WO2020248368A1 - 一种内网访问方法、系统及相关装置 - Google Patents

一种内网访问方法、系统及相关装置 Download PDF

Info

Publication number
WO2020248368A1
WO2020248368A1 PCT/CN2019/102346 CN2019102346W WO2020248368A1 WO 2020248368 A1 WO2020248368 A1 WO 2020248368A1 CN 2019102346 W CN2019102346 W CN 2019102346W WO 2020248368 A1 WO2020248368 A1 WO 2020248368A1
Authority
WO
WIPO (PCT)
Prior art keywords
intranet
firewall
access device
mobile wireless
wireless access
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2019/102346
Other languages
English (en)
French (fr)
Inventor
范安心
谢文
黄成尧
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Ping An Technology Shenzhen Co Ltd
Original Assignee
Ping An Technology Shenzhen Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Ping An Technology Shenzhen Co Ltd filed Critical Ping An Technology Shenzhen Co Ltd
Publication of WO2020248368A1 publication Critical patent/WO2020248368A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0227Filtering policies
    • H04L63/0236Filtering by address, protocol, port number or service, e.g. IP-address or URL
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources

Definitions

  • This application relates to the computer field, and in particular to an intranet access method, system and related devices.
  • VPN Virtual Private Network
  • This application provides an intranet access method, system, and related devices, through which the access efficiency for the target intranet can be improved.
  • the first aspect of the embodiments of the present application provides an intranet access method, including:
  • the intranet firewall distribution device receives the intranet connection request for the target intranet sent by the mobile wireless access device;
  • the intranet firewall distribution device Acquiring, by the intranet firewall distribution device, the geographic location of the mobile wireless access device according to the intranet connection request;
  • the intranet firewall allocation device determines the first intranet firewall matched by the mobile wireless access device from among the multiple intranet firewalls deployed for the target intranet according to the geographic location;
  • the intranet firewall allocation device sends the first IP address of the first intranet firewall to the mobile wireless access device, so that the mobile wireless access device communicates with the mobile wireless access device according to the first IP address
  • the first intranet firewall routes the received intranet access request to the intranet server of the target intranet, and the intranet access request is for the user terminal to pass through the mobile wireless
  • the access request for the intranet server of the target intranet sent by the access device, the first intranet firewall will also pass the intranet request response message returned by the intranet server in response to the intranet access request through all
  • the mobile wireless access device is sent to the user terminal.
  • the second aspect of the embodiments of the present application provides an intranet access method, including:
  • the mobile wireless access device sends an intranet connection request for the target intranet to the intranet firewall distribution device, so that the intranet firewall distribution device obtains the geographic location of the mobile wireless access device according to the intranet connection request. Location, and determine the first intranet firewall matched by the mobile wireless access device from among the multiple intranet firewalls deployed for the intranet according to the geographic location;
  • the mobile wireless access device sends a firewall connection request to the first intranet firewall according to the first IP address, so that the first intranet firewall communicates with the mobile radio according to the firewall connection request.
  • the device establishes a connection;
  • the mobile wireless access device After receiving the intranet access request for the target intranet sent by the user terminal, the mobile wireless access device routes the intranet access request to the target intranet through the first intranet firewall.
  • Intranet server
  • the mobile wireless access device After receiving the intranet request response message returned by the intranet server through the first intranet firewall in response to the intranet access request, the mobile wireless access device sends the intranet request response message to all The user terminal.
  • the third aspect of this application provides an intranet firewall distribution device, including:
  • the request receiving unit is configured to receive the intranet connection request for the target intranet sent by the mobile wireless access device;
  • a location obtaining unit configured to obtain the geographic location of the mobile wireless access device according to the intranet connection request
  • An intranet firewall determining unit configured to determine the first intranet firewall matched by the mobile wireless access device from a plurality of intranet firewalls deployed for the target intranet according to the geographic location;
  • the address sending unit is configured to send the first IP address of the first intranet firewall to the mobile wireless access device, so that the mobile wireless access device communicates with the first IP address according to the first IP address.
  • the first intranet firewall routes the received target intranet access request to the intranet server of the target intranet, and the intranet access request is for the user terminal to pass through the mobile wireless
  • the access request sent by the access device to the intranet server of the target intranet the first intranet firewall will also send the intranet request response message returned by the target intranet server in response to the intranet access request through
  • the mobile wireless access device is sent to the user terminal.
  • a fourth aspect of the embodiments of the present application provides a mobile wireless access device, including:
  • the request sending unit is configured to send an intranet connection request for the target intranet to an intranet firewall distribution device, so that the intranet firewall distribution device determines the mobile wireless access from the multiple intranet firewalls The first intranet firewall that the device matches;
  • An address receiving unit configured to receive the first IP address of the first intranet firewall sent by the intranet firewall distribution device
  • the firewall connection unit is configured to send a firewall connection request to the first intranet firewall according to the first IP address, so that the first intranet firewall communicates with the mobile wireless access device according to the firewall connection request establish connection;
  • the message transmission unit is configured to, after receiving the intranet access request for the target intranet from the user terminal, route the intranet access request to the intranet of the target intranet through the first intranet firewall server;
  • the message transmission unit is further configured to send the intranet request response message after receiving the intranet request response message returned by the intranet server in response to the intranet access request through the first intranet firewall To the user terminal.
  • the fifth aspect of the embodiments of the present application provides an intranet access system, including an intranet firewall distribution device and a mobile wireless access device, where:
  • the intranet firewall distribution device Acquiring, by the intranet firewall distribution device, the geographic location of the mobile wireless access device according to the intranet connection request;
  • the intranet firewall allocation device determines the first intranet firewall matched by the mobile wireless access device from among the multiple intranet firewalls deployed for the target intranet according to the geographic location;
  • the intranet firewall distribution device sends the first IP address of the first intranet firewall to the mobile wireless access device;
  • the mobile wireless access device sends a firewall connection request to the first intranet firewall according to the first IP address, so that the first intranet firewall communicates with the mobile wireless access device according to the firewall connection request. establish connection;
  • the mobile wireless access device After receiving the intranet access request for the target intranet sent by the user terminal, the mobile wireless access device routes the intranet access request to the target intranet through the first intranet firewall.
  • Intranet server
  • the mobile wireless access device After receiving the intranet request response message returned by the intranet server through the first intranet firewall in response to the intranet access request, the mobile wireless access device sends the intranet request response message to all The user terminal.
  • the sixth aspect of the embodiments of the present application provides an intranet firewall distribution device, including a processor, a memory, and a communication interface.
  • the processor, the memory, and the communication interface are connected to each other, wherein the communication interface is used to receive and send data
  • the memory is used for storing program code
  • the processor is used for calling the program code, and when the program code is executed by a computer, the computer executes the method of the first aspect.
  • a seventh aspect of the embodiments of the present application provides a mobile wireless access device, including a processor, a memory, and a communication interface.
  • the processor, the memory, and the communication interface are connected to each other, wherein the communication interface is used to receive and send data.
  • the memory is used for storing program code
  • the processor is used for calling the program code, and when the program code is executed by a computer, the computer executes the method of the second aspect.
  • the present application provides a computer non-volatile readable storage medium
  • the computer non-volatile readable storage medium stores a computer program
  • the computer program includes program instructions
  • the program instructions should be When the computer is executed, the computer is caused to execute any one of the methods in the first aspect and the second aspect.
  • the user terminal achieves access to the target intranet through the intranet access framework based on the mobile wireless access device and the firewall deployed for the target intranet. There is no need to configure any parameters before access, which improves the targeting of the target intranet. Access efficiency.
  • FIG. 1 is a schematic diagram of a framework of an intranet access system provided by an embodiment of this application;
  • FIG. 2 is a schematic diagram of system interaction of an intranet access method provided by an embodiment of this application.
  • FIG. 3 is a schematic diagram of system interaction of another intranet access method provided by an embodiment of this application.
  • FIG. 4 is a schematic diagram of system interaction of another intranet access method provided by an embodiment of this application.
  • FIG. 5 is a schematic structural diagram of an intranet firewall distribution device provided by an embodiment of the application.
  • FIG. 6 is a schematic structural diagram of a mobile wireless access device provided by an embodiment of this application.
  • FIG. 7 is a schematic structural diagram of another intranet firewall distribution device provided by an embodiment of the application.
  • FIG. 8 is a schematic structural diagram of another mobile wireless access device provided by an embodiment of this application.
  • FIG. 1 is a schematic diagram of the framework of an intranet access system provided by an embodiment of the application.
  • the intranet firewall 1, the intranet firewall 2, and the intranet firewall 3 are targeted Three intranet firewalls deployed in the intranet, mobile wireless access device 1 and mobile wireless access device 2 are respectively connected to the intranet firewall 1, the mobile wireless access device 3 is connected to the intranet firewall 3, and the user terminal 1 and The mobile wireless access device 1 is connected, and the user terminal 2 is connected with the mobile wireless access device 3.
  • the intranet firewall allocation device sends the allocated IP addresses of the intranet firewall to the mobile wireless access device 1, the mobile wireless access device 2 and the mobile wireless access device 3 respectively.
  • the target intranet is a local communication network that connects various computers, servers, and databases in a local geographic area of a specific enterprise, a specific institution, a specific school, and so on.
  • the terminal or server in the target intranet communicates with the terminal or server in the target intranet, it is realized through the data link layer, and the communication message does not need to be routed through the router; in the terminal or server outside the target intranet When communicating, it is achieved through the network layer.
  • the communication message sent by the terminal or server in the target intranet needs to be routed to the terminal or server outside the target intranet, the terminal or the terminal outside the target intranet, and
  • the communication message returned by the server needs to be routed to the terminal or server on the target intranet after the router undergoes network address translation.
  • the intranet firewall deployed for the target intranet can be a firewall deployed around the world for filtering data packets entering and leaving the target intranet.
  • the intranet firewall is connected to the router of the target intranet through the WAN, and then passes through the target intranet.
  • the router realizes the connection to the intranet server of the target intranet.
  • the mobile wireless access device is a mobile wireless access device that can transmit wireless network signals and has a routing function.
  • the mobile wireless access device will access the data network by inserting a SIM (Subscriber Identification Module) card. It can also access a wired network by inserting a network cable, and can also access a wireless network by connecting to WIFI.
  • the user terminal can access the wireless network transmitted by the mobile wireless access device to connect with the mobile wireless access device.
  • SIM Subscriber Identification Module
  • the intranet firewall distribution device may be a device that has a domain name resolution function for the target intranet, and stores the IP addresses and deployment locations of each firewall deployed for the target intranet, such as GTM (Global Traffic Manager, global traffic management) Equipment etc.
  • GTM Global Traffic Manager, global traffic management
  • the user terminal may be a terminal device with a wireless network receiving function, such as a notebook computer, a mobile phone, and a tablet computer.
  • the intranet access method may include:
  • S201 The mobile wireless access device sends an intranet connection request for the target intranet to the intranet firewall distribution device.
  • the mobile wireless access device may send an intranet connection request to the intranet firewall distribution device after being triggered to start, or it may be after receiving a function start instruction sent by the user to access the target intranet Later, sending an intranet connection request to the intranet firewall distribution device, or when receiving an intranet access request for the target intranet sent by a connected user terminal, sending an intranet connection request to the intranet firewall distribution device Network connection request.
  • the intranet connection request may carry the intranet domain name of the target intranet, so that the intranet firewall distribution device determines the intranet connection request for the target intranet after analyzing the intranet domain name.
  • the intranet firewall distribution device obtains the geographic location of the mobile wireless access device according to the intranet connection request.
  • the intranet connection request may carry the geographic location of the mobile wireless access device, and the intranet firewall distribution device directly obtains the geographic location of the mobile wireless access device from the intranet connection request;
  • the intranet connection request may also carry the positioning information of the mobile wireless access device, and the intranet firewall distribution device may obtain the positioning information from the intranet connection request, and use positioning technology according to the positioning information , Determine the location of the mobile wireless access device, for example, the positioning information may be the IP address of the mobile wireless access device, GPS data, WIFI access point information, connection base station information, etc., the positioning technology It can be IP positioning technology, GPS positioning technology, WIFI positioning technology, base station positioning technology, etc.
  • the intranet firewall allocation device determines a first intranet firewall matched by the mobile wireless access device from a plurality of intranet firewalls deployed for the target intranet according to the geographic location.
  • the intranet firewall distribution device can store the IP addresses and deployment locations of the firewalls separately deployed for multiple intranets.
  • the mobile wireless access device of company M can simultaneously store the IP addresses and deployment locations of each internal network firewall for the deployment of subsidiary A’s internal network , And the IP addresses and deployment locations of each intranet firewall deployed for subsidiary B's intranet.
  • the intranet connection request may carry the intranet domain name of the target intranet, so that the intranet firewall distribution device, after receiving the intranet connection request, resolves the intranet domain name and determines the
  • the intranet connection request is an intranet connection request for the target intranet, and then the IP addresses and deployment locations of multiple firewalls deployed for the target intranet are obtained.
  • the intranet firewall distribution device may, according to the geographic location and the deployment position of each intranet firewall deployed for the target intranet, combine the multiple intranet firewalls deployed for the target intranet Among the firewalls, the intranet firewall closest to the mobile wireless access device is determined to be the first intranet firewall.
  • all access areas for the target intranet are divided into intranet access sub-areas for each intranet firewall of the target intranet in advance, and the intranet firewall distribution device Setting the correspondence between the intranet access sub-area and the intranet firewall of the target intranet.
  • the intranet firewall distribution device determines the target intranet access subarea where the mobile wireless access device is located according to the geographic location of the mobile wireless access device, and then assigns the intranet corresponding to the target intranet access subarea to The network firewall is determined to be the first intranet firewall.
  • the intranet firewall distribution device sends the first IP address of the first intranet firewall to the mobile wireless access device.
  • S205 The mobile wireless access device establishes a connection with the first intranet firewall according to the first IP address.
  • the mobile wireless access device sends a firewall connection request to the first intranet firewall according to the first IP address, so that the first intranet firewall sends a firewall connection request to the mobile device according to the firewall connection request.
  • a connection with the mobile wireless access device is established.
  • the firewall connection request carries the access device identification code of the mobile wireless access device, such as a MAC address, and the first intranet firewall determines that the access device identification code is preset When one of the identification codes of the access device is allowed to be connected, it is determined that the identity authentication of the mobile wireless access device is passed.
  • the firewall connection request carries the user name and password input by the user through the mobile wireless access device
  • the first intranet firewall determines that the user name and password are preset users allowed to connect When one of the name and password is set, it is determined that the identity authentication of the mobile wireless access device is passed.
  • the firewall connection request carries the access device digital certificate of the mobile wireless access device
  • the first intranet firewall carries the access device digital certificate according to the access device digital certificate.
  • the issuer information of the device digital certificate determines the certificate issuer of the access device digital certificate; after the first intranet firewall obtains the issuer’s digital certificate of the certificate issuer, the issuer’s digital certificate contains The public key of the issuing party decrypts the digital signature in the digital certificate of the access device to obtain the certificate fingerprint of the digital certificate of the access device.
  • the first intranet firewall will use a specified hash algorithm to The digital certificate of the access device is hashed to obtain the hash value of the digital certificate; the first intranet firewall determines that the hash value of the digital certificate obtained by the hash calculation of the first intranet firewall and the access device certificate When the fingerprints are consistent, it is determined that the identity authentication of the mobile wireless access device is passed.
  • the mobile wireless access device initiates a three-way handshake to establish a connection based on the TCP/IP protocol with the first intranet firewall.
  • the specific steps are as follows: the mobile wireless access device sends to the first intranet firewall SYN (Synchronize Sequence Numbers, synchronization sequence number) data packet; after the first intranet firewall receives the SYN data packet, it sends a SYN+ACK (ACKnowledge Character, confirmation character) data packet to the mobile wireless access device After the mobile wireless access device receives the SYN+ACK data packet, it feeds back the ACK data packet to the first intranet firewall; the first intranet firewall receives the feedback from the mobile wireless access device After the ACK packet, the connection between the mobile wireless access device and the first intranet firewall is established.
  • SYN Synchromize Sequence Numbers, synchronization sequence number
  • S206 The user terminal sends an intranet access request for the target intranet to the mobile wireless access device.
  • the user terminal may send a wireless network connection request to the mobile wireless access device, and the mobile wireless access device may directly establish a connection with the user terminal, or through the wireless network After the user terminal identity information carried in the connection request is verified, a connection with the user terminal is established.
  • the user terminal identity information may be the user name and password input by the user inputted by the user terminal to access the wireless network established by the mobile wireless access device, and may also be the biometric input received by the user terminal.
  • the information may also be terminal equipment identification information of the user terminal.
  • step S206 can be performed at any time before step S207.
  • S207 The mobile wireless access device sends the intranet access request to the first intranet firewall.
  • S208 The first intranet firewall routes the intranet access request to the intranet server of the target intranet.
  • the intranet access request is an access request for a server in the target intranet, such as an access request for a Web server in the target intranet, an access request for an FTP server in the target intranet, and an access request for a server in the target intranet. State the access request of the mail server in the target intranet, etc.
  • the first intranet firewall After the first intranet firewall receives the intranet access request sent by the mobile wireless access device, it sends the intranet access request to the router of the target intranet through the external network. The router routes the intranet access request to the corresponding intranet server in the target intranet through the target intranet.
  • the specific method for the first intranet firewall to route the intranet access request to the intranet server may be as follows: the first intranet firewall selects the one to the intranet server according to its own configured network protocol and the routing principle corresponding to the protocol The optimal routing path, and then routing the intranet access request to the intranet server according to the optimal routing path.
  • the intranet server returns an intranet request response message in response to the intranet access request to the first intranet firewall.
  • the intranet server After the intranet server generates an intranet request response message in response to the intranet access request, it sends the intranet request response message to the router of the target intranet through the target intranet, and the target The router of the internal network sends the internal network request response message to the first internal network firewall through the external network.
  • the intranet access request is a request to obtain a file in a file server in the target intranet
  • the intranet request response message may be the file sent by the file server.
  • S210 The first intranet firewall sends the intranet request response message to the mobile wireless access device.
  • the mobile wireless access device sends the intranet request response message to the user terminal.
  • the intranet firewall distribution device After receiving the intranet connection request for the target intranet sent by the mobile wireless access device, the intranet firewall distribution device in the embodiment of the present application obtains the geographic location of the mobile wireless access device according to the intranet connection request, And according to the geographic location, the first intranet firewall matched by the mobile wireless access device is determined from among the multiple intranet firewalls deployed for the target intranet, and the mobile wireless access device receives the The intranet firewall assigns the first IP address of the first intranet firewall sent by the device, and sends a firewall connection request to the first intranet firewall, so that the first intranet firewall and the mobile wireless access device are established connection. After receiving the intranet access request for the target intranet sent by the user terminal, the mobile wireless access device routes the intranet access request to the target intranet through the first intranet firewall.
  • the intranet server after receiving an intranet request response message returned by the intranet server through the first intranet firewall in response to the intranet access request, sends the intranet request response message to the user terminal .
  • the user terminal realizes the access to the target intranet through the intranet access framework based on the mobile wireless access device and the firewall deployed for the target intranet. There is no need to configure any parameters before access, which improves the access efficiency to the target intranet.
  • Figure 3 is a schematic diagram of system interaction of another intranet access method provided by an embodiment of the application.
  • the intranet firewall distribution device can monitor whether the mobile wireless access device needs to switch the connected first intranet firewall.
  • the intranet firewall distribution device obtains the distance between the mobile wireless access device and the geographic location according to a preset period.
  • the geographic location is the geographic location where the mobile wireless access device is located when it sends an intranet connection request for the target intranet to the intranet firewall distribution device.
  • the distance between the mobile wireless access device and the geographic location may be periodically sent by the mobile wireless access device to the intranet firewall distribution device, or may be sent by the intranet firewall distribution device according to
  • the positioning information periodically sent by the mobile wireless access device is determined through positioning technology.
  • the intranet firewall distribution device obtains the real-time geographic location of the mobile wireless access device.
  • the real-time geographic location of the mobile wireless access device may be determined by the intranet firewall distribution device through positioning technology, or may be obtained from the mobile wireless access device.
  • the intranet firewall allocation device determines the network delay between the mobile wireless access device and the first intranet firewall Increase, in order to improve the network quality of the user accessing the target intranet, trigger the intranet firewall distribution device to re-match the connected firewall for the mobile wireless access device.
  • the intranet firewall distribution device serves the mobile wireless access device from the plurality of intranet firewalls according to the real-time geographic location of the mobile wireless access device and the deployment positions of the plurality of intranet firewalls Determine the matching second intranet firewall.
  • the intranet firewall distribution device sends the second IP address of the second intranet firewall to the mobile wireless access device.
  • S305 The mobile wireless access device sends a firewall connection request to the second intranet firewall according to the second IP address.
  • the second intranet firewall establishes a connection with the mobile wireless access device according to the firewall connection request.
  • S307 The mobile wireless access device disconnects from the first intranet firewall.
  • the mobile wireless access device disconnects the TCP/IP connection with the second intranet firewall by initiating four waves of hands.
  • the specific steps are as follows: the mobile wireless access device sends to the second intranet firewall FIN (Finish Character) data packet; after receiving the FIN data packet, the second intranet firewall sends an ACK data packet to the mobile wireless access device; the second intranet firewall sends an ACK data packet to the mobile wireless access device; The mobile wireless access device sends a FIN data packet; after the mobile wireless access device receives the FIN data packet, it sends an ACK data packet to the second intranet firewall; the second intranet firewall distribution device receives After the ACK packet, the disconnection of the connection between the mobile wireless access device and the second intranet firewall is completed.
  • FIN Franceish Character
  • step S308 is executed after step S307, and the intranet access request sent by the user terminal in step S308 is to connect to the mobile radio after the mobile radio access device is disconnected from the first intranet firewall.
  • Intranet access request sent by the incoming device is routed to the target intranet through the first intranet firewall of the target intranet The corresponding intranet server in the network.
  • the mobile wireless access device sends the intranet access request to the second intranet firewall.
  • S310 The second intranet firewall routes the intranet access request to the intranet server of the target intranet.
  • the intranet server returns an intranet request response message in response to the intranet access request to the second intranet firewall.
  • the second intranet firewall sends the intranet request response message to the mobile wireless access device.
  • the mobile wireless access device sends the intranet request response message to the user terminal.
  • step S308 to step S313 the connection between the mobile wireless access device and the second intranet firewall provides the user terminal with a service to access the target intranet, which can be referred to in Figure 2
  • the connection between the mobile wireless access device and the first intranet firewall in step S206 to step S211 provides the user terminal with a specific implementation method for accessing the target intranet service, which will not be repeated here. .
  • the intranet firewall distribution device checks the connection between the mobile wireless access device and the geographic location according to a preset period. The distance is detected, and when it is determined that the distance is greater than the preset distance, a second intranet firewall is re-allocated to the mobile wireless access device, so that the mobile wireless access device removes the connected intranet firewall from the first intranet firewall.
  • the network firewall is switched to the second intranet firewall to ensure that when the mobile wireless access device moves, the intranet firewall connected to the mobile wireless access device is always connected to the mobile wireless access device in real time.
  • the optimal intranet firewall with matching location ensures the network quality of the user accessing the intranet through the mobile wireless access device.
  • FIG. 4 is a schematic diagram of system interaction of another intranet access method provided by an embodiment of the application.
  • the mobile wireless access device can monitor whether the mobile wireless access device needs to switch the connected first intranet firewall.
  • the specific implementation steps may be as follows:
  • the mobile wireless access device acquires connection status information of the access device connected to the first intranet firewall according to a preset period, and/or, the user terminal is directed to the terminal access status information of the target intranet .
  • the access device connection state information may include indicator information such as the uplink packet loss rate, the downlink packet loss rate, the number of data packets sent per second, and the number of data packets received per second of the mobile wireless access device.
  • the terminal access state information may include indicator information such as the uplink packet loss rate, the downlink packet loss rate, the number of data packets sent per second, and the number of data packets received per second of the user terminal.
  • the terminal access state information may be determined by the user terminal and sent to the mobile wireless access device.
  • the intranet firewall distribution device sends a firewall switching request.
  • an evaluation model for each indicator in the connection status information of the access device and/or an evaluation model for each indicator in the terminal connection status information may be set in the mobile wireless access device in advance, so The mobile wireless access device may evaluate the connection state information of the access device and/or the terminal access state information through the above evaluation model to determine whether the user terminal's access to the target intranet is in Abnormal state.
  • the uplink packet loss rate in the connection status information of the access device will be greater than the preset packet loss rate threshold, and the mobile The wireless access device determines that the user terminal's access to the target intranet is in an abnormal state; if the first intranet firewall is congested, the number of data packets received per second in the terminal connection status information will be less than A threshold for receiving data packets is preset, and the mobile wireless access device determines that the access of the user terminal to the target intranet is in an abnormal state.
  • the intranet firewall distribution device determines a third intranet firewall matched by the mobile wireless access device from the multiple intranet firewalls according to the firewall swap request.
  • the intranet firewall distribution device determines from the multiple intranet firewalls according to the firewall switching request that the third intranet firewall matched by the mobile wireless access device is implemented, please refer to the implementation corresponding to FIG. 2
  • the intranet firewall allocation device determines the mobile wireless access device to match the mobile wireless access device from among multiple intranet firewalls deployed for the target intranet. The implementation of an intranet firewall will not be repeated here.
  • the third intranet firewall and the first intranet firewall determined in step S403 may be the same intranet firewall, and all of them can be removed from the firewall at this time.
  • the third intranet firewall is determined again among other intranet firewalls deployed for the target intranet of the first intranet firewall.
  • S404 The mobile wireless access device receives the third IP address of the third intranet firewall sent by the intranet firewall allocation device.
  • S405 The mobile wireless access device sends a firewall connection request to the third intranet firewall according to the third IP address.
  • the third intranet firewall establishes a connection with the mobile wireless access device according to the firewall connection request.
  • step S205 the first intranet firewall establishes a connection with the mobile wireless access device. The implementation method of is not repeated here.
  • S407 The mobile wireless access device disconnects from the first intranet firewall.
  • the disconnection of the connection between the mobile wireless access device and the first intranet firewall may refer to the disconnection of the connection between the mobile wireless access device and the first intranet firewall in step S307 in the embodiment corresponding to FIG.
  • the specific implementation method of opening will not be repeated here.
  • S408 The user terminal sends an intranet access request for the target intranet to the mobile wireless access device.
  • step S408 is performed after step S407, and the intranet access request sent by the user terminal in step S408 is that after the mobile wireless access device is disconnected from the first intranet firewall, the mobile wireless access Intranet access request sent by the incoming device. And before step S407, the intranet access request for the target intranet sent by the user terminal received by the mobile wireless access device is routed to the target intranet through the first intranet firewall of the target intranet The corresponding intranet server in the network.
  • S409 The mobile wireless access device sends the intranet access request to the second intranet firewall.
  • S410 The second intranet firewall routes the intranet access request to the intranet server of the target intranet.
  • the intranet server returns an intranet request response message in response to the intranet access request to the second intranet firewall.
  • S412 The second intranet firewall sends the intranet request response message to the mobile wireless access device.
  • S413 The mobile wireless access device sends the intranet request response message to the user terminal.
  • step S408 to step S413 the connection between the mobile wireless access device and the second intranet firewall provides the user terminal with a service to access the target intranet.
  • the connection between the mobile wireless access device and the first intranet firewall in step S206 to step S211 provides the user terminal with a specific implementation method for accessing the target intranet service, which will not be repeated here. .
  • the mobile wireless access device after the mobile wireless access device establishes a connection with the first intranet firewall, the mobile wireless access device checks the mobile wireless access device with the first intranet according to a preset period. Information about the connection status of the access device connected to the network firewall, and/or the user terminal detects the access status information of the terminal of the target intranet, based on the connection status information of the access device, and/or, The terminal connection status information, when it is determined that the user terminal's access to the target intranet is in an abnormal state, request the intranet firewall distribution device to switch the connected first intranet firewall, and the intranet firewall distribution device is After the mobile wireless access device reallocates the third intranet firewall, the mobile wireless access device switches the connected intranet firewall from the first intranet firewall to the third intranet firewall, and the user passes through the mobile wireless The network quality of the access device to access the intranet.
  • FIG. 5 is a schematic structural diagram of an intranet firewall distribution device provided by an embodiment of the application.
  • the intranet firewall distribution device 50 may at least include a request receiving unit 501, a location obtaining unit 502, Intranet firewall determining unit 503 and address sending unit 504, where:
  • the request receiving unit 501 is configured to receive an intranet connection request for a target intranet sent by a mobile wireless access device.
  • the location obtaining unit 502 is configured to obtain the geographic location of the mobile wireless access device according to the intranet connection request.
  • the intranet firewall determining unit 503 is configured to determine the first intranet firewall matched by the mobile wireless access device from a plurality of intranet firewalls deployed for the target intranet according to the geographic location.
  • the address sending unit 504 is configured to send the first IP address of the first intranet firewall to the mobile wireless access device, so that the mobile wireless access device communicates with the mobile wireless access device according to the first IP address.
  • the first intranet firewall After the first intranet firewall establishes a connection, the first intranet firewall routes the received target intranet access request to the intranet server of the target intranet, and the intranet access request is for the user terminal through the mobile
  • the access request for the intranet server of the target intranet sent by the wireless access device, and the first intranet firewall also returns an intranet request response message returned by the target intranet server in response to the intranet access request, Send to the user terminal through a mobile wireless access device.
  • the intranet firewall distribution device can execute each step performed by the intranet firewall distribution device described in the intranet access method shown in Figures 2 to 4 through its built-in functional modules.
  • the intranet firewall distribution device can execute each step performed by the intranet firewall distribution device described in the intranet access method shown in Figures 2 to 4 through its built-in functional modules.
  • the intranet firewall distribution device can execute each step performed by the intranet firewall distribution device described in the intranet access method shown in Figures 2 to 4 through its built-in functional modules.
  • the intranet firewall distribution device can execute each step performed by the intranet firewall distribution device described in the intranet access method shown in Figures 2 to 4 through its built-in functional modules.
  • the location obtaining unit obtains the geographic location of the mobile wireless access device according to the intranet connection request .
  • the intranet firewall determining unit determines the first intranet firewall that matches the mobile wireless access device from the multiple intranet firewalls deployed for the target intranet according to the geographic location, and the mobile wireless access device According to the received IP address of the first intranet firewall sent by the address sending unit, a firewall connection request is sent to the first intranet firewall, so that the first intranet firewall and the mobile wireless access device establish connection.
  • the mobile wireless access device After receiving the intranet access request for the target intranet sent by the user terminal, the mobile wireless access device routes the intranet access request to the target intranet through the first intranet firewall.
  • the intranet server After receiving an intranet request response message returned by the intranet server through the first intranet firewall in response to the intranet access request, sends the intranet request response message to the user terminal .
  • the user terminal realizes the access to the target intranet through the intranet access framework based on the mobile wireless access device and the firewall deployed for the target intranet. There is no need to configure any parameters before access, which improves the access efficiency to the target intranet.
  • FIG. 6 is a schematic structural diagram of a mobile wireless access device provided by an embodiment of the application.
  • the mobile wireless access device 60 may at least include a request sending unit 601, an address receiving unit 602, The firewall connection unit 603 and the message transmission unit 604, wherein:
  • the request sending unit 601 is configured to send an intranet connection request for the target intranet to an intranet firewall distribution device, so that the intranet firewall distribution device determines the mobile wireless connection from the multiple intranet firewalls. Enter the first intranet firewall that matches the device.
  • the address receiving unit 602 is configured to receive the first IP address of the first intranet firewall sent by the intranet firewall distribution device.
  • the firewall connection unit 603 is configured to send a firewall connection request to the first intranet firewall according to the first IP address, so that the first intranet firewall communicates with the mobile radio according to the firewall connection request
  • the device establishes a connection.
  • the message transmission unit 604 is configured to, after receiving the intranet access request for the target intranet from the user terminal, route the intranet access request to the intranet of the target intranet through the first intranet firewall. Web server.
  • the message transmission unit 605 is further configured to transmit the intranet request response message after receiving the intranet request response message returned by the intranet server in response to the intranet access request through the first intranet firewall Sent to the user terminal.
  • the mobile wireless access device can execute various steps performed by the mobile wireless access device in the intranet access methods shown in Figures 2 to 4 through its built-in functional modules.
  • the mobile wireless access device can execute various steps performed by the mobile wireless access device in the intranet access methods shown in Figures 2 to 4 through its built-in functional modules.
  • the intranet firewall distribution device obtains the geographic location according to the intranet connection request, and obtains the geographic location from the target according to the geographic location.
  • the first intranet firewall that matches the mobile wireless access device is determined among the multiple intranet firewalls deployed in the intranet, and the firewall connection unit receives the address sent by the intranet firewall distribution device according to the address receiving unit.
  • the IP address of the first intranet firewall sends a firewall connection request to the first intranet firewall, so that after the first intranet firewall establishes a connection with the firewall connection unit, the message transmission unit is
  • the user terminal connected to the mobile wireless access device provides a service for accessing the target intranet.
  • the user terminal realizes the access to the target intranet through the intranet access framework based on the mobile wireless access device and the firewall deployed for the target intranet. There is no need to configure any parameters before access, which improves the access efficiency to the target intranet.
  • FIG. 7 is a schematic structural diagram of another intranet firewall distribution device according to an embodiment of the application.
  • the intranet firewall distribution device 70 includes a processor 701, a memory 702, and a communication interface 703.
  • the processor 701 is connected to the memory 702 and the communication interface 703.
  • the processor 701 may be connected to the memory 702 and the communication interface 703 through a bus.
  • the processor 701 is configured to support the intranet firewall distribution device to perform the corresponding functions of the intranet firewall distribution device in the intranet access method described in FIGS. 2 to 4.
  • the processor 701 may be a central processing unit (Central Processing Unit, CPU), a network processor (Network Processor, NP), a hardware chip, or any combination thereof.
  • the foregoing hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (Programmable Logic Device, PLD), or a combination thereof.
  • the aforementioned PLD may be a complex programmable logic device (Complex Programmable Logic Device, CPLD), a field programmable logic gate array (Field-Programmable Gate Array, FPGA), a general array logic (Generic Array Logic, GAL) or any combination thereof.
  • CPLD Complex Programmable Logic Device
  • FPGA Field-Programmable Gate Array
  • GAL General array logic
  • the memory 702 is used to store program codes and the like.
  • the memory 702 includes internal memory, which may include at least one of the following: volatile memory (such as dynamic random access memory (DRAM), static RAM (SRAM), synchronous dynamic RAM (SDRAM), etc.) and non-volatile memory (For example, one-time programmable read-only memory (OTPROM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM).
  • volatile memory such as dynamic random access memory (DRAM), static RAM (SRAM), synchronous dynamic RAM (SDRAM), etc.
  • non-volatile memory for example, one-time programmable read-only memory (OTPROM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM).
  • OTPROM one-time programmable read-only memory
  • PROM programmable ROM
  • EPROM erasable programm
  • the memory 702 may also include external memory,
  • the memory may include at least one of the following: Hard Disk Drive (HDD) or Solid-State Drive (SSD), flash drive, such as high-density flash (CF), secure digital (SD), micro SD, mini type SD, limit number (xD), memory stick, etc.
  • HDD Hard Disk Drive
  • SSD Solid-State Drive
  • flash drive such as high-density flash (CF), secure digital (SD), micro SD, mini type SD, limit number (xD), memory stick, etc.
  • the communication interface 703 is used to receive or send data.
  • the processor 701 may call the program code to perform the following operations:
  • the first intranet firewall routes the received intranet access request to the intranet server of the target intranet, and the intranet access request is a user terminal sent by the mobile wireless access device for all users.
  • the access request of the intranet server of the target intranet, the first intranet firewall also sends the intranet request response message returned by the intranet server in response to the intranet access request through the mobile wireless access device To the user terminal.
  • each operation may also correspond to the corresponding description of the method embodiments shown in FIGS. 2 to 4; the processor 701 may also be used to perform other operations in the above method embodiments.
  • FIG. 8 is a schematic structural diagram of another mobile wireless access device according to an embodiment of the application.
  • the mobile wireless access device 80 includes a processor 801, a memory 802, and a communication interface 803.
  • the processor 801 is connected to the memory 802 and the communication interface 803.
  • the processor 801 may be connected to the memory 802 and the communication interface 803 through a bus.
  • the processor 801 is configured to support the mobile wireless access device to perform the corresponding functions of the mobile wireless access device in the intranet access methods described in FIGS. 2 to 4.
  • the processor 801 may be a central processing unit (Central Processing Unit, CPU), a network processor (Network Processor, NP), a hardware chip, or any combination thereof.
  • the foregoing hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (Programmable Logic Device, PLD), or a combination thereof.
  • the aforementioned PLD may be a complex programmable logic device (Complex Programmable Logic Device, CPLD), a field programmable logic gate array (Field-Programmable Gate Array, FPGA), a general array logic (Generic Array Logic, GAL) or any combination thereof.
  • CPLD Complex Programmable Logic Device
  • FPGA Field-Programmable Gate Array
  • GAL General array logic
  • the memory 802 is used to store program codes and the like.
  • the memory 802 includes internal memory, which may include at least one of the following: volatile memory (such as dynamic random access memory (DRAM), static RAM (SRAM), synchronous dynamic RAM (SDRAM), etc.) and nonvolatile memory (For example, one-time programmable read-only memory (OTPROM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM).
  • volatile memory such as dynamic random access memory (DRAM), static RAM (SRAM), synchronous dynamic RAM (SDRAM), etc.
  • nonvolatile memory for example, one-time programmable read-only memory (OTPROM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM).
  • OTPROM one-time programmable read-only memory
  • PROM programmable ROM
  • EPROM erasable programmable
  • the memory 802 may also include external memory, external
  • the memory may include at least one of the following: Hard Disk Drive (HDD) or Solid-State Drive (SSD), flash drive, such as high-density flash (CF), secure digital (SD), micro SD, mini type SD, limit number (xD), memory stick, etc.
  • HDD Hard Disk Drive
  • SSD Solid-State Drive
  • flash drive such as high-density flash (CF), secure digital (SD), micro SD, mini type SD, limit number (xD), memory stick, etc.
  • the communication interface 803 is used to receive or send data.
  • the processor 801 may call the program code to perform the following operations:
  • the intranet firewall distribution device send an intranet connection request for the target intranet to the intranet firewall distribution device, so that the intranet firewall distribution device obtains the geographic location of the mobile wireless access device according to the intranet connection request, and according to the The geographic location determines the first intranet firewall matched by the mobile wireless access device from a plurality of intranet firewalls deployed for the intranet;
  • the intranet request response message After receiving the intranet request response message returned by the intranet server through the first intranet firewall in response to the intranet access request, the intranet request response message is sent to the user terminal.
  • each operation may also correspond to the corresponding description of the method embodiments shown in FIGS. 2 to 4; the processor 801 may also be used to perform other operations in the above method embodiments.
  • the embodiments of the present application also provide a computer non-volatile readable storage medium, the computer non-volatile readable storage medium stores a computer program, the computer program includes program instructions, and the program instructions are executed by a computer.
  • the computer When the computer is caused to execute the method described in the foregoing embodiment, the computer may be the aforementioned intranet firewall distribution device or a part of the mobile wireless access device.
  • the program can be stored in a computer readable storage medium. During execution, it may include the procedures of the above-mentioned method embodiments.
  • the storage medium may be a magnetic disk, an optical disc, a read-only memory (Read-Only Memory, ROM), or a random access memory (Random Access Memory, RAM), etc.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本申请实施例适用于安全防护中的访问控制,公开了一种内网访问方法及相关装置,所述方法包括:内网防火墙分配设备获取移动无线接入设备对目标内网进行访问的计划行程信息;内网防火墙分配设备确定为所述移动无线接入设备分配的第一内网防火墙;内网防火墙分配设备在确定满足行程节点条件时,将所述第一内网防火墙的第一IP地址发送给所述移动无线接入设备,以使所述移动无线接入设备与所述第一内网防火墙建立连接,并断开与第二内网防火墙的连接,实现了与移动无线接入设备所连接的内网防火墙的切换。通过本申请可以实现根据移动无线接入设备的计划行程信息为移动无线接入设备推荐切换所连接的内网防火墙,保证了用户对目标内网进行访问的网络质量。

Description

一种内网访问方法、系统及相关装置
本申请要求于2019年06月10日提交中国专利局、申请号为2019104990380、申请名称为“一种内网访问方法、系统及相关装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及计算机领域,尤其涉及一种内网访问方法、系统及相关装置。
背景技术
随着全球经济的一体化,越来越多的企业在全球各地都开展了相关业务,这就需要企业的员工被派遣到全球各地去办公。在一些办公场景中,在外地的企业员工需要访问得到公司内网服务器的一些资源,例如访问企业内网网页、访问内网文件服务器中共享文件夹中存储的文件等。传统的方式中,通常通过VPN(Virtual Private Network,虚拟专用网络)实现,需要在公司内网建立VPN服务器,外地员工通过手机、电脑等在当地连上互联网后,通过互联网连接企业内网的VPN服务器,然后通过VPN服务器访问企业内网。在企业员工通过电脑等终端连接内网时,需要事先配置连接企业内网VPN的参数,例如内网VPN服务器的地址,用户的登录名和密码等,然后进行拨号并连接。这种连接内网的方式需要用户操作较多且等待时间较长,较为影响连接效率。
申请内容
本申请提供一种内网访问方法、系统及相关装置,通过本申请可以提高针对目标内网的访问效率。
本申请实施例第一方面提供了一种内网访问方法,包括:
内网防火墙分配设备接收移动无线接入设备发送的针对目标内网的内网连接请求;
所述内网防火墙分配设备根据所述内网连接请求获取所述移动无线接入设备的地理位置;
所述内网防火墙分配设备根据所述地理位置,从针对所述目标内网部署的多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙;
所述内网防火墙分配设备将所述第一内网防火墙的第一IP地址发送给所述移动无线接入设备,以使在所述移动无线接入设备根据所述第一IP地址与所述第一内网防火墙建立连接后,所述第一内网防火墙将接收到的内网访问请求路由至所述目标内网的内网服务器,所述内网访问请求为用户终端通过所述移动无线接入设备发送的针对所述目标内网的内网服务器的访问请求,所述第一内网防火墙还将所述内网服务器响应所述内网访问请求返回的内网请求响应消息,通过所述移动无线接入设备发送至所述用户终端。
本申请实施例第二方面提供了一种内网访问方法,包括:
移动无线接入设备向内网防火墙分配设备发送针对所述目标内网的内网连接请求,以使所述内网防火墙分配设备根据所述内网连接请求获取所述移动无线接入设备的地理位置,并根据所述地理位置从针对所述内网部署的多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙;
所述移动无线接入设备接收所述内网防火墙分配设备发送的所述第一内网防火墙的第 一IP地址;
所述移动无线接入设备根据所述第一IP地址,向所述第一内网防火墙发送防火墙连接请求,以使所述第一内网防火墙根据所述防火墙连接请求与所述移动无线接入设备建立连接;
所述移动无线接入设备在接收到用户终端发送的针对所述目标内网的内网访问请求后,将所述内网访问请求通过所述第一内网防火墙路由至所述目标内网的内网服务器;
所述移动无线接入设备在接收到所述内网服务器响应所述内网访问请求通过所述第一内网防火墙返回的内网请求响应消息后,将所述内网请求响应消息发送至所述用户终端。
本申请第三方面提供了一种内网防火墙分配设备,包括:
请求接收单元,用于接收移动无线接入设备发送的针对目标内网的内网连接请求;
位置获取单元,用于根据所述内网连接请求获取所述移动无线接入设备的地理位置;
内网防火墙确定单元,用于根据所述地理位置,从针对所述目标内网部署的多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙;
地址发送单元,用于将所述第一内网防火墙的第一IP地址发送给所述移动无线接入设备,以使在所述移动无线接入设备根据所述第一IP地址与所述第一内网防火墙建立连接后,所述第一内网防火墙将接收到的目标内网访问请求路由至所述目标内网的内网服务器,所述内网访问请求为用户终端通过所述移动无线接入设备发送的针对所述目标内网的内网服务器的访问请求,所述第一内网防火墙还将所述目标内网服务器响应所述内网访问请求返回的内网请求响应消息,通过移动无线接入设备发送至所述用户终端。
本申请实施例第四方面提供了一种移动无线接入设备,包括:
请求发送单元,用于向内网防火墙分配设备发送针对所述目标内网的内网连接请求,以使所述内网防火墙分配设备从所述多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙;
地址接收单元,用于接收所述内网防火墙分配设备发送的所述第一内网防火墙的第一IP地址;
防火墙连接单元,用于根据所述第一IP地址,向所述第一内网防火墙发送防火墙连接请求,以使所述第一内网防火墙根据所述防火墙连接请求与所述移动无线接入设备建立连接;
消息传输单元,用于在从用户终端接收到针对所述目标内网的内网访问请求后,将所述内网访问请求通过所述第一内网防火墙路由至所述目标内网的内网服务器;
所述消息传输单元,还用于在接收到所述内网服务器响应所述内网访问请求通过所述第一内网防火墙返回的内网请求响应消息后,将所述内网请求响应消息发送至所述用户终端。
本申请实施例第五方面提供了一种内网访问系统,包括内网防火墙分配设备和移动无线接入设备,其中:
所述移动无线接入设备向所述内网防火墙分配设备发送针对目标内网的内网连接请求;
所述内网防火墙分配设备根据所述内网连接请求获取所述移动无线接入设备的地理位置;
所述内网防火墙分配设备根据所述地理位置,从针对所述目标内网部署的多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙;
所述内网防火墙分配设备将所述第一内网防火墙的第一IP地址发送给所述移动无线接 入设备;
所述移动无线接入设备根据所述第一IP地址向所述第一内网防火墙发送防火墙连接请求,以使所述第一内网防火墙根据所述防火墙连接请求与所述移动无线接入设备建立连接;
所述移动无线接入设备在接收到用户终端发送的针对所述目标内网的内网访问请求后,将所述内网访问请求通过所述第一内网防火墙路由至所述目标内网的内网服务器;
所述移动无线接入设备在接收到所述内网服务器响应所述内网访问请求通过所述第一内网防火墙返回的内网请求响应消息后,将所述内网请求响应消息发送至所述用户终端。
本申请实施例第六方面提供了一种内网防火墙分配设备,包括处理器、存储器以及通信接口,所述处理器、存储器和通信接口相互连接,其中,所述通信接口用于接收和发送数据,所述存储器用于存储程序代码,所述处理器用于调用所述程序代码,所述程序代码当被计算机执行时使所述计算机执行上述第一方面的方法。
本申请实施例第七方面提供了一种移动无线接入设备,包括处理器、存储器以及通信接口,所述处理器、存储器和通信接口相互连接,其中,所述通信接口用于接收和发送数据,所述存储器用于存储程序代码,所述处理器用于调用所述程序代码,所述程序代码当被计算机执行时使所述计算机执行上述第二方面的方法。
第八方面,本申请提供了一种计算机非易失性可读存储介质,所述计算机非易失性可读存储介质存储有计算机程序,所述计算机程序包括程序指令,所述程序指令当被计算机执行时使所述计算机执行上述第一方面和第二方面中的任意一种方法。
通过本申请实施例,用户终端通过基于移动无线接入设备和针对目标内网部署的防火墙的内网访问框架实现了对目标内网的访问,访问之前无需配置任何参数,提高了针对目标内网的访问效率。
附图说明
图1为本申请实施例提供的一种内网访问系统的框架示意图;
图2为本申请实施例提供的一种内网访问方法的系统交互示意图;
图3为本申请实施例提供的另一种内网访问方法的系统交互示意图;
图4为本申请实施例提供的又一种内网访问方法的系统交互示意图;
图5为本申请实施例提供的一种内网防火墙分配设备的结构示意图;
图6为本申请实施例提供的一种移动无线接入设备的结构示意图;
图7为本申请实施例提供的另一种内网防火墙分配设备的结构示意图;
图8为本申请实施例提供的另一种移动无线接入设备的结构示意图。
具体实施方式
下面将结合图1至图8,对本申请实施例提供的内网访问方法、系统及相关装置进行说明。
图1为本申请实施例提供的一种内网访问系统的框架示意图,如图所示,在该内网访问系统框架中,内网防火墙1、内网防火墙2和内网防火墙3为针对目标内网部署的3个内网防火墙,移动无线接入设备1和移动无线接入设备2分别与内网防火墙1相连接,移动无线接入设备3与内网防火墙3相连接,用户终端1与移动无线接入设备1相连接,用户终端2与移动无线接入设备3相连接。内网防火墙分配设备分别向移动无线接入设备1、移动无线接入设备2和移动无线接入设备3发送为其分配的内网防火墙的IP地址。
这里,目标内网为将特定企业、特定机构、特定学校等的一个局部地理范围内的各种 计算机、服务器和数据库等互相连接起来的局域通信网络。目标内网中的终端或服务器在于所述目标内网中的终端或服务器等进行通信时,通过数据链路层实现,通信消息无需经过路由器的路由;在于所述目标内网外的终端或服务器进行通信时,通过网络层实现,目标内网内的终端或服务器发送的通信消息需要经过路由器经过网络地址转换后,路由至所述目标内网外的终端或服务器,目标内网外的终端或服务器返回的通信消息需要路由器经过网络地址转换后,路由至目标内网的终端或服务器。
这里,针对目标内网部署的内网防火墙可以是部署在全球各地的针对进出目标内网的数据包进行过滤的防火墙,内网防火墙通过广域网与目标内网的路由器相连接,进而通过目标内网的路由器实现于目标内网的内网服务器的连接。
这里,移动无线接入设备为可移动的,能发射无线网络信号的,且有路由功能的无线接入设备。移动无线接入设备将通过插入SIM(Subscriber Identification Module,用户身份识别)卡接入数据网络,也可以通过插入网线的方式接入有线网络,还可以通过连接WIFI的方式接入无线网络。用户终端可以接入移动无线接入设备发射的无线网络与移动无线接入设备连接。
这里,内网防火墙分配装置可以是具有针对目标内网的域名解析功能的,且存储有针对目标内网部署的各个防火墙IP地址和部署位置的设备,如GTM(Global Traffic Manager,全局流量管理)设备等。
这里,用户终端可以为包括笔记本电脑、手机、平板电脑等具有无线网络接收功能的终端设备。
图2为本申请实施例提供的一种内网访问方法的系统交互示意图,如图所示,所述内网访问方法可以包括:
S201,移动无线接入设备向内网防火墙分配设备发送针对目标内网的内网连接请求。
具体的,所述移动无线接入设备可以是在被触发启动后,即向所述内网防火墙分配设备发送内网连接请求,也可以是在接收到用户发送的访问目标内网的功能启动指令后,向所述内网防火墙分配设备发送内网连接请求,还可以是在接收到所连接的用户终端发送的针对目标内网的内网访问请求时,向所述内网防火墙分配设备发送内网连接请求。所述内网连接请求可以携带所述目标内网的内网域名,以使所述内网防火墙分配设备对所述内网域名进行解析后,确定为针对目标内网的内网连接请求。
S202,所述内网防火墙分配设备根据所述内网连接请求获取所述移动无线接入设备的地理位置。
具体的,所述内网连接请求可以携带所述移动无线接入设备的地理位置,所述内网防火墙分配设备直接从所述内网连接请求中获取所述移动无线接入设备的地理位置;所述内网连接请求也可以携带所述移动无线接入设备的定位信息,所述内网防火墙分配设备可以从所述内网连接请求中获取所述定位信息,根据所述定位信息通过定位技术,确定所述移动无线接入设备的地点位置,例如,所述定位信息可以是所述移动无线接入设备的IP地址、GPS数据、WIFI接入点信息、连接基站信息等,所述定位技术可以是IP定位技术、GPS定位技术、WIFI定位技术、基站定位技术等。
S203,所述内网防火墙分配设备根据所述地理位置,从针对所述目标内网部署的多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙。
这里,所述内网防火墙分配设备中可以存储针对多个内网的分别部署的防火墙的IP地址和部署位置,例如,针对公司M有子公司A和子公司B,子公司A和子公司B分别有针对各自子公司的内网,且内网之间需要通过外网连接,公司M的移动无线接入设备中可以同时存储针对子公司A内网的部署的各个内网防火墙的IP地址和部署位置,以及针对子 公司B内网部署的各个内网防火墙的IP地址和部署位置。所述内网连接请求可以携带所述目标内网的内网域名,以使所述内网防火墙分配设备在接收到所述内网连接请求后,对所述内网域名进行解析后确定所述内网连接请求为针对所述目标内网的内网连接请求,进而获取针对所述目标内网部署的多个防火墙的IP地址和部署位置。
一种实现方式中,所述内网防火墙分配设备可以根据所述地理位置,和针对所述目标内网部署的各个内网防火墙的部署位置,将所述针对所述目标内网部署的多个防火墙中,距离所述移动无线接入设备最近的内网防火墙确定为所述第一内网防火墙。
另一种实现方式中,预先将针对所述目标内网的全部的访问区域划分成针对所述目标内网的各个内网防火墙的内网访问子区域,在所述内网防火墙分配设备中预先设置针对所述内网访问子区域与所述目标内网的内网防火墙的对应关系。所述内网防火墙分配设备根据所述移动无线接入设备的地理位置,确定所述移动无线接入设备所处于的目标内网访问子区域,进而将所述目标内网访问子区域对应的内网防火墙确定为所述第一内网防火墙。
S204,所述内网防火墙分配设备将所述第一内网防火墙的第一IP地址发送给所述移动无线接入设备。
S205,所述移动无线接入设备根据所述第一IP地址与所述第一内网防火墙建立连接。
具体的,所述移动无线接入设备根据所述第一IP地址,向所述第一内网防火墙发送防火墙连接请求,以使所述第一内网防火墙根据所述防火墙连接请求对所述移动接入设备的身份验证通过后,建立与所述移动无线接入设备的连接。
一种实现方式中,所述防火墙连接请求中携带所述移动无线接入设备的接入设备识别码,如MAC地址,所述第一内网防火墙在确定所述接入设备识别码为预设的允许连接接入设备识别码中的其中一个时,确定对所述移动无线接入设备的身份认证通过。
另一种实现方式中,所述防火墙连接请求中携带用户通过所述移动无线接入设备输入的用户名和密码,所述第一内网防火墙在确定所述用户名和密码为预设的允许连接用户名和密码中的其中一组时,确定对所述移动无线接入设备的身份认证通过。
又一种实现方式中,所述防火墙连接请求中携带所述移动无线接入设备的接入设备数字证书,所述第一内网防火墙根据所述接入设备数字证书中携带的所述接入设备数字证书的发布方信息,确定所述接入设备数字证书的证书发布方;所述第一内网防火墙获取所述证书发布方的发布方数字证书后,通过所述发布方数字证书中包含的发布方公钥,对所述接入设备数字证书中的数字签名进行解密得到所述接入设备数字证书的证书指纹,所述第一内网防火墙在将使用指定的哈希算法对所述接入设备数字证书进行哈希计算得到数字证书哈希值;所述第一内网防火墙在确定所述第一内网防火墙进行哈希计算得到的数字证书哈希值与所述接入设备证书指纹一致时,确定对所述移动无线接入设备的身份认证通过。
具体的,所述移动无线接入设备发起三次握手与所述第一内网防火墙建立基于TCP/IP协议的连接,具体步骤如下:所述移动无线接入设备向所述第一内网防火墙发送SYN(Synchronize Sequence Numbers,同步序列编号)数据包;所述第一内网防火墙接收到所述SYN数据包后,向所述移动无线接入设备发送SYN+ACK(ACKnowledge Character,确认字符)数据包;所述移动无线接入设备接收到所述SYN+ACK数据包后,向所述第一内网防火墙反馈ACK数据包;所述第一内网防火墙接收到所述移动无线接入设备反馈的ACK数据包后,所述移动无线接入设备与所述第一内网防火墙之间的连接建立完成。
S206,用户终端向所述移动无线接入设备发送针对所述目标内网的内网访问请求。
具体的,步骤S206之前,所述用户终端可以向所述移动无线接入设备发送无线网络连接请求,所述移动无线接入设备可以直接与所述用户终端建立连接,也可以通过所述无线网络连接请求携带的用户终端身份信息进行验证后,建立与所述用户终端的连接。所述用 户终端身份信息可以为所述用户终端接收到的用户输入的接入所述移动无线接入设备建立的无线网络的用户名与密码,还可以为用户终端接收到的用户输入的生物特征信息,还可以为所述用户终端的终端设备标识信息。
可以理解的是,所述移动无线接入设备与所述用户终端建立连接后,步骤S206可以在步骤S207之前的任何时间执行。
S207,所述移动无线接入设备将所述内网访问请求发送给所述第一内网防火墙。
S208,所述第一内网防火墙将所述内网访问请求路由至所述目标内网的内网服务器。
具体的,所述内网访问请求为针对目标内网中的服务器的访问请求,例如针对所述目标内网中Web服务器的访问请求、针对所述目标内网中FTP服务器的访问请求、针对所述目标内网中邮件服务器的访问请求等。所述第一内网防火墙接收到所述移动无线接入设备发送的内网访问请求之后,通过外网将所述内网访问请求发送给所述目标内网的路由器,所述目标内网的路由器通过所述目标内网将所述内网访问请求路由至所述目标内网中对应的内网服务器。这里,第一内网防火墙将内网访问请求路由至内网服务器的具体方式可以为,第一内网防火墙根据自身配置的网络协议及该协议对应的选路原则,选出到内网服务器的最佳路由路径,进而按照该最佳路由路径,将所述内网访问请求路由至内网服务器。
S209,所述内网服务器向所述第一内网防火墙返回响应所述内网访问请求的内网请求响应消息。
具体的,所述内网服务器响应所述内网访问请求生成内网请求响应消息后,将所述内网请求响应消息通过所述目标内网发送给所述目标内网的路由器,所述目标内网的路由器通过外网将所述内网请求响应消息发送给所述第一内网防火墙。例如,若所述内网访问请求为请求获取目标内网中文件服务器中的某文件,则所述内网请求响应消息可以为文件服务器发送的该文件。
S210,所述第一内网防火墙将所述内网请求响应消息发送给所述移动无线接入设备。
S211,所述移动无线接入设备将所述内网请求响应消息发送给所述用户终端。
本申请实施例中内网防火墙分配设备在接收到移动无线接入设备发送的针对目标内网的内网连接请求后,根据所述内网连接请求获取所述移动无线接入设备的地理位置,并根据所述地理位置,从针对所述目标内网部署的多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙,所述移动无线接入设备根据接收到所述内网防火墙分配设备发送的所述第一内网防火墙的第IP地址,向所述第一内网防火墙发送防火墙连接请求,以使所述第一内网防火墙与所述移动无线接入设备建立连接。所述移动无线接入设备在接收到用户终端发送的针对所述目标内网的内网访问请求后,将所述内网访问请求通过所述第一内网防火墙路由至所述目标内网的内网服务器,在接收到所述内网服务器响应所述内网访问请求通过所述第一内网防火墙返回的内网请求响应消息后,将所述内网请求响应消息发送至所述用户终端。用户终端通过基于移动无线接入设备和针对目标内网部署的防火墙的内网访问框架实现了对目标内网的访问,访问之前无需配置任何参数,提高了针对目标内网的访问效率。
参见图3,图3为本申请实施例提供的另一种内网访问方法的系统交互示意图,在所述移动无线接入设备与所述目标内网的第一内网防火墙建立连接后,所述内网防火墙分配设备可以监控所述移动无线接入设备是否需要切换所连接的第一内网防火墙,具体实现步骤可以如下:
S301,所述内网防火墙分配设备按照预设周期获取所述移动无线接入设备与所述地理位置的距离。
具体的,所述地理位置为所述移动无线接入设备向所述内网防火墙分配设备发送针对 所述目标内网的内网连接请求时所处于的地理位置。所述移动无线接入设备与所述地理位置之间的距离,可以为所述移动无线接入设备向所述内网防火墙分配设备周期性发送的,也可以为所述内网防火墙分配设备根据所述移动无线接入设备周期性发送的定位信息,通过定位技术确定得到的。
S302,当所述移动无线接入设备与所述地理位置的距离大于第一阈值时,所述内网防火墙分配设备获取所述移动无线接入设备的实时地理位置。
具体的,这里所述移动无线接入设备的实时地理位置可以为所述内网防火墙分配设备通过定位技术确定的,也可以是从所述移动无线接入设备获取的。所述内网防火墙分配设备在确定所述移动无线接入设备与所述地理位置的距离大于第一阈值时,确定所述移动无线接入设备与所述第一内网防火墙之间的网络延迟增大,为提高用户访问所述目标内网的网络质量,触发所述内网防火墙分配设备为所述移动无线接入设备重新匹配连接的防火墙。
S303,所述内网防火墙分配设备根据所述移动无线接入设备的实时地理位置和所述多个内网防火墙的部署位置,从所述多个内网防火墙中为所述移动无线接入设备确定匹配的第二内网防火墙。
S304,所述内网防火墙分配设备将所述第二内网防火墙的第二IP地址发送给所述移动无线接入设备。
S305,所述移动无线接入设备根据所述第二IP地址向所述第二内网防火墙发送防火墙连接请求。
S306,所述第二内网防火墙根据所述防火墙连接请求与所述移动无线接入设备建立连接。
步骤S303~S306的具体实现方式可以参考实施例一中步骤S203~S306的实现方式,此处不再赘述。
S307,所述移动无线接入设备断开与所述第一内网防火墙的连接。
这里,所述移动无线接入设备通过发起四次挥手断开与所述第二内网防火墙的TCP/IP连接,具体步骤如下:所述移动无线接入设备向所述第二内网防火墙发送FIN(Finish Character,结束字符)数据包;所述第二内网防火墙接收到所述FIN数据包后,向所述移动无线接入设备发送ACK数据包;所述第二内网防火墙向所述移动无线接入设备发送FIN数据包;所述移动无线接入设备接收到所述FIN数据包后,向所述第二内网防火墙发送ACK数据包;所述第二内网防火墙分配设备接收到所述ACK数据包后,所述移动无线接入设备与所述第二内网防火墙之间的连接断开完成。
这里,步骤S308在步骤S307之后执行,步骤S308中用户终端发送的内网访问请求为在所述移动无线接入设备与所述第一内网防火墙的连接断开后,向所述移动无线接入设备发送的内网访问请求。而在步骤S307之前,所述移动无线接入设备接收到的用户终端发送的针对所述目标内网的内网访问请求,通过所述目标内网的第一内网防火墙路由至所述目标内网中对应的内网服务器。
S309,所述移动无线接入设备将所述内网访问请求发送给所述第二内网防火墙。
S310,所述第二内网防火墙将所述内网访问请求路由至所述目标内网的内网服务器。
S311,所述内网服务器向所述第二内网防火墙返回响应所述内网访问请求的内网请求响应消息。
S312,所述第二内网防火墙将所述内网请求响应消息发送给所述移动无线接入设备。
S313,所述移动无线接入设备将所述内网请求响应消息发送给所述用户终端。
这里,步骤S308~步骤S313中通过所述移动无线接入设备与所述第二内网防火墙的连接为所述用户终端提供访问所述目标内网的服务的具体实现方式可参阅图2对应的实施例 中步骤S206~步骤S211中所述移动无线接入设备与所述第一内网防火墙的连接为所述用户终端提供访问所述目标内网的服务的具体实现方式,此处不再赘述。
本申请实施例中,所述移动无线接入设备在于所述第一内网防火墙建立连接后,所述内网防火墙分配设备按照预设周期对所述移动无线接入设备与所述地理位置的距离进行检测,在确定所述距离大于预设距离时,重新为所述移动无线接入设备分配第二内网防火墙,使所述移动无线接入设备将所连接的内网防火墙从第一内网防火墙切换至第二内网防火墙,保证了在移动无线接入设备移动的过程中,与所述移动无线接入设备相连接的内网防火墙总是与所述移动无线接入设备的实时地理位置相匹配的最优内网防火墙,保证了用户通过所述移动无线接入设备访问内网的网络质量。
参见图4,图4为本申请实施例提供的又一种内网访问方法的系统交互示意图,在所述移动无线接入设备与所述目标内网的第一内网防火墙建立连接后,所述移动无线接入设备可以监控所述移动无线接入设备是否需要切换所连接的第一内网防火墙,具体实现步骤可以如下:
S401,所述移动无线接入设备按照预设周期获取与所述第一内网防火墙连接的接入设备连接状态信息,和/或,所述用户终端针对所述目标内网的终端访问状态信息。
这里,所述接入设备连接状态信息可以包括所述移动无线接入设备的上行丢包率、下行丢包率、每秒发送数据包个数、每秒接收数据包个数等指标信息。所述终端访问状态信息可以包括所述用户终端的上行丢包率、下行丢包率、每秒发送数据包个数、每秒接收数据包个数等指标信息。所述终端访问状态信息可以由所述用户终端确定后发送给所述移动无线接入设备。
S402,所述移动无线接入设备在根据所述接入设备连接状态信息,和/或,所述终端访问状态信息,确定所述用户终端对所述目标内网的访问处于异常状态时,向所述内网防火墙分配设备发送防火墙切换请求。
具体的,可以预先在所述移动无线接入设备中设置针对所述接入设备连接状态信息中的各项指标,和/或,所述终端连接状态信息中的各项指标的评估模型,所述移动无线接入设备可以通过上述评估模型对所述接入设备连接状态信息,和/或,所述终端访问状态信息进行评估,以判断所述用户终端对所述目标内网的访问是否处于异常状态。例如,若与所述第一内网防火墙的距离较远,连接网络质量较差时,所述接入设备连接状态信息中的上行丢包率会大于预设的丢包率阈值,所述移动无线接入设备确定所述用户终端对所述目标内网的访问处于异常状态;若所述第一内网防火墙出现拥塞时,所述终端连接状态信息中的每秒接收数据包个数会小于预设接收数据包阈值,所述移动无线接入设备确定所述用户终端对所述目标内网的访问处于异常状态。
S403,所述内网防火墙分配设备根据所述防火墙求换请求从所述多个内网防火墙中确定所述移动无线接入设备匹配的第三内网防火墙。
这里,所述内网防火墙分配设备根据所述防火墙切换请求从所述多个内网防火墙中确定所述移动无线接入设备匹配的第三内网防火墙的实现方式,可以参阅图2对应的实施例中,步骤S202~步骤S203中所述内网防火墙分配设备为所述移动无线接入设备从针对所述目标内网部署的多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙的实现方式,此处不再赘述。
可以理解的是,若所述第一内网防火墙出现故障时,步骤S403中确定的所述第三内网防火墙与所述第一内网防火墙可能为同一内网防火墙,此时可以从除去所述第一内网防火墙的其他针对目标内网部署的内网防火墙中再次确定所述第三内网防火墙。
S404,所述移动无线接入设备接收所述内网防火墙分配设备发送的所述第三内网防火 墙的第三IP地址。
S405,所述移动无线接入设备根据所述第三IP地址向所述第三内网防火墙发送防火墙连接请求。
S406,所述第三内网防火墙根据所述防火墙连接请求与所述移动无线接入设备建立连接。
这里,第三内网防火墙与所述移动无线接入设备建立连接的具体实现方式可以参与图2对应的实施例,步骤S205中所述第一内网防火墙与所述移动无线接入设备建立连接的实现方式,此处不再赘述。
S407,所述移动无线接入设备断开与所述第一内网防火墙的连接。
这里,所述移动无线接入设备与所述第一内网防火墙连接的断开可参阅图3对应的实施例中步骤S307中所述移动无线接入设备与所述第一内网防火墙连接断开的具体实现方式,此处不再赘述。
S408,用户终端向所述移动无线接入设备发送针对所述目标内网的内网访问请求。
这里,步骤S408在步骤S407之后执行,步骤S408中用户终端发送的内网访问请求为在所述移动无线接入设备与所述第一内网防火墙的连接断开后,向所述移动无线接入设备发送的内网访问请求。而在步骤S407之前,所述移动无线接入设备接收到的用户终端发送的针对所述目标内网的内网访问请求,通过所述目标内网的第一内网防火墙路由至所述目标内网中对应的内网服务器。
S409,所述移动无线接入设备将所述内网访问请求发送给所述第二内网防火墙。
S410,所述第二内网防火墙将所述内网访问请求路由至所述目标内网的内网服务器。
S411,所述内网服务器向所述第二内网防火墙返回响应所述内网访问请求的内网请求响应消息。
S412,所述第二内网防火墙将所述内网请求响应消息发送给所述移动无线接入设备。
S413,所述移动无线接入设备将所述内网请求响应消息发送给所述用户终端。
这里,步骤S408~步骤S413中通过所述移动无线接入设备与所述第二内网防火墙的连接为所述用户终端提供访问所述目标内网的服务的具体实现方式可参阅图2对应的实施例中步骤S206~步骤S211中所述移动无线接入设备与所述第一内网防火墙的连接为所述用户终端提供访问所述目标内网的服务的具体实现方式,此处不再赘述。
本申请实施例中,所述移动无线接入设备在于所述第一内网防火墙建立连接后,所述移动无线接入设备按照预设周期对所述移动无线接入设备与所述第一内网防火墙连接的接入设备连接状态信息,和/或,所述用户终端针对所述目标内网的终端访问状态信息进行检测,在根据所述接入设备连接状态信息,和/或,所述终端连接状态信息,确定所述用户终端对所述目标内网的访问处于异常状态时,向所述内网防火墙分配设备请求切换所连接的第一内网防火墙,所述内网防火墙分配设备为所述移动无线接入设备重新分配第三内网防火墙后,所述移动无线接入设备将所连接的内网防火墙从第一内网防火墙切换至第三内网防火墙,用户通过所述移动无线接入设备访问内网的网络质量。
参见图5,图5为本申请实施例提供的一种内网防火墙分配设备的结构示意图,如图所示,所述内网防火墙分配设备50可以至少包括请求接收单元501、位置获取单元502、内网防火墙确定单元503和地址发送单元504,其中:
请求接收单元501,用于接收移动无线接入设备发送的针对目标内网的内网连接请求。
位置获取单元502,用于根据所述内网连接请求获取所述移动无线接入设备的地理位置。
内网防火墙确定单元503,用于根据所述地理位置,从针对所述目标内网部署的多个 内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙。
地址发送单元504,用于将所述第一内网防火墙的第一IP地址发送给所述移动无线接入设备,以使在所述移动无线接入设备根据所述第一IP地址与所述第一内网防火墙建立连接后,所述第一内网防火墙将接收到的目标内网访问请求路由至所述目标内网的内网服务器,所述内网访问请求为用户终端通过所述移动无线接入设备发送的针对所述目标内网的内网服务器的访问请求,所述第一内网防火墙还将所述目标内网服务器响应所述内网访问请求返回的内网请求响应消息,通过移动无线接入设备发送至所述用户终端。
具体实现中,所述内网防火墙分配设备可以通过其内置的各个功能模块执行如图2至图4的内网访问方法中所述内网防火墙分配设备执行的各个步骤,具体实施细节可参阅图2至图4对应的实施例中各个步骤的实现细节,此处不再赘述。
本申请实施例中请求接收单元在接收到移动无线接入设备发送的针对目标内网的内网连接请求后,位置获取单元根据所述内网连接请求获取所述移动无线接入设备的地理位置,内网防火墙确定单元根据所述地理位置,从针对所述目标内网部署的多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙,所述移动无线接入设备根据接收到地址发送单元发送的所述第一内网防火墙的第IP地址,向所述第一内网防火墙发送防火墙连接请求,以使所述第一内网防火墙与所述移动无线接入设备建立连接。所述移动无线接入设备在接收到用户终端发送的针对所述目标内网的内网访问请求后,将所述内网访问请求通过所述第一内网防火墙路由至所述目标内网的内网服务器,在接收到所述内网服务器响应所述内网访问请求通过所述第一内网防火墙返回的内网请求响应消息后,将所述内网请求响应消息发送至所述用户终端。用户终端通过基于移动无线接入设备和针对目标内网部署的防火墙的内网访问框架实现了对目标内网的访问,访问之前无需配置任何参数,提高了针对目标内网的访问效率。
参见图6,图6为本申请实施例提供的一种移动无线接入设备的结构示意图,如图所示,所述移动无线接入设备60可以至少包括请求发送单元601、地址接收单元602、防火墙连接单元603和消息传输单元604,其中:
请求发送单元601,用于向内网防火墙分配设备发送针对所述目标内网的内网连接请求,以使所述内网防火墙分配设备从所述多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙。
地址接收单元602,用于接收所述内网防火墙分配设备发送的所述第一内网防火墙的第一IP地址。
防火墙连接单元603,用于根据所述第一IP地址,向所述第一内网防火墙发送防火墙连接请求,以使所述第一内网防火墙根据所述防火墙连接请求与所述移动无线接入设备建立连接。
消息传输单元604,用于在从用户终端接收到针对所述目标内网的内网访问请求后,将所述内网访问请求通过所述第一内网防火墙路由至所述目标内网的内网服务器。
所述消息传输单元605,还用于在接收到所述内网服务器响应所述内网访问请求通过所述第一内网防火墙返回的内网请求响应消息后,将所述内网请求响应消息发送至所述用户终端。
具体实现中,所述移动无线接入设备可以通过其内置的各个功能模块执行如图2至图4的内网访问方法中所述移动无线接入设备执行的各个步骤,具体实施细节可参阅图2至图4对应的实施例中各个步骤的实现细节,此处不再赘述。
本申请实施例中请求发送单元向内网防火墙分配设备发送内网连接请求后,内网防火墙分配设备根据所述内网连接请求获取所述地理位置,并根据所述地理位置从针对所述目 标内网部署的多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙,所述防火墙连接单元根据所述地址接收单元接收到所述内网防火墙分配设备发送的所述第一内网防火墙的第IP地址,向所述第一内网防火墙发送防火墙连接请求,以使所述第一内网防火墙与所述防火墙连接单元建立连接后,通过所述消息传输单元为与所述移动无线接入设备相连的用户终端提供访问所述目标内网的服务。用户终端通过基于移动无线接入设备和针对目标内网部署的防火墙的内网访问框架实现了对目标内网的访问,访问之前无需配置任何参数,提高了针对目标内网的访问效率。
参见图7,图7为本申请实施例提供的另一种内网防火墙分配设备的结构示意图,如图所示,所述内网防火墙分配设备70包括处理器701、存储器702以及通信接口703。处理器701连接到存储器702和通信接口703,例如处理器701可以通过总线连接到存储器702和通信接口703。
处理器701被配置为支持内网防火墙分配设备执行图2-图4所述的内网访问方法中内网防火墙分配设备的相应的功能。该处理器701可以是中央处理器(Central Processing Unit,CPU),网络处理器(Network Processor,NP),硬件芯片或者其任意组合。上述硬件芯片可以是专用集成电路(Application-Specific Integrated Circuit,ASIC),可编程逻辑器件(Programmable Logic Device,PLD)或其组合。上述PLD可以是复杂可编程逻辑器件(Complex Programmable Logic Device,CPLD),现场可编程逻辑门阵列(Field-Programmable Gate Array,FPGA),通用阵列逻辑(Generic Array Logic,GAL)或其任意组合。
存储器702用于存储程序代码等。存储器702包括内部存储器,内部存储器可以包括以下至少一项:易失性存储器(例如动态随机存取存储器(DRAM)、静态RAM(SRAM)、同步动态RAM(SDRAM)等)和非易失性存储器(例如一次性可编程只读存储器(OTPROM)、可编程ROM(PROM)、可擦除可编程ROM(EPROM)、电可擦除可编程ROM(EEPROM)。存储器702还可以包括外部存储器,外部存储器可以包括以下至少一项:硬盘(Hard Disk Drive,HDD)或固态硬盘(Solid-State Drive,SSD)、闪驱,例如高密度闪存(CF)、安全数字(SD)、微型SD、迷你型SD、极限数字(xD)、存储棒等。
所述通信接口703用于接收或发送数据。
处理器701可以调用所述程序代码以执行以下操作:
接收移动无线接入设备发送的针对目标内网的内网连接请求;
根据所述内网连接请求获取所述移动无线接入设备的地理位置;
根据所述地理位置,从针对所述目标内网部署的多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙;
将所述第一内网防火墙的第一IP地址发送给所述移动无线接入设备,以使在所述移动无线接入设备根据所述第一IP地址与所述第一内网防火墙建立连接后,所述第一内网防火墙将接收到的内网访问请求路由至所述目标内网的内网服务器,所述内网访问请求为用户终端通过所述移动无线接入设备发送的针对所述目标内网的内网服务器的访问请求,所述第一内网防火墙还将所述内网服务器响应所述内网访问请求返回的内网请求响应消息,通过所述移动无线接入设备发送至所述用户终端。
需要说明的是,各个操作的实现还可以对应参照图2-图4所示的方法实施例的相应描述;所述处理器701还可以用于执行上述方法实施例中的其他操作。
参见图8,图8为本申请实施例提供的另一种移动无线接入设备的结构示意图,如图所示所述移动无线接入设备80包括处理器801、存储器802以及通信接口803。处理器801连接到存储器802和通信接口803,例如处理器801可以通过总线连接到存储器802和通 信接口803。
处理器801被配置为支持移动无线接入设备执行图2-图4所述的内网访问方法中移动无线接入设备的相应的功能。该处理器801可以是中央处理器(Central Processing Unit,CPU),网络处理器(Network Processor,NP),硬件芯片或者其任意组合。上述硬件芯片可以是专用集成电路(Application-Specific Integrated Circuit,ASIC),可编程逻辑器件(Programmable Logic Device,PLD)或其组合。上述PLD可以是复杂可编程逻辑器件(Complex Programmable Logic Device,CPLD),现场可编程逻辑门阵列(Field-Programmable Gate Array,FPGA),通用阵列逻辑(Generic Array Logic,GAL)或其任意组合。
存储器802用于存储程序代码等。存储器802包括内部存储器,内部存储器可以包括以下至少一项:易失性存储器(例如动态随机存取存储器(DRAM)、静态RAM(SRAM)、同步动态RAM(SDRAM)等)和非易失性存储器(例如一次性可编程只读存储器(OTPROM)、可编程ROM(PROM)、可擦除可编程ROM(EPROM)、电可擦除可编程ROM(EEPROM)。存储器802还可以包括外部存储器,外部存储器可以包括以下至少一项:硬盘(Hard Disk Drive,HDD)或固态硬盘(Solid-State Drive,SSD)、闪驱,例如高密度闪存(CF)、安全数字(SD)、微型SD、迷你型SD、极限数字(xD)、存储棒等。
所述通信接口803用于接收或发送数据。
处理器801可以调用所述程序代码以执行以下操作:
向内网防火墙分配设备发送针对所述目标内网的内网连接请求,以使所述内网防火墙分配设备根据所述内网连接请求获取所述移动无线接入设备的地理位置,并根据所述地理位置从针对所述内网部署的多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙;
接收所述内网防火墙分配设备发送的所述第一内网防火墙的第一IP地址;
根据所述第一IP地址,向所述第一内网防火墙发送防火墙连接请求,以使所述第一内网防火墙根据所述防火墙连接请求与所述移动无线接入设备建立连接;
在接收到用户终端发送的针对所述目标内网的内网访问请求后,将所述内网访问请求通过所述第一内网防火墙路由至所述目标内网的内网服务器;
在接收到所述内网服务器响应所述内网访问请求通过所述第一内网防火墙返回的内网请求响应消息后,将所述内网请求响应消息发送至所述用户终端。
需要说明的是,各个操作的实现还可以对应参照图2-图4所示的方法实施例的相应描述;所述处理器801还可以用于执行上述方法实施例中的其他操作。
本申请实施例还提供一种计算机非易失性可读存储介质,所述计算机非易失性可读存储介质存储有计算机程序,所述计算机程序包括程序指令,所述程序指令当被计算机执行时使所述计算机执行如前述实施例所述的方法,所述计算机可以为上述提到的内网防火墙分配设备或所述移动无线接入设备的一部分。
本领域普通技术人员可以理解实现上述实施例方法中的全部或部分流程,是可以通过计算机程序来指令相关的硬件来完成,所述的程序可存储于一计算机可读取存储介质中,该程序在执行时,可包括如上述各方法的实施例的流程。其中,所述的存储介质可为磁碟、光盘、只读存储记忆体(Read-Only Memory,ROM)或随机存储记忆体(Random Access Memory,RAM)等。

Claims (20)

  1. 一种内网访问方法,其特征在于,包括:
    内网防火墙分配设备接收移动无线接入设备发送的针对目标内网的内网连接请求;
    所述内网防火墙分配设备根据所述内网连接请求获取所述移动无线接入设备的地理位置;
    所述内网防火墙分配设备根据所述地理位置,从针对所述目标内网部署的多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙;
    所述内网防火墙分配设备将所述第一内网防火墙的第一IP地址发送给所述移动无线接入设备,以使在所述移动无线接入设备根据所述第一IP地址与所述第一内网防火墙建立连接后,所述第一内网防火墙将接收到的内网访问请求路由至所述目标内网的内网服务器,所述内网访问请求为用户终端通过所述移动无线接入设备发送的针对所述目标内网的内网服务器的访问请求,所述第一内网防火墙还将所述内网服务器响应所述内网访问请求返回的内网请求响应消息,通过所述移动无线接入设备发送至所述用户终端。
  2. 如权利要求1所述的方法,其特征在于,所述内网防火墙分配设备根据所述地理位置,从针对所述目标内网部署的多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙包括:
    所述内网防火墙分配设备获取所述多个内网防火墙的部署位置,并根据所述地理位置和所述多个内网防火墙的部署位置,将所述多个内网防火墙中与所述移动无线接入设备距离最近的内网防火墙确定为所述第一内网防火墙。
  3. 如权利要求1~2任一所述的方法,其特征在于,所述内网防火墙分配设备根据所述地理位置,从针对所述目标内网部署的多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙包括:
    所述内网防火墙分配设备确定所述地理位置所在的针对所述目标内网的目标内网访问子区域;
    所述内网防火墙分配设备根据预设的内网访问子区域与所述目标内网的内网防火墙的对应关系,将与所述目标内网访问子区域对应的内网防火墙确定为所述第一内网防火墙。
  4. 如权利要求1~3中任一项所述的方法,其特征在于,所述方法还包括:
    所述内网防火墙分配设备按照预设周期获取所述移动无线接入设备与所述地理位置的距离;
    当所述移动无线接入设备与所述地理位置的距离大于第一阈值时,所述内网防火墙分配设备获取所述移动无线接入设备的实时地理位置;
    所述内网防火墙分配设备根据所述移动无线接入设备的实时地理位置和所述多个内网防火墙的部署位置,从所述多个内网防火墙中为所述移动无线接入设备确定匹配的第二内网防火墙;
    所述内网防火墙分配设备将所述第二内网防火墙的第二IP地址发送给所述移动无线接入设备,以使所述移动无线接入设备根据所述第二IP地址与所述第二内网防火墙建立连接,并与所述第一内网防火墙断开连接。
  5. 如权利要求1~4任一所述的方法,其特征在于,所述内网防火墙分配设备将所述第一内网防火墙的第一IP地址发送给所述移动无线接入设备之前,还包括:
    所述内网防火墙分配设备获取所述移动无线接入设备的设备身份信息,和/或,与所述移动无线接入设备连接的用户终端的终端身份信息;
    所述内网防火墙分配设备根据所述地理位置,从所述多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙包括:
    所述内网防火墙分配设备在根据所述设备身份信息对所述移动无线接入设备进行的身份验证通过后,和/或,在根据所述终端身份信息对与所述移动无线接入设备连接的用户终端进行的身份验证通过后,根据所述地理位置,从所述多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙。
  6. 一种内网访问方法,其特征在于,包括:
    移动无线接入设备向内网防火墙分配设备发送针对所述目标内网的内网连接请求,以使所述内网防火墙分配设备根据所述内网连接请求获取所述移动无线接入设备的地理位置,并根据所述地理位置从针对所述内网部署的多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙;
    所述移动无线接入设备接收所述内网防火墙分配设备发送的所述第一内网防火墙的第一IP地址;
    所述移动无线接入设备根据所述第一IP地址,向所述第一内网防火墙发送防火墙连接请求,以使所述第一内网防火墙根据所述防火墙连接请求与所述移动无线接入设备建立连接;
    所述移动无线接入设备在接收到用户终端发送的针对所述目标内网的内网访问请求后,将所述内网访问请求通过所述第一内网防火墙路由至所述目标内网的内网服务器;
    所述移动无线接入设备在接收到所述内网服务器响应所述内网访问请求通过所述第一内网防火墙返回的内网请求响应消息后,将所述内网请求响应消息发送至所述用户终端。
  7. 如权利要求6所述的方法,其特征在于,所述移动无线接入设备根据所述第一IP地址,向所述第一内网防火墙发送防火墙连接请求,还包括:
    所述移动无线接入设备按照预设周期获取与所述第一内网防火墙连接的接入设备连接状态信息,和/或,所述用户终端针对所述目标内网的终端访问状态信息;
    所述移动无线接入设备在根据所述接入设备连接状态信息,和/或,所述终端访问状态信息,确定所述用户终端对所述目标内网的访问处于异常状态时,向所述内网防火墙分配设备发送防火墙切换请求,以使所述内网防火墙分配设备根据所述防火墙求换请求从所述多个内网防火墙中确定所述移动无线接入设备匹配的第三内网防火墙;
    所述移动无线接入设备接收所述内网防火墙分配设备发送的所述第三内网防火墙的第三IP地址,并根据所述第三IP地址向所述第三内网防火墙发送防火墙请求,以使所述第三内网防火墙根据所述防火墙连接请求与所述移动无线接入设备建立连接;
    所述移动无线接入设备断开与所述第一内网防火墙的连接;
    所述移动无线接入设备在接收到所述用户终端发送的针对所述目标内网的内网访问请求后,将所述内网访问请求通过所述第三内网防火墙路由至所述目标内网的内网服务器;
    所述移动无线接入设备在接收到所述内网服务器响应所述内网访问请求通过所述第三内网防火墙返回的内网请求响应消息后,将所述内网请求响应消息发送至所述用户终端。
  8. 如权利要求6~7任一所述的方法,其特征在于,所述移动无线接入设备向内网防火墙分配设备发送针对所述目标内网的内网连接请求之前,还包括:
    所述移动无线接入设备接收所述用户终端发送的无线网络连接请求,所述无线网络连 接请求携带所述用户终端的用户终端身份信息,所述用户终端身份信息为用户输入的用户名和密码、用户输入的生物特征信息或所述用户终端的终端设别标识信息中的一种;
    所述移动无线接入设备对所述用户终端身份信息进行验证,并在验证通过的情况下,建立与所述用户终端的连接。
  9. 如权利要求6~8任一所述的方法,其特征在于,所述移动无线接入设备向所述第一内网防火墙发送的防火墙连接请求携带所述移动无线接入设备的接入设备数字证书;
    所述数字证书被所述第一内网防火墙用于根据所述接入设备数字证书中携带的发布方信息,确定所述接入设备数字证书的证书发布方,获取所述证书发布方的发布方数字证书后,通过所述发布方数字证书中包含的发布方公钥,对所述接入设备数字证书中的数字签名进行解密得到所述接入设备数字证书的证书指纹,所述第一内网防火墙在将使用指定的哈希算法对所述接入设备数字证书进行哈希计算得到数字证书哈希值,并在确定所述数字证书哈希值与所述接入设备数字证书的证书指纹一致时,确定对所述移动无线接入设备的身份认证通过,进而与所述移动无线设备建立连接。
  10. 一种内网防火墙分配设备,其特征在于,包括:
    请求接收单元,用于接收移动无线接入设备发送的针对目标内网的内网连接请求;
    位置获取单元,用于根据所述内网连接请求获取所述移动无线接入设备的地理位置;
    内网防火墙确定单元,用于根据所述地理位置,从针对所述目标内网部署的多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙;
    地址发送单元,用于将所述第一内网防火墙的第一IP地址发送给所述移动无线接入设备,以使在所述移动无线接入设备根据所述第一IP地址与所述第一内网防火墙建立连接后,所述第一内网防火墙将接收到的目标内网访问请求路由至所述目标内网的内网服务器,所述内网访问请求为用户终端通过所述移动无线接入设备发送的针对所述目标内网的内网服务器的访问请求,所述第一内网防火墙还将所述目标内网服务器响应所述内网访问请求返回的内网请求响应消息,通过所述移动无线接入设备发送至所述用户终端。
  11. 如权利要去10所述的设备,其特征在于,所述内网防火墙确定单元,具体用于:
    获取所述多个内网防火墙的部署位置,并根据所述地理位置和所述多个内网防火墙的部署位置,将所述多个内网防火墙中与所述移动无线接入设备距离最近的内网防火墙确定为所述第一内网防火墙。
  12. 如权利要求10~11任一所述的设备,其特征在于,所述内网防火墙确定单元,具体用于:
    确定所述地理位置所在的针对所述目标内网的目标内网访问子区域;
    根据预设的内网访问子区域与所述目标内网的内网防火墙的对应关系,将与所述目标内网访问子区域对应的内网防火墙确定为所述第一内网防火墙。
  13. 如权利要求10~12中任一所述的设备,其特征在于,所述内网防火墙确定单元还用于:
    按照预设周期获取所述移动无线接入设备与所述地理位置的距离;
    当所述移动无线接入设备与所述地理位置的距离大于第一阈值时,获取所述移动无线接入设备的实时地理位置;
    根据所述移动无线接入设备的实时地理位置和所述多个内网防火墙的部署位置,从所述多个内网防火墙中为所述移动无线接入设备确定匹配的第二内网防火墙;
    所述地址发送单元,还用于:
    所述内网防火墙分配设备将所述第二内网防火墙的第二IP地址发送给所述移动无线接入设备,以使所述移动无线接入设备根据所述第二IP地址与所述第二内网防火墙建立连接,并与所述第一内网防火墙断开连接。
  14. 如权利要求10~13任一所述的设备,其特征在于,所述地址获取单元,还用于获取所述移动无线接入设备的设备身份信息,和/或,与所述移动无线接入设备连接的用户终端的终端身份信息;
    所述内网防火墙确定单元具体用于:
    所述内网防火墙分配设备在根据所述设备身份信息对所述移动无线接入设备进行的身份验证通过后,和/或,在根据所述终端身份信息对与所述移动无线接入设备连接的用户终端进行的身份验证通过后,根据所述地理位置,从所述多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙。
  15. 一种移动无线接入设备,其特征在于,包括:
    请求传输单元,用于向内网防火墙分配设备发送针对所述目标内网的内网连接请求,以使所述内网防火墙分配设备根据所述内网连接请求获取所述移动无线接入设备的地理位置,并根据所述地理位置从针对所述内网部署的多个内网防火墙中确定所述移动无线接入设备匹配的第一内网防火墙;
    地址接收单元,用于接收所述内网防火墙分配设备发送的所述第一内网防火墙的第一IP地址;
    所述请求传输单元,还用于根据所述第一IP地址,向所述第一内网防火墙发送防火墙连接请求,以使所述第一内网防火墙根据所述防火墙连接请求与所述移动无线接入设备建立连接;
    消息传输单元,用于在接收到用户终端发送的针对所述目标内网的内网访问请求后,将所述内网访问请求通过所述第一内网防火墙路由至所述目标内网的内网服务器;
    所述消息传输单元,还用于在接收到所述内网服务器响应所述内网访问请求通过所述第一内网防火墙返回的内网请求响应消息后,将所述内网请求响应消息发送至所述用户终端。
  16. 如权利要求15所述的设备,其特征在于,所述地址接收单元,还用于:
    按照预设周期获取与所述第一内网防火墙连接的接入设备连接状态信息,和/或,所述用户终端针对所述目标内网的终端访问状态信息;
    在根据所述接入设备连接状态信息,和/或,所述终端访问状态信息,确定所述用户终端对所述目标内网的访问处于异常状态时,向所述内网防火墙分配设备发送防火墙切换请求,以使所述内网防火墙分配设备根据所述防火墙求换请求从所述多个内网防火墙中确定所述移动无线接入设备匹配的第三内网防火墙;
    接收所述内网防火墙分配设备发送的所述第三内网防火墙的第三IP地址;
    所述请求传输单元,还用于:
    根据所述第三IP地址向所述第三内网防火墙发送防火墙请求,以使所述第三内网防火墙根据所述防火墙连接请求与所述移动无线接入设备建立连接,并断开与所述第一内网防火墙的连接;
    所述消息传输单元,还用于:
    所述移动无线接入设备在接收到所述用户终端发送的针对所述目标内网的内网访问请求后,将所述内网访问请求通过所述第三内网防火墙路由至所述目标内网的内网服务器;
    所述移动无线接入设备在接收到所述内网服务器响应所述内网访问请求通过所述第三内网防火墙返回的内网请求响应消息后,将所述内网请求响应消息发送至所述用户终端。
  17. 如权利要求15~16任一所述的设备,其特征在于,所述请求传输单元,还用于:
    接收所述用户终端发送的无线网络连接请求,所述无线网络连接请求携带所述用户终端的用户终端身份信息,所述用户终端身份信息为用户输入的用户名和密码、用户输入的生物特征信息或所述用户终端的终端设别标识信息中的一种;
    对所述用户终端身份信息进行验证,并在验证通过的情况下,建立与所述用户终端的连接。
  18. 如权利要求15~17任一所述的设备,其特征在于,所述请求传输单元向所述第一内网防火墙发送的防火墙连接请求携带所述移动无线接入设备的接入设备数字证书;
    所述数字证书被所述第一内网防火墙用于根据所述接入设备数字证书中携带的发布方信息,确定所述接入设备数字证书的证书发布方,获取所述证书发布方的发布方数字证书后,通过所述发布方数字证书中包含的发布方公钥,对所述接入设备数字证书中的数字签名进行解密得到所述接入设备数字证书的证书指纹,所述第一内网防火墙在将使用指定的哈希算法对所述接入设备数字证书进行哈希计算得到数字证书哈希值,并在确定所述数字证书哈希值与所述接入设备数字证书的证书指纹一致时,确定对所述移动无线接入设备的身份认证通过,进而与所述移动无线设备建立连接。
  19. 一种移动无线接入设备,其特征在于,包括处理器、存储器以及通信接口,所述处理器、存储器和通信接口相互连接,其中,所述通信接口用于接收和发送数据,所述存储器用于存储程序代码,所述处理器用于调用所述程序代码,执行如权利要求6-9任一项所述的方法。
  20. 一种计算机非易失性可读存储介质,其特征在于,所述计算机非易失性可读存储介质存储有计算机程序,所述计算机程序包括程序指令,所述程序指令当被处理器执行时使所述处理器执行如权利要求1-9任一项所述的方法。
PCT/CN2019/102346 2019-06-10 2019-08-23 一种内网访问方法、系统及相关装置 Ceased WO2020248368A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201910499038.0 2019-06-10
CN201910499038.0A CN110336794B (zh) 2019-06-10 2019-06-10 一种内网访问方法、系统及相关装置

Publications (1)

Publication Number Publication Date
WO2020248368A1 true WO2020248368A1 (zh) 2020-12-17

Family

ID=68140876

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2019/102346 Ceased WO2020248368A1 (zh) 2019-06-10 2019-08-23 一种内网访问方法、系统及相关装置

Country Status (2)

Country Link
CN (1) CN110336794B (zh)
WO (1) WO2020248368A1 (zh)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111490993B (zh) * 2020-04-13 2021-03-30 江苏易安联网络技术有限公司 一种应用访问控制安全系统及方法
CN112150047B (zh) * 2020-11-24 2021-03-09 山东富通信息科技有限公司 专线网络环境下的资源管理系统
CN112867041B (zh) * 2020-12-28 2023-03-21 美的集团股份有限公司 家电设备的配网方法、家电设备、移动终端及介质

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102769631A (zh) * 2012-07-31 2012-11-07 华为技术有限公司 访问云服务器的方法、系统和接入设备
CN109076005A (zh) * 2018-04-28 2018-12-21 深圳前海达闼云端智能科技有限公司 一种vpn线路切换方法、装置及电子设备
CN109617780A (zh) * 2019-01-29 2019-04-12 新华三技术有限公司 接入网络的方法、装置、终端设备及机器可读存储介质

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7805756B2 (en) * 1996-11-29 2010-09-28 Frampton E Ellis Microchips with inner firewalls, faraday cages, and/or photovoltaic cells
US6880089B1 (en) * 2000-03-31 2005-04-12 Avaya Technology Corp. Firewall clustering for multiple network servers
CN101635759A (zh) * 2009-08-26 2010-01-27 深圳华为通信技术有限公司 一种移动终端防火墙的实现方法及装置
US8850513B2 (en) * 2011-12-28 2014-09-30 Samsung Electronics Co., Ltd. System for data flow protection and use control of applications and portable devices configured by location
CN109347783A (zh) * 2018-08-01 2019-02-15 株洲凯创技术有限公司 数据过滤方法、装置、系统及列车车载防火墙设备
CN108989352B (zh) * 2018-09-03 2022-11-11 平安科技(深圳)有限公司 防火墙实现方法、装置、计算机设备及存储介质
CN109246257B (zh) * 2018-10-12 2021-10-08 平安科技(深圳)有限公司 流量调配方法、装置、计算机设备及存储介质

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102769631A (zh) * 2012-07-31 2012-11-07 华为技术有限公司 访问云服务器的方法、系统和接入设备
CN109076005A (zh) * 2018-04-28 2018-12-21 深圳前海达闼云端智能科技有限公司 一种vpn线路切换方法、装置及电子设备
CN109617780A (zh) * 2019-01-29 2019-04-12 新华三技术有限公司 接入网络的方法、装置、终端设备及机器可读存储介质

Also Published As

Publication number Publication date
CN110336794B (zh) 2022-08-30
CN110336794A (zh) 2019-10-15

Similar Documents

Publication Publication Date Title
CN104767715B (zh) 网络接入控制方法和设备
CN105635084B (zh) 终端认证装置及方法
JP2017537576A (ja) モバイル仮想ネットワークにおけるモバイル認証
CN115706977B (zh) 一种数据传输方法及相关设备
US11743724B2 (en) System and method for accessing a privately hosted application from a device connected to a wireless network
CN103179100A (zh) 一种防止域名系统隧道攻击的方法及设备
WO2017167249A1 (zh) 一种专网接入方法、装置及系统
CN110311785B (zh) 一种内网访问方法及相关装置
WO2020248368A1 (zh) 一种内网访问方法、系统及相关装置
KR101991340B1 (ko) 보안 관리를 위한 장치 및 방법
CN110266674B (zh) 一种内网访问方法及相关装置
CN109936515A (zh) 接入配置方法、信息提供方法及装置
CN110336793B (zh) 一种内网访问方法及相关装置
CN110324826B (zh) 一种内网访问方法及相关装置
CN108600207A (zh) 基于802.1x与savi的网络认证与访问方法
CN110324318B (zh) 一种内网访问方法及相关装置
CN116471590A (zh) 终端接入方法、装置及鉴权服务功能网元
JP7842920B2 (ja) Ipネットワークにアクセスするための通信サービスを提供するための装置、方法及びそのためのプログラム
JP2023002448A (ja) Ipネットワークにアクセスするための通信サービスを提供するための装置、方法及びそのためのプログラム
WO2017084322A1 (zh) 一种基于路由器的网络访问控制方法、系统及相关设备
CN110213769B (zh) 一种内网访问方法及相关装置
CN105610599B (zh) 用户数据管理方法及装置
EP4064745A1 (en) Network device management method and apparatus, network management device, and medium
CN113747609A (zh) 无线基站装置、存储介质、无线通信系统及无线通信方法
WO2017091949A1 (zh) 通讯方法、微基站、微基站控制器、终端和系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19932473

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 19932473

Country of ref document: EP

Kind code of ref document: A1