WO2020108382A1 - 端口的安全策略合并 - Google Patents

端口的安全策略合并 Download PDF

Info

Publication number
WO2020108382A1
WO2020108382A1 PCT/CN2019/119996 CN2019119996W WO2020108382A1 WO 2020108382 A1 WO2020108382 A1 WO 2020108382A1 CN 2019119996 W CN2019119996 W CN 2019119996W WO 2020108382 A1 WO2020108382 A1 WO 2020108382A1
Authority
WO
WIPO (PCT)
Prior art keywords
switching device
port
security policy
request message
response message
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2019/119996
Other languages
English (en)
French (fr)
Inventor
赵丽丽
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
New H3C Technologies Co Ltd
Original Assignee
New H3C Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by New H3C Technologies Co Ltd filed Critical New H3C Technologies Co Ltd
Publication of WO2020108382A1 publication Critical patent/WO2020108382A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/74Address processing for routing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/20Network architectures or network communication protocols for network security for managing network security; network security policies in general

Definitions

  • Storage Area Network (Storage Area Network, SAN) is a dedicated network used to provide data transmission between servers and storage devices.
  • the servers and storage devices in the SAN are connected through switches.
  • Port security technology In order to guarantee the network security of SAN, port security technology is usually introduced to provide security control based on port level.
  • Port security technology mainly refers to: establishing the binding relationship between the port on the switch and the device that directly accesses the switch through the port, as part of the port's security policy, to allow devices that meet the port's security policy to log in to the SAN through the switch.
  • FIG. 1 is a flowchart of a port security policy merging method shown in an embodiment of the present disclosure.
  • FIG. 2 is an implementation flow of the first switching device detecting the second switching device shown in an embodiment of the present disclosure.
  • FIG. 3 is an implementation process of a security policy that a first switching device provides a port to a second switching device according to an embodiment of the present disclosure.
  • FC protocol message 4 is an example of an FC protocol message shown in an embodiment of the present disclosure.
  • FIG. 5A is a schematic diagram of a SAN shown in an embodiment of the present disclosure.
  • FIG. 5B is a schematic diagram of another SAN shown in an embodiment of the present disclosure.
  • FIG. 5C is a schematic diagram of the combined SAN network of FIGS. 5A and 5B shown in an embodiment of the present disclosure.
  • FIG. 6 is a schematic structural diagram of a port security policy merging device shown in an embodiment of the present disclosure.
  • FIG. 7 is a schematic diagram of a hardware structure of a switching device shown in an embodiment of the present disclosure.
  • first, second, third, etc. may be used to describe various information in the embodiments of the present disclosure, the information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other.
  • first information may also be referred to as second information, and similarly, the second information may also be referred to as first information.
  • word “if” as used herein may be interpreted as "when” or “when” or “in response to a determination”.
  • An embodiment of the present disclosure provides a method for merging security policies of a port.
  • the first switching device senses that the second switching device accesses the SAN, it uses the message interaction with the second switching device to obtain the security policy of the port in the second switching device to implement the security policy of the port Automatic merging improves the efficiency of merging port security policies.
  • FIG. 1 it is a flowchart of a security policy merging method for a port provided by an embodiment of the present disclosure. This process is applied to the first switching equipment in the SAN.
  • the process may include the following steps:
  • Step S101 If it is detected that the second switching device accesses the SAN, the first switching device sends a first request message to the second switching device.
  • the first switching device When the first switching device detects that the second switching device accesses the SAN, the first switching device needs to obtain the security policy of the port in the second switching device. At this time, the first switching device generates a first request message. The first request message is used to obtain the security policy of the port in the second switching device.
  • the first switching device sends the first request message to the second switching device.
  • the first switching device, the second switching device, and the first request message are only named for convenience of description, and are not used for limitation.
  • Step S102 The first switching device receives a first response message that the second switching device responds to according to the first request message.
  • the second switching device after receiving the first request message in step S101, parses the first request message to determine that the first switching device needs to acquire the security policy of the second switching device's own port.
  • the second switching device obtains the security policy of the port and generates a first response message. It can be understood that the first response message includes the security policy of the port in the second switching device.
  • the second switching device sends a first response message to the first switching device.
  • the first response message is only named for the convenience of description, not for limitation.
  • the security policy of the port may be stored in the port security policy table in the second switching device.
  • the second switching device may directly obtain the port security policy of the second switching device from the port security policy table.
  • each entry represents a port security policy.
  • the port security policy indicated in the first entry is: Allow server 1 to access the network through port 1 of switching device 1.
  • Step S103 The first switching device adds the security policy of the port in the second switching device to the port security policy table of the first switching device.
  • the first switching device After receiving the first response message, the first switching device parses and obtains the security policy of the port in the second switching device. The first switching device adds the acquired port security policy to the port security policy table of the switching device, that is, the merge of the port security policies is completed.
  • the first switching device determines whether the network device can log in to the network through the first switching device according to the combined port security policy.
  • the first switching device senses that the second switching device accesses the SAN, it uses message interaction with the second switching device to obtain the second switch
  • the security policies of the ports in the device can realize the automatic merge of the security policies of the ports and improve the efficiency of the merge of the security policies of the ports.
  • the process of detecting the second switching device by the first switching device is specifically described below. Referring to FIG. 2, it is an implementation process of the first switching device detecting the second switching device shown in the embodiment of the present disclosure. By detecting the process of the switching device accessing the SAN, the first switching device can quickly discover the newly accessed switching device, and Obtain the security policy of the port of the switching device.
  • the process may include the following steps:
  • Step S201 the first switching device learns the routing of each switching device in the SAN.
  • each switching device in the SAN When there are new switching devices connected to the SAN, each switching device in the SAN will re-collect the network topology and recalculate routes based on the collected network topology. That is, the access of the new switching device triggers each switching device in the SAN to re-learn the route.
  • the first switching device compares the learned route with the existing route in the routing table. If the learned route is not recorded in the routing table, it means that the route is a newly learned route, that is, the newly added route Route, add the new route to the routing table.
  • the destination address included in the route is the address of the switching device.
  • Step S202 if there is a newly added route, the first switching device obtains the destination address included in the route.
  • Step S203 The first switching device determines the switching device corresponding to the destination address as the second switching device.
  • the destination address included in the route is the address of the switching device. Therefore, the first switching device can determine that the switching device corresponding to the destination address is the switching device connected to the SAN according to the destination address obtained from the newly added route , Which is the second switching device.
  • FIG. 3 it is an implementation process of a security policy that a first switching device provides a port to a second switching device according to an embodiment of the present disclosure.
  • the process may include the following steps:
  • Step S301 The first switching device receives the second request message sent by the second switching device.
  • the second request message is used to obtain the security policy of the port in the first switching device.
  • the second request message is only named for convenience of description, and is not used for limitation.
  • Step S302 According to the second request message, the first switching device obtains the security policy of the port in the first switching device.
  • the process of the first switching device acquiring the security policy of its own port is the same as the process of the second switching device acquiring the security policy of its own port in step 102 of the foregoing embodiment, which will not be repeated here.
  • Step S303 the first switching device sends a second response message to the second switching device.
  • the process in which the first switching device sends the second response message to the second switching device is the same as the step S102 in the foregoing embodiment where the second switching device sends the first response message to the first switching device The process is the same and will not be repeated here.
  • the second response message includes the security policy of the port in the first switching device.
  • the second response message is only named for convenience of description, and is not used for limitation.
  • the first switching device provides the second switching device with a security policy of ports in the first switching device. That is, the second switching device obtains the security policy of the port in the first switching device.
  • the request message and the response message exchanged between the first switching device and the second switching device are both Fibre Channel (FC, Fiber) channel protocol messages.
  • the FC protocol packet includes the FC packet header and payload.
  • the FC protocol message may be specifically a Get Port Security Policy (Get Port Security Policies, GPSP) message.
  • GPSP messages are a type of FC protocol messages.
  • the FC packet header includes a routing control (R_CTL) field, a type special control (CS_CTL) field, a destination identifier (D_ID) field, a source identifier (S_ID) field, and a data structure type (TYPE) field. among them:
  • R_CTL field the value of this field in the request message is 02H, and the value of this field in the response message is 03H;
  • CS_CTL field the value is 00H
  • D_ID field and S_ID field the address of the destination switching device and the address of the source switching device, respectively;
  • TYPE field the value is 22H.
  • the payload of the request message includes a command code (Command Code) field.
  • the Command Code field carries an identifier, for example, the identifier is 70000004H, which is used to indicate that the current request packet is a packet for acquiring the security policy of the port.
  • the switching device that receives the request message determines that the request message is a message for acquiring the security policy of the port according to the identifier carried in the Command field, so as to provide the security policy of the port to the switching device that sent the request message.
  • the payload of the response message is shown in Table 3.
  • Table 3 is only an exemplary description.
  • port security policy entry 1 to port security policy entry n are entries of the port security policy table in the switching device.
  • the FC protocol message is extended as described above, so that the switching device can be based on the security policy of the FC protocol interaction port.
  • FIG. 5A it is a schematic diagram of a SAN shown in an embodiment of the present disclosure.
  • the node device is a server, storage device, or other switching device directly connected to the switching device;
  • the policy action is allow, indicating that the corresponding node device can log in to the network through the switching device;
  • the policy action is denying, indicating that the corresponding node device cannot pass the switching device Log in to the network.
  • the port security policy represented by the last entry is: prohibit the server 513 from accessing the network through any port.
  • the port identification or the identification of the node device is usually expressed by the World Wide Name (WWN).
  • WWN World Wide Name
  • the device name or port name shown in FIGS. 5A to 5C is used.
  • FIG. 5B it is a schematic diagram of another SAN shown in an embodiment of the present disclosure.
  • the switching device 522 and the switching device 523 in this network have been automatically merged or manually configured, and have the same port security policy, as shown in Table 5 and Table 6.
  • Table 5 is the security policy of the currently existing ports in the switching device 522;
  • Table 6 is the security policy of the currently existing ports in the switching device 523.
  • each switching device in FIG. 5C re-collects the network topology, and recalculates the route to each switching device based on the network topology, that is, the routing is completed Learn.
  • the switching device 521 learns the route to the address of the switching device 522 and the destination address to the address of the switching device 523; similarly, the switching device 522 learns the route to the address of the switching device 521 and the destination address It is the route of the address of the switching device 523; the switching device 523 learns the route to the address of the switching device 521 and the route of the destination address to the address of the switching device 522.
  • the switching device 521 to the switching device 523 compare the routes learned this time with the existing routes in their respective routing tables. For example, before the switching device 521 merges the network, there is no route in the routing table whose destination address is the address of the switching device 522, and no route whose destination address is the address of the switching device 523. Therefore, the switching device 521 may determine that the route learned this time with the destination address as the address of the switching device 522 and the route with the destination address as the address of the switching device 523 are newly added routes. Similarly, the switching device 522 may determine that the route with the destination address learned this time as the address of the switching device 521 is a newly added route. The switching device 523 may determine that the route with the destination address learned this time as the address of the switching device 521 is a newly added route.
  • the switching device 521 Based on the newly added route whose destination address is the address of the switching device 522, the switching device 521 sends a request message (denoted as Packet 11) to the switching device 522 to obtain the security policy of the port in the switching device 522.
  • the R_CTL field of the Packet 11 is 02H
  • the CS_CTL field is 00H
  • the D_ID field is the address of the switching device 522
  • the S_ID field is the address of the switching device 521
  • the TYPE field is 22H
  • the Command Code field is 70000004H.
  • the switching device 522 After receiving the Packet11, the switching device 522 determines that Packet11 is a request message based on the R_CTL field (02H). Based on the Command Code field (70000004H), it is determined that Packet 11 is a request message for acquiring the port security policy. That is, it is determined that the switching device 521 is to acquire the security policy of the port in the device. Therefore, the switching device 522 obtains the port security policy from the port security policy table (Table 5) maintained by itself. The switching device 522 sends a response message (denoted as Packet12) to the switching device 521.
  • a response message denoted as Packet12
  • the R_CTL field of the Packet12 is 03H
  • the CS_CTL field is 00H
  • the D_ID field is the address of the switching device 521
  • the S_ID field is the address of the switching device 522
  • the TYPE field It is 22H
  • the load is the security policy of the port obtained from Table 5.
  • the switching device 521 After receiving the Packet12, the switching device 521 determines that Packet12 is a response message based on the R_CTL field (03H), obtains the security policy of the port in the switching device 522 from the response message, and adds it to the local port security policy table. As shown in Table 7.
  • the switching device 521 Based on the newly added route whose destination address is the address of the switching device 523, the switching device 521 sends to the switching device 523 a request message (denoted as Packet21) for acquiring the security policy of the port in the switching device 523.
  • the R_CTL field of the Packet 21 is 02H
  • the CS_CTL field is 00H
  • the D_ID field is the address of the switching device 523
  • the S_ID field is the address of the switching device 521
  • the TYPE field is 22H
  • the Command Code field is 70000004H.
  • the switching device 523 After receiving the Packet 21, the switching device 523 determines that Packet 21 is a request message based on the R_CTL field (02H). Based on the Command Code field (70000004H), it is determined that Packet21 is a request message for acquiring the port security policy. That is, it is determined that the switching device 521 is to acquire the security policy of the port in the device. Therefore, the switching device 523 obtains the port security policy from the port security policy table (Table 6) maintained by itself. The switching device 523 sends a response message (denoted as Packet22) to the switching device 521.
  • a response message denoted as Packet22
  • the R_CTL field of the Packet22 is 03H
  • the CS_CTL field is 00H
  • the D_ID field is the address of the switching device 521
  • the S_ID field is the address of the switching device 523
  • the TYPE field It is 22H
  • the load is the security policy of the port obtained from Table 6.
  • the switching device 521 After receiving the Packet22, the switching device 521 determines that Packet22 is a response message based on the R_CTL field (03H), and obtains the security policy of the port in the switching device 523 from the response message. Since the security policy of the port in the switching device 523 is the same as the security policy of the port in the switching device 522, Table 6 does not need to be updated.
  • the switching device 522 Based on the newly added route whose destination address is the address of the switching device 521, the switching device 522 sends to the switching device 521 a request message (denoted as Packet 31) for acquiring the security policy of the port in the switching device 521.
  • the R_CTL field of this Packet 31 is 02H
  • the CS_CTL field is 00H
  • the D_ID field is the address of the switching device 521
  • the S_ID field is the address of the switching device 522
  • the TYPE field is 22H
  • the Command Code field is 70000004H.
  • the switching device 521 After receiving the Packet 31, the switching device 521 determines that Packet 31 is a request message based on the R_CTL field (02H). Based on the Command Field (70000004H), it is determined that Packet 31 is a request message for obtaining the port security policy. That is, it is determined that the switching device 522 is to acquire the security policy of the port in the device. Therefore, the switching device 521 obtains the port security policy from the port security policy table (Table 4) maintained by itself. The switching device 521 sends a response message (denoted as Packet32) to the switching device 522.
  • a response message denoted as Packet32
  • the R_CTL field of the Packet32 is 03H
  • the CS_CTL field is 00H
  • the D_ID field is the address of the switching device 522
  • the S_ID field is the address of the switching device 521
  • the TYPE field It is 22H
  • the load is the security policy of the port obtained from Table 4.
  • the switching device 522 After receiving the Packet32, the switching device 522 determines that Packet32 is a response message based on the R_CTL field (03H), obtains the security policy of the port in the switching device 521 from the response message, and adds it to the local port security policy table. As shown in Table 8.
  • the switching device 523 Based on the newly added route whose destination address is the address of the switching device 521, the switching device 523 sends a request message (denoted as Packet41) to the switching device 521 to obtain the security policy of the port in the switching device 521.
  • the R_CTL field of the Packet 41 is 02H
  • the CS_CTL field is 00H
  • the D_ID field is the address of the switching device 521
  • the S_ID field is the address of the switching device 523
  • the TYPE field is 22H
  • the Command Code field is 70000004H.
  • the switching device 521 After receiving the Packet41, the switching device 521 determines that Packet41 is a request message based on the R_CTL field (02H). Based on the Command Code field (70000004H), it is determined that Packet41 is a request message for acquiring the port security policy. That is, it is determined that the switching device 523 is to acquire the security policy of the port in the device. Therefore, the switching device 521 obtains the port security policy from the port security policy table (Table 4) maintained by itself. The switching device 521 sends a response message (denoted as Packet42) to the switching device 523.
  • a response message denoted as Packet42
  • the R_CTL field of the Packet42 is 03H
  • the CS_CTL field is 00H
  • the D_ID field is the address of the switching device 523
  • the S_ID field is the address of the switching device 521
  • the TYPE field It is 22H
  • the load is the security policy of the port obtained from Table 4.
  • the switching device 523 After receiving the Packet42, the switching device 523 determines that Packet42 is a response message based on the R_CTL field (03H), obtains the security policy of the port in the switching device 521 from the response message, and adds it to the local port security policy table. As shown in Table 9.
  • the server 513 cannot log in to the network through the switching device 521, the switching device 522, and the switching device 523.
  • FIG. 6 is a schematic structural diagram of an apparatus provided by an embodiment of the present disclosure.
  • the device includes: a sending unit 601, a receiving unit 602, and an adding unit 603, where:
  • the sending unit 601 is configured to send a first request message to the second switching device if it is detected that the second switching device accesses the SAN, and the first request message is used to obtain the second switching device Port security strategy;
  • the receiving unit 602 is configured to receive a first response message that the second switching device responds to according to the first request message, where the first response message includes the security policy of the port in the second switching device;
  • the adding unit 603 is configured to add the security policy of the port in the second switching device to the port security policy table of the first switching device.
  • the device further includes:
  • the learning unit is used to learn the routing of the switching equipment in the SAN;
  • An obtaining unit configured to obtain a destination address included in the route if there is a newly added route, and the destination address included in the route is an address of a switching device;
  • the determining unit is configured to determine the switching device corresponding to the destination address as the second switching device.
  • the receiving unit 602 is further configured to receive a second request packet sent by the second switching device, and the second request packet is used to obtain a security policy of a port in the first switching device ;
  • An obtaining unit configured to obtain the security policy of the port in the first switching device according to the second request message
  • the sending unit 601 is further configured to send a second response message to the second switching device, where the second response message includes the security policy of the port in the first switching device.
  • both the request message and the response message are FC protocol messages
  • the request message carries an identifier indicating that the request message is a message used to obtain the security policy of the port.
  • the first switching device when sensing that the second switching device accesses the SAN, uses the message interaction with the second switching device to obtain the security policy of the port in the second switching device to implement the port
  • the security policies of the port are automatically merged to improve the efficiency of port port security policies.
  • the switching device 700 may include a processor 701, a machine-readable storage medium 702 storing machine-executable instructions, and one or more input/output ports (not shown in the figure).
  • the processor 701 and the machine-readable storage medium 702 and the input/output ports can communicate via the system bus 703. And, by reading and executing the machine-executable instructions in the machine-readable storage medium 702 corresponding to the security policy merge logic of the port, the processor 701 can execute the security policy merge method of the port described above.
  • the switching device 700 If the switching device 700 detects that another switching device newly accesses the SAN, the switching device 700 sends a first request message to the newly accessed switching device to obtain the security policy of the port in the new switching device. After receiving the first request message, the new switching device carries the port security policy in the first response message and responds. The switching device 700 obtains the security policy of the port in the new access switching device by analyzing the received first response message, and adds the obtained security policy to the local port security policy table.
  • the switching device 700 may determine whether a new device is connected to the SAN by learning the routing of the switching device in the SAN. If there is a newly added route, the destination address included in the route is obtained, and the destination address included in the route is the address of the new access switching device. The switching device 700 determines the switching device corresponding to the acquired destination address as the new access switching device.
  • the switching device 700 receives the second request message sent by the new access switching device, and the second request message is used to obtain the security policy of the port in the switching device 700.
  • the switching device 700 sends a second response message to the new access switching device, where the second response message includes the security policy of the port in the switching device 700.
  • the request message and the response message are both Fibre Channel FC protocol messages; wherein, the request message carries an identifier indicating that the request message is a message used to obtain the security policy of the port .
  • the machine-readable storage medium 702 mentioned herein may be any electronic, magnetic, optical, or other physical storage device, and may contain or store information, such as executable instructions, data, and so on.
  • the machine-readable storage medium 702 may include at least one of the following storage media: volatile memory, non-volatile memory, and other types of storage media.
  • volatile memory can be RAM (Random Access Memory, random access memory)
  • non-volatile memory can be flash memory
  • storage drives such as hard drives
  • solid state hard drives storage disks (such as optical disks, DVDs, etc.).
  • Embodiments of the present disclosure also provide a machine-readable storage medium including machine-executable instructions, such as the machine-readable storage medium 702 in FIG. 7, the machine-executable instructions may be executed by the processor 701 in the switching device to implement The port security policy merging method described above.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本公开提供一种端口的安全策略合并方法,应用于存储区域网络SAN中的第一交换设备。若检测到第二交换设备接入SAN,向第二交换设备发送第一请求报文,第一请求报文用于获取所述第二交换设备中端口的安全策略。接收第二交换设备根据第一请求报文回应的第一响应报文,第一响应报文包括第二交换设备中端口的安全策略。将第二交换设备中端口的安全策略,添加到第一交换设备的端口安全策略表中。

Description

端口的安全策略合并 背景技术
存储区域网络(Storage Area Network,SAN)是用于提供服务器与存储设备之间进行数据传输的专用网络。SAN中的服务器和存储设备通过交换机连接。
为了保障SAN的网络安全,通常引入端口安全技术,以提供基于端口级别的安全控制。端口安全技术主要是指:建立交换机上的端口与通过该端口直接接入交换机的设备的绑定关系,作为端口的安全策略的一部分,以允许符合端口的安全策略的设备通过交换机登陆SAN。
在实际应用中,会有网络合并的情况。比如,将SAN1与SAN2合并。此时,需要对SAN1和SAN2中各个交换机的端口的安全策略进行合并,以达到合并后各交换机中端口的安全策略一致的效果。例如,设备A原本在SAN1中不允许通过交换机登录网络,网络合并后该设备A依然无法通过SAN2中的交换机登录网络。
目前,合并端口的安全策略的操作需要人工手动完成,合并效率不高,且容易出错。
附图说明
为了更清楚地说明本公开实施例中的技术方案,下面将对实施例描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本公开的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1是本公开实施例示出的一种端口的安全策略合并方法流程图。
图2是本公开实施例示出的第一交换设备检测第二交换设备的实现流程。
图3是本公开实施例示出的第一交换设备向第二交换设备提供端口的安全策略的实现流程。
图4是本公开实施例示出的FC协议报文示例。
图5A是本公开实施例示出的一个SAN的示意图。
图5B是本公开实施例示出的另一个SAN的示意图。
图5C是本公开实施例示出的图5A和图5B合并后的SAN网络的示意图。
图6是本公开实施例示出的一种端口的安全策略合并装置的结构示意图。
图7是本公开实施例示出的一种交换设备的硬件结构示意图。
具体实施方式
这里将详细地对示例性实施例进行说明,其示例表示在附图中。下面的描述涉及附图时,除非另有表示,不同附图中的相同数字表示相同或相似的要素。以下示例性实施例中所描述的实施方式并不代表与本公开相一致的所有实施方式。相反,它们仅是与如所附权利要求书中所详述的、本公开的一些方面相一致的装置和方法的例子。
在本公开实施例使用的术语是仅仅出于描述特定实施例的目的,而非旨在限制本公开实施例。在本公开实施例和所附权利要求书中所使用的单数形式的“一种”、“所述”和“该”也旨在包括多数形式,除非上下文清楚地表示其他含义。还应当理解,本文中使用的术语“和/或”是指并包含一个或多个相关联的列出项目的任何或所有可能组合。
应当理解,尽管在本公开实施例可能采用术语第一、第二、第三等来描述各种信息,但这些信息不应限于这些术语。这些术语仅用来将同一类型的信息彼此区分开。例如,在不脱离本公开实施例范围的情况下,第一信息也可以被称为第二信息,类似地,第二信息也可以被称为第一信息。取决于语境,如在此所使用的词语“如果”可以被解释成为“在……时”或“当……时”或“响应于确定”。
本公开实施例提供一种端口的安全策略合并方法。该方法中,第一交换设备在感知到第二交换设备接入SAN时,利用与第二交换设备之间的报文交互,获取第二交换设备中端口的安全策略,以实现端口的安全策略自动合并,提升端口的安全策略的合并效率。
为了使本公开实施例的目的、技术方案和优点更加清楚,下面结合附图和具体实施例对本公开实施例执行详细描述:
参见图1,为本公开实施例提供的端口的安全策略合并方法流程图。该流程应用于SAN中的第一交换设备。
如图1所示,该流程可包括以下步骤:
步骤S101,若检测到第二交换设备接入SAN,第一交换设备向第二交换设备发送第一请求报文。
当第一交换设备检测到第二交换设备接入SAN时,第一交换设备需获取第二交换设备中端口的安全策略,此时,第一交换设备生成第一请求报文。该第一请求报文用于获取第二交换设备中端口的安全策略。
第一交换设备向第二交换设备发送第一请求报文。
这里,第一交换设备、第二交换设备、第一请求报文只是为便于描述而进行的命名,并非用于限定。
第一交换设备检测第二交换设备的过程在下文描述,这里暂不赘述。
步骤S102,第一交换设备接收第二交换设备根据第一请求报文回应的第一响应报文。
在本公开实施例中,第二交换设备接收到步骤S101中的第一请求报文后,对第一请求报文进行解析,确定第一交换设备需获取第二交换设备自身端口的安全策略。第二交换设备获取端口的安全策略,并生成第一响应报文。可以理解的是,第一响应报文包括第二交换设备中端口的安全策略。
第二交换设备向第一交换设备发送第一响应报文。这里,第一响应报文只是为便于描述而进行的命名,并非用于限定。
作为示例而非限定,端口的安全策略可存储在第二交换设备中的端口安全策略表里。第二交换设备可直接从端口安全策略表中,获取第二交换设备的端口的安全策略。
参见表1,为交换设备中的端口安全策略表示例。
Figure PCTCN2019119996-appb-000001
表1
其中,每一条表项代表一个端口安全策略。比如,第一条表项表示的端口安全策略为:允许服务器1通过交换设备1的端口1接入网络。
步骤S103,第一交换设备将第二交换设备中端口的安全策略,添加到第一交换设备的端口安全策略表中。
第一交换设备接收到第一响应报文后,解析并从中获取第二交换设备中端口的安全策略。第一交换设备将获取的端口的安全策略,添加到本交换设备的端口安全策略表中,即完成对端口的安全策略的合并。
第一交换设备根据合并后的端口的安全策略,确定网络设备是否可以通过第一交换设备登录网络。
至此,完成图1所示流程。
通过图1所示流程可以看出,在本公开实施例中,第一交换设备在感知到第二交换设备接入SAN时,利用与第二交换设备之间的报文交互,获取第二交换设备中端口的安全策略,以实现端口的安全策略的自动合并,提升端口的安全策略的合并效率。
下面对第一交换设备检测第二交换设备的过程进行具体描述。参见图2,为本公开实施例示出的第一交换设备检测第二交换设备的实现流程,通过检测交换设备接入SAN的过程,可使第一交换设备快速发现新接入的交换设备,并获取到该交换设备的端口的安全策略。
如图2所示,该流程可包括以下步骤:
步骤S201,第一交换设备学习SAN中各个交换设备的路由。
当存在新的交换设备接入SAN时,SAN中的各个交换设备会重新收集网络拓扑,并基于收集到的网络拓扑重新计算路由。即新的交换设备的接入触发SAN中各交换设备重新学习路由。
第一交换设备将本次学习到的路由与路由表中已存在的路由进行比较,若此次学习到的路由未记录在路由表中,说明该路由为新学习到的路由,即新增的路由,将该新增的路由添加到路由表中。
路由包括的目的地址为交换设备的地址。
步骤S202,若存在新增的路由,第一交换设备获取该路由包括的目的地址。
步骤S203,第一交换设备将目的地址对应的交换设备确定为第二交换设备。
如前所述,路由包括的目的地址为交换设备的地址,因此,第一交换设备可根据从新增路由中获取到的目的地址,确定该目的地址对应的交换设备为接入SAN的交换设 备,即第二交换设备。
至此,完成图2所示流程。
通过图2所示流程,实现对第二交换设备的检测。
参见图3,为本公开实施例示出的第一交换设备向第二交换设备提供端口的安全策略的实现流程。
如图3所示,该流程可包括以下步骤:
步骤S301,第一交换设备接收第二交换设备发送的第二请求报文。
该第二请求报文用于获取第一交换设备中端口的安全策略。
需要说明的是,本公开实施例中,第二交换设备发送第二请求报文、第一交换设备接收第二请求报文的过程与前述实施例步骤101相同,在此不再复述。
这里,第二请求报文只是为便于描述而进行的命名,并非用于限定。
步骤S302,根据第二请求报文,第一交换设备获取第一交换设备中端口的安全策略。
需要说明的是,本公开实施例中,第一交换设备获取自身端口的安全策略的过程与前述实施例步骤102中第二交换设备获取自身端口的安全策略的过程相同,在此不再复述。
步骤S303,第一交换设备向第二交换设备发送第二响应报文。
需要说明的是,本公开实施例中,第一交换设备向第二交换设备发送第二响应报文的过程与前述实施例步骤S102中第二交换设备向第一交换设备发送第一响应报文的过程相同,在此不再复述。
第二响应报文包括第一交换设备中端口的安全策略。
这里,第二响应报文只是为便于描述而进行的命名,并非用于限定。
至此,完成图3所示流程。
通过图3所示流程,实现第一交换设备向第二交换设备提供第一交换设备中端口的安全策略。即第二交换设备获取到第一交换设备中端口的安全策略。
可选的,作为一个实施例,第一交换设备和第二交换设备之间交互的请求报文和响应报文均为光纤通道(FC,Fiber channel)协议报文。
参见图4,为FC协议报文示例。
FC协议报文包括FC报文头和负载。在本公开实施例中该FC协议报文可具体为获取端口安全策略(Get Port Security Policies,GPSP)报文。为了方便描述,下文以FC协议报文说明。GPSP报文为FC协议报文中的一种类型。
FC报文头包括路由控制(R_CTL)字段、类型特殊控制(CS_CTL)字段、目的标识符(D_ID)字段、源标识符(S_ID)字段以及数据结构类型(TYPE)字段。其中:
R_CTL字段:请求报文中该字段的值为02H,响应报文中该字段的值为03H;
CS_CTL字段:值为00H;
D_ID字段和S_ID字段:分别为目的交换设备的地址和源交换设备的地址;
TYPE字段:值为22H。
请求报文的负载,如表2所述,包括命令码(Command Code)字段。Command Code字段携带标识,比如,标识为70000004H,用于表示当前请求报文为获取端口的安全策略的报文。接收到请求报文的交换设备根据Command Code字段携带的标识,确定请求报文为用于获取端口的安全策略的报文,从而向发送该请求报文的交换设备提供端口的安全策略。
负载内容 字节数(Bytes)
70000004H 4
表2
响应报文的负载,如表3所示。表3仅为示例性说明。
负载内容 字节数(Bytes)
端口安全策略表项的数量 4
端口安全策略表项1 20
…… 20
端口安全策略表项n 20
表3
其中,端口安全策略表项1~端口安全策略表项n为交换设备中端口安全策略表的表 项。
本公开实施例通过对FC协议报文进行上述扩展,使交换设备之间可基于FC协议交互端口的安全策略。
下面通过具体实施例对本公开实施例提供的方法进行描述:
参见图5A,为本公开实施例示出的一个SAN的示意图。
图5A中,交换设备521当前已有的端口的安全策略,如表4所示。
Figure PCTCN2019119996-appb-000002
表4
其中,节点设备为与交换设备直连的服务器、存储设备或者其它交换设备;策略行为为允许,表示对应节点设备可以通过交换设备登录网络;策略行为为拒绝,表示对应节点设备不可以通过交换设备登录网络。比如,最后一条表项所代表的端口安全策略为:禁止服务器513通过任意端口接入网络。
需要说明的是,在SAN中,端口标识或节点设备的标识通常利用全球名字(World Wide Name,WWN)表示。本公开实施例中,为了更加直观的展现交换设备与节点设备的绑定关系(即端口的安全策略),利用图5A~图5C中示出的设备名称或端口名称表示。
参见图5B,为本公开实施例示出的另一个SAN的示意图。该组网中的交换设备522和交换设备523已通过自动合并或手动配置,具有相同的端口的安全策略,如表5和表6所示。
Figure PCTCN2019119996-appb-000003
表5
Figure PCTCN2019119996-appb-000004
表6
其中,表5为交换设备522中当前已有的端口的安全策略;表6为交换设备523中当前已有的端口的安全策略。
若将图5A与图5B所示SAN网络合并(合并后如图5C所示),图5C中的各个交换设备重新收集网络拓扑,并基于网络拓扑重新计算到各个交换设备的路由,即完成路由学习。
交换设备521学习到达目的地址为交换设备522的地址的路由,以及目的地址为交换设备523的地址的路由;同理,交换设备522学习到达目的地址为交换设备521的地址的路由,以及目的地址为交换设备523的地址的路由;交换设备523学习到达目的地址为交换设备521的地址的路由,以及目的地址为交换设备522的地址的路由。
交换设备521~交换设备523分别将本次学习到的路由与各自路由表中的已有路由进行比较。比如,交换设备521在网络合并之前,路由表中没有目的地址为交换设备522的地址的路由,也没有目的地址为交换设备523的地址的路由。因此,交换设备521可确定此次学习到的目的地址为交换设备522的地址的路由、目的地址为交换设备523的地址的路由均为新增路由。同理,交换设备522可确定此次学习到的目的地址为交换设备521的地址的路由为新增路由。交换设备523可确定此次学习到的目的地址为交换设备521的地址的路由为新增路由。
如前所述,交换设备521中存在两条新增路由。
交换设备521基于目的地址为交换设备522的地址的新增路由,向交换设备522发送获取交换设备522中端口的安全策略的请求报文(记为Packet11)。该Packet11的R_CTL字段为02H,CS_CTL字段为00H,D_ID字段为交换设备522的地址,S_ID字段为交换设备521的地址,TYPE字段为22H,Command Code字段为70000004H。
交换设备522接收到Packet11后,基于R_CTL字段(02H),确定Packet11为请求报文。基于Command Code字段(70000004H),确定Packet11为用于获取端口安全策略的请求报文。即确定交换设备521是要获取本设备中的端口的安全策略。因此,交换设备522从自身维护的端口安全策略表(表5)中获取端口的安全策略。交换设备522 向交换设备521发送响应报文(记为Packet12),该Packet12的R_CTL字段为03H,CS_CTL字段为00H,D_ID字段为交换设备521的地址,S_ID字段为交换设备522的地址,TYPE字段为22H,负载为从表5中获取的端口的安全策略。
交换设备521接收到Packet12后,基于R_CTL字段(03H),确定Packet12为响应报文,从该响应报文中获取到交换设备522中端口的安全策略,并添加到本地的端口安全策略表中,如表7所示。
Figure PCTCN2019119996-appb-000005
表7
交换设备521基于目的地址为交换设备523的地址的新增路由,向交换设备523发送获取交换设备523中端口的安全策略的请求报文(记为Packet21)。该Packet21的R_CTL字段为02H,CS_CTL字段为00H,D_ID字段为交换设备523的地址,S_ID字段为交换设备521的地址,TYPE字段为22H,Command Code字段为70000004H。
交换设备523接收到Packet21后,基于R_CTL字段(02H),确定Packet21为请求报文。基于Command Code字段(70000004H),确定Packet21为用于获取端口安全策略的请求报文。即确定交换设备521是要获取本设备中的端口的安全策略。因此,交换设备523从自身维护的端口安全策略表(表6)中获取端口的安全策略。交换设备523向交换设备521发送响应报文(记为Packet22),该Packet22的R_CTL字段为03H,CS_CTL字段为00H,D_ID字段为交换设备521的地址,S_ID字段为交换设备523的地址,TYPE字段为22H,负载为从表6中获取的端口的安全策略。
交换设备521接收到Packet22后,基于R_CTL字段(03H),确定Packet22为响应报文,从该响应报文中获取到交换设备523中端口的安全策略。由于交换设备523中端口的安全策略与交换设备522中端口的安全策略相同,因此,表6不需要更新。
交换设备522基于目的地址为交换设备521的地址的新增路由,向交换设备521发送获取交换设备521中端口的安全策略的请求报文(记为Packet31)。该Packet31的R_CTL字段为02H,CS_CTL字段为00H,D_ID字段为交换设备521的地址,S_ID字 段为交换设备522的地址,TYPE字段为22H,Command Code字段为70000004H。
交换设备521接收到Packet31后,基于R_CTL字段(02H),确定Packet31为请求报文。基于Command Code字段(70000004H),确定Packet31为用于获取端口安全策略的请求报文。即确定交换设备522是要获取本设备中的端口的安全策略。因此,交换设备521从自身维护的端口安全策略表(表4)中获取端口的安全策略。交换设备521向交换设备522发送响应报文(记为Packet32),该Packet32的R_CTL字段为03H,CS_CTL字段为00H,D_ID字段为交换设备522的地址,S_ID字段为交换设备521的地址,TYPE字段为22H,负载为从表4中获取的端口的安全策略。
交换设备522接收到Packet32后,基于R_CTL字段(03H),确定Packet32为响应报文,从该响应报文中获取到交换设备521中端口的安全策略,并添加到本地的端口安全策略表中,如表8所示。
Figure PCTCN2019119996-appb-000006
表8
交换设备523基于目的地址为交换设备521的地址的新增路由,向交换设备521发送获取交换设备521中端口的安全策略的请求报文(记为Packet41)。该Packet41的R_CTL字段为02H,CS_CTL字段为00H,D_ID字段为交换设备521的地址,S_ID字段为交换设备523的地址,TYPE字段为22H,Command Code字段为70000004H。
交换设备521接收到Packet41后,基于R_CTL字段(02H),确定Packet41为请求报文。基于Command Code字段(70000004H),确定Packet41为用于获取端口安全策略的请求报文。即确定交换设备523是要获取本设备中的端口的安全策略。因此,交换设备521从自身维护的端口安全策略表(表4)中获取端口的安全策略。交换设备521向交换设备523发送响应报文(记为Packet42),该Packet42的R_CTL字段为03H,CS_CTL字段为00H,D_ID字段为交换设备523的地址,S_ID字段为交换设备521的地址,TYPE字段为22H,负载为从表4中获取的端口的安全策略。
交换设备523接收到Packet42后,基于R_CTL字段(03H),确定Packet42为响 应报文,从该响应报文中获取到交换设备521中端口的安全策略,并添加到本地的端口安全策略表中,如表9所示。
Figure PCTCN2019119996-appb-000007
表9
至此,完成图5C中所有交换设备中端口的安全策略的合并。
合并后,服务器513通过交换设备521、交换设备522、交换设备523均无法登录网络。
以上对本公开实施例提供的方法进行了描述,下面对本公开实施例提供的装置进行描述:
参见图6,为本公开实施例提供的装置的结构示意图。该装置包括:发送单元601、接收单元602以及添加单元603,其中:
发送单元601,用于若检测到第二交换设备接入所述SAN,向所述第二交换设备发送第一请求报文,所述第一请求报文用于获取所述第二交换设备中端口的安全策略;
接收单元602,用于接收所述第二交换设备根据所述第一请求报文回应的第一响应报文,所述第一响应报文包括所述第二交换设备中端口的安全策略;
添加单元603,用于将所述第二交换设备中端口的安全策略,添加到所述第一交换设备的端口安全策略表中。
作为一个实施例,所述装置还包括:
学习单元,用于学习所述SAN中交换设备的路由;
获取单元,用于若存在新增的路由,获取所述路由包括的目的地址,所述路由包括的目的地址为交换设备的地址;
确定单元,用于将所述目的地址对应的交换设备确定为所述第二交换设备。
作为一个实施例,所述接收单元602,还用于接收所述第二交换设备发送的第二请 求报文,所述第二请求报文用于获取所述第一交换设备中端口的安全策略;
获取单元,用于根据所述第二请求报文,获取所述第一交换设备中端口的安全策略;
所述发送单元601,还用于向所述第二交换设备发送第二响应报文,所述第二响应报文包括所述第一交换设备中端口的安全策略。
作为一个实施例,所述请求报文和所述响应报文均为FC协议报文;
其中,所述请求报文携带用于表示所述请求报文为用于获取端口的安全策略的报文的标识。
至此,完成图6所示装置的描述。在本公开实施例中,第一交换设备在感知到第二交换设备接入SAN时,利用与第二交换设备之间的报文交互,获取第二交换设备中端口的安全策略,以实现端口的安全策略自动合并,提升端口的安全策略的合并效率。
下面对本公开实施例提供的交换设备进行描述:
参见图7,为本公开实施例提供的一种交换设备的硬件结构示意图。该交换设备700可包括处理器701、存储有机器可执行指令的机器可读存储介质702以及一个或多个输入/输出端口(图中未示出)。处理器701与机器可读存储介质702以及输入/输出端口可经由系统总线703通信。并且,通过读取并执行机器可读存储介质702中与端口的安全策略合并逻辑对应的机器可执行指令,处理器701可执行上文描述的端口的安全策略合并方法。
在本示例中对交换设备700的操作进行描述。若交换设备700检测到有另一交换设备新接入SAN,则交换设备700向新接入的交换设备发送第一请求报文,以获取该新的交换设备中端口的安全策略。新的交换设备接收到第一请求报文后,将端口安全策略携带在第一响应报文中进行回应。交换设备700通过分析接收的第一响应报文获取该新接入交换设备中端口的安全策略,并将获取的安全策略添加到本地的端口安全策略表中。
交换设备700可以通过学习SAN中交换设备的路由来确定是否有新的设备接入SAN。若存在新增的路由,则获取所述路由包括的目的地址,所述路由包括的目的地址为新接入交换设备的地址。交换设备700将获取的目的地址对应的交换设备确定为新接入交换设备。
交换设备700接收新接入交换设备发送的第二请求报文,所述第二请求报文用 于获取交换设备700中端口的安全策略。交换设备700向新接入交换设备发送第二响应报文,所述第二响应报文包括交换设备700中端口的安全策略。
在一个示例中,上述请求报文和响应报文均为光纤通道FC协议报文;其中,所述请求报文携带了用于表示请求报文为用于获取端口的安全策略的报文的标识。
本文提到的机器可读存储介质702可以是任何电子、磁性、光学或其他物理存储装置,可以包含或存储信息,如可执行指令、数据,等等。例如,所述机器可读存储介质702可以包括如下至少一个种存储介质:易失存储器、非易失性存储器、其它类型存储介质。其中,易失性存储器可为RAM(Random Access Memory,随机存取存储器),非易失性存储器可为闪存、存储驱动器(如硬盘驱动器)、固态硬盘、存储盘(如光盘、DVD等)。
本公开实施例还提供一种包括机器可执行指令的机器可读存储介质,例如图7中的机器可读存储介质702,所述机器可执行指令可由交换设备中的处理器701执行,以实现以上描述的端口的安全策略合并方法。
至此,完成图7所示设备的描述。
以上所述仅为本公开实施例的较佳实施例而已,并不用以限制本公开,凡在本公开实施例的精神和原则之内,所做的任何修改、等同替换、改进等,均应包含在本公开保护的范围之内。

Claims (13)

  1. 一种端口的安全策略合并方法,应用于存储区域网络SAN中的第一交换设备,其特征在于,所述方法包括:
    若检测到第二交换设备接入所述SAN,向所述第二交换设备发送第一请求报文,所述第一请求报文用于获取所述第二交换设备中端口的安全策略;
    接收所述第二交换设备根据所述第一请求报文回应的第一响应报文,所述第一响应报文包括所述第二交换设备中端口的安全策略;
    将所述第二交换设备中端口的安全策略,添加到所述第一交换设备的端口安全策略表中。
  2. 如权利要求1所述的方法,其特征在于,所述向所述第二交换设备发送第一请求报文之前,还包括:
    学习所述SAN中交换设备的路由;
    若存在新增的路由,获取所述路由包括的目的地址,所述路由包括的目的地址为交换设备的地址;
    将所述目的地址对应的交换设备确定为所述第二交换设备。
  3. 如权利要求1所述的方法,其特征在于,所述方法还包括:
    接收所述第二交换设备发送的第二请求报文,所述第二请求报文用于获取所述第一交换设备中端口的安全策略;
    根据所述第二请求报文,获取所述第一交换设备中端口的安全策略;
    向所述第二交换设备发送第二响应报文,所述第二响应报文包括所述第一交换设备中端口的安全策略。
  4. 如权利要求1所述的方法,其特征在于:所述请求报文和所述响应报文均为光纤通道FC协议报文;
    其中,所述请求报文携带用于表示所述请求报文为用于获取端口的安全策略的报文的标识。
  5. 一种端口的安全策略合并装置,应用于存储区域网络SAN中的第一交换设备,其特征在于,所述装置包括:
    发送单元,用于若检测到第二交换设备接入所述SAN,向所述第二交换设备发送第一请求报文,所述第一请求报文用于获取所述第二交换设备中端口的安全策略;
    接收单元,用于接收所述第二交换设备根据所述第一请求报文回应的第一响应报文,所述第一响应报文包括所述第二交换设备中端口的安全策略;
    添加单元,用于将所述第二交换设备中端口的安全策略,添加到所述第一交换设备的端口安全策略表中。
  6. 如权利要求5所述的装置,其特征在于,所述装置还包括:
    学习单元,用于学习所述SAN中交换设备的路由;
    获取单元,用于若存在新增的路由,获取所述路由包括的目的地址,所述路由包括的目的地址为交换设备的地址;
    确定单元,用于将所述目的地址对应的交换设备确定为所述第二交换设备。
  7. 如权利要求5所述的装置,其特征在于,所述装置还包括:获取单元,
    所述接收单元,还用于接收所述第二交换设备发送的第二请求报文,所述第二请求报文用于获取所述第一交换设备中端口的安全策略;
    所述获取单元,用于根据所述第二请求报文,获取所述第一交换设备中端口的安全策略;
    所述发送单元,还用于向所述第二交换设备发送第二响应报文,所述第二响应报文包括所述第一交换设备中端口的安全策略。
  8. 如权利要求5所述的装置,其特征在于:
    所述请求报文和所述响应报文均为光纤通道FC协议报文;
    其中,所述请求报文携带用于表示所述请求报文为用于获取端口的安全策略的报文的标识。
  9. 一种交换设备,其特征在于,所述交换设备包括:
    处理器;以及
    机器可读存储介质,所述机器可读存储介质存储有能够被所述处理器执行的机器可执行指令,
    其中,通过读取并执行所述机器可执行指令,所述处理器被促使:
    若检测到另一交换设备接入所述交换设备所在的存储区域网络SAN,向所述另一交换设备发送第一请求报文,所述第一请求报文用于获取所述另一交换设备中端口的安全策略;
    接收所述另一交换设备根据所述第一请求报文回应的第一响应报文,所述第一响应报文包括所述另一交换设备中端口的安全策略;
    将所述另一交换设备中端口的安全策略,添加到所述交换设备的端口安全策略表中。
  10. 如权利要求9所述的设备,其特征在于,在向所述另一交换设备发送第一请求报文之前,所述处理器还被所述机器可执行指令促使:
    学习所述SAN中交换设备的路由;
    若存在新增的路由,获取所述路由包括的目的地址,所述路由包括的目的地址为交换设备的地址;
    将所述目的地址对应的交换设备确定为所述另一交换设备。
  11. 如权利要求9所述的设备,其特征在于,所述处理器还被所述机器可执行指令促使:
    接收所述另一交换设备发送的第二请求报文,所述第二请求报文用于获取所述交换设备中端口的安全策略;
    根据所述第二请求报文,获取所述交换设备中端口的安全策略;
    向所述另一交换设备发送第二响应报文,所述第二响应报文包括所述交换设备中端口的安全策略。
  12. 如权利要求9所述的设备,其特征在于:所述请求报文和所述响应报文均为光纤通道FC协议报文;
    其中,所述请求报文携带用于表示所述请求报文为用于获取端口的安全策略的报文的标识。
  13. 一种机器可读存储介质,其特征在于,所述机器可读存储介质内存储有机器可执行指令,所述机器可执行指令被处理器执行时实现权利要求1-4任一所述的方法步骤。
PCT/CN2019/119996 2018-11-26 2019-11-21 端口的安全策略合并 Ceased WO2020108382A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201811415014.4 2018-11-26
CN201811415014.4A CN110611646B (zh) 2018-11-26 2018-11-26 一种端口的安全策略合并方法、装置及交换设备

Publications (1)

Publication Number Publication Date
WO2020108382A1 true WO2020108382A1 (zh) 2020-06-04

Family

ID=68888967

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2019/119996 Ceased WO2020108382A1 (zh) 2018-11-26 2019-11-21 端口的安全策略合并

Country Status (2)

Country Link
CN (1) CN110611646B (zh)
WO (1) WO2020108382A1 (zh)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050091353A1 (en) * 2003-09-30 2005-04-28 Gopisetty Sandeep K. System and method for autonomically zoning storage area networks based on policy requirements
US7817583B2 (en) * 2003-04-28 2010-10-19 Hewlett-Packard Development Company, L.P. Method for verifying a storage area network configuration
CN108092810A (zh) * 2017-12-13 2018-05-29 锐捷网络股份有限公司 一种虚拟机管理方法、vtep设备及管理设备
CN108259545A (zh) * 2017-01-13 2018-07-06 新华三技术有限公司 端口安全策略扩散方法及装置

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103795644B (zh) * 2014-01-27 2017-04-05 福建星网锐捷网络有限公司 策略表表项配置方法、装置及系统
CN104038424B (zh) * 2014-06-03 2018-02-09 新华三技术有限公司 一种下线报文的处理方法和设备
US10536357B2 (en) * 2015-06-05 2020-01-14 Cisco Technology, Inc. Late data detection in data center
CN105939268B (zh) * 2015-10-28 2019-11-08 杭州迪普科技股份有限公司 一种二层转发表项聚合方法及装置
CN106254244B (zh) * 2016-07-28 2020-01-07 上海斐讯数据通信技术有限公司 一种基于sdn网络的合并流表项方法
CN108616587B (zh) * 2018-04-24 2022-01-25 新华三技术有限公司 一种表项同步方法、装置及网络设备

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7817583B2 (en) * 2003-04-28 2010-10-19 Hewlett-Packard Development Company, L.P. Method for verifying a storage area network configuration
US20050091353A1 (en) * 2003-09-30 2005-04-28 Gopisetty Sandeep K. System and method for autonomically zoning storage area networks based on policy requirements
CN108259545A (zh) * 2017-01-13 2018-07-06 新华三技术有限公司 端口安全策略扩散方法及装置
CN108092810A (zh) * 2017-12-13 2018-05-29 锐捷网络股份有限公司 一种虚拟机管理方法、vtep设备及管理设备

Also Published As

Publication number Publication date
CN110611646B (zh) 2020-07-07
CN110611646A (zh) 2019-12-24

Similar Documents

Publication Publication Date Title
EP3461072B1 (en) Access control in a vxlan
JP6498230B2 (ja) フレキシブルなhdd/ssdストレージサポートのシステムおよび方法
US8566257B2 (en) Address data learning and registration within a distributed virtual bridge
US9871721B2 (en) Multicasting a data message in a multi-site network
US8131833B2 (en) Managing communication between nodes in a virtual network
JP5804061B2 (ja) 通信システム、制御装置、通信方法およびプログラム
EP3451592B1 (en) Packet transmission between vxlan domains
US9998375B2 (en) Transactional controls for supplying control plane data to managed hardware forwarding elements
US12052180B2 (en) Managing network state for high flow availability within distributed network platform
CN107820043B (zh) 视频监控系统的控制方法、装置及系统
CN103259725A (zh) 报文发送方法和网络设备
US20220210005A1 (en) Synchronizing communication channel state information for high flow availability
US11296981B2 (en) Serverless packet processing service with configurable exception paths
CN105490995A (zh) 一种在nvo3网络中nve转发报文的方法和设备
US20250062988A1 (en) Service chaining in fabric networks
CN112187635B (zh) 报文转发方法及装置
CN109922074B (zh) 接入带外管理网络的方法和装置、管理方法、设备、介质
CN104219159A (zh) 基于虚拟局域网的虚拟接口进行链路聚合方法和装置
US10764330B2 (en) LAN/SAN network security management
US8606890B2 (en) Managing communication between nodes in a virtual network
WO2020108382A1 (zh) 端口的安全策略合并
US9077741B2 (en) Establishing communication between entities in a shared network
JP4485875B2 (ja) ストレージ接続変更方法、ストレージ管理システム及びプログラム
WO2020119317A1 (zh) 报文转发方法及装置、存储介质、电子装置
CN120811980B (zh) 一种带宽限速方法、装置、设备、介质和产品

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19888491

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 19888491

Country of ref document: EP

Kind code of ref document: A1