenticated. The device information acquisition unit is used to acquire information about at least one network device from the configuration platform based on a first key.

[0083] In some optional implementations, the device information acquisition unit is specifically used to: generate a second key based on the first authentication information and the first key; and acquire information about at least one network device from the configuration platform based on the second key.

[0084] In some alternative implementations, the information of at least one network device includes a first address of at least one network device in the second network. The request receiving module 704 includes: The request sending unit is used to send an address request for the second network to the configuration platform and obtain the second address of the first server in the second network in response to the address request from the configuration platform. The second receiving unit is used to receive a configuration request sent by the first network device using the first address, the second address, and the second network.

[0085] In some alternative implementations, the first configuration module 706 includes: The address configuration acquisition unit is used to acquire network address configuration associated with the first network from the first device. The network address configuration includes a host address and an address range corresponding to at least one network device. The address setting unit is used to set the network address of the first server to the host address and to determine the network address of the first network device according to the address range. The device configuration unit is used to send the first configuration information, the host address, and the network address of the first network device to the first network device for configuration.

[0086] In some alternative implementations, the device configuration unit includes: The parameter generation subunit is used to generate request parameters corresponding to the first configuration information. The request parameters are used by the first network device to request the first configuration information from the first server. The device configuration subunit is used to send request parameters, host address, and network address of the first network device to the first network device for configuration.

[0087] In some optional implementations, the deployment apparatus for the network device of this disclosure further includes: The first detection module is used to detect the network connectivity between the first network device and the first server by using the host address and the network address of the first network device. The second detection module is used to determine the deployment status of the first network device based on network connectivity.

[0088] The network device deployment apparatus provided in this disclosure can execute the network device deployment method provided in any embodiment of this disclosure, and has the corresponding functional modules and beneficial effects of the method execution.

[0089] Further functional descriptions of the above modules and units are the same as those in the corresponding embodiments described above, and will not be repeated here.

[0090] Figure 8 This is a structural block diagram of an electronic device provided in an embodiment of the present disclosure.

[0091] The following is a detailed reference. Figure 8 The diagram illustrates a structural block diagram suitable for implementing an electronic device according to embodiments of the present disclosure. The electronic device may include a processor (e.g., a central processing unit, graphics processor, etc.) 801, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 802 or a program loaded from memory 808 into random access memory (RAM) 803. The RAM 803 also stores various programs and data required for the operation of the electronic device. The processor 801, ROM 802, and RAM 803 are interconnected via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.

[0092] Typically, the following devices can be connected to I / O interface 805: input devices 806 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 807 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; memory devices 808 including, for example, magnetic tapes, hard disks, etc.; and communication devices 809. Communication device 809 allows electronic devices to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 8 Electronic devices with various devices are shown, but it should be understood that it is not required to implement or have all of the devices shown, and more or fewer devices may be implemented or have instead.

[0093] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 809, or installed from a memory 808, or installed from a ROM 802. When the computer program is executed by the processor 801, it performs the functions defined in the deployment method of the network device according to embodiments of this disclosure.

[0094] Figure 8 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.

[0095] This disclosure also provides a computer-readable storage medium in which the methods described in this disclosure can be implemented in hardware or firmware, or implemented as recordable on a storage medium, or implemented as computer code downloaded over a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and subsequently stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium may also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code. When the software or computer code is accessed and executed by the computer, processor, or hardware, the deployment method of the network device shown in the above embodiments is implemented.

[0096] A portion of this disclosure can be applied to computer program products, such as computer program instructions, which, when executed by a computer, can invoke or provide methods and / or technical solutions according to this disclosure through the operation of the computer. Those skilled in the art will understand that the forms in which computer program instructions exist in a computer-readable medium include, but are not limited to, source files, executable files, and installation package files. Accordingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executing the instructions; the computer compiling the instructions and then executing the corresponding compiled program; the computer reading and executing the instructions; or the computer reading and installing the instructions and then executing the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to a computer.

[0097] Although embodiments of the present disclosure have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the present disclosure, and such modifications and variations all fall within the scope defined by the appended claims.

Claims

1. A method for deploying a network device, characterized in that, Applicable to the first server, the method includes: Obtain first authentication information associated with the first network from a first device in the first network; Based on the first authentication information, obtain information about at least one network device in the first network from the configuration platform; Based on the information of the at least one network device, obtain the configuration information corresponding to each of the at least one network device from the first storage space; Receive a configuration request sent by a first network device in the first network, wherein the configuration request carries first device information of the first network device; Based on the first device information, query and obtain the first configuration information of the first network device from the configuration information corresponding to the at least one network device respectively; The first configuration information is sent to the first network device for configuration.

2. The method according to claim 1, characterized in that, The step of obtaining information about at least one network device in the first network from the configuration platform based on the first authentication information includes: Based on the first authentication information, an authentication request is sent to the configuration platform; Receive the first key returned by the configuration platform if the authentication information passed the first authentication; Information about the at least one network device is obtained from the configuration platform based on the first key.

3. The method according to claim 2, characterized in that, The step of obtaining information about the at least one network device from the configuration platform based on the first key includes: A second key is generated based on the first authentication information and the first key; Information about the at least one network device is obtained from the configuration platform based on the second key.

4. The method according to claim 1, characterized in that, Sending the first configuration information to the first network device for configuration includes: Obtain the network address configuration associated with the first network from the first device, the network address configuration including the host address and the address range corresponding to the at least one network device; Set the network address of the first server to the host address, and determine the network address of the first network device according to the address range; The first configuration information, the host address, and the network address of the first network device are sent to the first network device for configuration.

5. The method according to claim 4, characterized in that, Sending the first configuration information, the host address, and the network address of the first network device to the first network device for configuration includes: Generate request parameters corresponding to the first configuration information, the request parameters being used by the first network device to request the first configuration information from the first server; The request parameters, the host address, and the network address of the first network device are sent to the first network device for configuration.

6. The method according to claim 4, characterized in that, Also includes: The network connectivity between the first network device and the first server is detected using the host address and the network address of the first network device. The deployment status of the first network device is determined based on the network connectivity status.

7. The method according to claim 1, characterized in that, The information of the at least one network device includes a first address of the at least one network device in the second network; receiving the configuration request sent by the first network device in the first network includes: Send an address request for the second network to the configuration platform, and obtain the second address of the first server in the second network as responded by the configuration platform to the address request; Using the first address, the second address, and the second network, the configuration request sent by the first network device is received.

8. A deployment apparatus for a network device, characterized in that, For use with a first server, the apparatus includes: The first acquisition module is used to acquire first authentication information associated with the first network from a first device in the first network; The second acquisition module is used to acquire information about at least one network device in the first network from the configuration platform based on the first authentication information; The third acquisition module is used to acquire configuration information corresponding to the at least one network device from the first storage space based on the information of the at least one network device; The request receiving module is used to receive a configuration request sent by a first network device in the first network, wherein the configuration request carries the first device information of the first network device; The data query module is used to query and obtain the first configuration information of the first network device from the configuration information corresponding to the at least one network device, based on the first device information. The first configuration module is used to send the first configuration information to the first network device for configuration.

9. An electronic device, characterized in that, include: A memory and a processor are communicatively connected, the memory storing computer instructions, and the processor executing the computer instructions to perform the deployment method of the network device according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a computer to perform the deployment method of the network device according to any one of claims 1 to 7.

11. A computer program product, characterized in that, Includes computer instructions for causing a computer to perform the deployment method of the network device according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Network device deployment method and device

    CN107294763A

  • Equipment configuration method and device, equipment and storage medium

    CN112491603A

  • Zero configuration method, device, equipment and system

    CN114465890A

  • Zero-contact service provisioning for policy-driven network devices

    CN115484168A

  • Zero-configuration opening method and network management system

    CN117749613A