The collocation method and device of virtual firewall
Technical field
The present invention relates to computer realm, and especially, it is related to the collocation method and device of a kind of virtual firewall.
Background technology
At present, physics fire wall signs in each firewall configuration page to anti-using the method being separately configured
The regularization term of wall with flues carries out various configurations.
In cloud computing environment, it will virtual firewall is automatically created or closed according to the demand of user.Also, according to
The characteristics of cloud computing, the quantity of virtual firewall can be a lot, if configured one by one, can cause managing for virtual firewall
Property reduce.Additionally, due to artificial operational error device can be caused unstable.And large number of fire wall is investigated one by one
Become unrealistic.
For needing to configure the regularization term of multiple virtual firewalls in correlation technique, virtual firewall is caused to manage
The problem that rationality is reduced, not yet proposes at present effective solution.
The content of the invention
For needing to configure the regularization term of multiple virtual firewalls in correlation technique, virtual firewall is caused to manage
The problem that rationality is reduced, the present invention proposes a kind of collocation method and device of virtual firewall, can be to needing in virtual firewall
The regularization term for being similarly configured carries out unifying configuration, so as to mitigate configuration burden, and avoid due to it is artificial one by one
Configuration, so as to improve the stability of device.
The technical scheme is that what is be achieved in that:
According to an aspect of the invention, there is provided a kind of collocation method of virtual firewall.
The collocation method of the virtual firewall includes:
Determine that multiple virtual firewalls need the regularization term for being similarly configured;
The regularization term for determining is extracted, and the regularization term to extracting carries out unifying configuration;
Other regularization terms of multiple virtual firewalls are configured.
And, before carrying out unifying configuration to the regularization term extracted, above-mentioned collocation method is further included:
It is determined that the virtual firewall having been switched on;
Also, determine that multiple virtual firewalls need the regularization term for being similarly configured to include:
It is determined that the virtual firewall having been switched on needs the regularization term for being similarly configured.
Also, above-mentioned collocation method is further included:
All fire walls are divided into multiple domains by the function of all fire walls for being configured as needed;
Also, determine that multiple virtual firewalls need the regularization term for being similarly configured to include:
The regularization term for needing to be similarly configured is determined to the virtual firewall in each domain.
Wherein, all fire walls are divided into into multiple domains includes:
It is function is identical or part identical virtual firewall is divided to a domain.
Further, above-mentioned collocation method includes:
Prestore the IP address of whole virtual machines.
Additionally, above-mentioned collocation method includes:
In the case where needing to configure virtual machine, the IP address corresponding to the virtual machine is extracted;
Pass through extracted IP address and be connected to the virtual machine, to determine the position of the virtual firewall corresponding to the virtual machine
Put.
According to an aspect of the invention, there is provided a kind of configuration device of virtual firewall.
The configuration device of the virtual firewall includes:
Determining module, the regularization term similarly configured for determining multiple virtual firewalls to need;
Extraction module, for extracting the regularization term for determining, and the regularization term to extracting carries out unifying configuration;
Configuration module, for configuring to other regularization terms of multiple virtual firewalls.
Also, above-mentioned configuration device is further included:
Division module, the function of all fire walls for being configured as needed is divided on all fire walls many
Individual domain;
Also, determining module is further used for determining the rule for needing to be similarly configured to the virtual firewall in each domain
Then item.
Wherein, division module is further used for that function is identical or part identical virtual firewall is divided to one
Domain.
Additionally, above-mentioned configuration device includes:
Module is prestored, for prestoring the IP address of whole virtual machines.
The present invention by needing the regularization term for being similarly configured to carry out to unify configuration in multiple virtual firewalls, so as to
Mitigate the configuration burden to multiple virtual firewalls, and avoid due to artificial configuration one by one, reduce the rate of mismatching, can
Improve the stability of device, user friendly unified management.Additionally, other regularization terms to different configuration of virtual firewall
Separately configured, be intactly configured with multiple virtual firewalls, it is to avoid the caused virtual firewall due to configuration disappearance
Leak.
Description of the drawings
Fig. 1 is the flow chart of the collocation method of virtual firewall according to embodiments of the present invention;
Fig. 2 is the signal in the virtual firewall domain used in the collocation method of virtual firewall according to embodiments of the present invention
Figure;
Fig. 3 be virtual firewall according to embodiments of the present invention collocation method in configuration when there is virtual firewall domain
Schematic diagram;
Fig. 4 is the block diagram of the configuration device of virtual firewall according to embodiments of the present invention.
Specific embodiment
Below in conjunction with the accompanying drawing in the embodiment of the present invention, the technical scheme in the embodiment of the present invention is carried out clear, complete
Site preparation is described, it is clear that described embodiment is only a part of embodiment of the invention, rather than the embodiment of whole.It is based on
Embodiment in the present invention, the every other embodiment that those of ordinary skill in the art are obtained belongs to present invention protection
Scope.
A kind of embodiments in accordance with the present invention, there is provided collocation method of virtual firewall.
As shown in figure 1, the collocation method of virtual firewall according to embodiments of the present invention includes:
Step S101, determines that multiple virtual firewalls need the regularization term for being similarly configured;
Step S103, extracts the regularization term for determining, and the regularization term to extracting carries out unifying configuration;
Other regularization terms of multiple virtual firewalls are configured by step S105.
And, before carrying out unifying configuration to the regularization term extracted, collocation method according to embodiments of the present invention can be with
Further determine that the virtual firewall having been switched on;Also, it is determined that multiple virtual firewalls need the rule for being similarly configured
Then while item, it is identical that collocation method according to embodiments of the present invention can determine that the virtual firewall having been switched on needs to carry out
The regularization term of configuration.
Also, collocation method according to embodiments of the present invention may further include:What is configured as needed is all
All fire walls are divided into multiple domains by the function of fire wall.Also, determine that multiple virtual firewalls need to be similarly configured
Regularization term when the virtual firewall that can be directed in each domain determine and need the regularization term that be similarly configured.
Wherein, all fire walls are divided into into multiple domains can be by function is identical or part identical virtual firewall
It is divided to a domain.
Further, collocation method according to embodiments of the present invention can prestore the IP address of whole virtual machines.
Additionally, collocation method according to embodiments of the present invention is in the case where needing to configure virtual machine, it is right to extract
Should be in the IP address of the virtual machine.Also, collocation method according to embodiments of the present invention passes through extracted IP address and is connected to
The virtual machine, to determine the position of the virtual firewall corresponding to the virtual machine.
All virtual firewalls are detected by the collocation method of virtual firewall according to embodiments of the present invention automatically,
Judge whether the state of fire wall opens according to corresponding result of detection.The unified configuration page is set, to needing to carry out identical matching somebody with somebody
The regularization term of the fire wall put carries out unifying to arrange, step S101 as shown in Figure 1.To needing to carry out different configuration of fire wall
Regularization term be respectively provided with, step S105 as shown in Figure 1.Wherein, the above-mentioned unified configuration page can be by virtual
The IP address of main frame is connected on fictitious host computer, and finds the configuration file of fire wall(In actual applications, configuration file leads to
The fixed position being often placed in fictitious host computer.)
According to another embodiment of the invention, design fire wall domain can be set, multiple virtual firewall needs are determined
The regularization term for being similarly configured, the fire wall with the regularization term for needing to be similarly configured is placed in same domain, with
Ensure that as far as possible many identical configurations are unified configurations.As shown in figure 3, with 4 virtual firewalls as example, arranging 2 fire prevention
Wall domain:Virtual firewall domain 1 and virtual firewall domain 2.To put with the virtual firewall 1 and virtual firewall 2 that similarly configure
In virtual firewall domain 1, virtual firewall domain 2 will be placed in the virtual firewall 3 and virtual firewall 4 that similarly configure
In.
As shown in figure 4, domain 1(That is virtual firewall domain 1)Be configured to be needed in virtual firewall 1 and virtual firewall 2 into
The regularization term that row is similarly configured, the regularization term unification decentralization order to needing to be similarly configured in domain 1.To virtual firewall 1
With need to carry out different configuration of regularization term in virtual firewall 2 to be respectively configured, such as configuration 1, configuration 2 ... configuration 6.Domain
2(That is virtual firewall domain 2)The regularization term for needing to be similarly configured is configured in virtual firewall 3 and virtual firewall 4, it is right
The regularization term for being similarly configured is needed to unify decentralization order in domain 2.To need in virtual firewall 3 and virtual firewall 4 into
The different configuration of regularization term of row is respectively configured, such as configuration 1, configuration 2 ... configuration 6.
A kind of embodiments in accordance with the present invention, there is provided configuration device of virtual firewall.
As shown in figure 4, the configuration device of virtual firewall according to embodiments of the present invention includes:
Determining module 41, the regularization term similarly configured for determining multiple virtual firewalls to need;
Extraction module 42, for extracting the regularization term for determining, and the regularization term to extracting carries out unifying configuration;
Configuration module 43, for configuring to other regularization terms of multiple virtual firewalls.
Also, configuration device according to embodiments of the present invention is further included:
Division module(It is not shown), the function of all fire walls for being configured as needed, by all fire walls
It is divided into multiple domains;
Also, determining module 41 is further used for determining the virtual firewall in each domain needs what is similarly configured
Regularization term.
Wherein, division module(It is not shown)It is further used for function is identical or part identical virtual firewall is drawn
Divide to a domain.
Additionally, configuration device according to embodiments of the present invention includes:
Prestore module(It is not shown), for prestoring the IP address of whole virtual machines.
In sum, by means of the above-mentioned technical proposal of the present invention, the present invention in multiple virtual firewalls by needing
The regularization term for being similarly configured carries out unifying configuration, so as to mitigate the configuration burden to multiple virtual firewalls, and avoids
Due to artificial configuration one by one, the stability of device can be improved.Further, void is confirmed by detecting automatically in advance
Intend the use state of fire wall, it is possible to increase allocative efficiency.Additionally, entering to other regularization terms of different configuration of virtual firewall
Row is separately configured, and is intactly configured with multiple virtual firewalls, it is to avoid due to configuration disappearance, caused virtual firewall leaks
Hole.
Presently preferred embodiments of the present invention is the foregoing is only, not to limit the present invention, all essences in the present invention
Within god and principle, any modification, equivalent substitution and improvements made etc. should be included within the scope of the present invention.