WO2023207202A1 - Method and apparatus for creating network configuration template, method and apparatus for network configuration, and device - Google Patents

Method and apparatus for creating network configuration template, method and apparatus for network configuration, and device Download PDF

Info

Publication number
WO2023207202A1
WO2023207202A1 PCT/CN2022/144058 CN2022144058W WO2023207202A1 WO 2023207202 A1 WO2023207202 A1 WO 2023207202A1 CN 2022144058 W CN2022144058 W CN 2022144058W WO 2023207202 A1 WO2023207202 A1 WO 2023207202A1
Authority
WO
WIPO (PCT)
Prior art keywords
configuration
template
address
network configuration
real
Prior art date
Application number
PCT/CN2022/144058
Other languages
French (fr)
Chinese (zh)
Inventor
钟志明
汪杰
鲁承波
陈杰生
Original Assignee
广东电网有限责任公司东莞供电局
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 广东电网有限责任公司东莞供电局 filed Critical 广东电网有限责任公司东莞供电局
Publication of WO2023207202A1 publication Critical patent/WO2023207202A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0803Configuration setting
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0803Configuration setting
    • H04L41/084Configuration by using pre-existing information, e.g. using templates or copying from other elements
    • H04L41/0843Configuration by using pre-existing information, e.g. using templates or copying from other elements based on generic templates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/22Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/12Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y04INFORMATION OR COMMUNICATION TECHNOLOGIES HAVING AN IMPACT ON OTHER TECHNOLOGY AREAS
    • Y04SSYSTEMS INTEGRATING TECHNOLOGIES RELATED TO POWER NETWORK OPERATION, COMMUNICATION OR INFORMATION TECHNOLOGIES FOR IMPROVING THE ELECTRICAL POWER GENERATION, TRANSMISSION, DISTRIBUTION, MANAGEMENT OR USAGE, i.e. SMART GRIDS
    • Y04S40/00Systems for electrical power generation, transmission, distribution or end-user application management characterised by the use of communication or information technologies, or communication or information technology specific aspects supporting them
    • Y04S40/20Information technology specific aspects, e.g. CAD, simulation, modelling, system security

Definitions

  • the present application relates to the technical field of data processing of power systems, and in particular to a method of creating a network configuration template, a method of network configuration, a device for creating a network configuration template, a device for network configuration, an electronic device and a device.
  • a computer-readable storage medium a computer-readable storage medium.
  • the power supply bureau In order to cope with the growing demand for electricity from residents, the power supply bureau needs to build new substations. During this process, on-site implementation personnel need to perform network configuration on the network equipment deployed in the newly built substation. Due to the special requirements of the power industry, network equipment is deployed in the intranet. In addition, the power supply bureau has high security requirements for the network environment, so the configuration content is extensive, including: network segment division of intranet equipment, IP allocation, switches, firewalls, encryption device routing tables, firewall NAT, firewalls, encryption machine policies, Encryptor tunnel configuration, device information connected to each network port of the switch, etc. Each site relies on manual configuration methods, which is time-consuming and labor-intensive. Moreover, due to the uneven levels of implementation personnel, configurations are often simple to save trouble, and there are problems with irregular and inaccurate information.
  • a method for creating a network configuration template is provided.
  • the method is applied in a network configuration system, and the method includes:
  • the template configuration information at least includes: business network segment information corresponding to the business configuration, and the IP address number of each business system corresponding to the IP address configuration;
  • a network configuration method is provided.
  • the method is applied in a network configuration system.
  • the method includes:
  • network configuration information is determined.
  • the network configuration information at least includes a starting IP address, and the starting IP address is used to determine the IP address when generating a network configuration plan. Address set, each IP address in the IP address set is used to replace the corresponding IP address number;
  • a device for creating a network configuration template is provided.
  • the device is used in a network configuration system.
  • the device includes:
  • the new template page display module is used to display the new template page in response to the new template operation initiated by the first user
  • a template basic information receiving module configured to receive template basic information associated with the network configuration template to be created input by the first user in the new template page;
  • a template frame display module is used to determine the template frame corresponding to the template basic information and display the template frame.
  • the template frame includes configuration items related to the template basic information, and the configuration items are used for power
  • the network equipment in the site must be configured as follows at least: business configuration and IP address configuration;
  • a template configuration information acquisition module is used to acquire the template configuration information input by the first user for each configuration item.
  • the template configuration information at least includes: business network segment information corresponding to the service configuration, and network segment information corresponding to the IP address configuration.
  • a network configuration template generating module is configured to generate a network configuration template according to the template configuration information and the template framework.
  • a network configuration page display module configured to generate a network configuration page based on the target network configuration template and display the network configuration page
  • a network configuration information determination module configured to determine network configuration information in response to the second user's operation on the network configuration page, where the network configuration information at least includes a starting IP address, and the starting IP address is used for Determine a set of IP addresses when generating a network configuration plan, and each IP address in the set of IP addresses is used to replace the corresponding IP address number;
  • a network configuration plan generation module is configured to generate a network configuration plan according to the target network configuration template and the network configuration information.
  • an electronic device includes:
  • the memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor, so that the at least one processor can execute the method described in any embodiment of the present application. Methods.
  • a computer-readable storage medium stores computer instructions, and the computer instructions are used to implement any of the embodiments of the present application when executed by a processor. Methods.
  • the first user when the first user needs to create a network configuration template, the first user can first enter basic template information in the displayed new template page, and then the system determines the corresponding template frame based on the basic template information and displays the template.
  • the template frame contains a variety of configuration items related to the basic information of the template.
  • the configuration items are used to configure at least the business configuration and IP address of the network equipment in the power site, so that the first user can enter the corresponding configuration items according to the configuration items.
  • Template configuration information includes business network segment information corresponding to the business configuration, IP address numbers of each business system corresponding to the IP address configuration, etc.
  • the system can generate network configuration based on the template configuration information filled in by the first user and the above template framework. template.
  • the entire process of generating network configuration templates is based on the specifications set by managers and combined with the logical relationship between the configuration information of each network device in the intranet environment to analyze the equipment configuration network configuration templates for substations with different voltage levels.
  • the logical relationship determines the accuracy of the configuration, and on the other hand, the compliance of the configuration is determined based on management specifications.
  • Figure 1 is a flow chart of a method for creating a template for network configuration provided in Embodiment 1 of the present application;
  • Figure 3 is a flow chart of a network configuration method provided in Embodiment 2 of the present application.
  • Figure 4 is a schematic diagram of a network configuration page provided in Embodiment 2 of the present application.
  • Figure 5 is a schematic structural diagram of a device for creating a network configuration template provided in Embodiment 3 of the present application;
  • FIG. 7 is a schematic structural diagram of an electronic device provided in Embodiment 5 of the present application.
  • Step 110 In response to the new template operation initiated by the first user, display the new template page.
  • the network configuration system (hereinafter referred to as "system") has the function of adding a template, and this function can be reflected through the "new template” entrance.
  • system has the function of adding a template, and this function can be reflected through the "new template” entrance.
  • the first user clicks on the "new template” entry it means that the first user initiates a new template operation.
  • the system detects the new template operation the new template page can be displayed to the first user.
  • the first user may be a user with template creation authority.
  • the system can first verify whether the user has the permission to create a new template. If the current user has the permission to create a new template, the "New Template" entry can be set to a clickable state. Otherwise, the "New Template” entry can be set to a non-clickable state, for example, the entry can be set to a grayscale state.
  • this embodiment does not limit the method for the system to verify whether the user has the permission to create a new template.
  • the matching verification can be performed through a whitelist mechanism, a conditional matching mechanism, etc.
  • Step 120 Receive basic template information associated with the network configuration template to be created input by the first user on the new template page.
  • switch A list of switch deployment methods can be provided in the field "Deployment Method" for the first user to choose.
  • the deployment methods in the switch deployment method list can be set by relevant personnel based on experience. For example, they can include Deployment methods such as "area I and area II share interconnection switches", “deploy real-time switches in area I and deploy non-real-time switches in area II".
  • the first user can choose the appropriate voltage level and switch deployment method according to the actual situation of the site.
  • Area I is also called the real-time area and is a controlled production area
  • Area II is called a non-real-time area and is a non-controlled production area.
  • Step 130 Determine the template frame corresponding to the template basic information, and display the template frame.
  • the template frame includes configuration items related to the template basic information.
  • the configuration items are used to configure the network in the power site.
  • the device must be configured with at least the following: service configuration and IP address configuration.
  • the template frames presented to the first user may be different according to different basic template information.
  • the system can present different template frames to the first user according to different voltage levels or switch deployment modes.
  • the system analyzes the basic template information input by the first user to generate a template frame that matches the voltage level and switch deployment mode selected by the first user, and displays the template frame to the first user.
  • basic template information such as the template name, voltage level, and switch deployment method filled in by the first user can be displayed.
  • the template framework can include a variety of configuration items.
  • the function of the configuration items is to configure at least the following for network equipment in the power site: business configuration, IP address configuration, interconnection interface planning, switch configuration, firewall configuration, encryption machine Configuration, etc., among which, IP address configuration can further include real-time IP address configuration and non-real-time IP address configuration.
  • Real-time IP address configuration is used to configure IP addresses for real-time business network segments
  • non-real-time IP address configuration is used for non-real-time services. Configure the IP address for the network segment.
  • each configuration item may further include multiple configuration fields, and each configuration field has a related configuration list to choose from. In this way, the first user only needs to make a selection or fill in a small amount of content to complete the template creation.
  • Step 140 Obtain the template configuration information input by the first user for each configuration item.
  • the template configuration information at least includes: business network segment information corresponding to the service configuration, and the IP of each business system corresponding to the IP address configuration. Address number.
  • the first user can select an appropriate field value from the configuration list in the drop-down list or fill in an appropriate field value.
  • step 140 may include the following steps:
  • the service network segment information of the service configuration page is determined, and the service network segment information includes the real-time service segment mask input by the first user and non- Real-time business segment mask.
  • step 140 may also include the following steps:
  • the configuration methods of the two configuration items are similar. The difference is that the former allocates addresses to the real-time business segment, while the latter allocates addresses to the non-real-time business segment.
  • the purpose IP address numbers are assigned to the business systems associated with each network device.
  • Both configuration methods include VLAN division and IP allocation.
  • the first user can add VLAN information or IP information by clicking the "Add" button on the project page.
  • the configuration fields included may include, for example, VLAN ID (VLAN identification), starting address, mask, ending address, gateway, remarks, etc.
  • the VLAN ID is determined according to the substation specifications, such as 199, 100, etc.
  • the mask entered in the mask field is the real-time service segment mask or non-real-time service segment mask configured in the service segment address configuration (that is, service configuration).
  • the system can calculate the IP address number set, that is, which IP address numbers are in the IP address number set. For example, if the mask is "255.255.255.240/28", it can be calculated that there are 32 IP address numbers.
  • the IP address in the template is replaced by an IP address number instead of a specific IP address. Assume that the 32 IP address numbers calculated above are divided into two VLANs, and each VLAN has 16 IP address numbers.
  • IP is allocated to the business system based on the set of IP address numbers contained in each VLAN ID in the above VLAN division.
  • the configuration fields included in this function can include, for example, VLAN ID, business system/interconnection equipment, communication Host & port, device type, IP address, subnet mask, gateway, remarks, etc.
  • the options in the VLAN ID field are derived from the VLAN ID in the VLAN division; the options in the business system/interconnected device field are derived from the business list and the interconnected device list. The first user can select the business system from the business list, or select the interconnected device from the service list.
  • the options in the IP address field are derived from the IP address number corresponding to the current VLAN ID in the VLAN division; the options in the subnet mask field are derived from the mask value in the VLAN division; the options in the gateway field are also sourced The gateway value in VLAN division; the device type is determined according to the value of the business system/interconnected device field; the field value of communication host & port can be the value filled in by the first user.
  • the business list may include business system names commonly used in the power industry and business types corresponding to each business system name.
  • business system names may include fault oscilloscopes, communication power supply systems, traveling wave ranging systems, dispatching and command devices, power collection systems, online monitoring systems, remote operation and maintenance systems, substation IoT systems, sensing systems, alarm systems, etc.
  • Business system names commonly used in the industry; business types can include real-time business types, non-real-time business types, etc.
  • the interconnected device list includes interconnected device information commonly used in the power industry.
  • the interconnected device information may include device names, device types, etc., for example.
  • Device types may be, for example, firewalls, routers, encryption machines, switches, etc.
  • step 140 may also include the following steps:
  • the first user can select from the options; the option of the interconnected VLAN It is also derived from the VLAN ID in real-time IP address configuration and non-real-time IP address configuration; the local interface and the peer interface can be filled in after the first user selects the local device or the peer device.
  • the first user can use the "New" button on the corresponding page to create a new interface for the interconnection switch that needs to be configured, which can include but is not limited to the following fields: interconnection VLAN, current switch interface, peer device name, Description etc.
  • interconnection VLAN is also derived from the VLAN ID in the real-time IP address configuration and non-real-time IP address configuration
  • the interface of the current switch can be the network port number of the current switch filled in by the user
  • the option of the peer device name is derived from the real-time Options for the business system/interconnected device fields in IP address configuration and non-real-time IP address configuration.
  • the corresponding device type for each real-time business system or non-real-time business system can also be determined from the preset device list.
  • the device type includes a switch, a firewall, and an encryption machine. Then determine the switch list, firewall list, and encryption machine list based on the device type. Then step 140 may further include the following steps:
  • the routing configuration includes a preset address list. , determine the routing address name and routing address network segment of the current switch, and determine the device name and IP address number of its next-hop device.
  • the switch configuration configuration item is used to configure static routing for interconnected switches.
  • the system will automatically identify the two configuration items, real-time IP address configuration and non-real-time IP address configuration, where the device type is a switch, and generate a corresponding switch configuration page for each switch.
  • the first user can click the "Add" button on the switch configuration page to add a new routing configuration.
  • the associated configuration fields can include but are not limited to: target address name, target address network segment, next hop device name, and next hop address. , remarks, etc.
  • the target address name also known as the routing address name
  • the destination address network segment can be obtained in the same way.
  • the address network segment corresponding to the address name can be obtained from the address list as the routing address network segment (ie, the destination address network segment).
  • the first user can set the target address as the business backhaul route.
  • the business backhaul route refers to the network segment range divided by the system based on the business segment address configuration item.
  • the next-hop device name refers to the device name of the next-hop device of the route. The first user can select from the devices allocated in the two items of real-time IP address configuration and non-real-time IP address configuration to determine the next-hop device. Afterwards, the system will automatically backfill the next hop address based on the IP address numbers assigned to each device in the two projects of real-time IP address configuration and non-real-time IP address configuration.
  • the address list may include IP address information commonly used in the power industry, and the IP address information may include IP address names and address network segments corresponding to each IP address name.
  • the IP address name can be the address name of the power equipment of the master station, such as the non-real-time encryption device of the xxx master station, the non-real-time traveling wave ranging master station, the online monitoring route of the xxx master station, the non-real-time situational awareness master station of the xxx master station, etc.
  • the address network segment may include the A-plane address network segment and the B-plane address network segment.
  • step 140 may further include the following steps:
  • a corresponding firewall configuration page is generated for each firewall in the firewall list, and in response to the first user's operation in the displayed firewall configuration page, routing configuration, network address translation NAT configuration and policy configuration are performed on the current firewall, so
  • the routing configuration includes determining the routing address name and routing address network segment of the current firewall according to the preset routing list, and determining the device name and IP address number of its next-hop device;
  • the NAT configuration includes determining the business system corresponding to the current firewall The real-time IP address number and the non-real-time IP address number;
  • the policy configuration includes determining the source IP address number, protocol, port alias and destination IP address number of the business system corresponding to the current firewall, where the port alias is derived from the preset port Select from the list.
  • the firewall configuration project is used to configure static routing, NAT (Network Address Translation, Network Address Translation) configuration and policy configuration for the interconnection firewall.
  • the system will automatically identify the two items, real-time IP address configuration and non-real-time IP address configuration, where the device type is firewall, and generate corresponding firewall configuration pages for each firewall.
  • the first user can perform static routing configuration, NAT configuration, and policy configuration on the firewall configuration page.
  • the configuration fields for static routing configuration of the firewall also include at least: target address name, target address network segment, next-hop device name, next-hop address, remarks, etc.
  • the configuration of each field For the method please refer to the configuration method of the switch.
  • the associated configuration fields of the NAT configuration may include but are not limited to: the real-time IP address number and non-real-time IP address, remarks, etc. of the business system to which the current firewall belongs. Since the IP address configuration item divides the business segment addresses, the first user needs to manually select the IP address number of the same service in different business segments (real-time business segment and non-real-time business segment).
  • the associated configuration fields of the policy configuration may include but are not limited to: system name, source address, protocol, port, destination address, etc. Since most of the services in the substation scenario are similar, a large number of common services have been predefined in the business list. The first user can manually select the business system name corresponding to each policy based on the business list. For the source IP address of the policy Number and destination IP address number. Since the source address and destination address of the firewall policy are often more commonly used addresses in the management master station, they have been defined in the address list. At this time, you can directly select them within the address list range.
  • the port list includes port information commonly used in the power industry.
  • the port information may include, for example, port aliases, port numbers, port protocols (such as tcp, udp, any, etc.), associated services, etc.
  • the associated service refers to the service system name associated with the current port alias.
  • step 140 may further include the following steps:
  • the routing configuration includes determining the routing address name and routing address network segment of the current encryption machine according to the preset routing list, and determining the device name and IP address number of its next-hop device;
  • the tunnel configuration includes determining the current encryption machine The tunnel local IP address number, tunnel peer IP address number, tunnel period and tunnel capacity of each tunnel;
  • the policy configuration includes determining the source IP address number, protocol, port alias and destination IP of the business system corresponding to the current encryption machine Address number, wherein the port alias is selected from a preset port list.
  • the encryption machine configuration project is used to perform static routing configuration, tunnel configuration, and policy configuration for the interconnection encryption machine configuration.
  • the system will automatically identify the two items, real-time IP address configuration and non-real-time IP address configuration, where the device type is an encryption machine, and generate the corresponding encryption machine configuration page for each encryption machine.
  • the first user can perform static routing configuration, tunnel configuration, and policy configuration on the encryption machine configuration page.
  • the configuration fields for static routing configuration of the encryption machine also include at least: target address name, target address network segment, next-hop device name, next-hop address, remarks, etc.
  • the fields of each field For the configuration method please refer to the switch configuration method.
  • the associated configuration fields of the tunnel configuration may include but are not limited to: tunnel number, tunnel mode, tunnel local address, tunnel peer address, tunnel period, tunnel capacity, etc.
  • the tunnel period and tunnel capacity are usually default and do not need to be filled in. They can be modified.
  • the tunnel number is filled in manually by the first user.
  • the local address and the opposite end address of the tunnel since in the actual scenario the local end address and the opposite end address of the tunnel may be the device IP address assigned by the business, or they may be some general master station addresses, the template is provided here.
  • IP address number of each device defined in the service allocation address configuration project There are two input sources, one is the IP address number of each device defined in the service allocation address configuration project, and the other is the fixed IP address or address network segment in the address list.
  • the user needs to manually select the local IP address corresponding to each tunnel. end address and peer address.
  • the associated configuration fields of the policy configuration may include but are not limited to: system name, source address, protocol, port, destination address, etc.
  • system name For how to configure the policy for the encryption machine, please refer to the above-mentioned policy configuration for the firewall, which will not be described again here.
  • the first user can manually select the business system name corresponding to each policy based on the business list.
  • the destination address because the source address and destination address of the encryption machine policy are often more commonly used addresses in the management master station, they have been defined in the address list. At this time, you can directly select it within the address list range.
  • Step 150 Generate a network configuration template according to the template configuration information and the template framework.
  • a preview function can also be set in the template frame page.
  • the system can centrally display the template configuration information filled in by the first user for each configuration item, so as to For the first user to check, the first user can modify the template configuration information during the checking process. After the check is correct, the first user clicks the "Save" button to save the template frame filled with template configuration information as a network configuration template.
  • the first user can also modify the template name of the network configuration template.
  • the first user when the first user needs to create a network configuration template, the first user can first enter basic template information in the displayed new template page, and then the system determines the corresponding template frame based on the basic template information and displays the template.
  • the template frame contains a variety of configuration items related to the basic information of the template.
  • the configuration items are used to configure at least the business configuration and IP address of the network equipment in the power site, so that the first user can enter the corresponding configuration items according to the configuration items.
  • Template configuration information includes business network segment information corresponding to the business configuration, IP address numbers of each business system corresponding to the IP address configuration, etc.
  • the system can generate network configuration based on the template configuration information filled in by the first user and the above template framework. template.
  • the entire process of generating network configuration templates is based on the specifications set by managers and combined with the logical relationship between the configuration information of each network device in the intranet environment to analyze the equipment configuration network configuration templates for substations with different voltage levels.
  • the logical relationship determines the accuracy of the configuration, and on the other hand, the compliance of the configuration is determined based on management specifications.
  • Step 210 In response to the second user's triggering behavior, obtain a previously configured template list of the site where the second user is located, and display the template list.
  • the second user in this embodiment and the first user in Embodiment 1 may be the same user, or they may be different users, which is not limited in this embodiment.
  • the second user can view a template list previously created by the site where the second user is located in the network configuration system (hereinafter referred to as the "system"), and the template list contains one or more network configuration templates.
  • the template list contains one or more network configuration templates.
  • the site where the second user is located can first be determined, and then the pre-configured site for the site can be obtained from the template library.
  • the key information of each network configuration template can be displayed.
  • the key information can include, for example, the template name, voltage level, switch deployment method, associated services (such as trust system, sensing system, telecontrol system, online monitoring system, etc.) etc.
  • this embodiment is not limited to the above-mentioned key information, and those skilled in the art can set other key information according to actual needs.
  • a search bar can also be set on the template list display page.
  • the second user can search for the template name, voltage level, switch deployment method, Related business and other keywords.
  • Step 220 Determine the target network configuration template selected by the second user from the template list.
  • the template list display page may also provide selection buttons for each network configuration template.
  • the selection button of a certain network configuration template it means that the second user selects the network configuration.
  • Template the selected network configuration template may be called a target network configuration template.
  • Step 230 Generate a network configuration page based on the target network configuration template, and display the network configuration page.
  • the system may generate a network configuration page based on the template name of the target network configuration template.
  • the network configuration page is then displayed to the second user.
  • Step 240 Determine network configuration information in response to the second user's operation on the network configuration page.
  • the network configuration information at least includes a starting IP address, the starting IP address is used to determine a set of IP addresses when generating a network configuration plan, and each IP address in the set of IP addresses is used to replace the corresponding IP address. serial number.
  • the starting IP address includes a real-time starting IP address and a non-real-time starting IP address.
  • Step 230 may further include the following steps:
  • the real-time starting IP address determine the real-time IP address set corresponding to the real-time IP address number set;
  • the non-real-time starting IP address determine the non-real-time IP address set corresponding to the non-real-time IP address number set; determine the business system involved in the target network configuration template, form a business list, and display the business list ; Detect the target business system selected by the second user from the business list; receive the compilation date input by the second user.
  • the network configuration page includes three configuration processes: "fill in the starting IP”, “confirm the business involved", and “confirm the compilation date”.
  • the second user can enter the starting IP address of the real-time service segment (i.e., the real-time starting IP address) and the starting IP address of the non-real-time service segment (i.e., the non-real-time starting IP address). Address), click "Next" to enter the "Confirm Business Involved” configuration process.
  • the starting IP address filled in on the "Fill in starting IP” configuration page is a specific IP address rather than an IP address number.
  • the second user can also fill in the template type in the "fill in the starting IP" configuration page.
  • the template type is the plane type corresponding to the template.
  • the plane type can include single plane and dual plane. The difference between the two is that a single plane will generate a set of IP allocation plans, while a dual plane will generate two sets of IP allocation plans.
  • the logical relationship of the new IP allocation plans in the dual plane is the same as that of the single plane IP allocation plan, but the starting IP The address is different.
  • the system will use the real-time starting IP address of the real-time service segment input by the second user as the first IP address of the real-time service segment, and the non-real-time starting IP address of the non-real-time service segment input by the second user as the first IP address of the real-time service segment.
  • the first IP address of the non-real-time business segment is used to calculate the real-time IP address set of the real-time business segment.
  • calculate the non-real-time IP address set of the non-real-time business segment based on the pattern of IP addresses and the number of IP addresses in the non-real-time IP address number set configured in the current target network configuration template.
  • Step 250 Generate a network configuration plan according to the target network configuration template and the network configuration information.
  • the system can generate a network configuration plan based on the network configuration information and the selected target network configuration template.
  • step 250 may further include the following steps:
  • Modify the target network configuration template as follows according to the network configuration information, and use the modified target network configuration template as the network configuration plan:
  • the system can assign the intranet IP addresses in the template according to the logical mapping relationship in the target network configuration template.
  • the numbers are replaced one by one with actual specific IP addresses.
  • the system can compare the existing business systems involved in the target network configuration template with the target business system, and then eliminate the configuration information corresponding to the unselected business systems.
  • the generated network configuration plan can be displayed to the second user, and the second user can export the network configuration plan through the export function on the page.
  • This network configuration solution can be provided to relevant personnel for network configuration reference, and can also be provided to auditors for auditing. This embodiment does not limit this.
  • the user can select the required target network configuration template, and then determine the basic network configuration information through the network configuration page. Then the system will compare the network configuration information with the target network configuration template.
  • the network configuration information of multiple intranet devices can be configured in a unified manner, which improves the efficiency of batch configuration of network devices.
  • the network configuration template already integrates data in advance based on the logical relationship between fields, it is equivalent to completing 60 to 70% of the work in advance to reduce manpower consumption and information deviation caused by manual intervention.
  • supporting restrictive deletions and modifications based on the compliance plan in order to cope with actual situations requirements.
  • the new template page display module 310 is configured to display the new template page in response to the new template operation initiated by the first user;
  • the template basic information receiving module 320 is configured to receive the basic template information entered by the first user in the new template page and associated with the network configuration template to be created;
  • the template frame display module 330 is used to determine the template frame corresponding to the basic template information and display the template frame.
  • the template frame includes configuration items related to the basic template information.
  • the configuration items are used to The network equipment in the power site must be configured as follows at least: business configuration and IP address configuration;
  • the template configuration information obtaining module 340 is used to obtain the template configuration information input by the first user for each configuration item.
  • the template configuration information at least includes: business network segment information corresponding to the service configuration, and corresponding IP address configuration. The IP address number of each business system;
  • the template configuration information acquisition module 340 is also used to::
  • the corresponding device type is determined from the preset device list for each real-time business system or non-real-time business system.
  • the device types include switches, firewalls and encryption machines;
  • a device for creating a network configuration template provided by an embodiment of the present application can execute a method of creating a network configuration template provided by any embodiment of the present application, and has functional modules and beneficial effects corresponding to the execution method.
  • FIG. 6 is a schematic structural diagram of a network configuration device provided in Embodiment 4 of the present application.
  • the device can be applied in a network configuration system and can include the following modules:
  • the target network configuration template determination module 420 is used to determine the target network configuration template selected by the second user from the template list;
  • the network configuration page display module 430 is used to generate a network configuration page based on the target network configuration template and display the network configuration page;
  • the network configuration information determining module 440 is configured to determine network configuration information in response to the second user's operation on the network configuration page.
  • the network configuration information at least includes a starting IP address, and the starting IP address is Determining a set of IP addresses when generating a network configuration plan, and each IP address in the set of IP addresses is used to replace the corresponding IP address number;
  • the network configuration plan generation module 450 is configured to generate a network configuration plan according to the target network configuration template and the network configuration information.
  • the starting IP address includes a real-time starting IP address and a non-real-time starting IP address
  • the target network configuration template includes a real-time IP address number set and a non-real-time IP address number set
  • the network configuration information determination module 440 is specifically used to:
  • the real-time starting IP address determine the real-time IP address set corresponding to the real-time IP address number set;
  • a compilation date input by the second user is received.
  • the network configuration scheme generation module 450 is specifically used to:
  • Modify the target network configuration template as follows according to the network configuration information, and use the modified target network configuration template as the network configuration plan:
  • the cover date in the target network configuration template is updated to be the compilation date.
  • a network configuration device provided by an embodiment of the present application can execute a network configuration method provided by any embodiment of the present application, and has functional modules and beneficial effects corresponding to the execution method.
  • FIG. 7 shows a schematic structural diagram of an electronic device 10 that can be used to implement method embodiments of the present application.
  • Electronic devices are intended to refer to various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers.
  • Electronic devices may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, wearable devices (eg, helmets, glasses, watches, etc.), and other similar computing devices.
  • the components shown herein, their connections and relationships, and their functions are examples only and are not intended to limit the implementation of the present application as described and/or claimed herein.
  • the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores There is a computer program that can be executed by at least one processor.
  • the processor 11 can perform the operation according to the computer program stored in the read-only memory (ROM) 12 or loaded from the storage unit 18 into the random access memory (RAM) 13. Perform various appropriate actions and processing.
  • RAM 13 various programs and data required for the operation of the electronic device 10 can also be stored.
  • the processor 11, the ROM 12 and the RAM 13 are connected to each other via the bus 14.
  • An input/output (I/O) interface 15 is also connected to bus 14 .
  • the I/O interface 15 Multiple components in the electronic device 10 are connected to the I/O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc. etc.; and communication unit 19, such as network card, modem, wireless communication transceiver, etc.
  • the communication unit 19 allows the electronic device 10 to exchange information/data with other devices through computer networks such as the Internet and/or various telecommunications networks.
  • Processor 11 may be a variety of general and/or special purpose processing components having processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processing processor (DSP), and any appropriate processor, controller, microcontroller, etc.
  • the processor 11 executes each method and process described above, such as the method described in Embodiment 1 or Embodiment 2.
  • Various implementations of the systems and techniques described above may be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip implemented in a system (SOC), load programmable logic device (CPLD), computer hardware, firmware, software, and/or a combination thereof.
  • FPGAs field programmable gate arrays
  • ASICs application specific integrated circuits
  • ASSPs application specific standard products
  • SOC system
  • CPLD load programmable logic device
  • computer hardware firmware, software, and/or a combination thereof.
  • These various embodiments may include implementation in one or more computer programs executable and/or interpreted on a programmable system including at least one programmable processor, the programmable processor
  • the processor which may be a special purpose or general purpose programmable processor, may receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
  • An output device may be a special purpose or general purpose programmable processor, may receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
  • An output device may be a special purpose or general purpose programmable processor, may receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
  • Computer programs for implementing the methods of the present application may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that the computer program, when executed by the processor, causes the functions/operations specified in the flowcharts and/or block diagrams to be implemented.
  • a computer program may execute entirely on the machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.
  • a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device.
  • Computer-readable storage media may include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or devices, or any suitable combination of the foregoing.
  • the computer-readable storage medium may be a machine-readable signal medium.
  • machine-readable storage media would include one or more wire-based electrical connections, laptop disks, hard drives, random access memory (RAM), read only memory (ROM), erasable programmable read only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination of the above.
  • RAM random access memory
  • ROM read only memory
  • EPROM or flash memory erasable programmable read only memory
  • CD-ROM portable compact disk read-only memory
  • magnetic storage device or any suitable combination of the above.
  • the systems and techniques described herein may be implemented on an electronic device having a display device (eg, a CRT (cathode ray tube) or LCD (liquid crystal display)) for displaying information to the user monitor); and a keyboard and pointing device (e.g., a mouse or a trackball) through which a user can provide input to the electronic device.
  • a display device eg, a CRT (cathode ray tube) or LCD (liquid crystal display)
  • a keyboard and pointing device e.g., a mouse or a trackball
  • Other kinds of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and may be provided in any form, including Acoustic input, voice input or tactile input) to receive input from the user.
  • the systems and techniques described herein may be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., A user's computer having a graphical user interface or web browser through which the user can interact with implementations of the systems and technologies described herein), or including such backend components, middleware components, or any combination of front-end components in a computing system.
  • the components of the system may be interconnected by any form or medium of digital data communication (eg, a communications network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Human Computer Interaction (AREA)
  • Health & Medical Sciences (AREA)
  • Computing Systems (AREA)
  • General Health & Medical Sciences (AREA)
  • Medical Informatics (AREA)
  • Small-Scale Networks (AREA)

Abstract

The present application discloses a method and apparatus for creating a network configuration template, a method and apparatus for network configuration, and a device, applied to a network configuration system. The method for network configuration comprises: in response to a trigger behavior of a second user, obtaining a previously configured template list of a station where the second user is located, and displaying the template list; determining a target network configuration template selected by the second user from the template list; generating a network configuration page on the basis of the target network configuration template, and displaying the network configuration page; in response to an operation of the second user in the network configuration page, determining network configuration information; and generating a network configuration scheme according to the target network configuration template and the network configuration information. Therefore, unified configuration of network configuration information of a plurality of intranet devices is achieved by using a template, manpower consumption is reduced, and the efficiency of batched network device configuration is improved.

Description

创建网络配置模板及网络配置的方法、装置和设备Methods, devices and equipment for creating network configuration templates and network configuration
本申请要求在2022年04月28日提交中国专利局、申请号为202210455222.7的中国专利申请的优先权,该申请的全部内容通过引用结合在本申请中。This application claims priority to the Chinese patent application with application number 202210455222.7, which was submitted to the China Patent Office on April 28, 2022. The entire content of this application is incorporated into this application by reference.
技术领域Technical field
本申请涉及电力系统的数据处理技术领域,尤其涉及一种创建网络配置模板方法、一种网络配置的方法、一种创建网络配置模板的装置、一种网络配置的装置、一种电子设备以及一种计算机可读存储介质。The present application relates to the technical field of data processing of power systems, and in particular to a method of creating a network configuration template, a method of network configuration, a device for creating a network configuration template, a device for network configuration, an electronic device and a device. A computer-readable storage medium.
背景技术Background technique
为应对居民日益增长的用电需求,供电局需新建变电站。在此过程中,现场实施人员需对新建的变电站中部署的网络设备进行网络配置。由于电力行业的特殊要求,网络设备都部署在内网中。另外供电局对网络环境的安全性要求较高,故配置内容繁多,其中包括:内网设备的网段划分、IP分配、交换机、防火墙、加密装置路由表、防火墙NAT、防火墙、加密机策略、加密机隧道配置、交换机各网口连接的设备信息等。每个站点都依赖手动配置的方法,费时费力。且由于实施人员水平层次不齐,为图省事往往简单配置,存在信息不规范、不准确的问题。In order to cope with the growing demand for electricity from residents, the power supply bureau needs to build new substations. During this process, on-site implementation personnel need to perform network configuration on the network equipment deployed in the newly built substation. Due to the special requirements of the power industry, network equipment is deployed in the intranet. In addition, the power supply bureau has high security requirements for the network environment, so the configuration content is extensive, including: network segment division of intranet equipment, IP allocation, switches, firewalls, encryption device routing tables, firewall NAT, firewalls, encryption machine policies, Encryptor tunnel configuration, device information connected to each network port of the switch, etc. Each site relies on manual configuration methods, which is time-consuming and labor-intensive. Moreover, due to the uneven levels of implementation personnel, configurations are often simple to save trouble, and there are problems with irregular and inaccurate information.
发明内容Contents of the invention
本申请提供了一种创建网络配置模板及网络配置的方法、装置和设备,以解决手动配置变电站的网络设备时导致的费时费力、信息不规范、不准确的问题。This application provides a method, device and equipment for creating a network configuration template and network configuration to solve the problems of time-consuming, labor-intensive, non-standard and inaccurate information caused by manually configuring network equipment in a substation.
根据本申请的第一方面,提供了一种创建网络配置模板的方法,所述方法应用于网络配置系统中,所述方法包括:According to a first aspect of the present application, a method for creating a network configuration template is provided. The method is applied in a network configuration system, and the method includes:
响应于第一用户发起的新建模板操作,展示新建模板页面;In response to the new template operation initiated by the first user, display the new template page;
接收第一用户在所述新建模板页面中输入的与待创建的网络配置模板相关联的模板基础信息;Receive basic template information associated with the network configuration template to be created input by the first user on the new template page;
确定与所述模板基础信息对应的模板框架,并展示所述模板框架,所述模板框架包括与所述模板基础信息相关的配置项目,所述配置项目用于对电力站点中的网络设备至少进行如下配置:业务配置及IP地址配置;Determine a template frame corresponding to the template basic information, and display the template frame. The template frame includes configuration items related to the template basic information, and the configuration items are used to perform at least on the network equipment in the power site. The following configurations: business configuration and IP address configuration;
获取第一用户针对各配置项目输入的模板配置信息,所述模板配置信息至 少包括:与所述业务配置对应的业务网段信息、与所述IP地址配置对应的各业务系统的IP地址编号;Obtain the template configuration information input by the first user for each configuration item, the template configuration information at least includes: business network segment information corresponding to the business configuration, and the IP address number of each business system corresponding to the IP address configuration;
根据所述模板配置信息以及所述模板框架生成网络配置模板。Generate a network configuration template according to the template configuration information and the template framework.
根据本申请的第二方面,提供了一种网络配置的方法,所述方法应用于网络配置系统中,所述方法包括:According to a second aspect of the present application, a network configuration method is provided. The method is applied in a network configuration system. The method includes:
响应于第二用户的触发行为,获取所述第二用户所在站点的、在先配置的模板列表,并展示所述模板列表;In response to the second user's triggering behavior, obtain a previously configured template list of the site where the second user is located, and display the template list;
确定所述第二用户从所述模板列表中选定的目标网络配置模板;Determine the target network configuration template selected by the second user from the template list;
基于所述目标网络配置模板生成网络配置页面,并展示所述网络配置页面;Generate a network configuration page based on the target network configuration template, and display the network configuration page;
响应于所述第二用户在所述网络配置页面中的操作,确定网络配置信息,所述网络配置信息至少包括起始IP地址,所述起始IP地址用于在生成网络配置方案时确定IP地址集合,所述IP地址集合中的各IP地址用于替换对应的IP地址编号;In response to the operation of the second user in the network configuration page, network configuration information is determined. The network configuration information at least includes a starting IP address, and the starting IP address is used to determine the IP address when generating a network configuration plan. Address set, each IP address in the IP address set is used to replace the corresponding IP address number;
根据所述目标网络配置模板以及所述网络配置信息生成网络配置方案。Generate a network configuration plan according to the target network configuration template and the network configuration information.
根据本申请的第三方面,提供了一种创建网络配置模板的装置,所述装置应用于网络配置系统中,所述装置包括:According to a third aspect of the present application, a device for creating a network configuration template is provided. The device is used in a network configuration system. The device includes:
新建模板页面展示模块,用于响应于第一用户发起的新建模板操作,展示新建模板页面;The new template page display module is used to display the new template page in response to the new template operation initiated by the first user;
模板基础信息接收模块,用于接收第一用户在所述新建模板页面中输入的与待创建的网络配置模板相关联的模板基础信息;A template basic information receiving module, configured to receive template basic information associated with the network configuration template to be created input by the first user in the new template page;
模板框架展示模块,用于确定与所述模板基础信息对应的模板框架,并展示所述模板框架,所述模板框架包括与所述模板基础信息相关的配置项目,所述配置项目用于对电力站点中的网络设备至少进行如下配置:业务配置及IP地址配置;A template frame display module is used to determine the template frame corresponding to the template basic information and display the template frame. The template frame includes configuration items related to the template basic information, and the configuration items are used for power The network equipment in the site must be configured as follows at least: business configuration and IP address configuration;
模板配置信息获取模块,用于获取第一用户针对各配置项目输入的模板配置信息,所述模板配置信息至少包括:与所述业务配置对应的业务网段信息、与所述IP地址配置对应的各业务系统的IP地址编号;A template configuration information acquisition module is used to acquire the template configuration information input by the first user for each configuration item. The template configuration information at least includes: business network segment information corresponding to the service configuration, and network segment information corresponding to the IP address configuration. The IP address number of each business system;
网络配置模板生成模块,用于根据所述模板配置信息以及所述模板框架生成网络配置模板。A network configuration template generating module is configured to generate a network configuration template according to the template configuration information and the template framework.
根据本申请的第四方面,提供了一种网络配置的装置,所述装置应用于网络配置系统中,所述装置包括:According to a fourth aspect of the present application, a network configuration device is provided. The device is used in a network configuration system. The device includes:
模板列表获取模块,用于响应于第二用户的触发行为,获取所述第二用户所在站点的、在先配置的模板列表,并展示所述模板列表;A template list acquisition module, configured to respond to the second user's triggering behavior, acquire a previously configured template list of the site where the second user is located, and display the template list;
目标网络配置模板确定模块,用于确定所述第二用户从所述模板列表中选定的目标网络配置模板;A target network configuration template determination module, configured to determine the target network configuration template selected by the second user from the template list;
网络配置页面展示模块,用于基于所述目标网络配置模板生成网络配置页面,并展示所述网络配置页面;A network configuration page display module, configured to generate a network configuration page based on the target network configuration template and display the network configuration page;
网络配置信息确定模块,用于响应于所述第二用户在所述网络配置页面中的操作,确定网络配置信息,所述网络配置信息至少包括起始IP地址,所述起始IP地址用于在生成网络配置方案时确定IP地址集合,所述IP地址集合中的各IP地址用于替换对应的IP地址编号;A network configuration information determination module, configured to determine network configuration information in response to the second user's operation on the network configuration page, where the network configuration information at least includes a starting IP address, and the starting IP address is used for Determine a set of IP addresses when generating a network configuration plan, and each IP address in the set of IP addresses is used to replace the corresponding IP address number;
网络配置方案生成模块,用于根据所述目标网络配置模板以及所述网络配置信息生成网络配置方案。A network configuration plan generation module is configured to generate a network configuration plan according to the target network configuration template and the network configuration information.
根据本申请的第五方面,提供了一种电子设备,所述电子设备包括:According to a fifth aspect of the present application, an electronic device is provided, and the electronic device includes:
至少一个处理器;以及at least one processor; and
与所述至少一个处理器通信连接的存储器;其中,a memory communicatively connected to the at least one processor; wherein,
所述存储器存储有可被所述至少一个处理器执行的计算机程序,所述计算机程序被所述至少一个处理器执行,以使所述至少一个处理器能够执行本申请任一实施例所述的的方法。The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor, so that the at least one processor can execute the method described in any embodiment of the present application. Methods.
根据本申请的第六方面,提供了一种计算机可读存储介质,所述计算机可读存储介质存储有计算机指令,所述计算机指令用于使处理器执行时实现本申请任一实施例所述的方法。According to a sixth aspect of the present application, a computer-readable storage medium is provided. The computer-readable storage medium stores computer instructions, and the computer instructions are used to implement any of the embodiments of the present application when executed by a processor. Methods.
在本实施例中,当第一用户需要创建网络配置模板时,第一用户首先可以在展示的新建模板页面中输入模板基础信息,然后系统根据该模板基础信息确定对应的模板框架并展示该模板框架,该模板框架中包含与模板基础信息相关的多种配置项目,配置项目用于对电力站点中的网络设备至少进行业务配置及IP地址配置,这样第一用户可以根据配置项目来输入对应的模板配置信息,包括与业务配置对应的业务网段信息、与IP地址配置对应的各业务系统的IP地址编号等,系统则可以根据第一用户填入的模板配置信息以及上述模板框架生成网络配置模板。整个生成网络配置模板的过程,根据管理人员制定的规范,并结合内网环境下各网络设备配置信息间的逻辑关系,分析出不同电压等级变电站的设备配置网络配置模板,一方面通过配置信息间的逻辑关系确定了配置的准确性,另一方面根据管理规范确定了配置的合规性。In this embodiment, when the first user needs to create a network configuration template, the first user can first enter basic template information in the displayed new template page, and then the system determines the corresponding template frame based on the basic template information and displays the template. The template frame contains a variety of configuration items related to the basic information of the template. The configuration items are used to configure at least the business configuration and IP address of the network equipment in the power site, so that the first user can enter the corresponding configuration items according to the configuration items. Template configuration information includes business network segment information corresponding to the business configuration, IP address numbers of each business system corresponding to the IP address configuration, etc. The system can generate network configuration based on the template configuration information filled in by the first user and the above template framework. template. The entire process of generating network configuration templates is based on the specifications set by managers and combined with the logical relationship between the configuration information of each network device in the intranet environment to analyze the equipment configuration network configuration templates for substations with different voltage levels. On the one hand, through the configuration information The logical relationship determines the accuracy of the configuration, and on the other hand, the compliance of the configuration is determined based on management specifications.
另外,通过预先配置好的模板列表,用户可以选择所需的目标网络配置模板,然后通过网络配置页面确定基础的网络配置信息,接着系统会将网络配置信息与目标网络配置模板进行结合生成一套符合规范的、针对多台内网设备的网络配置方案,以此实现对多台内网设备的网络配置信息进行统一配置,提高了批量配置网络设备的效率。同时,由于网络配置模板中已经是根据各字段间的逻辑关系,提前进行数据整合,相当于提前完成了六七成的工作,以减少人力消耗以及人工干预带来的信息偏差,同时为应对实际需求,支持在合规方案基础上的限制性删改。In addition, through the pre-configured template list, users can select the required target network configuration template, and then determine the basic network configuration information through the network configuration page. Then the system will combine the network configuration information with the target network configuration template to generate a set of A standard-compliant network configuration solution for multiple intranet devices, which enables unified configuration of network configuration information for multiple intranet devices and improves the efficiency of batch configuration of network devices. At the same time, since the network configuration template already integrates data in advance based on the logical relationship between fields, it is equivalent to completing 60 to 70% of the work in advance to reduce manpower consumption and information deviation caused by manual intervention. At the same time, in order to cope with actual situations requirements, supporting restrictive deletions and modifications based on the compliance plan.
附图说明Description of the drawings
图1是本申请实施例一提供的一种创建网络配置的模板方法的流程图;Figure 1 is a flow chart of a method for creating a template for network configuration provided in Embodiment 1 of the present application;
图2是本申请实施例一提供的一种新建模板页面示意图;Figure 2 is a schematic diagram of a new template page provided in Embodiment 1 of the present application;
图3是本申请实施例二提供了一种网络配置的方法的流程图;Figure 3 is a flow chart of a network configuration method provided in Embodiment 2 of the present application;
图4是本申请实施例二提供的一种网络配置页面示意图;Figure 4 is a schematic diagram of a network configuration page provided in Embodiment 2 of the present application;
图5是本申请实施例三提供的一种创建网络配置模板的装置的结构示意图;Figure 5 is a schematic structural diagram of a device for creating a network configuration template provided in Embodiment 3 of the present application;
图6是本申请实施例四提供的一种网络配置的装置的结构示意图;Figure 6 is a schematic structural diagram of a network configuration device provided in Embodiment 4 of the present application;
图7是本申请实施例五提供的一种电子设备的结构示意图。FIG. 7 is a schematic structural diagram of an electronic device provided in Embodiment 5 of the present application.
具体实施方式Detailed ways
为了使本技术领域的人员更好地理解本申请方案,下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,所描述的实施例仅仅是本申请一部分的实施例,而不是全部的实施例。In order to enable those in the technical field to better understand the solutions of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. The described embodiments are only for the purpose of this application. Apply for some of the embodiments, not all of them.
需要说明的是,本申请的说明书和权利要求书及上述附图中的术语“第一”、“第二”等是用于区别类似的对象,而不必用于描述特定的顺序或先后次序。应该理解这样使用的数据在适当情况下可以互换,以便这里描述的本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施。此外,术语“包括”和“具有”以及他们的任何变形,意图在于覆盖不排他的包含,例如,包含了一系列步骤或单元的过程、方法、系统、产品或设备不必限于清楚地列出的那些步骤或单元,而是可包括没有清楚地列出的或对于这些过程、方法、产品或设备固有的其它步骤或单元。It should be noted that the terms "first", "second", etc. in the description and claims of this application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It is to be understood that the data so used are interchangeable under appropriate circumstances so that the embodiments of the application described herein can be practiced in sequences other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, e.g., a process, method, system, product, or apparatus that encompasses a series of steps or units and need not be limited to those explicitly listed. Those steps or elements may instead include other steps or elements not expressly listed or inherent to the process, method, product or apparatus.
实施例一Embodiment 1
图1为本申请实施例一提供的一种创建网络配置的模板方法的流程图。可以应用于网络配置系统中,本实施例可以应用于自定义网络配置模板的场景中。如图1所示,该方法可以包括如下步骤:Figure 1 is a flow chart of a method for creating a network configuration template provided in Embodiment 1 of the present application. It can be applied to a network configuration system, and this embodiment can be applied to a scenario of customizing a network configuration template. As shown in Figure 1, the method may include the following steps:
步骤110,响应于第一用户发起的新建模板操作,展示新建模板页面。Step 110: In response to the new template operation initiated by the first user, display the new template page.
在一种实现中,在网络配置系统(后称为“系统”)中具有新增模板的功能,该功能可以通过“新增模板”入口体现。第一用户点击该“新增模板”入口则表示第一用户发起新建模板操作。当系统检测到该新建模板操作时,则可以向第一用户展示新建模板页面。In one implementation, the network configuration system (hereinafter referred to as "system") has the function of adding a template, and this function can be reflected through the "new template" entrance. When the first user clicks on the "new template" entry, it means that the first user initiates a new template operation. When the system detects the new template operation, the new template page can be displayed to the first user.
其中,该第一用户可以为具有模板创建权限的用户。在实现时,当用户登录系统以后,系统可以首先校验该用户是否具有新建模板的权限。如果当前用户具有新建模板的权限,则可以设置“新增模板”入口为可点击的状态,否则,设置“新增模板”入口为不可点击的状态,比如将该入口设置为灰度状态。The first user may be a user with template creation authority. During implementation, when a user logs in to the system, the system can first verify whether the user has the permission to create a new template. If the current user has the permission to create a new template, the "New Template" entry can be set to a clickable state. Otherwise, the "New Template" entry can be set to a non-clickable state, for example, the entry can be set to a grayscale state.
需要说明的是,关于系统对用户是否具有新建模板的权限的校验方式,本实施例不作限定,例如可以通过白名单机制、条件匹配机制等进行匹配校验。It should be noted that this embodiment does not limit the method for the system to verify whether the user has the permission to create a new template. For example, the matching verification can be performed through a whitelist mechanism, a conditional matching mechanism, etc.
步骤120,接收第一用户在所述新建模板页面中输入的与待创建的网络配置模板相关联的模板基础信息。Step 120: Receive basic template information associated with the network configuration template to be created input by the first user on the new template page.
具体的,新建模板页面中可以包括与模板配置相关联的、用于填写模板基础信息的基础信息填写项。例如,如图2所示,新建模板页面中包含的基础信息填写项可以包括但不限于:新增模板名称、电压等级以及交换机部署方式等。其中,“新增模板名称”填写项中,第一用户可以按照填写规范填写想要的模板名称,例如模板名称中可以包含供电站的站点名称、模板创建时间等信息;“电压等级”填写项中可以提供电压等级列表供第一用户选择,第一用户点击下拉按钮则弹出电压等级列表,电压等级列表中包含了供电站常用的电压等级例如可以包括35kV、110kV、220kV、500Kv等;“交换机部署方式”填写项中可以提供交换机部署方式列表供第一用户选择,第一用户点击下拉按钮则弹出交换机部署方式列表,交换机部署方式列表中的部署方式可以由相关人员根据经验设置,例如可以包括“Ⅰ区Ⅱ区共用互联交换机”、“Ⅰ区部署实时交换机,Ⅱ区部署非实时交换机”等部署方式。第一用户可以根据站点的实际情况选择合适的电压等级和交换机部署方式。其中,Ⅰ区又称为实时区、是控制生产区;Ⅱ区称为非实时区、是非控制生产区。Specifically, the new template page may include basic information filling items associated with the template configuration and used to fill in the basic information of the template. For example, as shown in Figure 2, the basic information items included in the new template page may include but are not limited to: new template name, voltage level, switch deployment method, etc. Among them, in the "New Template Name" filling item, the first user can fill in the desired template name according to the filling specifications. For example, the template name can include the site name of the power supply station, template creation time and other information; in the "Voltage Level" filling item A voltage level list can be provided for the first user to choose. When the first user clicks the drop-down button, a voltage level list will pop up. The voltage level list contains commonly used voltage levels in power supply stations. For example, it can include 35kV, 110kV, 220kV, 500Kv, etc.; "Switch A list of switch deployment methods can be provided in the field "Deployment Method" for the first user to choose. When the first user clicks the drop-down button, a list of switch deployment methods will pop up. The deployment methods in the switch deployment method list can be set by relevant personnel based on experience. For example, they can include Deployment methods such as "area I and area II share interconnection switches", "deploy real-time switches in area I and deploy non-real-time switches in area II". The first user can choose the appropriate voltage level and switch deployment method according to the actual situation of the site. Among them, Area I is also called the real-time area and is a controlled production area; Area II is called a non-real-time area and is a non-controlled production area.
当第一用户在新建模板页面中填写完新增模板名称、电压等级、交换机部署方式等模板基础信息以后,触发“创建模板”功能按键,则可以将模板基础信息提交到网络配置系统中。After the first user fills in the new template name, voltage level, switch deployment method and other basic template information on the new template page, and triggers the "Create Template" function button, the basic template information can be submitted to the network configuration system.
步骤130,确定与所述模板基础信息对应的模板框架,并展示所述模板框架,所述模板框架包括与所述模板基础信息相关的配置项目,所述配置项目用于对电力站点中的网络设备至少进行如下配置:业务配置及IP地址配置。Step 130: Determine the template frame corresponding to the template basic information, and display the template frame. The template frame includes configuration items related to the template basic information. The configuration items are used to configure the network in the power site. The device must be configured with at least the following: service configuration and IP address configuration.
在实际中,根据模板基础信息的不同,呈现给第一用户的模板框架可以是不相同的。例如系统可以根据不同的电压等级或交换机部署方式可以呈现不同的模板框架给第一用户。系统通过对第一用户输入的模板基础信息进行分析,从而生成与第一用户选择的电压等级以及交换机部署方式匹配的模板框架,并将模板框架展示给第一用户。其中,在展示的模板框架页面中,可以显示上述第一用户填写的模板名称、电压等级、交换机部署方式等模板基础信息。In practice, the template frames presented to the first user may be different according to different basic template information. For example, the system can present different template frames to the first user according to different voltage levels or switch deployment modes. The system analyzes the basic template information input by the first user to generate a template frame that matches the voltage level and switch deployment mode selected by the first user, and displays the template frame to the first user. Among them, in the displayed template frame page, basic template information such as the template name, voltage level, and switch deployment method filled in by the first user can be displayed.
其中,模板框架中可以包括多种配置项目,配置项目的作用是用于对电力站点中的网络设备至少进行如下配置:业务配置、IP地址配置、互联接口规划、交换机配置、防火墙配置、加密机配置等,其中,IP地址配置进一步又可以包括实时IP地址配置以及非实时IP地址配置,实时IP地址配置用于对实时业务网段进行IP地址配置,非实时IP地址配置用于对非实时业务网段进行IP地址配置。Among them, the template framework can include a variety of configuration items. The function of the configuration items is to configure at least the following for network equipment in the power site: business configuration, IP address configuration, interconnection interface planning, switch configuration, firewall configuration, encryption machine Configuration, etc., among which, IP address configuration can further include real-time IP address configuration and non-real-time IP address configuration. Real-time IP address configuration is used to configure IP addresses for real-time business network segments, and non-real-time IP address configuration is used for non-real-time services. Configure the IP address for the network segment.
在进一步的示例中,每种配置项目进一步可以包括多个配置字段,各配置字段具有相关的配置清单可供选择,这样,第一用户只需要进行选择或者少量的填写内容即可完成模板创建。In a further example, each configuration item may further include multiple configuration fields, and each configuration field has a related configuration list to choose from. In this way, the first user only needs to make a selection or fill in a small amount of content to complete the template creation.
步骤140,获取第一用户针对各配置项目输入的模板配置信息,所述模板配置信息至少包括:与所述业务配置对应的业务网段信息、与所述IP地址配置对应的各业务系统的IP地址编号。Step 140: Obtain the template configuration information input by the first user for each configuration item. The template configuration information at least includes: business network segment information corresponding to the service configuration, and the IP of each business system corresponding to the IP address configuration. Address number.
在创建网络配置模板时,针对各配置项目中的各配置字段,第一用户可以从下拉列表的配置清单中选择合适的字段值或者填写合适的字段值。When creating a network configuration template, for each configuration field in each configuration item, the first user can select an appropriate field value from the configuration list in the drop-down list or fill in an appropriate field value.
在一种实施例中,步骤140可以包括如下步骤:In one embodiment, step 140 may include the following steps:
响应于所述第一用户在展示的业务配置页面中的操作,确定所述业务配置页面的业务网段信息,所述业务网段信息包括所述第一用户输入的实时业务段掩码以及非实时业务段掩码。In response to the first user's operation in the displayed service configuration page, the service network segment information of the service configuration page is determined, and the service network segment information includes the real-time service segment mask input by the first user and non- Real-time business segment mask.
其中,业务配置这个配置项目用于确定内网IP地址集合,其包含的配置字段有实时业务段配置以及非实时业务段配置,在配置时第一用户可从字段下拉列表给出的多个掩码地址中、选择实时业务段对应的实时业务段掩码,以及非实时业务段对应的非实时业务段掩码。Among them, the configuration item of business configuration is used to determine the set of intranet IP addresses. The configuration fields it contains include real-time business segment configuration and non-real-time business segment configuration. During configuration, the first user can select multiple masks given by the field drop-down list. In the code address, select the real-time business segment mask corresponding to the real-time business segment, and the non-real-time business segment mask corresponding to the non-real-time business segment.
在一种实施例中,步骤140还可以包括如下步骤:In an embodiment, step 140 may also include the following steps:
响应于所述第一用户在展示的实时IP地址配置页面中的操作,确定所述实时业务段掩码对应的实时IP地址编号集合,以及确定所述第一用户从预设业务清单 中选择的实时业务系统,并根据所述实时IP地址编号集合为各实时业务系统分配实时IP地址编号。In response to the first user's operation on the displayed real-time IP address configuration page, determine the real-time IP address number set corresponding to the real-time service segment mask, and determine the first user's selected from the preset service list. A real-time business system, and allocates real-time IP address numbers to each real-time business system according to the real-time IP address number set.
响应于所述第一用户在展示的非实时IP地址配置页面中的操作,确定所述非实时业务段掩码对应的非实时IP地址编号集合,以及确定所述第一用户从预设业务清单中选择的非实时业务系统,并根据所述非实时IP地址编号集合为各非实时业务系统分配非实时IP地址编号。In response to the first user's operation on the displayed non-real-time IP address configuration page, determine the non-real-time IP address number set corresponding to the non-real-time service segment mask, and determine that the first user selects the non-real-time IP address from the default service list non-real-time business systems selected from among the non-real-time business systems, and allocate non-real-time IP address numbers to each non-real-time business system according to the non-real-time IP address number set.
具体的,实时IP地址配置以及非实时IP地址配置这两个配置项目的配置方式是类似的,区别在于前者是对实时业务段进行地址分配,后者是对非实时业务段进行地址分配,目的都是为各个网络设备关联的业务系统分配IP地址编号。这两种配置方式都包含VLAN划分以及IP分配两个部分。在实时业务分配地址配置或者非实时业务分配地址配置的项目中,第一用户可以通过点击该项目页面中的“新增”按钮来新增VLAN信息或IP信息。在VLAN划分功能中,包含的配置字段例如可以包括VLAN ID(VLAN标识)、起始地址、掩码、结束地址、网关、备注等。其中,VLAN ID根据变电站规范确定,比如为199、100等。掩码字段输入的掩码为业务段地址配置(即业务配置)中配置的实时业务段掩码或非实时业务段掩码。根据掩码字段中的掩码,系统可计算出IP地址编号集合,即IP地址编号集合中有哪些IP地址编号。例如,若掩码为“255.255.255.240/28”则可计算出有32个IP地址编号。在本实施例中,模板中的IP地址采用IP地址编号来代替,而不是具体的IP地址。假设将上面计算出的32个IP地址编号划分出两个VLAN,则每个VLAN有16个IP地址编号,这样第一个VLAN的起止地址编号可以表示为IP-1且结束地址编号表示为IP-16,第二个VLAN的起止地址编号可以表示为IP-17且结束地址编号表示为IP-32。在其他实施例中,还可以根据当前掩码对应的业务段为实时业务段或者非实时业务段,在起始地址编号和结束地址编号中标明业务段信息,例如,实时业务段IP-1,实时业务段IP-16等。网关可以是第一用户从当前VLAN ID对应的IP地址编号中选择的其中一个IP地址编号。Specifically, the configuration methods of the two configuration items, real-time IP address configuration and non-real-time IP address configuration, are similar. The difference is that the former allocates addresses to the real-time business segment, while the latter allocates addresses to the non-real-time business segment. The purpose IP address numbers are assigned to the business systems associated with each network device. Both configuration methods include VLAN division and IP allocation. In the project of real-time service distribution address configuration or non-real-time service distribution address configuration, the first user can add VLAN information or IP information by clicking the "Add" button on the project page. In the VLAN division function, the configuration fields included may include, for example, VLAN ID (VLAN identification), starting address, mask, ending address, gateway, remarks, etc. Among them, the VLAN ID is determined according to the substation specifications, such as 199, 100, etc. The mask entered in the mask field is the real-time service segment mask or non-real-time service segment mask configured in the service segment address configuration (that is, service configuration). According to the mask in the mask field, the system can calculate the IP address number set, that is, which IP address numbers are in the IP address number set. For example, if the mask is "255.255.255.240/28", it can be calculated that there are 32 IP address numbers. In this embodiment, the IP address in the template is replaced by an IP address number instead of a specific IP address. Assume that the 32 IP address numbers calculated above are divided into two VLANs, and each VLAN has 16 IP address numbers. In this way, the starting and ending address numbers of the first VLAN can be expressed as IP-1 and the ending address number is expressed as IP -16, the start and end address numbers of the second VLAN can be expressed as IP-17 and the end address number as IP-32. In other embodiments, according to whether the service segment corresponding to the current mask is a real-time service segment or a non-real-time service segment, the service segment information can be indicated in the start address number and the end address number, for example, the real-time service segment IP-1, Real-time business segment IP-16, etc. The gateway may be one of the IP address numbers selected by the first user from the IP address numbers corresponding to the current VLAN ID.
在IP分配功能中,是针对上述VLAN划分中的各VLAN ID所包含的IP地址编号集合,对业务系统进行IP分配,该功能包含的配置字段例如可以包括VLAN ID、业务系统/互联设备、通信主机&端口、设备类型、IP地址、子网掩码、网关、备注等。其中,VLAN ID字段中的选项来源于VLAN划分中的VLAN ID;业务系统/互联设备字段的选项来源于业务清单以及互联设备清单,第一用户可以从业务清单中选择业务系统,或者从互联设备清单中选择网络设备;IP地址字段的选项来源于VLAN划分中的当前VLAN ID对应的IP地址编号;子网掩码字段中的选项来源于VLAN划分中的掩码值;网关字段的选项也是来源于VLAN划分中的网关值;设备类型根据业务系统/互联设备字段的值确定;通信主机&端口的字段值可以是第一用户填写的值。In the IP allocation function, IP is allocated to the business system based on the set of IP address numbers contained in each VLAN ID in the above VLAN division. The configuration fields included in this function can include, for example, VLAN ID, business system/interconnection equipment, communication Host & port, device type, IP address, subnet mask, gateway, remarks, etc. Among them, the options in the VLAN ID field are derived from the VLAN ID in the VLAN division; the options in the business system/interconnected device field are derived from the business list and the interconnected device list. The first user can select the business system from the business list, or select the interconnected device from the service list. Select the network device from the list; the options in the IP address field are derived from the IP address number corresponding to the current VLAN ID in the VLAN division; the options in the subnet mask field are derived from the mask value in the VLAN division; the options in the gateway field are also sourced The gateway value in VLAN division; the device type is determined according to the value of the business system/interconnected device field; the field value of communication host & port can be the value filled in by the first user.
其中,业务清单可以包括电力行业中常用的业务系统名称以及各业务系统名称对应的业务类型。例如,业务系统名称可以包括故障示波器、通信电源系统、行波测距系统、调度发令装置、电量采集系统、在线监测系统、远程运维系统、变电物联系统、感知系统、告警系统等电力行业常用的业务系统名称;业务类型可以包括实时业务类型、非实时业务类型等。The business list may include business system names commonly used in the power industry and business types corresponding to each business system name. For example, business system names may include fault oscilloscopes, communication power supply systems, traveling wave ranging systems, dispatching and command devices, power collection systems, online monitoring systems, remote operation and maintenance systems, substation IoT systems, sensing systems, alarm systems, etc. Business system names commonly used in the industry; business types can include real-time business types, non-real-time business types, etc.
互联设备清单包括电力行业中常用的互联设备信息,该互联设备信息示例性地可以包括设备名称、设备类型等。设备类型例如可以是防火墙、路由器、加密机、交换机等。在一种实施例中,步骤140还可以包括如下步骤:The interconnected device list includes interconnected device information commonly used in the power industry. The interconnected device information may include device names, device types, etc., for example. Device types may be, for example, firewalls, routers, encryption machines, switches, etc. In an embodiment, step 140 may also include the following steps:
响应于所述第一用户在展示的互联接口规划页面中的操作,确定两个互联的网络设备分别连接的交换机网口编号。In response to the first user's operation on the displayed interconnection interface planning page, determine the switch network port numbers to which the two interconnected network devices are respectively connected.
具体的,本实施例用于互联接口规划配置,这个配置项目用于进行互联接口规划以及交换机接口规划。在互联接口规划中,第一用户可以通过对应页面中的“新增”按钮新建需要配置的两互联的网络设备所连接的交换机网口编号,可以包括但不限于如下字段:本端设备名称、本端接口(即本端网口编号)、对端设备名称、对端接口(即对端网口编号)、互联VLAN、备注等。其中,本端设备名称以及对端设备名称的选项来源于实时IP地址配置以及非实时IP地址配置中的业务系统/互联设备字段的选项,第一用户可从选项中进行选择;互联VLAN的选项也是来源于实时IP地址配置以及非实时IP地址配置中的VLAN ID;本端接口与对端接口可以是在第一用户选定本端设备或对端设备后再填入的该本端设备或对端设备所对应的交换机网口编号。Specifically, this embodiment is used for interconnection interface planning and configuration. This configuration item is used for interconnection interface planning and switch interface planning. In the interconnection interface planning, the first user can use the "Add" button on the corresponding page to create a new switch network port number connected to the two interconnected network devices that needs to be configured, which can include but is not limited to the following fields: local device name, Local interface (i.e. local network port number), peer device name, peer interface (i.e. peer network port number), interconnecting VLAN, remarks, etc. Among them, the options of the local device name and the peer device name are derived from the options of the business system/interconnected device field in the real-time IP address configuration and non-real-time IP address configuration. The first user can select from the options; the option of the interconnected VLAN It is also derived from the VLAN ID in real-time IP address configuration and non-real-time IP address configuration; the local interface and the peer interface can be filled in after the first user selects the local device or the peer device. The switch network port number corresponding to the peer device.
在交换机接口规划中,第一用户可以通过对应页面中的“新增”按钮新建需要配置的互联交换机的接口,可以包括但不限于如下字段:互联VLAN、当前交换机的接口、对端设备名称、说明等。其中,互联VLAN的选项也是来源于实时IP地址配置以及非实时IP地址配置中的VLAN ID;当前交换机的接口可以是用户填入的当前交换机的网口编号;对端设备名称的选项来源于实时IP地址配置以及非实时IP地址配置中的业务系统/互联设备字段的选项。In the switch interface planning, the first user can use the "New" button on the corresponding page to create a new interface for the interconnection switch that needs to be configured, which can include but is not limited to the following fields: interconnection VLAN, current switch interface, peer device name, Description etc. Among them, the option of interconnecting VLAN is also derived from the VLAN ID in the real-time IP address configuration and non-real-time IP address configuration; the interface of the current switch can be the network port number of the current switch filled in by the user; the option of the peer device name is derived from the real-time Options for the business system/interconnected device fields in IP address configuration and non-real-time IP address configuration.
在一种实施例中,在上述IP地址配置中,还可以针对各实时业务系统或非实时业务系统从预设设备清单中确定其对应的设备类型,该设备类型包括交换机、防火墙及加密机。然后根据设备类型确定交换机列表、防火墙列表以及加密机列表。则步骤140进一步还可以包括如下步骤:In one embodiment, in the above IP address configuration, the corresponding device type for each real-time business system or non-real-time business system can also be determined from the preset device list. The device type includes a switch, a firewall, and an encryption machine. Then determine the switch list, firewall list, and encryption machine list based on the device type. Then step 140 may further include the following steps:
针对所述交换机列表中的各交换机生成对应的交换机配置页面,响应于所述第一用户在展示的交换机配置页面中的操作,对当前交换机进行路由配置,所述路由配置包括根据预设地址清单,确定当前交换机的路由地址名称和路由地址网段,并确定其下一跳设备的设备名称及IP地址编号。Generate a corresponding switch configuration page for each switch in the switch list, and perform routing configuration on the current switch in response to the first user's operation on the displayed switch configuration page. The routing configuration includes a preset address list. , determine the routing address name and routing address network segment of the current switch, and determine the device name and IP address number of its next-hop device.
具体的,交换机配置这个配置项目用于对互联交换机进行静态路由配置。系统会自动识别实时IP地址配置以及非实时IP地址配置这两个配置项目中,设备类型为交换机的项,并针对各个交换机生成对应的交换机配置页面。第一用户可以点击交换机配置页面的“新增”按钮来新增路由配置,相关联的配置字段可以包括但不限于:目标地址名称、目标地址网段、下一跳设备名称、下一跳地址、备注等。具体的,目标地址名称(又称为路由地址名称)通常是在管理主站中较为常用的地址,故已在地址清单中定义好,则第一用户可以在地址清单范围内进行选择即可,目标地址网段同理可得,当确定了路由地址名称以后,则可以从地址清单中获得该地址名称对应的地址网段作为路由地址网段(即目标地址网段)。对于回程路由,第一用户可以将目标地址设置为业务回程路由,此时业务回程路由指的是系统根据业务段地址配置这个项目划分的网段范围。下一跳设备名称指的是路由的下一跳设备的设备名称,第一用户可以在实时IP地址配置以及非实时IP地址配置这两个项目中分配的设备中进行选择,确定下一跳设备后,系统将会自动根据实时IP地址配置以及非实时IP地址配置这两个项目中为各设备分配的IP地址编号,自动回填下一跳地址。Specifically, the switch configuration configuration item is used to configure static routing for interconnected switches. The system will automatically identify the two configuration items, real-time IP address configuration and non-real-time IP address configuration, where the device type is a switch, and generate a corresponding switch configuration page for each switch. The first user can click the "Add" button on the switch configuration page to add a new routing configuration. The associated configuration fields can include but are not limited to: target address name, target address network segment, next hop device name, and next hop address. , remarks, etc. Specifically, the target address name (also known as the routing address name) is usually a commonly used address in the management master station, so it has been defined in the address list. Then the first user can select within the address list range. The destination address network segment can be obtained in the same way. After the routing address name is determined, the address network segment corresponding to the address name can be obtained from the address list as the routing address network segment (ie, the destination address network segment). For the backhaul route, the first user can set the target address as the business backhaul route. At this time, the business backhaul route refers to the network segment range divided by the system based on the business segment address configuration item. The next-hop device name refers to the device name of the next-hop device of the route. The first user can select from the devices allocated in the two items of real-time IP address configuration and non-real-time IP address configuration to determine the next-hop device. Afterwards, the system will automatically backfill the next hop address based on the IP address numbers assigned to each device in the two projects of real-time IP address configuration and non-real-time IP address configuration.
其中,地址清单可以包括电力行业中常用的IP地址信息,该IP地址信息可以包括IP地址名称以及各IP地址名称对应的地址网段。其中,IP地址名称可以是主站的电力设备的地址名称,如xxx主站非实时加密装置、非实时行波测距主站、xxx主站在线监测路由、xxx非实时态势感知主站等;地址网段可以包括A平面地址网段以及B平面地址网段。The address list may include IP address information commonly used in the power industry, and the IP address information may include IP address names and address network segments corresponding to each IP address name. Among them, the IP address name can be the address name of the power equipment of the master station, such as the non-real-time encryption device of the xxx master station, the non-real-time traveling wave ranging master station, the online monitoring route of the xxx master station, the non-real-time situational awareness master station of the xxx master station, etc.; The address network segment may include the A-plane address network segment and the B-plane address network segment.
在一种实施例中,步骤140进一步还可以包括如下步骤:In one embodiment, step 140 may further include the following steps:
针对所述防火墙列表中的各防火墙生成对应的防火墙配置页面,响应于所述第一用户在展示的防火墙配置页面中的操作,对当前防火墙进行路由配置、网络地址转换NAT配置以及策略配置,所述路由配置包括根据预设路由清单,确定当前防火墙的路由地址名称和路由地址网段,并确定其下一跳设备的设备名称及IP地址编号;所述NAT配置包括确定当前防火墙对应的业务系统的实时IP地址编号以及非实时IP地址编号;所述策略配置包括确定当前防火墙对应的业务系统的源IP地址编号、协议、端口别名以及目的IP地址编号,其中,所述端口别名从预设端口清单中选取。A corresponding firewall configuration page is generated for each firewall in the firewall list, and in response to the first user's operation in the displayed firewall configuration page, routing configuration, network address translation NAT configuration and policy configuration are performed on the current firewall, so The routing configuration includes determining the routing address name and routing address network segment of the current firewall according to the preset routing list, and determining the device name and IP address number of its next-hop device; the NAT configuration includes determining the business system corresponding to the current firewall The real-time IP address number and the non-real-time IP address number; the policy configuration includes determining the source IP address number, protocol, port alias and destination IP address number of the business system corresponding to the current firewall, where the port alias is derived from the preset port Select from the list.
具体的,防火墙配置这个项目用于对互联防火墙进行静态路由配置、NAT(Network Address Translation,网络地址转换)配置以及策略配置。系统会自动识别实时IP地址配置以及非实时IP地址配置这两个项目中,设备类型为防火墙的项,并对各个防火墙生成对应的防火墙配置页面。第一用户可以在防火墙配置页面中进行静态路由配置、NAT配置以及策略配置。与上述对交换机进行静态 路由配置类似,对防火墙进行静态路由配置的配置字段至少也包括:目标地址名称、目标地址网段、下一跳设备名称、下一跳地址、备注等,各字段的配置方式可参考交换机的配置方式。Specifically, the firewall configuration project is used to configure static routing, NAT (Network Address Translation, Network Address Translation) configuration and policy configuration for the interconnection firewall. The system will automatically identify the two items, real-time IP address configuration and non-real-time IP address configuration, where the device type is firewall, and generate corresponding firewall configuration pages for each firewall. The first user can perform static routing configuration, NAT configuration, and policy configuration on the firewall configuration page. Similar to the static routing configuration of the switch mentioned above, the configuration fields for static routing configuration of the firewall also include at least: target address name, target address network segment, next-hop device name, next-hop address, remarks, etc. The configuration of each field For the method, please refer to the configuration method of the switch.
NAT配置的关联配置字段可以包括但不限于:当前防火墙所属的业务系统的实时IP地址编号以及非实时IP地址、备注等。由于在IP地址配置这个项目对业务段地址进行了划分,故此处需要第一用户手动选择同一业务在不同业务段(实时业务段和非实时业务段)的IP地址编号。The associated configuration fields of the NAT configuration may include but are not limited to: the real-time IP address number and non-real-time IP address, remarks, etc. of the business system to which the current firewall belongs. Since the IP address configuration item divides the business segment addresses, the first user needs to manually select the IP address number of the same service in different business segments (real-time business segment and non-real-time business segment).
策略配置的关联配置字段可以包括但不限于:系统名称、源地址、协议、端口、目的地址等。由于在变电站场景下的业务大多相似,故在业务清单中已预定义了大量通用的业务,第一用户在此可根据业务清单手动选择每条策略对应的业务系统名称,对于策略的源IP地址编号和目的IP地址编号,由于防火墙策略的源地址和目的地址,往往是在管理主站中较为常用的地址,故已在地址清单中定义好,此时直接在地址清单范围内选取即可。The associated configuration fields of the policy configuration may include but are not limited to: system name, source address, protocol, port, destination address, etc. Since most of the services in the substation scenario are similar, a large number of common services have been predefined in the business list. The first user can manually select the business system name corresponding to each policy based on the business list. For the source IP address of the policy Number and destination IP address number. Since the source address and destination address of the firewall policy are often more commonly used addresses in the management master station, they have been defined in the address list. At this time, you can directly select them within the address list range.
其中,端口清单包括电力行业中常用的端口信息,该端口信息示例性地可以包括端口别名、端口号、端口协议(如tcp、udp、any等)、关联业务等。其中,关联业务是指与当前端口别名相关联的业务系统名称。The port list includes port information commonly used in the power industry. The port information may include, for example, port aliases, port numbers, port protocols (such as tcp, udp, any, etc.), associated services, etc. Among them, the associated service refers to the service system name associated with the current port alias.
在一种实施例中,步骤140进一步还可以包括如下步骤:In one embodiment, step 140 may further include the following steps:
针对所述加密机列表中的各加密机生成对应的加密机配置页面,响应于所述第一用户在展示的加密机配置页面中的操作,对当前加密机进行路由配置、隧道配置以及策略配置,所述路由配置包括根据预设路由清单,确定当前加密机的路由地址名称和路由地址网段,并确定其下一跳设备的设备名称及IP地址编号;所述隧道配置包括确定当前加密机的各隧道的隧道本端IP地址编号、隧道对端IP地址编号、隧道周期及隧道容量;所述策略配置包括确定当前加密机对应的业务系统的源IP地址编号、协议、端口别名以及目的IP地址编号,其中,所述端口别名从预设端口清单中选取。Generate a corresponding encryption machine configuration page for each encryption machine in the encryption machine list, and perform routing configuration, tunnel configuration and policy configuration on the current encryption machine in response to the first user's operation on the displayed encryption machine configuration page. , the routing configuration includes determining the routing address name and routing address network segment of the current encryption machine according to the preset routing list, and determining the device name and IP address number of its next-hop device; the tunnel configuration includes determining the current encryption machine The tunnel local IP address number, tunnel peer IP address number, tunnel period and tunnel capacity of each tunnel; the policy configuration includes determining the source IP address number, protocol, port alias and destination IP of the business system corresponding to the current encryption machine Address number, wherein the port alias is selected from a preset port list.
具体的,加密机配置这个项目用于对互联加密机配置进行静态路由配置、隧道配置和策略配置。系统会自动识别实时IP地址配置以及非实时IP地址配置这两个项目中,设备类型为加密机的项,并针对各个加密机生成对应的加密机配置页面。第一用户可以在加密机配置页面中进行静态路由配置、隧道配置以及策略配置。与上述对交换机进行静态路由配置类似,对加密机进行静态路由配置的配置字段至少也包括:目标地址名称、目标地址网段、下一跳设备名称、下一跳地址、备注等,各字段的配置方式可参考交换机的配置方式。Specifically, the encryption machine configuration project is used to perform static routing configuration, tunnel configuration, and policy configuration for the interconnection encryption machine configuration. The system will automatically identify the two items, real-time IP address configuration and non-real-time IP address configuration, where the device type is an encryption machine, and generate the corresponding encryption machine configuration page for each encryption machine. The first user can perform static routing configuration, tunnel configuration, and policy configuration on the encryption machine configuration page. Similar to the static routing configuration of the switch mentioned above, the configuration fields for static routing configuration of the encryption machine also include at least: target address name, target address network segment, next-hop device name, next-hop address, remarks, etc. The fields of each field For the configuration method, please refer to the switch configuration method.
隧道配置的关联配置字段可以包括但不限于:隧道号、隧道模式、隧道本 端地址、隧道对端地址、隧道周期、隧道容量等。其中,隧道周期和隧道容量通常是默认的,无须填写,支持修改。而隧道号则由第一用户手动填写。根据实际场景需要,内置加密和明文两种隧道模式。在隧道的本端地址和对端地址方面,由于实际场景中隧道的本端地址和对端地址可能为业务分配的设备IP地址,也可能为某些通用的主站地址,故模板此处提供了两种输入源,一是在业务分配地址配置项目中定义的各设备的IP地址编号,二是地址清单中的固定IP地址或地址网段,第一用户需要手动选择每条隧道对应的本端地址和对端地址。The associated configuration fields of the tunnel configuration may include but are not limited to: tunnel number, tunnel mode, tunnel local address, tunnel peer address, tunnel period, tunnel capacity, etc. Among them, the tunnel period and tunnel capacity are usually default and do not need to be filled in. They can be modified. The tunnel number is filled in manually by the first user. According to the needs of actual scenarios, there are two built-in tunnel modes: encryption and plaintext. In terms of the local address and the opposite end address of the tunnel, since in the actual scenario the local end address and the opposite end address of the tunnel may be the device IP address assigned by the business, or they may be some general master station addresses, the template is provided here. There are two input sources, one is the IP address number of each device defined in the service allocation address configuration project, and the other is the fixed IP address or address network segment in the address list. First, the user needs to manually select the local IP address corresponding to each tunnel. end address and peer address.
策略配置的关联配置字段可以包括但不限于:系统名称、源地址、协议、端口、目的地址等。对加密机进行策略配置的方式可参考上述对防火墙的策略配置方式,此处不再赘述了。The associated configuration fields of the policy configuration may include but are not limited to: system name, source address, protocol, port, destination address, etc. For how to configure the policy for the encryption machine, please refer to the above-mentioned policy configuration for the firewall, which will not be described again here.
由于在变电站场景下的业务大多相似,故在业务清单中已预定义了大量通用的业务,第一用户在此可根据业务清单手动选择每条策略对应的业务系统名称,对于策略的源地址和目的地址,由于加密机策略的源地址和目的地址,往往是在管理主站中较为常用的地址,故已在地址清单中定义好,此时直接在地址清单范围内选取即可。Since most of the services in the substation scenario are similar, a large number of common services have been predefined in the business list. The first user can manually select the business system name corresponding to each policy based on the business list. For the source address and source address of the policy, The destination address, because the source address and destination address of the encryption machine policy are often more commonly used addresses in the management master station, they have been defined in the address list. At this time, you can directly select it within the address list range.
步骤150,根据所述模板配置信息以及所述模板框架生成网络配置模板。Step 150: Generate a network configuration template according to the template configuration information and the template framework.
在实现时,当第一用户对各配置项目都完成配置以后,则可以触发生成网络配置模板。具体的,在一种实施例中,在模板框架页面中还可以设置预览功能,当第一用户触发预览功能时,系统可以将第一用户对各配置项目填写的模板配置信息进行集中展示,以供第一用户检查,第一用户检查过程中可修改模板配置信息。检查无误后,第一用户点击“保存”按钮,则可以将该填写了模板配置信息的模板框架保存为网络配置模板。除此以外,第一用户还可以修改网络配置模板的模板名称。During implementation, when the first user completes configuration of each configuration item, the generation of the network configuration template may be triggered. Specifically, in one embodiment, a preview function can also be set in the template frame page. When the first user triggers the preview function, the system can centrally display the template configuration information filled in by the first user for each configuration item, so as to For the first user to check, the first user can modify the template configuration information during the checking process. After the check is correct, the first user clicks the "Save" button to save the template frame filled with template configuration information as a network configuration template. In addition, the first user can also modify the template name of the network configuration template.
通过上述方式生成网络配置模板以后,则可以知道一个网络配置模板里面有哪些主机IP、交换机中有哪些路由、防火墙和加密机中有哪些策略、NAT配置分别属于哪些业务,等等。这样,由于在模板中已经配置好大部分的数据,后续在利用模板生成方案时只需要进行少量的处理即可快速生成方案。After generating a network configuration template through the above method, you can know which host IPs are in a network configuration template, which routes are in the switch, which policies are in the firewall and encryption machine, which services the NAT configuration belongs to, etc. In this way, since most of the data has been configured in the template, only a small amount of processing is required when using the template to generate a plan to quickly generate the plan.
在本实施例中,当第一用户需要创建网络配置模板时,第一用户首先可以在展示的新建模板页面中输入模板基础信息,然后系统根据该模板基础信息确定对应的模板框架并展示该模板框架,该模板框架中包含与模板基础信息相关的多种配置项目,配置项目用于对电力站点中的网络设备至少进行业务配置及IP地址配置,这样第一用户可以根据配置项目来输入对应的模板配置信息,包括与业务配置对应的业务网段信息、与IP地址配置对应的各业务系统的IP地址编号等,系统则可以根据第一用户填入的模板配置信息以及上述模板框架生成网络 配置模板。整个生成网络配置模板的过程,根据管理人员制定的规范,并结合内网环境下各网络设备配置信息间的逻辑关系,分析出不同电压等级变电站的设备配置网络配置模板,一方面通过配置信息间的逻辑关系确定了配置的准确性,另一方面根据管理规范确定了配置的合规性。In this embodiment, when the first user needs to create a network configuration template, the first user can first enter basic template information in the displayed new template page, and then the system determines the corresponding template frame based on the basic template information and displays the template. The template frame contains a variety of configuration items related to the basic information of the template. The configuration items are used to configure at least the business configuration and IP address of the network equipment in the power site, so that the first user can enter the corresponding configuration items according to the configuration items. Template configuration information includes business network segment information corresponding to the business configuration, IP address numbers of each business system corresponding to the IP address configuration, etc. The system can generate network configuration based on the template configuration information filled in by the first user and the above template framework. template. The entire process of generating network configuration templates is based on the specifications set by managers and combined with the logical relationship between the configuration information of each network device in the intranet environment to analyze the equipment configuration network configuration templates for substations with different voltage levels. On the one hand, through the configuration information The logical relationship determines the accuracy of the configuration, and on the other hand, the compliance of the configuration is determined based on management specifications.
实施例二 Embodiment 2
图3为本申请实施例二提供了一种网络配置的方法的流程图。可以应用于网络配置系统中,应用于对站点的多个网络设备统一生成配置方案的场景中。如图3所示,该方法可以包括如下步骤:Figure 3 is a flow chart of a network configuration method provided in Embodiment 2 of the present application. It can be used in network configuration systems and in scenarios where configuration plans are uniformly generated for multiple network devices on a site. As shown in Figure 3, the method may include the following steps:
步骤210,响应于第二用户的触发行为,获取所述第二用户所在站点的、在先配置的模板列表,并展示所述模板列表。Step 210: In response to the second user's triggering behavior, obtain a previously configured template list of the site where the second user is located, and display the template list.
本实施例中的第二用户与实施例一中的第一用户可以为同一用户,或者为不同的用户,本实施例对此不作限定。The second user in this embodiment and the first user in Embodiment 1 may be the same user, or they may be different users, which is not limited in this embodiment.
在一种实现中,第二用户可在网络配置系统(后称为“系统”)中查看其所在站点在先创建的模板列表,该模板列表中包含一个或多个网络配置模板。例如,在网络配置系统中可以具有“模板列表”入口,当第二用户点击该“模板列表”入口时,首先可以确定该第二用户所在的站点,然后从模板库中获取该站点预先配置的模板列表,并向第二用户展示该模板列表。In one implementation, the second user can view a template list previously created by the site where the second user is located in the network configuration system (hereinafter referred to as the "system"), and the template list contains one or more network configuration templates. For example, there may be a "template list" entry in the network configuration system. When the second user clicks on the "template list" entry, the site where the second user is located can first be determined, and then the pre-configured site for the site can be obtained from the template library. A list of templates and displaying the list of templates to the second user.
在展示模板列表时,可以展示每个网络配置模板的关键信息,该关键信息示例性地可以包括模板名称、电压等级、交换机部署方式、关联业务(如保信系统、感知系统、远动系统、在线监测系统等)等。当然,本实施例并不限于上述的关键信息,本领域技术人员可以根据实际需求设定其他关键信息均是可行的。When displaying the template list, the key information of each network configuration template can be displayed. The key information can include, for example, the template name, voltage level, switch deployment method, associated services (such as trust system, sensing system, telecontrol system, online monitoring system, etc.) etc. Of course, this embodiment is not limited to the above-mentioned key information, and those skilled in the art can set other key information according to actual needs.
在实际中,为了便于第二用户快速查找到想要的网络配置模板,在模板列表展示页面中还可以设置搜索栏,第二用户可以在搜索栏中检索模板名称、电压等级、交换机部署方式、关联业务等关键词。In practice, in order to facilitate the second user to quickly find the desired network configuration template, a search bar can also be set on the template list display page. The second user can search for the template name, voltage level, switch deployment method, Related business and other keywords.
步骤220,确定所述第二用户从所述模板列表中选定的目标网络配置模板。Step 220: Determine the target network configuration template selected by the second user from the template list.
在实现时,模板列表展示页面中还可以提供对各网络配置模板的选择按钮,当检测到第二用户对某个网络配置模板的选择按钮的触发时,则表示第二用户选定该网络配置模板,该被选定的网络配置模板可以称为目标网络配置模板。During implementation, the template list display page may also provide selection buttons for each network configuration template. When it is detected that the second user triggers the selection button of a certain network configuration template, it means that the second user selects the network configuration. Template, the selected network configuration template may be called a target network configuration template.
步骤230,基于所述目标网络配置模板生成网络配置页面,并展示所述网络配置页面。Step 230: Generate a network configuration page based on the target network configuration template, and display the network configuration page.
在实现时,当第二用户选定目标网络配置模板以后,则系统可以基于目标网络配置模板的模板名称,生成网络配置页面。然后向第二用户展示该网络配置页面。During implementation, after the second user selects the target network configuration template, the system may generate a network configuration page based on the template name of the target network configuration template. The network configuration page is then displayed to the second user.
步骤240,响应于所述第二用户在所述网络配置页面中的操作,确定网络配置信息。Step 240: Determine network configuration information in response to the second user's operation on the network configuration page.
其中,所述网络配置信息至少包括起始IP地址,所述起始IP地址用于在生成网络配置方案时确定IP地址集合,所述IP地址集合中的各IP地址用于替换对应的IP地址编号。Wherein, the network configuration information at least includes a starting IP address, the starting IP address is used to determine a set of IP addresses when generating a network configuration plan, and each IP address in the set of IP addresses is used to replace the corresponding IP address. serial number.
在一种实施例中,起始IP地址包括实时起始IP地址以及非实时起始IP地址,步骤230进一步可以包括如下步骤:In one embodiment, the starting IP address includes a real-time starting IP address and a non-real-time starting IP address. Step 230 may further include the following steps:
根据所述实时起始IP地址,确定所述实时IP地址编号集合对应的实时IP地址集合;According to the real-time starting IP address, determine the real-time IP address set corresponding to the real-time IP address number set;
根据所述非实时起始IP地址,确定所述非实时IP地址编号集合对应的非实时IP地址集合;确定所述目标网络配置模板所涉及的业务系统,组成业务列表,并展示所述业务列表;检测所述第二用户从所述业务列表中选定的目标业务系统;接收所述第二用户输入的编撰日期。According to the non-real-time starting IP address, determine the non-real-time IP address set corresponding to the non-real-time IP address number set; determine the business system involved in the target network configuration template, form a business list, and display the business list ; Detect the target business system selected by the second user from the business list; receive the compilation date input by the second user.
例如,一种示例性的网络配置页面如图4所示,网络配置页面中包含“填写起始IP”、“确认涉及业务”、“确认编撰日期”三个配置过程。在“填写起始IP”的配置页面中,第二用户可以输入实时业务段的起始IP地址(即实时起始IP地址)以及非实时业务段的起始IP地址(即非实时起始IP地址),点击“下一步”则进入“确认涉及业务”配置过程。其中,在“填写起始IP”的配置页面中填入的起始IP地址为具体的IP地址而不是IP地址编号。For example, an exemplary network configuration page is shown in Figure 4. The network configuration page includes three configuration processes: "fill in the starting IP", "confirm the business involved", and "confirm the compilation date". In the configuration page of "Fill in the starting IP", the second user can enter the starting IP address of the real-time service segment (i.e., the real-time starting IP address) and the starting IP address of the non-real-time service segment (i.e., the non-real-time starting IP address). Address), click "Next" to enter the "Confirm Business Involved" configuration process. Among them, the starting IP address filled in on the "Fill in starting IP" configuration page is a specific IP address rather than an IP address number.
此外,在“填写起始IP”的配置页面中第二用户还可以填写模板类型,该模板类型为模板对应的平面类型,平面类型可以包括单平面和双平面。两者的区别在于单平面会生成一组IP分配方案,而双平面会生成两组IP分配方案,双平面新增的IP分配方案的逻辑关系与单平面IP分配方案的一致,但起始IP地址不同。In addition, the second user can also fill in the template type in the "fill in the starting IP" configuration page. The template type is the plane type corresponding to the template. The plane type can include single plane and dual plane. The difference between the two is that a single plane will generate a set of IP allocation plans, while a dual plane will generate two sets of IP allocation plans. The logical relationship of the new IP allocation plans in the dual plane is the same as that of the single plane IP allocation plan, but the starting IP The address is different.
在“确认涉及业务”配置页面中,向第二用户展示该模板目标网络配置模板所涉及的业务系统,第二用户可以从中选择具备网络接入条件的业务作为目标业务系统。点击“下一步”则进入“确认编撰日期”配置过程,第二用户在“确认编撰日期”配置页面中填入编撰日期并点击“确定”按钮,则完成网络配置信息的输入。On the "Confirm Business Involved" configuration page, the business systems involved in the target network configuration template of the template are displayed to the second user, from which the second user can select a business with network access conditions as the target business system. Click "Next" to enter the "Confirm compilation date" configuration process. The second user fills in the compilation date in the "Confirm compilation date" configuration page and clicks the "OK" button to complete the input of network configuration information.
在实现时,系统会将第二用户输入的实时业务段的实时起始IP地址作为实时业务段的第一个IP地址,将第二用户输入的非实时业务段的非实时起始IP地址作 为非实时业务段的第一个IP地址。然后根据IP地址的规律(根据对实际方案的观察可以得到,现场设备的IP地址往往都存在逻辑关系,比如在起始IP基础上往后延伸),以及当前目标网络配置模板中配置的实时IP地址编号集合的IP地址的数量,计算出实时业务段的实时IP地址集合。以及,根据IP地址的规律以及当前目标网络配置模板中配置的非实时IP地址编号集合的IP地址的数量,计算出非实时业务段的非实时IP地址集合。During implementation, the system will use the real-time starting IP address of the real-time service segment input by the second user as the first IP address of the real-time service segment, and the non-real-time starting IP address of the non-real-time service segment input by the second user as the first IP address of the real-time service segment. The first IP address of the non-real-time business segment. Then according to the rules of IP addresses (according to the observation of actual solutions, it can be obtained that the IP addresses of field devices often have logical relationships, such as extending backward based on the starting IP), and the real-time IP configured in the current target network configuration template The number of IP addresses in the address number set is used to calculate the real-time IP address set of the real-time business segment. And, calculate the non-real-time IP address set of the non-real-time business segment based on the pattern of IP addresses and the number of IP addresses in the non-real-time IP address number set configured in the current target network configuration template.
步骤250,根据所述目标网络配置模板以及所述网络配置信息生成网络配置方案。Step 250: Generate a network configuration plan according to the target network configuration template and the network configuration information.
当第二用户输入网络配置信息以后,系统可以根据该网络配置信息以及选定的目标网络配置模板结合,生成网络配置方案。After the second user inputs the network configuration information, the system can generate a network configuration plan based on the network configuration information and the selected target network configuration template.
在一种实施例中,步骤250进一步可以包括如下步骤:In one embodiment, step 250 may further include the following steps:
根据所述网络配置信息对所述目标网络配置模板进行如下修改,并将修改后的目标网络配置模板作为网络配置方案:Modify the target network configuration template as follows according to the network configuration information, and use the modified target network configuration template as the network configuration plan:
1)将所述目标网络配置模板中的各实时IP地址编号替换为对应的实时IP地址;将所述目标网络配置模板中的各非实时IP地址编号替换为对应的非实时IP地址。1) Replace each real-time IP address number in the target network configuration template with a corresponding real-time IP address; replace each non-real-time IP address number in the target network configuration template with a corresponding non-real-time IP address.
由于目标网络配置模板中的IP地址为IP地址编号,当确定内网IP集合中的所有具体的IP地址以后,系统可以根据目标网络配置模板中的逻辑映射关系,将模板中的内网IP地址编号逐个更换为实际的具体IP地址。Since the IP addresses in the target network configuration template are IP address numbers, after determining all the specific IP addresses in the intranet IP set, the system can assign the intranet IP addresses in the template according to the logical mapping relationship in the target network configuration template. The numbers are replaced one by one with actual specific IP addresses.
需要说明的是,如果目标网络配置模板中还包括端口别名,则还可以将端口别名替换为实际的端口号。如果目标网络配置模板中还包括IP地址别名,则还可以将IP地址别名替换为实际的IP地址。It should be noted that if the target network configuration template also includes a port alias, you can also replace the port alias with the actual port number. If the target network configuration template also includes an IP address alias, you can also replace the IP address alias with the actual IP address.
2)从所述目标网络配置模板中删除除所述目标业务系统以外的其它业务系统相关的配置信息。2) Delete configuration information related to other business systems other than the target business system from the target network configuration template.
在业务方面,当用户选定了目标业务系统以后,系统可以将目标网络配置模板中涉及的已有的业务系统与目标业务系统进行比较,然后剔除掉没有选中的业务系统对应的配置信息。In terms of business, when the user selects the target business system, the system can compare the existing business systems involved in the target network configuration template with the target business system, and then eliminate the configuration information corresponding to the unselected business systems.
3)更新所述目标网络配置模板中具有的封面日期为所述编撰日期。3) Update the cover date in the target network configuration template to the compilation date.
目标网络配置模板中还包括封面日期,当采用其生成网络配置方案时,则将该封面日期修改为第二用户输入的编撰日期。The target network configuration template also includes a cover date, and when it is used to generate the network configuration plan, the cover date is modified to the compilation date input by the second user.
生成的网络配置方案可以展示给第二用户,第二用户可以通过页面中的导出功能导出该网络配置方案。该网络配置方案可以提供给相关人员进行网络配 置参考,也可以提供给审计人员进行审计,本实施例对此不作限制。The generated network configuration plan can be displayed to the second user, and the second user can export the network configuration plan through the export function on the page. This network configuration solution can be provided to relevant personnel for network configuration reference, and can also be provided to auditors for auditing. This embodiment does not limit this.
在本实施例中,通过预先配置好的模板列表,用户可以选择所需的目标网络配置模板,然后通过网络配置页面确定基础的网络配置信息,接着系统会将网络配置信息与目标网络配置模板进行结合生成一套符合规范的、针对多台内网设备的网络配置方案,以此实现对多台内网设备的网络配置信息进行统一配置,提高了批量配置网络设备的效率。同时,由于网络配置模板中已经是根据各字段间的逻辑关系,提前进行数据整合,相当于提前完成了六七成的工作,以减少人力消耗以及人工干预带来的信息偏差,同时为应对实际需求,支持在合规方案基础上的限制性删改。In this embodiment, through the pre-configured template list, the user can select the required target network configuration template, and then determine the basic network configuration information through the network configuration page. Then the system will compare the network configuration information with the target network configuration template. Combined with the generation of a standard-compliant network configuration solution for multiple intranet devices, the network configuration information of multiple intranet devices can be configured in a unified manner, which improves the efficiency of batch configuration of network devices. At the same time, since the network configuration template already integrates data in advance based on the logical relationship between fields, it is equivalent to completing 60 to 70% of the work in advance to reduce manpower consumption and information deviation caused by manual intervention. At the same time, in order to cope with actual situations requirements, supporting restrictive deletions and modifications based on the compliance plan.
实施例三 Embodiment 3
图5为本申请实施例三提供的一种创建网络配置模板的装置的结构示意图,所述装置可以应用于网络配置系统中,可以包括如下模块:Figure 5 is a schematic structural diagram of a device for creating a network configuration template provided in Embodiment 3 of the present application. The device can be applied in a network configuration system and can include the following modules:
新建模板页面展示模块310,用于响应于第一用户发起的新建模板操作,展示新建模板页面;The new template page display module 310 is configured to display the new template page in response to the new template operation initiated by the first user;
模板基础信息接收模块320,用于接收第一用户在所述新建模板页面中输入的与待创建的网络配置模板相关联的模板基础信息;The template basic information receiving module 320 is configured to receive the basic template information entered by the first user in the new template page and associated with the network configuration template to be created;
模板框架展示模块330,用于确定与所述模板基础信息对应的模板框架,并展示所述模板框架,所述模板框架包括与所述模板基础信息相关的配置项目,所述配置项目用于对电力站点中的网络设备至少进行如下配置:业务配置及IP地址配置;The template frame display module 330 is used to determine the template frame corresponding to the basic template information and display the template frame. The template frame includes configuration items related to the basic template information. The configuration items are used to The network equipment in the power site must be configured as follows at least: business configuration and IP address configuration;
模板配置信息获取模块340,用于获取第一用户针对各配置项目输入的模板配置信息,所述模板配置信息至少包括:与所述业务配置对应的业务网段信息、与所述IP地址配置对应的各业务系统的IP地址编号;The template configuration information obtaining module 340 is used to obtain the template configuration information input by the first user for each configuration item. The template configuration information at least includes: business network segment information corresponding to the service configuration, and corresponding IP address configuration. The IP address number of each business system;
网络配置模板生成模块350,用于根据所述模板配置信息以及所述模板框架生成网络配置模板。The network configuration template generating module 350 is configured to generate a network configuration template according to the template configuration information and the template framework.
在一种实施例中,所述IP地址配置包括实时IP地址配置以及非实时IP地址配置;所述模板配置信息获取模块340具体用于:In one embodiment, the IP address configuration includes real-time IP address configuration and non-real-time IP address configuration; the template configuration information acquisition module 340 is specifically used to:
响应于所述第一用户在展示的业务配置页面中的操作,确定所述业务配置页面的业务网段信息,所述业务网段信息包括所述第一用户输入的实时业务段掩码以及非实时业务段掩码;In response to the first user's operation in the displayed service configuration page, the service network segment information of the service configuration page is determined, and the service network segment information includes the real-time service segment mask input by the first user and non- Real-time business segment mask;
响应于所述第一用户在展示的实时IP地址配置页面中的操作,确定所述实时 业务段掩码对应的实时IP地址编号集合,以及确定所述第一用户从预设业务清单中选择的实时业务系统,并根据所述实时IP地址编号集合为各实时业务系统分配实时IP地址编号;In response to the first user's operation on the displayed real-time IP address configuration page, determine the real-time IP address number set corresponding to the real-time service segment mask, and determine the first user's selected from the preset service list. A real-time business system, and allocates real-time IP address numbers to each real-time business system according to the real-time IP address number set;
响应于所述第一用户在展示的非实时IP地址配置页面中的操作,确定所述非实时业务段掩码对应的非实时IP地址编号集合,以及确定所述第一用户从预设业务清单中选择的非实时业务系统,并根据所述非实时IP地址编号集合为各非实时业务系统分配非实时IP地址编号。In response to the first user's operation on the displayed non-real-time IP address configuration page, determine the non-real-time IP address number set corresponding to the non-real-time service segment mask, and determine that the first user selects the non-real-time IP address from the default service list non-real-time business systems selected from among the non-real-time business systems, and allocate non-real-time IP address numbers to each non-real-time business system according to the non-real-time IP address number set.
在一种实施例中,所述配置项目还用于对所述网络设备进行如下配置:交换机配置、防火墙配置、加密机配置;In one embodiment, the configuration items are also used to configure the network device as follows: switch configuration, firewall configuration, and encryption machine configuration;
所述模板配置信息获取模块340还用于::The template configuration information acquisition module 340 is also used to::
在所述IP地址配置中,针对各实时业务系统或非实时业务系统从预设设备清单中确定其对应的设备类型,所述设备类型包括交换机、防火墙及加密机;In the IP address configuration, the corresponding device type is determined from the preset device list for each real-time business system or non-real-time business system. The device types include switches, firewalls and encryption machines;
根据所述设备类型确定交换机列表、防火墙列表以及加密机列表;Determine the switch list, firewall list and encryption machine list according to the device type;
针对所述交换机列表中的各交换机生成对应的交换机配置页面,响应于所述第一用户在展示的交换机配置页面中的操作,对当前交换机进行路由配置,所述路由配置包括根据预设地址清单,确定当前交换机的路由地址名称和路由地址网段,并确定其下一跳设备的设备名称及IP地址编号;Generate a corresponding switch configuration page for each switch in the switch list, and perform routing configuration on the current switch in response to the first user's operation on the displayed switch configuration page. The routing configuration includes a preset address list. , determine the routing address name and routing address network segment of the current switch, and determine the device name and IP address number of its next-hop device;
针对所述防火墙列表中的各防火墙生成对应的防火墙配置页面,响应于所述第一用户在展示的防火墙配置页面中的操作,对当前防火墙进行路由配置、网络地址转换NAT配置以及策略配置,所述路由配置包括根据预设路由清单,确定当前防火墙的路由地址名称和路由地址网段,并确定其下一跳设备的设备名称及IP地址编号;所述NAT配置包括确定当前防火墙对应的业务系统的实时IP地址编号以及非实时IP地址编号;所述策略配置包括确定当前防火墙对应的业务系统的源IP地址编号、协议、端口别名以及目的IP地址编号,其中,所述端口别名从预设端口清单中选取;A corresponding firewall configuration page is generated for each firewall in the firewall list, and in response to the first user's operation in the displayed firewall configuration page, routing configuration, network address translation NAT configuration and policy configuration are performed on the current firewall, so The routing configuration includes determining the routing address name and routing address network segment of the current firewall according to the preset routing list, and determining the device name and IP address number of its next-hop device; the NAT configuration includes determining the business system corresponding to the current firewall The real-time IP address number and the non-real-time IP address number; the policy configuration includes determining the source IP address number, protocol, port alias and destination IP address number of the business system corresponding to the current firewall, where the port alias is derived from the preset port Select from list;
针对所述加密机列表中的各加密机生成对应的加密机配置页面,响应于所述第一用户在展示的加密机配置页面中的操作,对当前加密机进行路由配置、隧道配置以及策略配置,所述路由配置包括根据预设路由清单,确定当前加密机的路由地址名称和路由地址网段,并确定其下一跳设备的设备名称及IP地址编号;所述隧道配置包括确定当前加密机的各隧道的隧道本端IP地址编号、隧道对端IP地址编号、隧道周期及隧道容量;所述策略配置包括确定当前加密机对应的业务系统的源IP地址编号、协议、端口别名以及目的IP地址编号,其中,所述端口别名从预设端口清单中选取。Generate a corresponding encryption machine configuration page for each encryption machine in the encryption machine list, and perform routing configuration, tunnel configuration and policy configuration on the current encryption machine in response to the first user's operation on the displayed encryption machine configuration page. , the routing configuration includes determining the routing address name and routing address network segment of the current encryption machine according to the preset routing list, and determining the device name and IP address number of its next-hop device; the tunnel configuration includes determining the current encryption machine The tunnel local IP address number, tunnel peer IP address number, tunnel period and tunnel capacity of each tunnel; the policy configuration includes determining the source IP address number, protocol, port alias and destination IP of the business system corresponding to the current encryption machine Address number, wherein the port alias is selected from a preset port list.
本申请实施例所提供的一种创建网络配置模板的装置可执行本申请任意实施例所提供的一种创建网络配置模板的方法,具备执行方法相应的功能模块和有益效果。A device for creating a network configuration template provided by an embodiment of the present application can execute a method of creating a network configuration template provided by any embodiment of the present application, and has functional modules and beneficial effects corresponding to the execution method.
实施例四Embodiment 4
图6为本申请实施例四提供的一种网络配置的装置的结构示意图,所述装置可以应用于网络配置系统中,可以包括如下模块:Figure 6 is a schematic structural diagram of a network configuration device provided in Embodiment 4 of the present application. The device can be applied in a network configuration system and can include the following modules:
模板列表获取模块410,用于响应于第二用户的触发行为,获取所述第二用户所在站点的、在先配置的模板列表,并展示所述模板列表;The template list acquisition module 410 is configured to, in response to the second user's triggering behavior, acquire a previously configured template list of the site where the second user is located, and display the template list;
目标网络配置模板确定模块420,用于确定所述第二用户从所述模板列表中选定的目标网络配置模板;The target network configuration template determination module 420 is used to determine the target network configuration template selected by the second user from the template list;
网络配置页面展示模块430,用于基于所述目标网络配置模板生成网络配置页面,并展示所述网络配置页面;The network configuration page display module 430 is used to generate a network configuration page based on the target network configuration template and display the network configuration page;
网络配置信息确定模块440,用于响应于所述第二用户在所述网络配置页面中的操作,确定网络配置信息,所述网络配置信息至少包括起始IP地址,所述起始IP地址用于在生成网络配置方案时确定IP地址集合,所述IP地址集合中的各IP地址用于替换对应的IP地址编号;The network configuration information determining module 440 is configured to determine network configuration information in response to the second user's operation on the network configuration page. The network configuration information at least includes a starting IP address, and the starting IP address is Determining a set of IP addresses when generating a network configuration plan, and each IP address in the set of IP addresses is used to replace the corresponding IP address number;
网络配置方案生成模块450,用于根据所述目标网络配置模板以及所述网络配置信息生成网络配置方案。The network configuration plan generation module 450 is configured to generate a network configuration plan according to the target network configuration template and the network configuration information.
在一种实施例中,所述起始IP地址包括实时起始IP地址以及非实时起始IP地址;所述目标网络配置模板包括实时IP地址编号集合以及非实时IP地址编号集合;In one embodiment, the starting IP address includes a real-time starting IP address and a non-real-time starting IP address; the target network configuration template includes a real-time IP address number set and a non-real-time IP address number set;
所述网络配置信息确定模块440具体用于:The network configuration information determination module 440 is specifically used to:
根据所述实时起始IP地址,确定所述实时IP地址编号集合对应的实时IP地址集合;According to the real-time starting IP address, determine the real-time IP address set corresponding to the real-time IP address number set;
根据所述非实时起始IP地址,确定所述非实时IP地址编号集合对应的非实时IP地址集合;Determine a non-real-time IP address set corresponding to the non-real-time IP address number set according to the non-real-time starting IP address;
确定所述目标网络配置模板所涉及的业务系统,组成业务列表,并展示所述业务列表;Determine the business systems involved in the target network configuration template, form a business list, and display the business list;
检测所述第二用户从所述业务列表中选定的目标业务系统;Detecting the target service system selected by the second user from the service list;
接收所述第二用户输入的编撰日期。A compilation date input by the second user is received.
在一种实施例中,所述网络配置方案生成模块450具体用于:In one embodiment, the network configuration scheme generation module 450 is specifically used to:
根据所述网络配置信息对所述目标网络配置模板进行如下修改,并将修改后的目标网络配置模板作为网络配置方案:Modify the target network configuration template as follows according to the network configuration information, and use the modified target network configuration template as the network configuration plan:
将所述目标网络配置模板中的各实时IP地址编号替换为对应的实时IP地址;Replace each real-time IP address number in the target network configuration template with the corresponding real-time IP address;
将所述目标网络配置模板中的各非实时IP地址编号替换为对应的非实时IP地址;Replace each non-real-time IP address number in the target network configuration template with the corresponding non-real-time IP address;
从所述目标网络配置模板中删除除所述目标业务系统以外的其它业务系统相关的配置信息;Delete configuration information related to other business systems other than the target business system from the target network configuration template;
更新所述目标网络配置模板中具有的封面日期为所述编撰日期。The cover date in the target network configuration template is updated to be the compilation date.
本申请实施例所提供的一种网络配置的装置可执行本申请任意实施例所提供的一种网络配置的方法,具备执行方法相应的功能模块和有益效果。A network configuration device provided by an embodiment of the present application can execute a network configuration method provided by any embodiment of the present application, and has functional modules and beneficial effects corresponding to the execution method.
实施例五Embodiment 5
图7示出了可以用来实施本申请的方法实施例的电子设备10的结构示意图。电子设备旨在表示各种形式的数字计算机,诸如,膝上型计算机、台式计算机、工作台、个人数字助理、服务器、刀片式服务器、大型计算机、和其它适合的计算机。电子设备还可以表示各种形式的移动装置,诸如,个人数字处理、蜂窝电话、智能电话、可穿戴设备(如头盔、眼镜、手表等)和其它类似的计算装置。本文所示的部件、它们的连接和关系、以及它们的功能仅仅作为示例,并且不意在限制本文中描述的和/或者要求的本申请的实现。FIG. 7 shows a schematic structural diagram of an electronic device 10 that can be used to implement method embodiments of the present application. Electronic devices are intended to refer to various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. Electronic devices may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, wearable devices (eg, helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are examples only and are not intended to limit the implementation of the present application as described and/or claimed herein.
如图7所示,电子设备10包括至少一个处理器11,以及与至少一个处理器11通信连接的存储器,如只读存储器(ROM)12、随机访问存储器(RAM)13等,其中,存储器存储有可被至少一个处理器执行的计算机程序,处理器11可以根据存储在只读存储器(ROM)12中的计算机程序或者从存储单元18加载到随机访问存储器(RAM)13中的计算机程序,来执行各种适当的动作和处理。在RAM 13中,还可存储电子设备10操作所需的各种程序和数据。处理器11、ROM 12以及RAM 13通过总线14彼此相连。输入/输出(I/O)接口15也连接至总线14。As shown in Figure 7, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores There is a computer program that can be executed by at least one processor. The processor 11 can perform the operation according to the computer program stored in the read-only memory (ROM) 12 or loaded from the storage unit 18 into the random access memory (RAM) 13. Perform various appropriate actions and processing. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12 and the RAM 13 are connected to each other via the bus 14. An input/output (I/O) interface 15 is also connected to bus 14 .
电子设备10中的多个部件连接至I/O接口15,包括:输入单元16,例如键盘、鼠标等;输出单元17,例如各种类型的显示器、扬声器等;存储单元18,例如磁盘、光盘等;以及通信单元19,例如网卡、调制解调器、无线通信收发机等。通信单元19允许电子设备10通过诸如因特网的计算机网络和/或各种电信网络与其他设备交换信息/数据。Multiple components in the electronic device 10 are connected to the I/O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc. etc.; and communication unit 19, such as network card, modem, wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information/data with other devices through computer networks such as the Internet and/or various telecommunications networks.
处理器11可以是各种具有处理和计算能力的通用和/或专用处理组件。处理 器11的一些示例包括但不限于中央处理单元(CPU)、图形处理单元(GPU)、各种专用的人工智能(AI)计算芯片、各种运行机器学习模型算法的处理器、数字信号处理器(DSP)、以及任何适当的处理器、控制器、微控制器等。处理器11执行上文所描述的各个方法和处理,例如实施例一或实施例二所述的方法。 Processor 11 may be a variety of general and/or special purpose processing components having processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processing processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes each method and process described above, such as the method described in Embodiment 1 or Embodiment 2.
在一些实施例中,实施例一或实施例二所述的方法可被实现为计算机程序,其被有形地包含于计算机可读存储介质,例如存储单元18。在一些实施例中,计算机程序的部分或者全部可以经由ROM 12和/或通信单元19而被载入和/或安装到电子设备10上。当计算机程序加载到RAM 13并由处理器11执行时,可以执行上文描述的实施例一或实施例二所述的方法的一个或多个步骤。备选地,在其他实施例中,处理器11可以通过其他任何适当的方式(例如,借助于固件)而被配置为执行实施例一或实施例二所述的方法。In some embodiments, the method described in Embodiment 1 or Embodiment 2 can be implemented as a computer program, which is tangibly included in a computer-readable storage medium, such as the storage unit 18 . In some embodiments, part or all of the computer program may be loaded and/or installed onto the electronic device 10 via the ROM 12 and/or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the method described in Embodiment 1 or Embodiment 2 described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to perform the method described in Embodiment 1 or Embodiment 2 in any other appropriate manner (for example, by means of firmware).
本文中以上描述的系统和技术的各种实施方式可以在数字电子电路系统、集成电路系统、场可编程门阵列(FPGA)、专用集成电路(ASIC)、专用标准产品(ASSP)、芯片上系统的系统(SOC)、负载可编程逻辑设备(CPLD)、计算机硬件、固件、软件、和/或它们的组合中实现。这些各种实施方式可以包括:实施在一个或者多个计算机程序中,该一个或者多个计算机程序可在包括至少一个可编程处理器的可编程系统上执行和/或解释,该可编程处理器可以是专用或者通用可编程处理器,可以从存储系统、至少一个输入装置、和至少一个输出装置接收数据和指令,并且将数据和指令传输至该存储系统、该至少一个输入装置、和该至少一个输出装置。Various implementations of the systems and techniques described above may be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip implemented in a system (SOC), load programmable logic device (CPLD), computer hardware, firmware, software, and/or a combination thereof. These various embodiments may include implementation in one or more computer programs executable and/or interpreted on a programmable system including at least one programmable processor, the programmable processor The processor, which may be a special purpose or general purpose programmable processor, may receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device. An output device.
用于实施本申请的方法的计算机程序可以采用一个或多个编程语言的任何组合来编写。这些计算机程序可以提供给通用计算机、专用计算机或其他可编程数据处理装置的处理器,使得计算机程序当由处理器执行时使流程图和/或框图中所规定的功能/操作被实施。计算机程序可以完全在机器上执行、部分地在机器上执行,作为独立软件包部分地在机器上执行且部分地在远程机器上执行或完全在远程机器或服务器上执行。Computer programs for implementing the methods of the present application may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that the computer program, when executed by the processor, causes the functions/operations specified in the flowcharts and/or block diagrams to be implemented. A computer program may execute entirely on the machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.
在本申请的上下文中,计算机可读存储介质可以是有形的介质,其可以包含或存储以供指令执行系统、装置或设备使用或与指令执行系统、装置或设备结合地使用的计算机程序。计算机可读存储介质可以包括但不限于电子的、磁性的、光学的、电磁的、红外的、或半导体系统、装置或设备,或者上述内容的任何合适组合。备选地,计算机可读存储介质可以是机器可读信号介质。机器可读存储介质的更具体示例会包括基于一个或多个线的电气连接、便携式计算机盘、硬盘、随机存取存储器(RAM)、只读存储器(ROM)、可擦除可编程只读存储器(EPROM或快闪存储器)、光纤、便捷式紧凑盘只读存储器 (CD-ROM)、光学储存设备、磁储存设备、或上述内容的任何合适组合。In the context of this application, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. Computer-readable storage media may include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media would include one or more wire-based electrical connections, laptop disks, hard drives, random access memory (RAM), read only memory (ROM), erasable programmable read only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination of the above.
为了提供与用户的交互,可以在电子设备上实施此处描述的系统和技术,该电子设备具有:用于向用户显示信息的显示装置(例如,CRT(阴极射线管)或者LCD(液晶显示器)监视器);以及键盘和指向装置(例如,鼠标或者轨迹球),用户可以通过该键盘和该指向装置来将输入提供给电子设备。其它种类的装置还可以用于提供与用户的交互;例如,提供给用户的反馈可以是任何形式的传感反馈(例如,视觉反馈、听觉反馈、或者触觉反馈);并且可以用任何形式(包括声输入、语音输入或者、触觉输入)来接收来自用户的输入。To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having a display device (eg, a CRT (cathode ray tube) or LCD (liquid crystal display)) for displaying information to the user monitor); and a keyboard and pointing device (e.g., a mouse or a trackball) through which a user can provide input to the electronic device. Other kinds of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and may be provided in any form, including Acoustic input, voice input or tactile input) to receive input from the user.
可以将此处描述的系统和技术实施在包括后台部件的计算系统(例如,作为数据服务器)、或者包括中间件部件的计算系统(例如,应用服务器)、或者包括前端部件的计算系统(例如,具有图形用户界面或者网络浏览器的用户计算机,用户可以通过该图形用户界面或者该网络浏览器来与此处描述的系统和技术的实施方式交互)、或者包括这种后台部件、中间件部件、或者前端部件的任何组合的计算系统中。可以通过任何形式或者介质的数字数据通信(例如,通信网络)来将系统的部件相互连接。通信网络的示例包括:局域网(LAN)、广域网(WAN)、区块链网络和互联网。The systems and techniques described herein may be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., A user's computer having a graphical user interface or web browser through which the user can interact with implementations of the systems and technologies described herein), or including such backend components, middleware components, or any combination of front-end components in a computing system. The components of the system may be interconnected by any form or medium of digital data communication (eg, a communications network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.
计算系统可以包括客户端和服务器。客户端和服务器一般远离彼此并且通常通过通信网络进行交互。通过在相应的计算机上运行并且彼此具有客户端-服务器关系的计算机程序来产生客户端和服务器的关系。服务器可以是云服务器,又称为云计算服务器或云主机,是云计算服务体系中的一项主机产品,以解决了传统物理主机与VPS服务中,存在的管理难度大,业务扩展性弱的缺陷。Computing systems may include clients and servers. Clients and servers are generally remote from each other and typically interact over a communications network. The relationship of client and server is created by computer programs running on corresponding computers and having a client-server relationship with each other. The server can be a cloud server, also known as cloud computing server or cloud host. It is a host product in the cloud computing service system to solve the problems of difficult management and weak business scalability in traditional physical hosts and VPS services. defect.
应该理解,可以使用上面所示的各种形式的流程,重新排序、增加或删除步骤。例如,本申请中记载的各步骤可以并行地执行也可以顺序地执行也可以不同的次序执行,只要能够实现本申请的技术方案所期望的结果,本文在此不进行限制。It should be understood that various forms of the process shown above may be used, with steps reordered, added or deleted. For example, each step described in this application can be executed in parallel, sequentially, or in a different order. As long as the desired results of the technical solution of this application can be achieved, there is no limitation here.

Claims (10)

  1. 一种创建网络配置模板的方法,应用于网络配置系统中,所述方法包括:A method of creating a network configuration template, applied in a network configuration system, the method includes:
    响应于第一用户发起的新建模板操作,展示新建模板页面;In response to the new template operation initiated by the first user, display the new template page;
    接收第一用户在所述新建模板页面中输入的与待创建的网络配置模板相关联的模板基础信息;Receive basic template information associated with the network configuration template to be created input by the first user on the new template page;
    确定与所述模板基础信息对应的模板框架,并展示所述模板框架,所述模板框架包括与所述模板基础信息相关的配置项目,所述配置项目用于对电力站点中的网络设备至少进行如下配置:业务配置及IP地址配置;Determine a template frame corresponding to the template basic information, and display the template frame. The template frame includes configuration items related to the template basic information, and the configuration items are used to perform at least on the network equipment in the power site. The following configurations: business configuration and IP address configuration;
    获取第一用户针对各配置项目输入的模板配置信息,所述模板配置信息至少包括:与所述业务配置对应的业务网段信息、与所述IP地址配置对应的各业务系统的IP地址编号;Obtain the template configuration information input by the first user for each configuration item, the template configuration information at least includes: business network segment information corresponding to the service configuration, and the IP address number of each business system corresponding to the IP address configuration;
    根据所述模板配置信息以及所述模板框架生成网络配置模板。Generate a network configuration template according to the template configuration information and the template framework.
  2. 根据权利要求1所述的方法,其中,所述IP地址配置包括实时IP地址配置以及非实时IP地址配置;所述获取第一用户针对各配置输入的模板配置信息,包括:The method according to claim 1, wherein the IP address configuration includes real-time IP address configuration and non-real-time IP address configuration; and obtaining the template configuration information input by the first user for each configuration includes:
    响应于所述第一用户在展示的业务配置页面中的操作,确定所述业务配置页面的业务网段信息,所述业务网段信息包括所述第一用户输入的实时业务段掩码以及非实时业务段掩码;In response to the first user's operation in the displayed service configuration page, the service network segment information of the service configuration page is determined, and the service network segment information includes the real-time service segment mask input by the first user and non- Real-time business segment mask;
    响应于所述第一用户在展示的实时IP地址配置页面中的操作,确定所述实时业务段掩码对应的实时IP地址编号集合,以及确定所述第一用户从预设业务清单中选择的实时业务系统,并根据所述实时IP地址编号集合为各实时业务系统分配实时IP地址编号;In response to the first user's operation on the displayed real-time IP address configuration page, determine the real-time IP address number set corresponding to the real-time service segment mask, and determine the first user's selected from the preset service list. A real-time business system, and allocates real-time IP address numbers to each real-time business system according to the real-time IP address number set;
    响应于所述第一用户在展示的非实时IP地址配置页面中的操作,确定所述非实时业务段掩码对应的非实时IP地址编号集合,以及确定所述第一用户从预设业务清单中选择的非实时业务系统,并根据所述非实时IP地址编号集合为各非实时业务系统分配非实时IP地址编号。In response to the first user's operation on the displayed non-real-time IP address configuration page, determine the non-real-time IP address number set corresponding to the non-real-time service segment mask, and determine that the first user selects the non-real-time IP address from the default service list non-real-time business systems selected from among the non-real-time business systems, and allocate non-real-time IP address numbers to each non-real-time business system according to the non-real-time IP address number set.
  3. 根据权利要求2所述的方法,其中,所述配置项目还用于对所述网络设备进行如下配置:交换机配置、防火墙配置、加密机配置;The method according to claim 2, wherein the configuration item is also used to configure the network device as follows: switch configuration, firewall configuration, and encryption machine configuration;
    所述获取第一用户针对各配置输入的的模板配置信息,还包括:The obtaining the template configuration information input by the first user for each configuration also includes:
    在所述IP地址配置中,针对各实时业务系统或非实时业务系统从预设设备清单中确定其对应的设备类型,所述设备类型包括交换机、防火墙及加密机;In the IP address configuration, the corresponding device type is determined from the preset device list for each real-time business system or non-real-time business system. The device types include switches, firewalls and encryption machines;
    根据所述设备类型确定交换机列表、防火墙列表以及加密机列表;Determine the switch list, firewall list and encryption machine list according to the device type;
    针对所述交换机列表中的各交换机生成对应的交换机配置页面,响应于所述第一用户在展示的交换机配置页面中的操作,对当前交换机进行路由配置,所述路由配置包括根据预设地址清单,确定当前交换机的路由地址名称和路由地址网段,并确定其下一跳设备的设备名称及IP地址编号;Generate a corresponding switch configuration page for each switch in the switch list, and perform routing configuration on the current switch in response to the first user's operation on the displayed switch configuration page. The routing configuration includes a preset address list. , determine the routing address name and routing address network segment of the current switch, and determine the device name and IP address number of its next-hop device;
    针对所述防火墙列表中的各防火墙生成对应的防火墙配置页面,响应于所述第一用户在展示的防火墙配置页面中的操作,对当前防火墙进行路由配置、网络地址转换NAT配置以及策略配置,所述路由配置包括根据预设路由清单,确定当前防火墙的路由地址名称和路由地址网段,并确定其下一跳设备的设备名称及IP地址编号;所述NAT配置包括确定当前防火墙对应的业务系统的实时IP地址编号以及非实时IP地址编号;所述策略配置包括确定当前防火墙对应的业务系统的源IP地址编号、协议、端口别名以及目的IP地址编号,其中,所述端口别名从预设端口清单中选取;A corresponding firewall configuration page is generated for each firewall in the firewall list, and in response to the first user's operation in the displayed firewall configuration page, routing configuration, network address translation NAT configuration and policy configuration are performed on the current firewall, so The routing configuration includes determining the routing address name and routing address network segment of the current firewall according to the preset routing list, and determining the device name and IP address number of its next-hop device; the NAT configuration includes determining the business system corresponding to the current firewall The real-time IP address number and the non-real-time IP address number; the policy configuration includes determining the source IP address number, protocol, port alias and destination IP address number of the business system corresponding to the current firewall, where the port alias is derived from the preset port Select from list;
    针对所述加密机列表中的各加密机生成对应的加密机配置页面,响应于所述第一用户在展示的加密机配置页面中的操作,对当前加密机进行路由配置、隧道配置以及策略配置,所述路由配置包括根据预设路由清单,确定当前加密机的路由地址名称和路由地址网段,并确定其下一跳设备的设备名称及IP地址编号;所述隧道配置包括确定当前加密机的各隧道的隧道本端IP地址编号、隧道对端IP地址编号、隧道周期及隧道容量;所述策略配置包括确定当前加密机对应的业务系统的源IP地址编号、协议、端口别名以及目的IP地址编号,其中,所述端口别名从预设端口清单中选取。Generate a corresponding encryption machine configuration page for each encryption machine in the encryption machine list, and perform routing configuration, tunnel configuration and policy configuration on the current encryption machine in response to the first user's operation on the displayed encryption machine configuration page. , the routing configuration includes determining the routing address name and routing address network segment of the current encryption machine according to the preset routing list, and determining the device name and IP address number of its next-hop device; the tunnel configuration includes determining the current encryption machine The tunnel local IP address number, tunnel peer IP address number, tunnel period and tunnel capacity of each tunnel; the policy configuration includes determining the source IP address number, protocol, port alias and destination IP of the business system corresponding to the current encryption machine Address number, wherein the port alias is selected from a preset port list.
  4. 一种网络配置的方法,应用于网络配置系统中,所述方法包括:A method of network configuration, applied in a network configuration system, the method includes:
    响应于第二用户的触发行为,获取所述第二用户所在站点的、在先配置的模板列表,并展示所述模板列表;In response to the second user's triggering behavior, obtain a previously configured template list of the site where the second user is located, and display the template list;
    确定所述第二用户从所述模板列表中选定的目标网络配置模板;Determine the target network configuration template selected by the second user from the template list;
    基于所述目标网络配置模板生成网络配置页面,并展示所述网络配置页面;Generate a network configuration page based on the target network configuration template, and display the network configuration page;
    响应于所述第二用户在所述网络配置页面中的操作,确定网络配置信息,所述网络配置信息至少包括起始IP地址,所述起始IP地址用于在生成网络配置方案时确定IP地址集合,所述IP地址集合中的各IP地址用于替换对应的IP地址编号;In response to the operation of the second user in the network configuration page, network configuration information is determined. The network configuration information at least includes a starting IP address, and the starting IP address is used to determine the IP address when generating a network configuration plan. Address set, each IP address in the IP address set is used to replace the corresponding IP address number;
    根据所述目标网络配置模板以及所述网络配置信息生成网络配置方案。Generate a network configuration plan according to the target network configuration template and the network configuration information.
  5. 根据权利要求4所述的方法,其中,所述起始IP地址包括实时起始IP地址以及非实时起始IP地址;所述目标网络配置模板包括实时IP地址编号集合以及非实时IP地址编号集合;The method according to claim 4, wherein the starting IP address includes a real-time starting IP address and a non-real-time starting IP address; the target network configuration template includes a real-time IP address number set and a non-real-time IP address number set. ;
    所述响应于所述第二用户在所述网络配置页面中的操作,确定网络配置信息,包括:Determining network configuration information in response to the second user's operation on the network configuration page includes:
    根据所述实时起始IP地址,确定所述实时IP地址编号集合对应的实时IP地址集合;According to the real-time starting IP address, determine the real-time IP address set corresponding to the real-time IP address number set;
    根据所述非实时起始IP地址,确定所述非实时IP地址编号集合对应的非实时IP地址集合;Determine a non-real-time IP address set corresponding to the non-real-time IP address number set according to the non-real-time starting IP address;
    确定所述目标网络配置模板所涉及的业务系统,组成业务列表,并展示所述业务列表;Determine the business systems involved in the target network configuration template, form a business list, and display the business list;
    检测所述第二用户从所述业务列表中选定的目标业务系统;Detecting the target service system selected by the second user from the service list;
    接收所述第二用户输入的编撰日期。A compilation date input by the second user is received.
  6. 根据权利要求5所述的方法,其中,所述根据所述目标网络配置模板以及所述网络配置信息生成网络配置方案,包括:The method according to claim 5, wherein generating a network configuration scheme according to the target network configuration template and the network configuration information includes:
    根据所述网络配置信息对所述目标网络配置模板进行如下修改,并将修改后的目标网络配置模板作为网络配置方案:Modify the target network configuration template as follows according to the network configuration information, and use the modified target network configuration template as the network configuration plan:
    将所述目标网络配置模板中的各实时IP地址编号替换为对应的实时IP地址;Replace each real-time IP address number in the target network configuration template with the corresponding real-time IP address;
    将所述目标网络配置模板中的各非实时IP地址编号替换为对应的非实时IP地址;Replace each non-real-time IP address number in the target network configuration template with the corresponding non-real-time IP address;
    从所述目标网络配置模板中删除除所述目标业务系统以外的其它业务系统相关的配置信息;Delete configuration information related to other business systems other than the target business system from the target network configuration template;
    更新所述目标网络配置模板中具有的封面日期为所述编撰日期。The cover date in the target network configuration template is updated to be the compilation date.
  7. 一种创建网络配置模板的装置,应用于网络配置系统中,所述装置包括:A device for creating a network configuration template, used in a network configuration system, the device includes:
    新建模板页面展示模块,用于响应于第一用户发起的新建模板操作,展示新建模板页面;The new template page display module is used to display the new template page in response to the new template operation initiated by the first user;
    模板基础信息接收模块,用于接收第一用户在所述新建模板页面中输入的与待创建的网络配置模板相关联的模板基础信息;A template basic information receiving module, configured to receive template basic information associated with the network configuration template to be created input by the first user in the new template page;
    模板框架展示模块,用于确定与所述模板基础信息对应的模板框架,并展示所述模板框架,所述模板框架包括与所述模板基础信息相关的配置项目,所述配置项目用于对电力站点中的网络设备至少进行如下配置:业务配置及IP地址配置;A template frame display module, configured to determine a template frame corresponding to the template basic information and display the template frame, where the template frame includes configuration items related to the template basic information, and the configuration items are used for power The network equipment in the site must be configured as follows at least: business configuration and IP address configuration;
    模板配置信息获取模块,用于获取第一用户针对各配置项目输入的模板配置信息,所述模板配置信息至少包括:与所述业务配置对应的业务网段信息、 与所述IP地址配置对应的各业务系统的IP地址编号;A template configuration information acquisition module is used to acquire the template configuration information input by the first user for each configuration item. The template configuration information at least includes: business network segment information corresponding to the service configuration, and network segment information corresponding to the IP address configuration. The IP address number of each business system;
    网络配置模板生成模块,用于根据所述模板配置信息以及所述模板框架生成网络配置模板。A network configuration template generating module is configured to generate a network configuration template according to the template configuration information and the template framework.
  8. 一种网络配置的装置,应用于网络配置系统中,所述装置包括:A network configuration device, used in a network configuration system, the device includes:
    模板列表获取模块,用于响应于第二用户的触发行为,获取所述第二用户所在站点的、在先配置的模板列表,并展示所述模板列表;A template list acquisition module, configured to respond to the second user's triggering behavior, acquire a previously configured template list of the site where the second user is located, and display the template list;
    目标网络配置模板确定模块,用于确定所述第二用户从所述模板列表中选定的目标网络配置模板;A target network configuration template determination module, configured to determine the target network configuration template selected by the second user from the template list;
    网络配置页面展示模块,用于基于所述目标网络配置模板生成网络配置页面,并展示所述网络配置页面;A network configuration page display module, configured to generate a network configuration page based on the target network configuration template and display the network configuration page;
    网络配置信息确定模块,用于响应于所述第二用户在所述网络配置页面中的操作,确定网络配置信息,所述网络配置信息至少包括起始IP地址,所述起始IP地址用于在生成网络配置方案时确定IP地址集合,所述IP地址集合中的各IP地址用于替换对应的IP地址编号;A network configuration information determination module, configured to determine network configuration information in response to the second user's operation on the network configuration page, where the network configuration information at least includes a starting IP address, and the starting IP address is used for Determine a set of IP addresses when generating a network configuration plan, and each IP address in the set of IP addresses is used to replace the corresponding IP address number;
    网络配置方案生成模块,用于根据所述目标网络配置模板以及所述网络配置信息生成网络配置方案。A network configuration plan generation module is configured to generate a network configuration plan according to the target network configuration template and the network configuration information.
  9. 一种电子设备,包括:An electronic device including:
    至少一个处理器;以及at least one processor; and
    与所述至少一个处理器通信连接的存储器;其中,a memory communicatively connected to the at least one processor; wherein,
    所述存储器存储有可被所述至少一个处理器执行的计算机程序,所述计算机程序被所述至少一个处理器执行,以使所述至少一个处理器能够执行权利要求1-6中任一项所述的方法。The memory stores a computer program executable by the at least one processor, the computer program being executed by the at least one processor, so that the at least one processor can execute any one of claims 1-6 the method described.
  10. 一种计算机可读存储介质,所述计算机可读存储介质存储有计算机指令,所述计算机指令用于使处理器执行时实现权利要求1-6中任一项所述的方法。A computer-readable storage medium stores computer instructions, and the computer instructions are used to implement the method of any one of claims 1-6 when executed by a processor.
PCT/CN2022/144058 2022-04-28 2022-12-30 Method and apparatus for creating network configuration template, method and apparatus for network configuration, and device WO2023207202A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202210455222.7 2022-04-28
CN202210455222.7A CN114553691B (en) 2022-04-28 2022-04-28 Method, device and equipment for creating network configuration template and network configuration

Publications (1)

Publication Number Publication Date
WO2023207202A1 true WO2023207202A1 (en) 2023-11-02

Family

ID=81666958

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2022/144058 WO2023207202A1 (en) 2022-04-28 2022-12-30 Method and apparatus for creating network configuration template, method and apparatus for network configuration, and device

Country Status (2)

Country Link
CN (1) CN114553691B (en)
WO (1) WO2023207202A1 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN117793151A (en) * 2024-02-28 2024-03-29 深圳桑达银络科技有限公司 Distributed network security monitoring system and method based on cloud computing

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114553691B (en) * 2022-04-28 2022-07-29 广东电网有限责任公司东莞供电局 Method, device and equipment for creating network configuration template and network configuration

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2018113241A1 (en) * 2016-12-20 2018-06-28 上海壹账通金融科技有限公司 Page presentation method and device, server and storage medium
CN110865807A (en) * 2018-08-27 2020-03-06 北京京东金融科技控股有限公司 Active page creation system, method, device and storage medium
CN111371595A (en) * 2020-02-25 2020-07-03 深信服科技股份有限公司 Network security deployment method, device, equipment and readable storage medium
CN113971191A (en) * 2020-07-23 2022-01-25 腾讯科技(深圳)有限公司 Data import method and device and computer readable storage medium
CN114553691A (en) * 2022-04-28 2022-05-27 广东电网有限责任公司东莞供电局 Method, device and equipment for creating network configuration template and network configuration

Family Cites Families (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100440809C (en) * 2006-11-13 2008-12-03 杭州华三通信技术有限公司 Method and device for service configuration of network equipment
WO2009028098A1 (en) * 2007-08-31 2009-03-05 Fujitsu Limited Configuration information generation device, configuration information generation method, program, and recording medium
US8595625B2 (en) * 2007-10-09 2013-11-26 Tellabs San Jose, Inc. Method and apparatus to automate configuration of network entities
CN107846313B (en) * 2017-10-30 2019-04-30 中国联合网络通信集团有限公司 A kind of method and the network equipment of the generation of network service moulding plate
CN109474467B (en) * 2018-11-15 2022-02-01 上海携程商务有限公司 Network automation management method and device, storage medium and electronic equipment
CN110661670A (en) * 2019-10-21 2020-01-07 中国民航信息网络股份有限公司 Network equipment configuration management method and device
CN111835794B (en) * 2020-09-17 2021-01-05 腾讯科技(深圳)有限公司 Firewall policy control method and device, electronic equipment and storage medium
CN113660126B (en) * 2021-08-18 2024-04-12 奇安信科技集团股份有限公司 Networking file generation method, networking method and networking device
CN114036443A (en) * 2021-11-29 2022-02-11 北京百度网讯科技有限公司 Page generation method and device

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2018113241A1 (en) * 2016-12-20 2018-06-28 上海壹账通金融科技有限公司 Page presentation method and device, server and storage medium
CN110865807A (en) * 2018-08-27 2020-03-06 北京京东金融科技控股有限公司 Active page creation system, method, device and storage medium
CN111371595A (en) * 2020-02-25 2020-07-03 深信服科技股份有限公司 Network security deployment method, device, equipment and readable storage medium
CN113971191A (en) * 2020-07-23 2022-01-25 腾讯科技(深圳)有限公司 Data import method and device and computer readable storage medium
CN114553691A (en) * 2022-04-28 2022-05-27 广东电网有限责任公司东莞供电局 Method, device and equipment for creating network configuration template and network configuration

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN117793151A (en) * 2024-02-28 2024-03-29 深圳桑达银络科技有限公司 Distributed network security monitoring system and method based on cloud computing
CN117793151B (en) * 2024-02-28 2024-04-30 深圳桑达银络科技有限公司 Distributed network security monitoring system and method based on cloud computing

Also Published As

Publication number Publication date
CN114553691B (en) 2022-07-29
CN114553691A (en) 2022-05-27

Similar Documents

Publication Publication Date Title
WO2023207202A1 (en) Method and apparatus for creating network configuration template, method and apparatus for network configuration, and device
EP3211831B1 (en) N-tiered end user response time eurt breakdown graph for problem domain isolation
US20230300044A1 (en) Unique id generation for sensors
US10797970B2 (en) Interactive hierarchical network chord diagram for application dependency mapping
US9992082B2 (en) Classifier based graph rendering for visualization of a telecommunications network topology
CN101414935B (en) Method and system for generating test case
CN112511660B (en) Management system, method and device of edge terminal equipment and storage medium
CN102427445B (en) Safe auditing method of IT simulation infrastructure offline compliance
EP3544233B1 (en) System and method to provide network insights for correct and efficient network configuration
EP3544330A1 (en) System and method for validating correctness of changes to network device configurations
EP3360285B1 (en) System and method to reconcile cabling test results with cabling test configurations
KR20230042118A (en) Edge Computing Environment Configuration Tool for Telecom Networks
CN104468505B (en) A kind of security audit daily record player method and device
CN115695165A (en) Automatic operation and maintenance method and system for firewall, electronic equipment and storage medium
CN106789873B (en) Inspection method for level protection safety boundary
EP4290819A1 (en) Service deployment method, apparatus, and system
US9553767B2 (en) Host connectivity templates to configure host of virtual machines
CN207586323U (en) A kind of unit negative damping online recognition system
CN116599838A (en) Substation equipment information configuration management method, device, equipment and storage medium
CN115695191A (en) Switching method and device of terminal network and electronic equipment
Garcia Cabot Evaluation of an IP Fabric network architecture for CERN's data center
CN115225634A (en) Data forwarding method and device under virtual network and computer program product
CN116827812A (en) Network asset account display method and device, electronic equipment and storage medium
CN114513437A (en) Network testing method, device, medium and computing equipment

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 22940008

Country of ref document: EP

Kind code of ref document: A1