A network management-based terminal control configuration method and system

By linking the network management terminal and the device terminal, configuration messages are generated and sent out. The device terminal downloads and loads the configuration file to realize WIFI access control, which solves the problem of lack of adaptability in enterprise WIFI access management and provides an efficient, stable and accurate terminal access solution.

CN122137739APending Publication Date: 2026-06-02WUHAN SIPU TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
WUHAN SIPU TECH CO LTD
Filing Date
2026-04-07
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing technologies lack adaptability in enterprise WIFI access control and management, making it difficult to meet the security management needs of accurate terminal access to WIFI.

Method used

By linking the network management terminal and the device terminal, a configuration message carrying the download path and size of the configuration file is generated and sent. The device terminal downloads and loads the configuration file for verification, thereby realizing WIFI access control.

Benefits of technology

It achieves efficient, stable, highly compatible, easy-to-configure, and scalable precise Wi-Fi access control, meeting the needs of enterprise network security for precise terminal access to Wi-Fi and reducing deployment costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122137739A_ABST
    Figure CN122137739A_ABST
Patent Text Reader

Abstract

This application provides a network management-based terminal control configuration method and system for linking the network management end and the device end to create a high-efficiency, stable, highly compatible, easy-to-configure, highly scalable, non-dependent, and low-deployment-cost precise WIFI access control solution. Compared with existing network management solutions based on whitelists, access control, and internet behavior management, it can better meet the security management needs of enterprises for precise terminal access to WIFI in their network security work.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, specifically to a terminal control configuration method and system based on network management. Background Technology

[0002] As enterprise networks expand and security management requirements increase, most enterprises adopt distributed deployment of Internet access behavior management devices and central control through a Network Management System (NMS) to achieve unified management and security compliance verification of the enterprise network.

[0003] However, the inventors of this application have found that these methods are mainly based on whitelists, access control, and internet behavior management. However, they lack adaptability for enterprise wireless Fidelity (WIFI) access control and management tasks, resulting in poor management effectiveness and failing to meet the security management needs of enterprise network security work for accurate terminal access to WIFI. Summary of the Invention

[0004] This application provides a network management-based terminal control configuration method and system for linking the network management end and the device end to create a high-efficiency, stable, highly compatible, easy-to-configure, highly scalable, non-dependent, and low-deployment-cost precise WIFI access control solution. Compared with existing network management solutions based on whitelists, access control, and internet behavior management, it can better meet the security management needs of enterprises for precise terminal access to WIFI in their network security work.

[0005] Firstly, this application provides a terminal control configuration method based on network management, the method comprising: The network management terminal generates a configuration message, which carries the download path and file size of the configuration file; The network management terminal sends configuration messages to the pre-registered devices. The device downloads the configuration file based on the configuration message; The device loads a configuration file to verify access to the enterprise Wi-Fi when requesting access, and then connects to the enterprise Wi-Fi normally after passing the verification.

[0006] In conjunction with the first aspect of this application, in a first possible implementation of the first aspect of this application, the method further includes: After the network administrator logs in, the network management terminal identifies the devices that can access the enterprise WIFI, completes the configuration of the control policy that only allows terminals to access the WIFI, and generates a configuration file with a unique tag based on the configuration template.

[0007] In conjunction with the first aspect of this application, in a second possible implementation of the first aspect of this application, the method further includes: The network management system uses the Docker container volume mounting method to mount the configuration file and store it in the specified directory in the background to complete the storage of the configuration file.

[0008] In conjunction with the first aspect of this application, in the third possible implementation of the first aspect of this application, the method further includes: The network management terminal agrees on the message configuration for configuration messages with all devices in advance.

[0009] In conjunction with the first aspect of this application, in the fourth possible implementation of the first aspect of this application, the device downloads the configuration file based on the configuration message, including: The device parses the download path and file size of the configuration file from the configuration message; Based on the download path and file size of the configuration file, the device starts a timer and an independent download thread to download the configuration file and renames it to the preset terminal configuration file name.

[0010] In conjunction with the first aspect of this application, in the fifth possible implementation of the first aspect of this application, the device loads a configuration file, including: On the device side, the configuration template is imported by executing a configuration template import command via command line. The device executes the core command to activate the configuration, thereby loading and activating the control policy that only allows terminals to access WIFI in the form of configuration restoration.

[0011] In conjunction with the first aspect of this application, in the sixth possible implementation of the first aspect of this application, the pre-registered device is specifically a Windows terminal type, and the configuration file is used to restrict terminals other than Windows terminal types from accessing the enterprise WIFI. Types other than Windows terminal types include IoT terminal types, mobile terminal types, network device types, and PC terminal types other than Windows terminals.

[0012] In conjunction with the first aspect of this application, in the seventh possible implementation of the first aspect of this application, the method further includes: The network management system checks the distribution of configuration files to different devices and the configuration of configuration files on different devices.

[0013] Secondly, this application provides a network management-based terminal control and configuration system, which includes a network management terminal and a device terminal, for executing the method provided by the first aspect of this application or any possible implementation of the first aspect of this application.

[0014] Thirdly, this application provides a computer-readable storage medium storing a plurality of instructions adapted for loading by a processor to perform the method provided by the first aspect of this application or any possible implementation thereof.

[0015] From the above, it can be concluded that this application has the following beneficial effects: For network management objectives involving WIFI access management, this application integrates the network management end and the device end to create a high-efficiency, stable, highly compatible, easy-to-configure, highly scalable, non-dependent, and low-deployment-cost precise WIFI access control solution. Compared with existing network management solutions based on whitelists, access control, and internet behavior management, it can better meet the security management needs of enterprises for precise terminal access to WIFI in their network security work. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0017] Figure 1 This is a flowchart illustrating a terminal control configuration method based on network management according to this application; Figure 2 This is a schematic diagram illustrating an example of configuring a specified device using the WEBUI visual interface, as described in this application. Figure 3 This is a schematic diagram of the processing equipment involved in the network management-based terminal control and configuration system of this application. Detailed Implementation

[0018] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0019] The terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in a sequence other than that illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or device that includes a series of steps or modules is not necessarily limited to those explicitly listed, but may include other steps or modules not explicitly listed or inherent to such processes, methods, products, or devices. The naming or numbering of steps appearing in this application does not imply that the steps in the method flow must be performed in the chronological / logical order indicated by the naming or numbering. The execution order of named or numbered process steps can be changed according to the desired technical purpose, as long as the same or similar technical effect is achieved.

[0020] The module division described in this application is a logical division. In practical applications, there may be other division methods. For example, multiple modules may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the shown or discussed mutual coupling, direct coupling, or communication connections may be through interfaces, and the indirect coupling or communication connections between modules may be electrical or other similar forms, none of which are limited in this application. Moreover, the modules or sub-modules described as separate components may or may not be physically separated, may or may not be physical modules, or may be distributed across multiple circuit modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution in this application.

[0021] For network management objectives involving WIFI access management, this application provides a terminal control configuration method based on network management, linking the network management end and the device end, thereby meeting the enterprise network security work's security management needs for accurate terminal access to WIFI with high quality.

[0022] For this, please refer to Figure 1 The diagram shown illustrates a flowchart of a terminal control configuration method based on network management according to this application. The terminal control configuration method based on network management provided by this application may specifically include the following steps S101 to S104: Step S101: The network management terminal generates a configuration message, which carries the download path and file size of the configuration file. As is understandable, this application does not involve the network management end directly configuring and executing the corresponding WIFI access policies on the device end. This application involves the linkage operation between the network management end and the device end to achieve high-performance WIFI access management.

[0023] As can be seen, the network management end first needs to be involved in generating configuration messages, so that the devices that receive the configuration messages can perform further configuration operations to enable them to access the enterprise WIFI normally and use the Internet.

[0024] This configuration message carries or describes the download path and file size of the configuration file, providing accurate information for the device to download the corresponding configuration file correctly based on this configuration message.

[0025] The download path mentioned here can be either a direct Uniform Resource Locator (URL) address or a description of the corresponding configuration file download service node that indirectly provides the configuration file download address. In other words, it is a download path indirect description information that does not directly describe the download address, thus meeting the flexible and ever-changing configuration requirements of configuration file download services in actual situations.

[0026] For example, if network security is a concern, the actual download address of the configuration file can be updated periodically or irregularly. When obtaining the actual download address, a corresponding verification process is required, and the specific download address is provided only after the security verification is passed.

[0027] Step S102: The network management terminal sends a configuration message to the pre-registered device. It's easy to understand that the network management end is usually the device on the side of the network administrator in the enterprise network architecture, while the device end is the device on the side of ordinary Internet users in the enterprise network architecture, that is, user equipment (UE).

[0028] For devices included in the WIFI access control scope of this application, they specifically need to register with the system (usually the Network Management System, NMS) in advance and be included in the solution's processing scope.

[0029] In this case, the network management terminal can send the generated configuration message to the device terminal that has completed system registration in advance through the communication link during the previous registration, or other communication links, so as to trigger the device terminal to carry out further configuration work based on the configuration message.

[0030] Step S103: The device downloads the configuration file based on the configuration message; As mentioned earlier, the configuration message itself carries and describes the relevant information required to download the configuration file. Therefore, after receiving the configuration message from the network management terminal, the device can trigger the download operation of the corresponding configuration file according to the triggering mechanism pre-configured in the message.

[0031] Thus, after downloading the configuration file, it can be stored in the location to be loaded, or other loading configuration work can be completed for further loading.

[0032] Step S104: The device loads a configuration file to verify the connection to the enterprise WIFI when requesting access, and to connect to the enterprise WIFI normally after passing the verification.

[0033] After completing the initial configuration file setup, including storage, the device can load the configuration according to the corresponding loading strategy, making the WIFI access control strategy configured in the configuration file effective. This allows for local verification or verification with the network management system when requesting WIFI access in subsequent requests.

[0034] It's easy to understand: if the verification passes, you can access the company's Wi-Fi normally; otherwise, if the verification fails, you cannot access the company's Wi-Fi normally, and your internet access through the company's Wi-Fi will be restricted.

[0035] Thus, as can be seen from the above, for network management objectives involving WIFI access management, this application links the network management end and the device end to create a high-efficiency, stable, highly compatible, easy-to-configure, highly scalable, non-dependent, and low-deployment-cost precise WIFI access control solution. Compared with existing network management solutions based on whitelists, access control, and internet behavior management, it can better meet the security management needs of enterprise network security work for precise terminal access to WIFI.

[0036] Continue with the above Figure 1 The steps of the illustrated embodiment and their possible implementation methods in practical applications are described in detail.

[0037] As an exemplary embodiment, this application may further include the following preliminary environmental preparation work: Network management end: It can be developed based on Docker 6.0 x86, and the neutral network management system (NMS) version can be developed based on R4.3 mainline, and customized testing can be completed to ensure that the WEBUI interface can be operated normally and the configuration files can be exported and stored normally; On the device side: Function development can be completed by pulling a branch from R6.3, and the terminal control configuration policy can be merged into the R6.3 version to ensure that the device can be registered to the network management system, receive messages issued by the network management system, and execute relevant commands. Network environment: Ensure that the network management NMS terminal is connected to the network of all distributed devices, and that all devices are registered with the network management terminal, thus meeting the prerequisites for configuration distribution.

[0038] The corresponding step S101, the network management terminal's generation and processing of configuration messages, as an exemplary implementation method, may also involve the generation and processing of corresponding configuration files.

[0039] Understandably, during the implementation of this application, the configuration file can be either a ready-made / pre-generated file or a file generated in real time. This is quite flexible and can be adjusted according to specific circumstances.

[0040] For the latter, as an exemplary embodiment, the method of this application may further include: After the network administrator logs in, the network management terminal identifies the devices that can access the enterprise WIFI, completes the configuration of the control policy that only allows terminals to access the WIFI, and generates a configuration file with a unique tag based on the configuration template.

[0041] The user login operation for network administrators not only provides operation permissions, but also provides operational space for manual verification / adjustment operations involved in the device side. Although the entire operation can be automated in actual applications, this can also be understood as a fallback configuration.

[0042] Furthermore, it is understandable that devices that have registered in advance and are allowed to access the enterprise WIFI are selected from any available devices. It does not mean that as long as a device has registered, it is allowed to access the enterprise WIFI. This depends on whether a configuration message is received within the effective time to activate the WIFI access control policy.

[0043] As an example, in the configuration template of the Network Management System (NMS), select the Control Policy module, then select the Matching Conditions module. In the WEBUI interface at this time, add a device configuration option to configure a control policy template that only allows specified devices to access the enterprise WIFI. After the user clicks to confirm and create a new application, the system adds a unique tag "nms-cfg-template" to the configuration template. Save the configuration template and name it. Then, use the command "export nms-cfg-template NAME" to export the tagged configuration file to the specified / home directory to achieve precise filtering and identification of the configuration file.

[0044] Understandably, adding extra configuration and binding of exclusive tags in the details to achieve precise filtering and identification of configuration files helps to promote more refined configuration file processing effects.

[0045] Furthermore, corresponding to cloud storage of the configuration file, as an exemplary embodiment, the method of this application may also include: The network management system uses the Docker container volume mounting method to mount the configuration file and store it in the specified directory in the background to complete the storage of the configuration file.

[0046] Understandably, combining the network management end with the Docker container volume mounting method helps to achieve efficient storage and access performance of configuration files (mainly access efficiency).

[0047] Of course, in practice, besides the Docker container volume mounting method, other methods can also be used to achieve high-performance storage of configuration files.

[0048] In addition, in order to push the configuration of WIFI access control policies to the device through configuration messages and achieve better linkage, it may also involve the configuration of the configuration messages themselves.

[0049] Specifically, as an exemplary embodiment, the method of this application may further include: The network management terminal agrees on the message configuration for configuration messages with all devices in advance.

[0050] For example, the download path and file size of the configuration file carried in the configuration message can be agreed upon, as well as the content fields and location fields.

[0051] As an example, the device can also monitor in real time whether the network management terminal has issued a configuration message under the configuration message settings through the message receiving module.

[0052] Meanwhile, for the device that receives the configuration message and triggers the configuration file download operation, as an exemplary embodiment, the device downloads the configuration file based on the configuration message, which may specifically include: The device parses the download path and file size of the configuration file from the configuration message; Based on the download path and file size of the configuration file, the device starts a timer and an independent download thread to download the configuration file and renames it to the preset terminal configuration file name.

[0053] It is understandable that the timer setting can constrain or control the request scale during the specific configuration file download process, avoiding excessive bandwidth consumption and network congestion, and also preventing high-frequency request interception, thus achieving a more stable configuration file download effect. Meanwhile, the independent download line helps to achieve concurrent downloads, resume interrupted downloads, and background operation, greatly improving the download speed of large files and the user experience.

[0054] To further standardize the process and ensure consistent device identification, the downloaded configuration files can be renamed uniformly, such as nms_template.conf.

[0055] As for the specific operations involved in loading the configuration file on the device side, as an exemplary embodiment, loading the configuration file on the device side may specifically include: On the device side, the configuration template is imported by executing a configuration template import command via command line. The device executes the core command to activate the configuration, thereby loading and activating the control policy that only allows terminals to access WIFI in the form of configuration restoration.

[0056] As an example, the device can import the configuration template by executing the command `-import nms-cfg-template NAME` via the command line. Then, execute the core command to activate the configuration: `- / usr / local / sbin / vtysh -F config_file`. This will restore the configuration and load the control policy that only allows specified devices to access the enterprise Wi-Fi. After the configuration is activated, the device will automatically verify the terminals connected to the enterprise Wi-Fi, allowing only the specified devices to access the enterprise Wi-Fi normally, while other devices will be blocked, thus achieving precise access control for the specified devices.

[0057] Furthermore, for the designated device terminals involved in the above-mentioned solutions, this application can also be divided by terminal type to achieve WIFI network control for designated terminal types.

[0058] Taking Windows terminals as an example, as an exemplary embodiment, The pre-registered device can be a Windows terminal. Correspondingly, the configuration file is used to restrict terminals other than Windows terminals from accessing the enterprise WIFI. The types other than Windows terminals can include IoT terminal types (such as network cameras, multimedia devices, game consoles, projectors, smart TVs, 3D printers, printers, surveillance cameras, etc.), mobile terminal types, network device types, and PC terminals other than Windows terminals, such as specific PC terminal types like Linux_PC, UOS_PC, kylin_PC, and mac_PC.

[0059] As yet another example, this can also be combined with Figure 2 The illustration shown is an example of configuring a specified device through the WEBUI visual interface, which is intended to provide a more intuitive understanding.

[0060] In addition, dynamic monitoring may be involved during the implementation of the solution or during the operation of the system.

[0061] Correspondingly, as an exemplary embodiment, the method of this application may further include: The network management system checks the distribution of configuration files to different devices and the configuration of configuration files on different devices.

[0062] As an example, after the device is configured, the configuration status can be viewed on the network management end. It can be clearly seen that the configuration file or control policy named "WIFI_Windows_Access" has been successfully configured on all devices.

[0063] In addition, the implementation of the solution may also involve corresponding verification operations. For example, Windows terminals, Linux terminals, and mobile terminals can be used to try to access the enterprise WIFI to verify whether only Windows terminals can access normally and other terminals fail to access, which meets the security management specifications. Operations such as restarting, interface up / down, and function deletion and creation can be performed on the device to further verify whether the configuration policy is still stable and effective, and whether the original configuration restoration logic on the device is running normally without any conflict issues.

[0064] Meanwhile, the method in this application can also involve a further result display stage regarding the implementation progress of the solution and the dynamic operation of the system. In this regard, the network management terminal can use its own configured display screen (including touch screen), external monitor, or other devices with display screens to display the specific results.

[0065] In conclusion, the above solutions can achieve the following beneficial effects: 1. Achieve precise access control based on terminal type: The addition of terminal type matching conditions to the network management configuration template fills the gap in existing technology that cannot perform WIFI access control based on terminal type. It can realize the requirement of only allowing specified terminal types (such as Windows terminals) to access enterprise WIFI, meet enterprise network security compliance verification standards, and improve the security of enterprise networks.

[0066] 2. Precise configuration file identification and efficient transmission: The configuration template is identified by the exclusive tag "nms-cfg-template", which enables precise filtering and export of configuration files and avoids confusion with other configuration files. Combined with Docker container volume mounting technology, configuration files are stored efficiently. The network management system sends a message with the download path and file size to the device, ensuring the accuracy and efficiency of configuration file transmission.

[0067] 3. Stable device-side configuration with strong compatibility: The device uses timers and threads to stably download configuration files, and executes commands to make the policy take effect in the form of configuration restoration. It is fully compatible with the device configuration restoration logic before modification, avoids conflicts between new configuration items and the original configuration, and ensures the stability of network management on the device.

[0068] 4. Easy to configure and operate, with good scalability: The network management side completes the terminal control policy configuration through the WEBUI visual interface, supports the selection of terminal category directories, and is simple and easy to understand to operate; the network management side is developed based on the R4.3 mainline, and the device side pulls the branch from R6.3 for processing, and the configuration policy is merged into the corresponding mainline and subsequent versions, supports customized testing, can adapt to the network management needs of different enterprises, and has good scalability.

[0069] 5. No additional dependencies and low deployment cost: The technical solution of this invention has no external dependencies, requires no additional hardware or third-party software, and only optimizes and adds functions to the existing network management terminal and device terminal at the software level. It has low deployment and implementation costs and is easy to promote and apply in the existing network architecture of enterprises.

[0070] The above is an introduction to the terminal control configuration method based on network management in this application. Correspondingly, this application also provides a terminal control configuration system based on network management from the perspective of hardware structure. It mainly includes a network management end and a device end. In addition, other types of devices can be included according to specific application requirements to form a more complex system cluster.

[0071] In this context, the equipment involved in the system may be collectively referred to as processing equipment, see reference. Figure 3 , Figure 3 This diagram illustrates a structural schematic of the processing device involved in the network management-based terminal control and configuration system of this application. Specifically, the processing device of this application may include a processor 301, a memory 302, and an input / output device 303. The processor 301 is used to execute the computer program stored in the memory 302 to implement, for example... Figure 1 The steps of the terminal control configuration method based on network management in the corresponding embodiment.

[0072] For example, a computer program may be divided into one or more modules / units, one or more of which are stored in memory 302 and executed by processor 301 to complete this application. One or more modules / units may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program in a computer device.

[0073] The processing device may include, but is not limited to, processor 301, memory 302, and input / output device 303. Those skilled in the art will understand that the illustrations are merely examples of the processing device and do not constitute a limitation on the processing device. It may include more or fewer components than illustrated, or combine certain components, or different components. For example, the processing device may also include network access devices, buses, etc., and processor 301, memory 302, input / output device 303, etc., are connected via a bus.

[0074] Processor 301 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor. The processor is the control center of the processing device, connecting various parts of the device through various interfaces and lines.

[0075] The memory 302 can be used to store computer programs and / or modules. The processor 301 implements various functions of the computer device by running or executing the computer programs and / or modules stored in the memory 302 and by calling data stored in the memory 302. The memory 302 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, application programs required for at least one function, etc.; the data storage area may store data created according to the use of the processing device, etc. In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, RAM, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device or other volatile solid-state storage device.

[0076] When processor 301 executes a computer program stored in memory 302, it can specifically perform the following functions: The network management terminal generates a configuration message, which carries the download path and file size of the configuration file; The network management terminal sends configuration messages to the pre-registered devices. The device downloads the configuration file based on the configuration message; The device loads a configuration file to verify access to the enterprise Wi-Fi when requesting access, and then connects to the enterprise Wi-Fi normally after passing the verification.

[0077] Furthermore, it may also include: After the network administrator logs in, the network management terminal identifies the devices that can access the enterprise WIFI, completes the configuration of the control policy that only allows terminals to access the WIFI, and generates a configuration file with a unique tag based on the configuration template.

[0078] Furthermore, it may also include: The network management system uses the Docker container volume mounting method to mount the configuration file and store it in the specified directory in the background to complete the storage of the configuration file.

[0079] Furthermore, it may also include: The network management terminal agrees on the message configuration for configuration messages with all devices in advance.

[0080] Furthermore, the device downloads the configuration file based on the configuration message, which may include: The device parses the download path and file size of the configuration file from the configuration message; Based on the download path and file size of the configuration file, the device starts a timer and an independent download thread to download the configuration file and renames it to the preset terminal configuration file name.

[0081] Furthermore, it may also include: On the device side, the configuration template is imported by executing a configuration template import command via command line. The device executes the core command to activate the configuration, thereby loading and activating the control policy that only allows terminals to access WIFI in the form of configuration restoration.

[0082] Furthermore, the pre-registered device is specifically a Windows terminal type. The configuration file is used to restrict terminals other than Windows terminal types from accessing the enterprise WIFI. Types other than Windows terminal types include IoT terminal types, mobile terminal types, network device types, and PC terminal types other than Windows terminals.

[0083] Furthermore, it may also include: The network management system checks the distribution of configuration files to different devices and the configuration of configuration files on different devices.

[0084] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the network management-based terminal control and configuration system described above can be found in, for example... Figure 1 The specific details of the terminal control configuration method based on network management in the corresponding embodiment will not be repeated here.

[0085] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be performed by instructions, or by instructions controlling related hardware. These instructions can be stored in a computer-readable storage medium and loaded and executed by a processor.

[0086] Therefore, this application provides a computer-readable storage medium storing a plurality of instructions that can be loaded by a processor to execute the present application. Figure 1 For details on the steps of the terminal control configuration method based on network management in the corresponding embodiment, please refer to the following: Figure 1 The description of the terminal control configuration method based on network management in the corresponding embodiment will not be repeated here.

[0087] The computer-readable storage medium may include: read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.

[0088] Because of the instructions stored in the computer-readable storage medium, the present application can be executed as described above. Figure 1 The steps of the terminal control configuration method based on network management in the corresponding embodiment can therefore achieve the purpose of this application. Figure 1 The beneficial effects that the network management-based terminal control configuration method can achieve in the corresponding embodiment are detailed in the preceding description and will not be repeated here.

[0089] The foregoing has provided a detailed description of the network management-based terminal control configuration method, system, and computer-readable storage medium provided in this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the embodiments above are merely for the purpose of helping to understand the core ideas of this application; furthermore, those skilled in the art will recognize that, based on the ideas of this application, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A terminal control configuration method based on network management, characterized in that, The method includes: The network management terminal generates a configuration message, wherein the configuration message carries the download path of the configuration file and the file size of the configuration file; The network management terminal sends the configuration message to the pre-registered device terminal; The device downloads the configuration file based on the configuration message; The device loads the configuration file to perform verification when requesting access to the enterprise WIFI, and to access the enterprise WIFI normally after passing the verification.

2. The method according to claim 1, characterized in that, The method further includes: After the network administrator logs in, the network management terminal identifies the devices that can access the enterprise WIFI, completes the configuration of the control policy that only allows terminals to access the WIFI, and generates the configuration file with a unique tag based on the configuration template.

3. The method according to claim 1, characterized in that, The method further includes: The network management terminal uses the Docker container volume mounting method to mount the configuration file and store it in a specified directory in the background to complete the storage of the configuration file.

4. The method according to claim 1, characterized in that, The method further includes: The network management terminal agrees on the message configuration for the configuration message with all the devices in advance.

5. The method according to claim 1, characterized in that, The device downloads the configuration file based on the configuration message, including: The device parses the download path and file size of the configuration file from the configuration message; Based on the download path and file size of the configuration file, the device starts a timer and an independent download thread to download the configuration file and renames it to a preset terminal configuration file name.

6. The method according to claim 1, characterized in that, The device loads the configuration file, including: The device executes a configuration template import command via command line to import the configuration template; The device executes the configuration activation core command to load and activate the control policy that only allows terminals to access WIFI in the form of configuration restoration.

7. The method according to claim 1, characterized in that, The pre-registered device is specifically a Windows terminal type. The configuration file is used to restrict terminals other than the Windows terminal type from accessing the enterprise WIFI. The types other than the Windows terminal type include IoT terminal types, mobile terminal types, network device types, and PC terminals other than the Windows terminal type.

8. The method according to claim 1, characterized in that, The method further includes: The network management terminal checks the distribution of the configuration file to different devices and the configuration of the configuration file on different devices.

9. A terminal control and configuration system based on network management, characterized in that, The system includes a network management terminal and a device terminal, used to execute the method as described in any one of claims 1 to 8.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a plurality of instructions adapted for loading by a processor to perform the method of any one of claims 1 to 8.