WO2020181735A1 - 一种提供网络地址转换nat服务的方法及控制器 - Google Patents
一种提供网络地址转换nat服务的方法及控制器 Download PDFInfo
- Publication number
- WO2020181735A1 WO2020181735A1 PCT/CN2019/103258 CN2019103258W WO2020181735A1 WO 2020181735 A1 WO2020181735 A1 WO 2020181735A1 CN 2019103258 W CN2019103258 W CN 2019103258W WO 2020181735 A1 WO2020181735 A1 WO 2020181735A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- controller
- message
- host server
- flow table
- host
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L45/00—Routing or path finding of packets in data switching networks
- H04L45/74—Address processing for routing
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/09—Mapping addresses
- H04L61/25—Mapping addresses of the same type
- H04L61/2503—Translation of Internet protocol [IP] addresses
- H04L61/2521—Translation architectures other than single NAT servers
- H04L61/2532—Clique of NAT servers
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/10—Protocols in which an application is distributed across nodes in the network
- H04L67/1001—Protocols in which an application is distributed across nodes in the network for accessing one among a plurality of replicated servers
- H04L67/1036—Load balancing of requests to servers for services different from user content provisioning, e.g. load balancing across domain name servers
Definitions
- This application relates to the field of communication technology, and in particular to a method and controller for providing network address translation NAT services.
- the gateway device Due to the limited public address resources in the actual network, the gateway device usually uses the NAT (Network Address Translation, network address translation) function to achieve access to the Internet from the internal network.
- NAT is the conversion of the IP address in the IP data packet header to another IP
- the process of addressing, that is, NAT converts the private network address in the data to a public network address, so that the private network can access the public network, and NAT uses a small number of public network addresses to represent more private network addresses, which can slow down the available address space Depletion.
- NAT gateway instances to provide NAT services. Such instances can be deployed in virtual machines or in clusters of physical machines. Either way, traffic needs to be distributed to NAT gateway instances.
- the NAT gateway itself has high performance requirements. Once the traffic exceeds the designed performance limit, the NAT gateway can easily become a bottleneck.
- the embodiment of the present application provides a method and a controller for providing a network address translation NAT service.
- the NAT service is distributed to various computing nodes through the controller, thereby eliminating the bottleneck caused by the upper limit of the performance of the NAT gateway.
- an embodiment of the present application provides a method for providing a network address translation NAT service, and the method includes:
- the controller establishes communication with multiple host servers
- the controller generates a flow table for a first home server, the first home server is any one of the multiple home servers that establishes communication with the controller, and the flow table includes a plurality of table entries , Each entry in the multiple entries records a NAT forwarding rule;
- the controller sends the flow table to the first home server, where the flow table is used by the first home server to provide a NAT service for the cloud host on the first home server.
- an embodiment of the present application provides a controller, which includes:
- the configuration unit is used to establish communication with multiple host servers
- a generating unit configured to generate a flow table for a first home server, where the first home server is any one of the multiple home servers that establishes communication with the controller, and the flow table includes multiple tables Item, each of the multiple items records a NAT forwarding rule;
- the first sending unit is configured to send the flow table to the first host server, where the flow table is used by the first host server to provide a NAT service for the cloud host on the first host server.
- an embodiment of the present application provides a computer-readable storage medium that stores a computer program.
- the computer program includes program instructions that, when executed by a processor, cause all The processor executes the method described in the first aspect above.
- an embodiment of the present application provides a server, including a processor, a communication interface, and a computer-readable storage medium.
- the processor, the communication interface, and the computer-readable storage medium are connected to each other.
- the storage medium is used to store application program code, and the processor is configured to call the application program code to execute the method described in the first aspect.
- the embodiment of the application distributes the NAT service to each computing node through the controller, and each computing node provides the NAT service through a flow table, thereby improving the efficiency of the NAT service and eliminating the performance of the NAT gateway.
- FIG. 1 is a schematic diagram of a system architecture of a method for providing NAT services according to an embodiment of the application
- FIG. 2 is a schematic flowchart of a method for providing NAT services provided by an embodiment of the application
- FIG. 3 is a schematic diagram of a host server provided by an embodiment of the application providing a NAT service for packets sent by a cloud host it bears;
- FIG. 4 is a schematic structural diagram of a controller provided by an embodiment of the application.
- FIG. 5 is a schematic structural diagram of a server provided by an embodiment of the application.
- FIG. 1 is a schematic diagram of a system architecture of a method for providing a network address translation NAT service provided by an embodiment of the solution.
- the system architecture may include a controller 101, one or more host servers 102, and one or more cloud hosts 103.
- the controller 101 can communicate with the host server 102, each host server 102 carries one or more cloud hosts 103, and the host server 102 and the cloud host 103 carried by itself can communicate with each other.
- system architecture of a method for providing network address translation NAT services provided in this application is not limited to the system architecture shown in FIG. 1.
- Step S201 The controller establishes communication with multiple host servers.
- the controller can be configured with the network addresses of the multiple host servers (which can be addresses in the Internet, or addresses in a local area network, or other addresses that are the same as communications) to identify the multiple host servers And send data packets to the multiple host servers in a targeted manner; correspondingly, the network address of the controller can also be configured on the multiple host servers to identify the data packets from the controller and target Send data packets to the controller.
- data transmission between the controller and the multiple host servers may be performed in a wired or wireless manner.
- the controller generates a flow table for the first host server.
- the first host server is any one of the multiple host servers that establishes communication with the controller
- the flow table includes multiple entries, and each entry in the multiple entries A NAT forwarding rule is recorded.
- the controller when the first home server establishes communication with the controller for the first time or when the first home server sends a NAT service request instruction to the controller, the controller is the first The host server generates a corresponding flow table.
- the flow table contains multiple entries, and each entry records a NAT forwarding rule.
- the aforementioned NAT forwarding rule may include a conversion rule between private network information and public network information, where the private network information includes the Internet Protocol IP address of the private network and the port information of the private network
- the public network information includes the IP address of the public network and the port information of the public network
- the private network is a private network to which the cloud host on the first host server belongs.
- Table 1 gives an example of the information contained in NAT forwarding rules, mainly the address and port mapping table for private network access to public network.
- the private network IP address is 10.0.0.2, and the cloud host with the corresponding port number of 1723 accesses the public network.
- Table 1 Address and port mapping table for private network to access public network
- the method before the controller generates the flow table for the first host server, the method further includes: the controller receives a NAT service request instruction sent by the first host server, and the request instruction uses Requesting the controller to generate the flow table for the first host server.
- the first host server when the cloud host on the first host server needs to access the public network and send a message to the first host server, the first host server sends a NAT service request instruction to the controller according to the message information, and this request instruction is used for The request controller generates a flow table for the first host server. After receiving the request instruction, the controller generates a corresponding flow table for the first host server according to the request instruction, and then sends the flow table to the first host server.
- the controller is requested to generate a flow table for the host server through a request instruction, which can optimize the resources of the controller and promptly respond to the NAT service request of the host server, thereby further improving the processing efficiency of the NAT service.
- the controller sends the flow table to the first host server.
- the flow table is used by the first host server to provide a NAT service for the cloud host on the first host server.
- the controller after the controller generates a corresponding flow table for the first host server, the controller sends the flow table to the first host server.
- the first host server receives the flow table.
- the first host server after receiving the flow table sent by the controller, stores the flow table in the local storage.
- the cloud host on the first host server needs to access the public network and send a message to the first host server
- the first host server calls the flow table stored locally, and matches the flow table entry for the message according to the flow table. After reaching the flow table entry, replace the private network IP address and private network port number of the message with the public network IP address and public network port number according to the flow table entry, and then forward the message with the replaced IP address and port to the public network .
- FIG. 3 shows a schematic diagram of the host server providing NAT services for the packets sent by the cloud host it bears.
- the cloud host wants to access the public network server with the destination IP address and port number of 202.99.160.2 and 80 respectively.
- the private network IP address and port number of the cloud host are 10.0.0.2. and 1723 respectively.
- the cloud host uses the private network IP address
- the server on the external network cannot be accessed, so the private network IP address needs to be replaced with the IP address of the external network.
- the corresponding port information needs to be added. Therefore, in Figure 3, the cloud host sends a message carrying the private network IP address and port number, and the destination IP address and port number to the host server.
- the host server matches the flow entry for the packet according to the flow table. For specific entries, please refer to Table 1. After matching the flow entry, replace the private network IP address and port number of the packet with 131.107.0.1/4000 according to the flow entry, and the destination IP address and port number remain unchanged, so the source IP address and source of the packet
- the port number belongs to the IP address and port number of the public network, so that the cloud host can access the public network server with the destination IP address and port number of 202.99.160.2 and 80 respectively.
- the method further includes: the controller receives a message sent by the first host server; The controller determines, according to the message, an entry containing the NAT forwarding rule of the message; the controller sends the entry containing the NAT forwarding rule of the message to the first home server.
- the first host server fails to match the flow entry for the packet according to the above flow table, the first host server sends the packet to the controller, and the controller receives the packet, According to the message, the corresponding flow entry is generated for it.
- the entry contains the NAT forwarding rule of the message, which is used by the first host server to perform the NAT operation on the message, and then the controller
- the flow entry is sent to the first host server.
- the first host server replaces the IP address and port number for the message according to the flow entry, and then forwards the message to the public network.
- the controller when a message sent by the host server for the cloud host carried by the host server fails according to the flow table matching entry, the controller can generate the message for the message or select its corresponding entry from the existing flow table And send the entry to the host server, so that the host server can successfully provide the NAT service for the message.
- the controller after the controller receives the packet sent by the first host server due to the failure of the matching entry, the controller matches the flow of the packet from the flow table maintained by the controller. Entry, after determining the flow entry, the flow entry is sent to the first host server, and the first host server also receives the flow entry, and replaces the IP address and port number for the packet according to the flow entry , And then forward the message to the public network.
- the controller after the controller receives the message sent by the first host server due to the failure of the matching table entry, the message matching table entry fails, and the controller will The message that the message matching entry fails is returned to the first host server, and the first host server discards the message.
- the packet is directly discarded.
- this method distributes the NAT service to each computing node through the controller, and each computing node provides the NAT service through a flow table, thereby improving the efficiency of the NAT service and eliminating the upper limit of the performance of the NAT gateway.
- the bottleneck caused.
- FIG. 4 shows a schematic structural diagram of a controller 400.
- the controller 400 may be the controller 101 in the system architecture of the method for providing network address translation NAT service described in FIG. 1, and the controller 400 includes : The configuration unit 401, the generating unit 402 and the first sending unit 403, where:
- the configuration unit 401 is used to establish communication with multiple host servers;
- the generating unit 402 is configured to generate a flow table for a first home server, where the first home server is any one of the multiple home servers that establishes communication with the controller, and the flow table includes multiple An entry, each entry in the multiple entries records a NAT forwarding rule;
- the first sending unit 403 is configured to send the flow table to the first host server, where the flow table is used by the first host server to provide a NAT service for the cloud host on the first host server.
- the controller 400 further includes a first receiving unit, a determining unit, and a second sending unit, where:
- the first receiving unit is configured to receive a message sent by the first host server after the first sending unit sends the flow table to the first host server;
- the determining unit is configured to determine an entry containing the NAT forwarding rule of the message according to the message;
- the second sending unit is configured to send the entry containing the NAT forwarding rule of the message to the first home server, and the entry containing the NAT forwarding rule of the message is used for all
- the first host server performs a NAT operation on the message.
- the receiving unit is configured to receive a message sent by the first host server, specifically:
- the controller 400 further includes:
- the second receiving unit is configured to receive a NAT service request instruction sent by the first host server before the generation unit generates the flow table for the first host server, and the request instruction is used to request the controller to provide the The first host server generates the flow table.
- the NAT forwarding rule includes a conversion rule between private network information and public network information, where the private network information includes the Internet Protocol IP address of the private network and private network port information, and the The public network information includes the IP address and public network port information of the public network, and the private network is a private network to which the cloud host on the first host server belongs.
- FIG. 5 is a server 500 provided by an embodiment of the present application.
- the server 500 includes a processor 501, a memory 502 (that is, a computer-readable storage medium), and a communication interface 503.
- the processor 501 and the memory 502 And the communication interface 503 are connected to each other through the bus 504.
- the memory 502 includes, but is not limited to, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (erasable programmable read only memory, EPROM), or A portable read-only memory (compact disc read-only memory, CD-ROM), the memory 502 is used for storage of related instructions and data.
- the communication interface 503 is used to receive and send data.
- the processor 501 may be one or more central processing units (CPU).
- the CPU may be a single-core CPU or a multi-core CPU.
- the processor 501 in the server 500 is configured to read the program code stored in the memory 502, and perform the following operations:
- the processor 501 establishes communication with multiple host servers;
- the processor 501 generates a flow table for a first home server, where the first home server is any one of the multiple home servers that establishes communication with the controller, and the flow table includes multiple entries, Each entry in the multiple entries records a NAT forwarding rule;
- the processor 501 sends the flow table to the first host server through the communication interface 503, where the flow table is used by the first host server to provide a NAT service for the cloud host on the first host server.
- the method further includes:
- the processor 501 receives the message sent by the first host server through the communication interface 503;
- the processor 501 determines, according to the message, an entry containing the NAT forwarding rule of the message;
- the processor 501 sends the entry containing the NAT forwarding rule of the message to the first home server through the communication interface 503, and the entry containing the NAT forwarding rule of the message is used for the first host server.
- a host server performs a NAT operation on the message.
- the processor 501 receives the message sent by the first host server through the communication interface 503, specifically:
- the processor 501 receives the message sent by the first host server after failing to match the entry for the message through the communication interface 503.
- the method before the processor 501 generates the flow table for the first host server, the method further includes:
- the processor 501 receives a NAT service request instruction sent by the first host server through the communication interface 503, where the request instruction is used to request the controller to generate the flow table for the first host server.
- the NAT forwarding rule includes a conversion rule between private network information and public network information, wherein the private network information includes the Internet Protocol IP address and private network port information of the private network.
- the public network information includes the IP address and public network port information of the public network, and the private network is a private network to which the cloud host on the first host server belongs.
- the server 500 described in FIG. 5 distributes the NAT service to each computing node through the controller, and each computing node provides the NAT service through a flow table, thereby improving the efficiency of the NAT service and eliminating the bottleneck of the NAT gateway. .
- the embodiment of the present application also provides a computer-readable storage medium, the computer storage medium stores a computer program, the computer program includes program instructions, when the program instructions are executed by a processor, the method shown in FIG. 2 The process is realized.
- the embodiments of the present application provide a method and controller for providing network address translation NAT service.
- the NAT service is distributed to each computing node through the controller, and each computing node provides the NAT service through a flow table. This improves the efficiency of the NAT service and also eliminates the bottleneck caused by the upper limit of the performance of the NAT gateway.
- the process can be completed by a computer program instructing relevant hardware.
- the program can be stored in a computer readable storage medium. , May include the processes of the foregoing method embodiments.
- the aforementioned storage media include: ROM or random storage RAM, magnetic disks or optical discs and other media that can store program codes.
- the disclosed device and method may be implemented in other ways.
- the device embodiments described above are merely illustrative.
- the division of the units is only a logical function division, and there may be other divisions in actual implementation, for example, multiple units or components can be combined or It can be integrated into another system, or some features can be ignored or not implemented.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
本申请实施例公开了一种提供网络地址转换NAT服务的方法及控制器,该方法包括:控制器与多个宿主服务器建立通信,控制器为第一宿主服务器生成流表,所述第一宿主服务器为与所述控制器建立通信的多个宿主服务器中的任意一个宿主服务器,所述流表包括多个表项,所述多个表项中每个表项记录了一条NAT转发规则;所述控制器将所述流表发送给所述第一宿主服务器,所述流表用于所述第一宿主服务器为所述第一宿主服务器上的云主机提供NAT服务。本申请实施例提高了NAT服务的效率,同时也消除了NAT网关的性能上限所造成的瓶颈。
Description
本申请要求于2019年03月08日提交中国专利局、申请号为201910178099.7、申请名称为“一种提供网络地址转换NAT服务的方法及控制器”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
本申请涉及通信技术领域,尤其涉及一种提供网络地址转换NAT服务的方法和控制器。
由于实际网络中公网地址资源有限,网关设备通常使用NAT(Network Address Translation,网络地址转换)功能来实现内网对Internet的访问,NAT是将IP数据报文头中的IP地址转换为另一个IP地址的过程,即NAT将数据中的私网地址转换为公网地址,以实现私有网络访问公共网络,且NAT通过使用少量的公网地址表示较多的私网地址,从而可减缓可用地址空间的枯竭。
业界通常使用NAT网关实例的方式提供NAT服务,这种实例可以采用虚拟机的方式部署,也可以用物理机集群的方式进行部署,不论哪种方式,都需要将流量分发到NAT网关实例处,对NAT网关本身的性能要求较高,一旦流量超过了设计的性能上限,NAT网关很容易成为瓶颈点。
发明内容
本申请实施例提供了一种提供网络地址转换NAT服务的方法和控制器,通过控制器将NAT服务分散到各个计算节点上,消除了NAT网关的性能上限造成的瓶颈。
第一方面,本申请实施例提供了一种提供网络地址转换NAT服务的方法,该方法包括:
控制器与多个宿主服务器建立通信;
所述控制器为第一宿主服务器生成流表,所述第一宿主服务器为与所述控制器建立通信的所述多个宿主服务器中的任意一个宿主服务器,所述流表包括多个表项,所述多个表项中每个表项记录了一条NAT转发规则;
所述控制器将所述流表发送给所述第一宿主服务器,所述流表用于所述第一宿主服务器为所述第一宿主服务器上的云主机提供NAT服务。
第二方面,本申请实施例提供了一种控制器,该控制器包括:
配置单元,用于与多个宿主服务器建立通信;
生成单元,用于为第一宿主服务器生成流表,所述第一宿主服务器为与所述控制器建立通信的所述多个宿主服务器中的任意一个宿主服务器,所述流表包括多个表项,所述多个表项中每个表项记录了一条NAT转发规则;
第一发送单元,用于将所述流表发送给所述第一宿主服务器,所述流表用于所述第一宿主服务器为所述第一宿主服务器上的云主机提供NAT服务。
第三方面,本申请实施例提供了一种计算机可读存储介质,所述计算机可读存储介质 存储有计算机程序,所述计算机程序包括程序指令,所述程序指令当被处理器执行时使所述处理器执行上述第一方面所述的方法。
第四方面,本申请实施例提供了一种服务器,包括处理器、通信接口和计算机可读存储介质,所述处理器、通信接口和计算机可读存储介质相互连接,其中,所述计算机可读存储介质用于存储应用程序代码,所述处理器被配置用于调用所述应用程序代码,执行上述第一方面所述的方法。
综上所述,本申请实施例通过控制器将NAT服务分散到各个计算节点上,各个计算节点通过流表的方式提供NAT服务,从而提高了NAT服务的效率,同时也消除了NAT网关的性能上限造成的瓶颈。
下面将对本申请实施例中所需要使用的附图作介绍。
图1为本申请实施例提供的一种提供NAT服务的方法的系统架构示意图;
图2为本申请实施例提供的一种提供NAT服务的方法的流程示意图;
图3为本申请实施例提供的宿主服务器为其承载的云主机发送的报文提供NAT服务的示意图;
图4为本申请实施例提供的一种控制器的结构示意图;
图5为本申请实施例提供的一种服务器的结构示意图。
本申请说明书、权利要求书和附图中出现的术语“包括”和“具有”以及它们任何变形,意图在于覆盖不排他的包含。例如包含了一系列步骤或单元的过程、方法、系统、产品或设备没有限定于已列出的步骤或单元,而是可选地还包括没有列出的步骤或单元,或可选地还包括对于这些过程、方法、产品或设备固有的其它步骤或单元。此外,术语“第一”、“第二”和“第三”等是用于区别不同的对象,而并非用于描述特定的顺序。
为了使本领域技术人员更好地理解本申请方案,下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本申请一部分的实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都应当属于本申请保护的范围。
以下分别进行详细说明。
为了更好的理解本申请实施例提供的一种提供网络地址转换NAT服务的方法和控制器,下面先对本申请实施例适用的一种提供网络地址转换NAT服务的方法的系统构架进行描述。参阅图1,图1是本方案实施例提供的一种提供网络地址转换NAT服务的方法的系统架构示意图。如图1所示,系统架构可以包括一个控制器101、一个或多个宿主服务器102以及一个或多个云主机103。控制器101可以和宿主服务器102互相通信,各个宿主服务器102承载着一个或多个云主机103,宿主服务器102和自身承载的云主机103可以互相通信。
需要说明的是,本申请提供的一种提供网络地址转换NAT服务的方法的系统构架不限 于图1所示系统架构。
基于图1给出的一种提供网络地址转换NAT服务的方法的系统架构,下面提供一种提供网络地址转换NAT服务的方法,一种提供网络地址转换NAT服务的方法的流程图如图2所示,可以包括以下步骤:
步骤S201:控制器与多个宿主服务器建立通信。
具体地,该控制器上可以配置该多个宿主服务器的网络地址(可以是互联网中的地址,也可以是局域网中的地址,或者其他同于通信的地址),从而识别来自该多个宿主服务器的数据包,以及针对性地向该多个宿主服务器发送数据包;相应的,该多个宿主服务器上也都可以配置该控制器的网络地址,从而识别来自该控制器的数据包,以及针对性地向该控制器器发送数据包。另外,该控制器与该多个宿主服务器之间可以通过有线,或者无线的方式进行数据传输。
S202、控制器为第一宿主服务器生成流表。
具体的,所述第一宿主服务器为与所述控制器建立通信的多个宿主服务器中的任意一个宿主服务器,所述流表包括多个表项,所述多个表项中每个表项记录了一条NAT转发规则。
在具体实施方式中,当所述第一宿主服务器与所述控制器第一次建立通信时或者在所述第一宿主服务器发送NAT服务请求指令给控制器时,所述控制器为该第一宿主服务器生成对应的流表。该流表中包含多个表项,每个表项都记录了一条NAT转发规则。
在其中一种可能的实施方案中,上述NAT转发规则可以包括私网信息与公网信息之间的转换规则,其中,所述私网信息包括私网的互联网协议IP地址和私网的端口信息,所述公网信息包括公网的IP地址和公网的端口信息,所述私网为所述第一宿主服务器上的云主机所属的专用网络。具体的NAT转发规则示例可以参考表1,表1给出了NAT转发规则包含的信息的示例,主要是私网访问公网的地址和端口映射表。私网IP地址为10.0.0.2,对应的端口号为1723的云主机访问公网,需要将该云主机的私网IP地址和端口号替换为公网IP地址和公网的端口号,根据表1,可以将云主机的私网IP地址为10.0.0.2替换为131.107.0.1,端口号1723替换为4000,替换完成后云主机使用新的IP地址和端口号131.107.0.1/4000即可访问公网。
表1私网访问公网的地址和端口映射表
| - | 私网IP地址 | 私网端口号 | 公网IP地址 | 公网端口号 |
| 第一表项 | 10.0.0.2 | 1723 | 131.107.0.1 | 4000 |
| 第二表项 | 10.0.0.3 | 1723 | 131.107.0.1 | 4001 |
| 第三表项 | 10.0.0.4 | 1724 | 131.107.0.1 | 4002 |
在其中一种可能的实施方式中,所述控制器为第一宿主服务器生成流表之前,还包括:所述控制器接收所述第一宿主服务器发送的NAT服务请求指令,所述请求指令用于请求所述控制器为所述第一宿主服务器生成所述流表。
具体的,当第一宿主服务器上的云主机需要访问公网,向该第一宿主服务器发送报文,则第一宿主服务器根据报文信息向控制器发送NAT服务请求指令,这个请求指令用于请求 控制器为所述第一宿主服务器生成流表,控制器接收到请求指令后,根据请求指令为第一宿主服务器生成对应的流表,然后将该流表发送给第一宿主服务器。
本实施例通过请求指令请求控制器为宿主服务器生成流表,可以使得控制器的资源优化并及时对宿主服务器的NAT服务请求作出相应,进一步提高了NAT服务的处理效率。
S203、所述控制器将所述流表发送给所述第一宿主服务器。
具体的,所述流表用于所述第一宿主服务器为所述第一宿主服务器上的云主机提供NAT服务。在具体的实施方式中,所述控制器为所述第一宿主服务器生成对应的流表后,将该流表发送给第一宿主服务器。
S204、第一宿主服务器接收所述流表。
在具体的实施方式中,第一宿主服务器接收所述控制器发送的流表后,将该流表存储在本地存储器中。当第一宿主服务器上的云主机需要访问公网,向该第一宿主服务器发送报文,则第一宿主服务器调用存储在本地的流表,根据该流表为报文匹配流表项,匹配到流表项之后根据流表项将报文的私网IP地址和私网端口号替换为公网IP地址和公网端口号,然后将替换了IP地址和端口的报文转发到公网中。
为了便于理解,图3给出了宿主服务器为其承载的云主机发送的报文提供NAT服务的示意图。假设云主机要访问目的IP地址和端口号分别为202.99.160.2和80的公网服务器,该云主机的私网IP地址和端口号分别为10.0.0.2和1723,该云主机使用私网IP地址不能访问外网的服务器,因而需要将其私网IP地址替换为外网的IP地址,为了外网反馈信息时能准确反馈到对应的云主机上也需要添加上对应的端口信息。所以图3中云主机将携带了私网IP地址和端口号以及目的IP地址和端口号的报文发送到宿主服务器,宿主服务器根据流表为该报文匹配流表项,具体表项可以参考表1,匹配到流表项后根据流表项将报文的私网IP地址和端口号替换为131.107.0.1/4000,目的IP地址和端口号不变,这样报文的源IP地址和源端口号属于公网的IP地址和端口号,从而使得云主机可以访问目的IP地址和端口号分别为202.99.160.2和80的公网服务器。
在其中一种可能的实施方式中,所述控制器将所述流表发送给所述第一宿主服务器之后,还包括:所述控制器接收所述第一宿主服务器发送的报文;所述控制器根据所述报文确定包含所述报文的NAT转发规则的表项;所述控制器将所述包含所述报文的NAT转发规则的表项发送给所述第一宿主服务器。
具体的,在所述第一宿主服务器根据上述流表为所述报文匹配流表项失败的情况下,所述第一宿主服务器将该报文发送给控制器,控制器接收该报文,根据该报文为其生成对应的流表项,同样的,该表项包含了所述报文的NAT转发规则,用于所述第一宿主服务器对所述报文执行NAT操作,然后控制器将其流表项发送给第一宿主服务器,第一宿主服务器接收该流表项之后根据该流表项为所述报文替换IP地址和端口号,然后将报文转发到公网中。
采用本申请实施例,当宿主服务器为自身承载的云主机发送的报文根据流表匹配表项失败时,控制器可以为该报文生成或从现有的流表中选择其对应的表项并将该表项发送宿主服务器,从而使得宿主服务器可以成功地为该报文提供NAT服务。
或者,在另一种可能的情况下,控制器接收所述第一宿主服务器因匹配表项失败而发 送的报文后,控制器从该控制器维护的流表中为所述报文匹配流表项,确定了流表项之后,将该流表项发送给第一宿主服务器,第一宿主服务器同样地接收该流表项,根据该流表项为所述报文替换IP地址和端口号,然后将报文转发到公网中。
或者,在另一种可能的实施方式中,控制器接收所述第一宿主服务器因匹配表项失败而发送的报文后,为所述报文匹配表项失败,所述控制器将为所述报文匹配表项失败的信息返回给第一宿主服务器,第一宿主服务器将所述报文丢弃。
在其中一种可能的实施方式中,在所述第一宿主服务器根据上述流表为所述报文匹配流表项失败的情况下,直接将报文丢弃。
综上所述,该方法通过控制器将NAT服务分散到各个计算节点上,各个计算节点通过流表的方式提供NAT服务,从而提高了NAT服务的效率,同时也消除了NAT网关的性能上限所造成的瓶颈。
为了便于更好地实施本申请的上述方案,本申请实施例还对应提供了一种控制器,下面结合附图来进行详细说明:
图4所示为一种控制器400的结构示意图,所述控制器400可以是图1所述一种提供网络地址转换NAT服务的方法的系统构架中的控制器101,所述控制器400包括:配置单元401、生成单元402和第一发送单元403,其中:
配置单元401,用于与多个宿主服务器建立通信;
生成单元402,用于为第一宿主服务器生成流表,所述第一宿主服务器为与所述控制器建立通信的所述多个宿主服务器中的任意一个宿主服务器,所述流表包括多个表项,所述多个表项中每个表项记录了一条NAT转发规则;
第一发送单元403,用于将所述流表发送给所述第一宿主服务器,所述流表用于所述第一宿主服务器为所述第一宿主服务器上的云主机提供NAT服务。
在其中一种实施方式中,控制器400还包括第一接收单元、确定单元和第二发送单元,其中:
所述第一接收单元,用于在所述第一发送单元将所述流表发送给所述第一宿主服务器之后接收所述第一宿主服务器发送的报文;
所述确定单元,用于根据所述报文确定包含所述报文的NAT转发规则的表项;
所述第二发送单元,用于将所述包含所述报文的NAT转发规则的表项发送给所述第一宿主服务器,所述包含所述报文的NAT转发规则的表项用于所述第一宿主服务器对所述报文执行NAT操作。
在其中一种实施方式中,所述接收单元用于接收所述第一宿主服务器发送的报文,具体为:
用于接收所述第一宿主服务器在为报文匹配表项失败后发送的所述报文。
在其中一种实施方式中,控制器400还包括:
第二接收单元,用于在所述生成单元为第一宿主服务器生成流表之前,接收所述第一宿主服务器发送的NAT服务请求指令,所述请求指令用于请求所述控制器为所述第一宿主服务器生成所述流表。
在其中一种实施方式中,所述NAT转发规则包括私网信息与公网信息之间的转换规则, 其中,所述私网信息包括私网的互联网协议IP地址和私网端口信息,所述公网信息包括公网的IP地址和公网端口信息,所述私网为所述第一宿主服务器上的云主机所属的专用网络。
图4所示的服务器400中各个单元的具体实现及有益效果可以对应参照图2所示的方法实施例中的相应描述,此处不再赘述。
请参见图5,图5是本申请实施例提供的一种服务器500,该服务器500包括处理器501、存储器502(即计算机可读存储介质)和通信接口503,所述处理器501、存储器502和通信接口503通过总线504相互连接。
存储器502包括但不限于是随机存储记忆体(random access memory,RAM)、只读存储器(read-only memory,ROM)、可擦除可编程只读存储器(erasable programmable read only memory,EPROM)、或便携式只读存储器(compact disc read-only memory,CD-ROM),该存储器502用于相关指令及数据的存储。通信接口503用于接收和发送数据。
处理器501可以是一个或多个中央处理器(central processing unit,CPU),在处理器501是一个CPU的情况下,该CPU可以是单核CPU,也可以是多核CPU。
该服务器500中的处理器501用于读取所述存储器502中存储的程序代码,执行以下操作:
处理器501与多个宿主服务器建立通信;
处理器501为第一宿主服务器生成流表,所述第一宿主服务器为与所述控制器建立通信的所述多个宿主服务器中的任意一个宿主服务器,所述流表包括多个表项,所述多个表项中每个表项记录了一条NAT转发规则;
处理器501通过通信接口503将所述流表发送给所述第一宿主服务器,所述流表用于所述第一宿主服务器为所述第一宿主服务器上的云主机提供NAT服务。
在其中一种实施方式中,处理器501通过通信接口503将所述流表发送给所述第一宿主服务器之后,还包括:
处理器501通过通信接口503接收所述第一宿主服务器发送的报文;
处理器501根据所述报文确定包含所述报文的NAT转发规则的表项;
处理器501通过通信接口503将所述包含所述报文的NAT转发规则的表项发送给所述第一宿主服务器,所述包含所述报文的NAT转发规则的表项用于所述第一宿主服务器对所述报文执行NAT操作。
在其中一种实施方式中,处理器501通过通信接口503接收所述第一宿主服务器发送的报文,具体为:
处理器501通过通信接口503接收所述第一宿主服务器在为报文匹配表项失败后发送的所述报文。
在其中一种实施方式中,处理器501为第一宿主服务器生成流表之前,还包括:
处理器501通过通信接口503接收所述第一宿主服务器发送的NAT服务请求指令,所述请求指令用于请求所述控制器为所述第一宿主服务器生成所述流表。
在其中一种实施方式中,所述NAT转发规则包括私网信息与公网信息之间的转换规则,其中,所述私网信息包括私网的互联网协议IP地址和私网端口信息,所述公网信息包括公网的IP地址和公网端口信息,所述私网为所述第一宿主服务器上的云主机所属的专用网络。
需要说明的是,上述各个操作的实现还可以对应参照图2所示的方法实施例的相应描述。
在图5所描述的服务器500通过控制器将NAT服务分散到各个计算节点上,各个计算节点通过流表的方式提供NAT服务,从而提高了NAT服务的效率,同时也消除了NAT网关的瓶颈点。
本申请实施例还提供了一种计算机可读存储介质,所述计算机存储介质存储有计算机程序,所述计算机程序包括程序指令,当所述程序指令被处理器执行时,图2所示的方法流程得以实现。
综上所述,本申请实施例提供了一种提供网络地址转换NAT服务的方法和控制器,通过控制器将NAT服务分散到各个计算节点上,各个计算节点通过流表的方式提供NAT服务,从而提高了NAT服务的效率,同时也消除了NAT网关的性能上限所造成的瓶颈。
本领域普通技术人员可以理解实现上述实施例方法中的全部或部分流程,该流程可以由计算机程序来指令相关的硬件完成,该程序可存储于计算机可读取存储介质中,该程序在执行时,可包括如上述各方法实施例的流程。而前述的存储介质包括:ROM或随机存储记忆体RAM、磁碟或者光盘等各种可存储程序代码的介质。
在本申请所提供的几个实施例中,应该理解到,所揭露的装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。
最后应说明的是:以上各实施例仅用以说明本申请的技术方案,而非对其限制;尽管参照前述各实施例对本申请进行了详细的说明,本领域的普通技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分或者全部技术特征进行等同替换;而这些修改或者替换,并不使相应技术方案的本质脱离本申请各实施例技术方案的范围。
Claims (20)
- 一种提供网络地址转换NAT服务的方法,其特征在于,包括:控制器与多个宿主服务器建立通信;所述控制器为第一宿主服务器生成流表,所述第一宿主服务器为与所述控制器建立通信的所述多个宿主服务器中的任意一个宿主服务器,所述流表包括多个表项,所述多个表项中每个表项记录了一条NAT转发规则;所述控制器将所述流表发送给所述第一宿主服务器,所述流表用于所述第一宿主服务器为所述第一宿主服务器上的云主机提供NAT服务。
- 根据权利要求1所述方法,其特征在于,所述控制器将所述流表发送给所述第一宿主服务器之后,还包括:所述控制器接收所述第一宿主服务器发送的报文;所述控制器根据所述报文确定包含所述报文的NAT转发规则的表项;所述控制器将所述包含所述报文的NAT转发规则的表项发送给所述第一宿主服务器,所述包含所述报文的NAT转发规则的表项用于所述第一宿主服务器对所述报文执行NAT操作。
- 根据权利要求2所述方法,其特征在于,所述控制器接收所述第一宿主服务器发送的报文,包括:所述控制器接收所述第一宿主服务器在为报文匹配表项失败后发送的所述报文。
- 根据权利要求1-3任一项所述方法,其特征在于,所述控制器为第一宿主服务器生成流表之前,还包括:所述控制器接收所述第一宿主服务器发送的NAT服务请求指令,所述请求指令用于请求所述控制器为所述第一宿主服务器生成所述流表。
- 根据权利要求1所述方法,其特征在于,所述NAT转发规则包括私网信息与公网信息之间的转换规则,其中,所述私网信息包括私网的互联网协议IP地址和私网端口信息,所述公网信息包括公网的IP地址和公网端口信息,所述私网为所述第一宿主服务器上的云主机所属的专用网络。
- 根据权利要求3所述的方法,其特征在于,所述控制器接收所述第一宿主服务器在为报文匹配表项失败后发送的所述报文之后,还包括:所述控制器从所述控制器维护的流表中为所述报文匹配流表项,确定了流表项之后,将所述流表项发送给第一宿主服务器。
- 根据权利要求3所述的方法,其特征在于,所述控制器接收所述第一宿主服务器在 为报文匹配表项失败后发送的所述报文之后,还包括:若所述控制器为所述报文匹配表项失败,所述控制器将为所述报文匹配表项失败的信息返回给所述第一宿主服务器,以提示所述第一宿主服务器将所述报文丢弃。
- 根据权利要求1-3任一项所述的方法,其特征在于,所述控制器为第一宿主服务器生成流表,包括:在所述控制器接收到所述第一宿主服务器发送的NAT服务请求指令时,所述控制器为所述第一宿主服务器生成对应的流表。
- 根据权利要求1-3任一项所述的方法,其特征在于,所述控制器上配置了所述多个宿主服务器的网络地址,以用于识别来自所述多个宿主服务器的数据包,以及用于针对性地向所述多个宿主服务器发送数据包;所述多个宿主服务器上配置了所述控制器的网络地址,以用于识别来自所述控制器的数据包,以及用于针对性地向所述控制器器发送数据包。
- 一种控制器,其特征在于,包括:配置单元,用于与多个宿主服务器建立通信;生成单元,用于为第一宿主服务器生成流表,所述第一宿主服务器为与所述控制器建立通信的所述多个宿主服务器中的任意一个宿主服务器,所述流表包括多个表项,所述多个表项中每个表项记录了一条NAT转发规则;第一发送单元,用于将所述流表发送给所述第一宿主服务器,所述流表用于所述第一宿主服务器为所述第一宿主服务器上的云主机提供NAT服务。
- 根据权利要求10所述控制器,其特征在于,还包括第一接收单元、确定单元和第二发送单元,其中:所述第一接收单元,用于在所述第一发送单元将所述流表发送给所述第一宿主服务器之后接收所述第一宿主服务器发送的报文;所述确定单元,用于根据所述报文确定包含所述报文的NAT转发规则的表项;所述第二发送单元,用于将所述包含所述报文的NAT转发规则的表项发送给所述第一宿主服务器,所述包含所述报文的NAT转发规则的表项用于所述第一宿主服务器对所述报文执行NAT操作。
- 根据权利要求11所述控制器,其特征在于,所述第一接收单元,用于接收所述第一宿主服务器发送的报文,具体为:用于接收所述第一宿主服务器在为报文匹配表项失败后发送的所述报文。
- 根据权利要求10-12任一项所述控制器,其特征在于,所述第一接收单元,还用于在所述生成单元为第一宿主服务器生成流表之前,接收所述第一宿主服务器发送的NAT服务请求指令,所述请求指令用于请求所述控制器为所述第一宿主服务器生成所述流表。
- 根据权利要求10所述控制器,其特征在于,所述NAT转发规则包括私网信息与公网信息之间的转换规则,其中,所述私网信息包括私网的互联网协议IP地址和私网端口信息,所述公网信息包括公网的IP地址和公网端口信息,所述私网为所述第一宿主服务器上的云主机所属的专用网络。
- 根据权利要求12所述的控制器,其特征在于,所述第一发送单元,用于在所述第一接收单元接收所述第一宿主服务器在为报文匹配表项失败后发送的所述报文之后,从所述控制器维护的流表中为所述报文匹配流表项,确定了流表项之后,将所述流表项发送给第一宿主服务器。
- 根据权利要求12所述的控制器,其特征在于,所述第一发送单元,用于在所述第一接收单元接收所述第一宿主服务器在为报文匹配表项失败后发送的所述报文之后,若所述控制器为所述报文匹配表项失败,为所述报文匹配表项失败的信息返回给所述第一宿主服务器,以提示所述第一宿主服务器将所述报文丢弃。
- 根据权利要求10-12任一项所述的控制器,其特征在于,所述生成单元具体用于:在所述控制器接收到所述第一宿主服务器发送的NAT服务请求指令时,为所述第一宿主服务器生成对应的流表。
- 根据权利要求10-12任一项所述的控制器,其特征在于,所述控制器上配置了所述多个宿主服务器的网络地址,以用于识别来自所述多个宿主服务器的数据包,以及用于针对性地向所述多个宿主服务器发送数据包;所述多个宿主服务器上配置了所述控制器的网络地址,以用于识别来自所述控制器的数据包,以及用于针对性地向所述控制器器发送数据包。
- 一种控制器,其特征在于,所述控制器包括处理器、计算机可读存储介质和通信接口,其中,所述计算机可读存储介质用于存储程序指令,所述通信接口用于在所述处理器的控制下执行数据的接收和发送操作,所述处理器用于调用所述程序指令来执行权利要求1-9任一项所述的方法。
- 一种计算机可读存储介质,其特征在于,所述计算机可读存储介质用于存储程序指令,所述程序指令在处理器上运行时,实现权利要求1-9任一项所述的方法。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201910178099.7 | 2019-03-08 | ||
| CN201910178099.7A CN110012118B (zh) | 2019-03-08 | 2019-03-08 | 一种提供网络地址转换nat服务的方法及控制器 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2020181735A1 true WO2020181735A1 (zh) | 2020-09-17 |
Family
ID=67166686
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2019/103258 Ceased WO2020181735A1 (zh) | 2019-03-08 | 2019-08-29 | 一种提供网络地址转换nat服务的方法及控制器 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN110012118B (zh) |
| WO (1) | WO2020181735A1 (zh) |
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN112333298A (zh) * | 2020-12-01 | 2021-02-05 | 武汉绿色网络信息服务有限责任公司 | 报文传输方法、装置、计算机设备及存储介质 |
| CN113645188A (zh) * | 2021-07-07 | 2021-11-12 | 中国电子科技集团公司第三十研究所 | 一种基于安全关联的数据包快速转发方法 |
| CN116032837A (zh) * | 2022-12-22 | 2023-04-28 | 珠海星云智联科技有限公司 | 一种流表卸载方法及装置 |
| CN119892431A (zh) * | 2024-12-30 | 2025-04-25 | 浙江吉利控股集团有限公司 | 内网设备访问外网方法、装置、设备、介质及程序产品 |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110012118B (zh) * | 2019-03-08 | 2022-07-22 | 平安科技(深圳)有限公司 | 一种提供网络地址转换nat服务的方法及控制器 |
| CN114710465B (zh) * | 2022-04-07 | 2023-05-02 | 中国联合网络通信集团有限公司 | 网络地址转换方法、装置、设备及存储介质 |
Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103581324A (zh) * | 2013-11-11 | 2014-02-12 | 中国联合网络通信集团有限公司 | 一种云计算资源池系统及其实现方法 |
| CN104601738A (zh) * | 2014-12-09 | 2015-05-06 | 国家计算机网络与信息安全管理中心 | 一种分布式网络地址转换系统 |
| CN104601432A (zh) * | 2014-12-31 | 2015-05-06 | 杭州华三通信技术有限公司 | 一种报文传输方法和设备 |
| WO2017032300A1 (zh) * | 2015-08-25 | 2017-03-02 | 华为技术有限公司 | 一种数据传输方法、虚拟网络管理装置及数据传输系统 |
| CN107172120A (zh) * | 2017-03-27 | 2017-09-15 | 联想(北京)有限公司 | 信息处理方法、处理节点及网络节点 |
| CN110012118A (zh) * | 2019-03-08 | 2019-07-12 | 平安科技(深圳)有限公司 | 一种提供网络地址转换nat服务的方法及控制器 |
Family Cites Families (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102035900B (zh) * | 2009-09-24 | 2015-05-06 | 日电(中国)有限公司 | 用于通过中继方式进行nat穿越的方法、系统和中继服务器 |
| CN104780232B (zh) * | 2014-01-13 | 2018-07-31 | 华为技术有限公司 | 一种资源分配方法、控制器及系统 |
| CN103795805B (zh) * | 2014-02-27 | 2017-08-25 | 中国科学技术大学苏州研究院 | 基于sdn的分布式服务器负载均衡方法 |
| US9930008B2 (en) * | 2014-03-25 | 2018-03-27 | Cisco Technology, Inc. | Dynamic service chain with network address translation detection |
| JP2016092485A (ja) * | 2014-10-30 | 2016-05-23 | 富士通株式会社 | 情報処理システム、管理装置及び情報処理システムの制御方法 |
| CN105554065B (zh) * | 2015-12-03 | 2019-06-18 | 华为技术有限公司 | 处理报文的方法、转换单元和应用单元 |
| US10382392B2 (en) * | 2016-08-01 | 2019-08-13 | Big Switch Networks, Inc. | Systems and methods for network address translation |
| CN108040134A (zh) * | 2017-12-06 | 2018-05-15 | 杭州迪普科技股份有限公司 | 一种dns透明代理的方法及装置 |
-
2019
- 2019-03-08 CN CN201910178099.7A patent/CN110012118B/zh active Active
- 2019-08-29 WO PCT/CN2019/103258 patent/WO2020181735A1/zh not_active Ceased
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103581324A (zh) * | 2013-11-11 | 2014-02-12 | 中国联合网络通信集团有限公司 | 一种云计算资源池系统及其实现方法 |
| CN104601738A (zh) * | 2014-12-09 | 2015-05-06 | 国家计算机网络与信息安全管理中心 | 一种分布式网络地址转换系统 |
| CN104601432A (zh) * | 2014-12-31 | 2015-05-06 | 杭州华三通信技术有限公司 | 一种报文传输方法和设备 |
| WO2017032300A1 (zh) * | 2015-08-25 | 2017-03-02 | 华为技术有限公司 | 一种数据传输方法、虚拟网络管理装置及数据传输系统 |
| CN107172120A (zh) * | 2017-03-27 | 2017-09-15 | 联想(北京)有限公司 | 信息处理方法、处理节点及网络节点 |
| CN110012118A (zh) * | 2019-03-08 | 2019-07-12 | 平安科技(深圳)有限公司 | 一种提供网络地址转换nat服务的方法及控制器 |
Cited By (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN112333298A (zh) * | 2020-12-01 | 2021-02-05 | 武汉绿色网络信息服务有限责任公司 | 报文传输方法、装置、计算机设备及存储介质 |
| CN113645188A (zh) * | 2021-07-07 | 2021-11-12 | 中国电子科技集团公司第三十研究所 | 一种基于安全关联的数据包快速转发方法 |
| CN113645188B (zh) * | 2021-07-07 | 2023-05-09 | 中国电子科技集团公司第三十研究所 | 一种基于安全关联的数据包快速转发方法 |
| CN116032837A (zh) * | 2022-12-22 | 2023-04-28 | 珠海星云智联科技有限公司 | 一种流表卸载方法及装置 |
| CN119892431A (zh) * | 2024-12-30 | 2025-04-25 | 浙江吉利控股集团有限公司 | 内网设备访问外网方法、装置、设备、介质及程序产品 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN110012118A (zh) | 2019-07-12 |
| CN110012118B (zh) | 2022-07-22 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11659441B2 (en) | Load balance method and apparatus thereof | |
| WO2020181735A1 (zh) | 一种提供网络地址转换nat服务的方法及控制器 | |
| CN107026890B (zh) | 一种基于服务器集群的报文生成方法和负载均衡器 | |
| US10608866B2 (en) | Forwarding Ethernet packets | |
| CN112040030B (zh) | 报文传输方法、装置、计算机设备及存储介质 | |
| WO2014190791A1 (zh) | 一种网关设备身份设置的方法及管理网关设备 | |
| CN105144652A (zh) | 软件定义的网络中的地址解析 | |
| US9584481B2 (en) | Host providing system and communication control method | |
| CN109525684B (zh) | 报文转发方法和装置 | |
| WO2016134624A1 (zh) | 路由方法、装置及系统、网关调度方法及装置 | |
| US10764241B2 (en) | Address assignment and data forwarding in computer networks | |
| CN112583655B (zh) | 数据传输方法、装置、电子设备及可读存储介质 | |
| CN114095430A (zh) | 一种访问报文的处理方法、系统及工作节点 | |
| CN109743414B (zh) | 利用冗余连接提高地址翻译可用性的方法及计算机可读存储介质 | |
| CN112242952A (zh) | 一种数据转发方法、柜顶式交换机和存储介质 | |
| CN107547346B (zh) | 一种报文传输方法和装置 | |
| CN112040029A (zh) | Nat转换方法、装置、计算机设备及存储介质 | |
| CN113676409B (zh) | 一种报文转发方法、装置、电子设备以及存储介质 | |
| CN114785733A (zh) | 一种实现跨vpc网络流量转发中会话溯源的方法 | |
| CN102572012B (zh) | 一种消息处理方法、交换机及系统 | |
| CN106330492B (zh) | 一种配置用户设备转发表的方法、装置及系统 | |
| WO2018019216A1 (zh) | Ap接入控制 | |
| US20090292796A1 (en) | Method and device for providing routing policies to user terminals according to applications executed on user terminals | |
| CN114244842B (zh) | 一种安全资源调度方法、装置、电子设备及存储介质 | |
| CN112787932A (zh) | 一种用于生成转发信息的方法、装置和系统 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 19919143 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 19919143 Country of ref document: EP Kind code of ref document: A1 |