Summary of the invention
The shortcoming of prior art in view of the above, the object of the present invention is to provide a kind of network equipment access control method and system, cannot carry out unified management for solving in prior art to the access control of the network equipment.
For achieving the above object and other relevant objects, the invention provides a kind of network equipment access control method, described network equipment access control method comprises: for the access control scheme setting of access and net control equipment responds priority; The management item that described access control scheme is managed is added in the management information bank of the described network equipment; When the described network equipment receives the request that each access control scheme sends, according to each described access control scheme of described response two priority classes of the management item in described management information bank and setting to the access of the described network equipment and control.
Preferably, described management item comprise the information storing each described access control scheme, the IP address setting each described access control scheme, set each described access control scheme access port and control each described access control scheme to the access limit of the described network equipment.
Preferably, described management item also comprises: enter access by each described access control scheme of stack structure control and exit the order of access.
Preferably, described network equipment access control method also comprises: in the management information bank of the described network equipment, add alarming processing item.
Preferably, when adopting access control scheme access and the net control equipment of network management system, described network management system adopts Simple Network Management Protocol conduct interviews to the described network equipment and control.
For achieving the above object, the present invention also provides a kind of network equipment access control system, and described network equipment access control system comprises: response priority level initializing module, for the access control scheme setting response priority for access and net control equipment; Management item adds module, for adding the management item managed described access control scheme in the management information bank of the described network equipment; Control module, add module with described response priority level initializing module with described management item to be respectively connected, during for receiving request that each access control scheme sends at the described network equipment, according to each described access control scheme of described response two priority classes of the management item in described management information bank and setting to the access of the described network equipment and control.
Preferably, described management item comprise the information storing each described access control scheme, the IP address setting each described access control scheme, set each described access control scheme access port and control each described access control scheme to the access limit of the described network equipment.
Preferably, described management item also comprises: enter access by each described access control scheme of stack structure control and exit the order of access.
Preferably, described network equipment access control system also comprises: alarming processing item adds module, for adding alarming processing item in the management information bank of the described network equipment.
Preferably, when adopting access control scheme access and the net control equipment of network management system, described network management system adopts Simple Network Management Protocol conduct interviews to the described network equipment and control.
As mentioned above, a kind of network equipment access control method of the present invention and system, have following beneficial effect:
The present invention is by the access control scheme setting response priority for access and net control equipment, in the management information bank of the described network equipment, add management item that described access control scheme is managed and add alarming processing item, when the described network equipment receives the request of each access control scheme transmission, each described access control scheme can be effectively controlled to the access of the described network equipment and control according to the described response priority of the management item in described management information bank and setting, inconsistent or chaotic situation occurs can effectively to avoid the configuration data on the network equipment to occur, ensure that the uniqueness to network equipment access, invention also avoids configure network devices manually simultaneously.
Embodiment
Below by way of specific instantiation, embodiments of the present invention are described, those skilled in the art the content disclosed by this specification can understand other advantages of the present invention and effect easily.The present invention can also be implemented or be applied by embodiments different in addition, and the every details in this specification also can based on different viewpoints and application, carries out various modification or change not deviating under spirit of the present invention.
The object of the present embodiment is to provide a kind of network equipment access control method and system, cannot carry out unified management for solving in prior art to the access control of the network equipment.Below by the principle of a kind of network equipment access control method and system that elaborate the present embodiment and execution mode, those skilled in the art are made not need creative work can understand a kind of network equipment access control method and the system of the present embodiment.
The present embodiment provides a kind of network equipment access control method, and particularly, as shown in Figure 1, described network equipment access control method comprises the following steps.
Step S11, for the access control scheme setting of access and net control equipment responds priority.
Step S12, adds the management item managed described access control scheme in the management information bank of the described network equipment.
Step S13, when the described network equipment receives the request that each access control scheme sends, according to each described access control scheme of described response two priority classes of the management item in described management information bank and setting to the access of the described network equipment and control.
Below step S11 is described in detail to step S13.
Step S11, for the access control scheme setting of access and net control equipment responds priority.According to commodity network equipment maintenance work characteristic, response priority level initializing is carried out to the access control scheme of the network equipment.In the present embodiment, described access control scheme comprises: order line (CommandLineInterface, CLI), (ElementManager, EM) and webmaster management system (NetworkManagementSystem, NMS), such as, order line can be set to high priority response, also webmaster management system can be set to high priority response.In the present embodiment, to the response priority level initializing that the access control scheme of the network equipment carries out, as shown in table 1.
Table 1
Access mode |
Priority |
Order line (CLI) |
High priority responds |
Equipment manager (EM) |
Medium priority responds |
Webmaster management software (NMS) |
Low priority responds |
The network equipment, according to the priority level initializing in table 1, responds the access control scheme of each access and control.
Step S12, adds the management item managed described access control scheme in the management information bank of the described network equipment.
Management information bank (MIB, ManagementInformationBase) be one of the content of TCP/IP NMP standard card cage, MIB defines data item that managed device must preserve, allow the operation carried out each data item and implication thereof, and namely the data variable such as control and state information of the addressable managed device of network management system is all kept in MIB.
In the present embodiment, described network equipment access control method also comprises: in the management information bank of the described network equipment, add alarming processing item.
That is, in the present embodiment, newly-increased to the management item managed described access control scheme (function items) and corresponding alarming processing item (Trap) in the management information bank (ManagementInformationBase, MIB) of the network equipment.
Particularly, in the present embodiment, described management item include but not limited to store each described access control scheme information, set each described access control scheme IP address, set each described access control scheme access port and control each described access control scheme to the one or more combination in the access limit of the described network equipment.
Particularly, increase one newly for adding the MIB form of described management item, MIB form specifically defines such as but not limited to as follows:
accessControlTableOBJECT-TYPE
SYNTAXSEQUENCEOFaccessControlEntry
MAX-ACCESSnot-accessible
STATUScurrent
::={NetworkElement1}
accessControlEntryOBJECT-TYPE
SYNTAXaccessControlEntry
MAX-ACCESSnot-accessible
STATUScurrent
INDEX{acIPAddress}
::={accessControlTable1}
accessControlEntry::=SEQUENCE{
acIPAddressString,
acPortNumberInteger32,
acReadWriteInteger32,
acRowStatusInterger32,
}
acIPAddressOBJECT-TYPE
SYNTAXString
MAX-ACCESSread-only
STATUScurrent
::={accessControlEntry1}
acPortNumberOBJECT-TYPE
SYNTAXInteger32
MAX-ACCESSread-only
STATUScurrent
::={accessControlEntry2}
acReadWriteOBJECT-TYPE
SYNTAXInteger32
MAX-ACCESSread-write
STATUScurrent
::={accessControlEntry3}
acRowStatusOBJECT-TYPE
SYNTAXInteger32
MAX-ACCESSread-write
STATUScurrent
::={accessControlEntry4}
Wherein, the information of each access control scheme of accessControlTable storage networking device, acIPAddress is the IP address information of access control scheme (access side); AcPortNumber is the port information of access control scheme; AcReadWrite is the control authority state of access control scheme, read-only or read-write.
Newly-increased following MIBTrap definition:
TrapaccessControlTrap{
acIPAddress
acPortNumber
acReadWrite
TimeStamp}
Step S13, when the described network equipment receives the request that each access control scheme sends, according to each described access control scheme of described response two priority classes of the management item in described management information bank and setting to the access of the described network equipment and control.
Particularly, the network equipment is when receiving the request of each access control scheme, in accessControlTable, store the attribute information of each access control scheme, and press the response priority of above-mentioned setting, carry out the access privilege control to each access control scheme at acReadWrite.
Therefore, the present invention can control each described access control scheme effectively to the access of the described network equipment and control, inconsistent or chaotic situation occurs can effectively to avoid the configuration data on the network equipment to occur, ensure that the uniqueness to network equipment access, invention also avoids configure network devices manually simultaneously.
In addition, in the present embodiment, described management item also comprises: enter access by each described access control scheme of stack structure control and exit the order of access.
That is, except storing information at accessControlTable, all access sides are maintained in stack (Stack) data structure by network device internal, and service logic is as follows:
1) newly-increased access side's press-in (Push);
2) access side exited ejects (Pop).
When adopting access control scheme access and the net control equipment of network management system, described network management system adopts Simple Network Management Protocol conduct interviews to the described network equipment and control.
Wherein, SNMP (SimpleNetworkManagementProtocol, Simple Network Management Protocol), the standard managed by a group network forms, and comprises an application layer protocol (applicationlayerprotocol), database model (databaseschema) and one group of resource object.Whether this agreement can network enabled management system, have anyly cause the upper situation about paying close attention to of management in order to the monitoring equipment be connected on network.This agreement is a part for the internet protocol family that Internet Engineering Task group (IETF, InternetEngineeringTaskForce) defines.The target of SNMP is the hardware and software platform of numerous manufacturer production on managing internet Internet, and therefore SNMP is also very large by the impact of Internet standard network Governance framework.
So based on the acReadWrite field of accessControlTable, present embodiments provide the scheme of preemptive type access, the network management software is by simple webmaster management agreement (SNMP), the acReadWrite field value of specific access side is set, for specific access side seizes the write permission to the network equipment.
For realizing above-mentioned network equipment access control method, the present embodiment correspondence provides a kind of network equipment access control system, particularly, as shown in Figure 2, network equipment access control system 1 comprises: response priority level initializing module 11, management item adds module 12 and control module 13.
Described response priority level initializing module 11 is for the access control scheme setting response priority for access and net control equipment.
According to commodity network equipment maintenance work characteristic, the access control scheme of described response priority level initializing module 11 pairs of network equipments carries out response priority level initializing.In the present embodiment, described access control scheme comprises: order line (CommandLineInterface, CLI), (ElementManager, EM) and webmaster management system (NetworkManagementSystem, NMS), such as, order line can be set to high priority response by described response priority level initializing module 11, also webmaster management system can be set to high priority response.In the present embodiment, the response priority level initializing that the access control scheme of described response priority level initializing module 11 pairs of network equipments carries out, as shown in Table 1.The network equipment, according to the priority level initializing in table 1, responds the access control scheme of each access and control.
Described management item adds module 12 for adding the management item managed described access control scheme in the management information bank of the described network equipment.
Management information bank (MIB, ManagementInformationBase) be one of the content of TCP/IP NMP standard card cage, MIB defines data item that managed device must preserve, allow the operation carried out each data item and implication thereof, and namely the data variable such as control and state information of the addressable managed device of network management system is all kept in MIB.
In addition, as shown in Figure 3, described network equipment access control system 1 also comprises: alarming processing item adds module 14, for adding alarming processing item in the management information bank of the described network equipment.
That is, in the present embodiment, newly-increased to the management item managed described access control scheme (function items) and corresponding alarming processing item (Trap) in the management information bank (ManagementInformationBase, MIB) of the network equipment.
Particularly, in the present embodiment, described management item include but not limited to store each described access control scheme information, set each described access control scheme IP address, set each described access control scheme access port and control each described access control scheme to the one or more combination in the access limit of the described network equipment.
Particularly, described management item is added module 12 and is increased one newly for adding the MIB form of described management item, and MIB form specifically defines such as but not limited to as follows:
accessControlTableOBJECT-TYPE
SYNTAXSEQUENCEOFaccessControlEntry
MAX-ACCESSnot-accessible
STATUScurrent
::={NetworkElement1}
accessControlEntryOBJECT-TYPE
SYNTAXaccessControlEntry
MAX-ACCESSnot-accessible
STATUScurrent
INDEX{acIPAddress}
::={accessControlTable1}
accessControlEntry::=SEQUENCE{
acIPAddressString,
acPortNumberInteger32,
acReadWriteInteger32,
acRowStatusInterger32,
}
acIPAddressOBJECT-TYPE
SYNTAXString
MAX-ACCESSread-only
STATUScurrent
::={accessControlEntry1}
acPortNumberOBJECT-TYPE
SYNTAXInteger32
MAX-ACCESSread-only
STATUScurrent
::={accessControlEntry2}
acReadWriteOBJECT-TYPE
SYNTAXInteger32
MAX-ACCESSread-write
STATUScurrent
::={accessControlEntry3}
acRowStatusOBJECT-TYPE
SYNTAXInteger32
MAX-ACCESSread-write
STATUScurrent
::={accessControlEntry4}
Wherein, the information of each access control scheme of accessControlTable storage networking device, acIPAddress is the IP address information of access control scheme (access side); AcPortNumber is the port information of access control scheme; AcReadWrite is the control authority state of access control scheme, read-only or read-write.
Described alarming processing item adds the newly-increased following MIBTrap definition of module 14:
TrapaccessControlTrap{
acIPAddress
acPortNumber
acReadWrite
TimeStamp}
Described control module 13 is added module 12 with described response priority level initializing module 11 with described management item respectively and is connected, during for receiving request that each access control scheme sends at the described network equipment, according to each described access control scheme of described response two priority classes of the management item in described management information bank and setting to the access of the described network equipment and control.
Particularly, the network equipment is when receiving the request of each access control scheme, in accessControlTable, store the attribute information of each access control scheme, and press the response priority of above-mentioned setting, carry out the access privilege control to each access control scheme at acReadWrite.
Therefore, the present invention can control each described access control scheme effectively to the access of the described network equipment and control, inconsistent or chaotic situation occurs can effectively to avoid the configuration data on the network equipment to occur, ensure that the uniqueness to network equipment access, invention also avoids configure network devices manually simultaneously.
In addition, in the present embodiment, described management item also comprises: enter access by each described access control scheme of stack structure control and exit the order of access.
That is, except storing information at accessControlTable, all access sides are maintained in stack (Stack) data structure by network device internal, and service logic is as follows:
1) newly-increased access side's press-in (Push);
2) access side exited ejects (Pop).
When adopting access control scheme access and the net control equipment of network management system, described network management system adopts Simple Network Management Protocol conduct interviews to the described network equipment and control.So based on the acReadWrite field of accessControlTable, present embodiments provide the scheme of preemptive type access, the network management software is by simple webmaster management agreement (SNMP), the acReadWrite field value of specific access side is set, for specific access side seizes the write permission to the network equipment.
In sum, the present invention is by the access control scheme setting response priority for access and net control equipment, in the management information bank of the described network equipment, add management item that described access control scheme is managed and add alarming processing item, when the described network equipment receives the request of each access control scheme transmission, each described access control scheme can be effectively controlled to the access of the described network equipment and control according to the described response priority of the management item in described management information bank and setting, inconsistent or chaotic situation occurs can effectively to avoid the configuration data on the network equipment to occur, ensure that the uniqueness to network equipment access, invention also avoids configure network devices manually simultaneously.So the present invention effectively overcomes various shortcoming of the prior art and tool high industrial utilization.
Above-described embodiment is illustrative principle of the present invention and effect thereof only, but not for limiting the present invention.Any person skilled in the art scholar all without prejudice under spirit of the present invention and category, can modify above-described embodiment or changes.Therefore, such as have in art usually know the knowledgeable do not depart from complete under disclosed spirit and technological thought all equivalence modify or change, must be contained by claim of the present invention.