WO2021184551A1 - 基于多个网络的通信方法、装置、电子设备及存储介质 - Google Patents
基于多个网络的通信方法、装置、电子设备及存储介质 Download PDFInfo
- Publication number
- WO2021184551A1 WO2021184551A1 PCT/CN2020/093312 CN2020093312W WO2021184551A1 WO 2021184551 A1 WO2021184551 A1 WO 2021184551A1 CN 2020093312 W CN2020093312 W CN 2020093312W WO 2021184551 A1 WO2021184551 A1 WO 2021184551A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- message
- gateway node
- session
- address
- port
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L45/00—Routing or path finding of packets in data switching networks
- H04L45/22—Alternate routing
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/66—Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L45/00—Routing or path finding of packets in data switching networks
- H04L45/28—Routing or path finding of packets in data switching networks using route fault recovery
Definitions
- This application relates to the field of network communication technology, and in particular to a communication method, device, electronic device, and storage medium based on multiple networks.
- the internal network accesses the external network, it needs to map the Internet Protocol address requested by the internal network to a legal address through NAT (Network Address Translation) processing before accessing the external network.
- NAT Network Address Translation
- a Session (session) related to the access request will be established, and the relevant information will be saved through the session.
- a gateway node fails during the access process, the gateway node cannot continue to process the user's access request, and the user's access request needs to be sent to other gateway nodes, so that the other gateway node will serve as the gateway node. The user processes the access request.
- the inventor realizes that because other gateway nodes do not have a session related to this access request, other gateway nodes cannot be used to continue processing related services of the access request, resulting in poor network service quality. Therefore, how to ensure the normal processing of the user's access request to improve the network service quality is a technical problem that needs to be solved urgently.
- a communication method based on multiple networks including:
- the first gateway node When the first gateway node receives the first access request sent from the internal network to the external network, determining whether the first gateway node stores a first session that matches the first message carried in the first access request;
- the first gateway node does not store a first session that matches the first message carried in the first access request, a hash algorithm is used to determine the destination address of the first message and the first message.
- the destination port of the message determines the second gateway node that manages the first message;
- a communication device based on multiple networks including:
- the judging module is used for judging whether the first gateway node stores the first message that matches the first message carried in the first access request when the first gateway node receives the first access request sent from the internal network to the external network 'S first conversation;
- the determining module is configured to, if the first gateway node does not store a first session that matches the first message carried in the first access request, use a hash algorithm according to the destination address of the first message and The destination port of the first message, determining the second gateway node that manages the first message;
- An allocation module configured to reallocate all network address resources to the remaining gateway nodes except for the second gateway node among all gateway nodes when a failure of the second gateway node is detected;
- the determining module is further configured to re-determine the first packet managing the first packet according to the network address resources of the remaining gateway nodes, the destination address of the first packet, and the destination port of the first packet.
- the sending module is configured to send the first message to the external network according to the multiple sessions stored by the third gateway node.
- An electronic device including a processor and a memory, and the processor is configured to execute computer-readable instructions stored in the memory to implement the following steps:
- the first gateway node When the first gateway node receives the first access request sent from the internal network to the external network, determining whether the first gateway node stores a first session that matches the first message carried in the first access request;
- the first gateway node does not store a first session that matches the first message carried in the first access request, a hash algorithm is used to determine the destination address of the first message and the first message.
- the destination port of the message determines the second gateway node that manages the first message;
- One or more readable storage media storing computer readable instructions
- the computer readable storage medium storing computer readable instructions
- the one Or multiple processors perform the following steps:
- the first gateway node When the first gateway node receives the first access request sent from the internal network to the external network, determining whether the first gateway node stores a first session that matches the first message carried in the first access request;
- the first gateway node does not store a first session that matches the first message carried in the first access request, a hash algorithm is used to determine the destination address of the first message and the first message.
- the destination port of the message determines the second gateway node that manages the first message;
- the first gateway node When the first gateway node receives an access request sent from the internal network to the external network, because the Internet protocol address used in the message carried in the access request from the internal network is an illegal address, it cannot access the external network and needs to store information based on the session , The illegal address of the message is mapped to a legal address to access the external network. Therefore, it is necessary to determine whether the first gateway node stores a session matching the message. If the first gateway node does not store a session matching the message, The session that may match the message has not been synchronized to the first gateway node or has not been created yet, you need to send the message to the second gateway node that manages the message, because the second gateway node can use its own network address Resource to create a session matching the message.
- the network address resource can be reallocated so that other gateway nodes can create the session originally created by the second gateway node, and then it can be re-determined
- the third gateway node that manages the message and sends the message to the third gateway node. If the third gateway node stores a session that matches the message, the message may be stored according to the relevant information stored in the session. Send to the external network to ensure that the internal network can access the external network normally and improve the network service quality.
- Fig. 1 is a flowchart of a preferred embodiment of a communication method based on multiple networks disclosed in the present application.
- Fig. 2 is a functional module diagram of a preferred embodiment of a communication device based on multiple networks disclosed in the present application.
- FIG. 3 is a schematic structural diagram of an electronic device according to a preferred embodiment of a communication method based on multiple networks according to the present application.
- the communication method based on multiple networks in the embodiments of the present application is applied to an electronic device, and can also be applied to a hardware environment composed of an electronic device and a server connected to the electronic device through a network, and is executed by the server and the electronic device.
- Networks include, but are not limited to: wide area networks, metropolitan area networks, or local area networks.
- the electronic device is a device that can automatically perform numerical calculation and/or information processing in accordance with pre-set or stored instructions.
- Its hardware includes, but is not limited to, a microprocessor, an application specific integrated circuit (ASIC), and a field programmable gate. Array (FPGA), digital processor (DSP), embedded device, etc.
- the electronic equipment may also include network equipment and/or user equipment.
- the network device includes, but is not limited to, a single network device, a server group composed of multiple network devices, or a cloud composed of a large number of hosts or network devices based on Cloud Computing, where cloud computing is distributed computing One type, a super virtual computer composed of a group of loosely coupled computer sets.
- the user equipment includes, but is not limited to, any electronic product that can interact with the user through a keyboard, a mouse, a remote control, a touch panel, or a voice control device, for example, a personal computer, a tablet computer, a smart phone, and a personal digital device. Assistant PDA, etc.
- FIG. 1 is a flowchart of a preferred embodiment of a communication method based on multiple networks disclosed in the present application. Among them, according to different needs, the order of the steps in the flowchart can be changed, and some steps can be omitted.
- step S11 When the first gateway node receives the first access request sent from the internal network to the external network, the electronic device determines whether the first gateway node stores data matching the first message carried in the first access request For the first session, if not, execute step S12, if yes, end this process.
- the first gateway node may be any gateway device.
- the session can be a data structure that saves the IP (Internet Protocol, Internet Protocol address) quintuple before entering the gateway node and after entering the gateway node and going through NAT (Network Address Translation, network address translation) processing The mapping relationship of the IP quintuple.
- IP Internet Protocol, Internet Protocol address
- NAT Network Address Translation, network address translation
- the five-tuple can refer to a collection of source IP address, source port, destination IP address, destination port, and transport layer protocol
- the gateway node when the first gateway node receives the first access request sent from the internal network to the external network, because the source address of the first message carried in the first access request is the network address used by the internal network, it cannot To access the external network, the gateway node is required to assign a legal network address and a port to the first message to ensure that the first message can be sent to the external network normally. After the gateway node assigns a legal address and port to the first message, the related information It will be saved in the session. Before the communication connection is disconnected, all packets with the same source address and the same source port can be converted to the network address according to this session, and then sent to the external network normally. Therefore, it is necessary to determine whether the first gateway node stores a session that matches the first message carried in the first access request.
- the electronic device determines the second gateway node that manages the first packet according to the destination address of the first packet and the destination port of the first packet by using a hash algorithm.
- the first gateway node if the first gateway node does not store the first session that matches the first message carried in the first access request, the first session may not have been created yet, or the first session may not have been synchronized to the first session.
- a gateway node can determine the second gateway node that manages the first packet according to the destination address of the first packet and the destination port of the first packet through a hash algorithm, and the second gateway node can allocate the first packet Used to access the network address and port of the external network, and create a session matching the first message. If the first session has been created, the second gateway node will store the first session. If the first session has not been created, Then the second gateway node can create the first session.
- the source address of the first message may be mapped to the stored value of the first session for accessing the external network.
- Network address, and mapping the source port of the first message to the port stored in the first session for accessing the external network may be mapped to the stored value of the first session for accessing the external network.
- step S12 the method further includes:
- the heartbeat may refer to the behavior of periodically sending information between the main server and each device to determine the health status of the device and determine whether the other party is "alive". If you still do not receive the heartbeat information of the device within the specified time, you can suspect that the device is malfunctioning.
- the number of timeout heartbeats for determining device failure can be preset, for example, 3 times. If the number of heartbeat information (timeout heartbeats) of the second gateway node is not received within a specified period of time exceeds 3 times, you can It is considered that the second gateway node has failed, and if the number of times that the heartbeat information of the second gateway node is not received at a specified time does not exceed 3 times, it can be considered that the second gateway node is in a normal operating state.
- the method further includes:
- the gateway node that manages each intersection session is re-determined.
- the remaining gateway nodes need to synchronize the session, and each node gateway can broadcast its own session ID ( Unique identification), and then determine the intersection session of the remaining gateway nodes, and delete other sessions except the intersection session, so as to ensure that the sessions of all gateway nodes are the same. Because the specific network address resource associated with the session is only allocated and released on a fixed gateway node, all sessions are created and deleted on the same gateway node. It is necessary to reallocate all network address resources to the remaining gateway nodes so that the remaining gateway nodes can manage the sessions originally managed by the second gateway node. Therefore, it is also necessary to re-determine the gateway node that manages each intersection session.
- session ID Unique identification
- a session deletion request can be sent to the gateway node that manages the session. If the gateway node that manages the session receives two or more session deletion requests, it can The conversation is deleted.
- the electronic device When detecting that the second gateway node fails, the electronic device reallocates all network address resources to the remaining gateway nodes except for the second gateway node among all gateway nodes.
- the electronic device re-determines the third gateway node that manages the first packet according to the network address resources of the remaining gateway nodes, the destination address of the first packet, and the destination port of the first packet.
- the third gateway node that manages the first message needs to be re-determined.
- the third gateway node that manages the first message can be determined by performing hash calculation on the destination address of the first message and the destination port of the first message.
- the algorithm used for hash calculation can be a general address hash (IP HASH) algorithm, for example: assuming there are 4 gateway nodes, you can use the address plus the port number to take the remainder of 4, and the result is the node of the gateway node ID, if one gateway node fails and there are 3 gateway nodes, adjust the hash function to address plus port number and take the remainder of 3, and the result is the node ID of the gateway node.
- IP HASH IP HASH
- the electronic device sends the first message to the external network according to the multiple sessions stored by the third gateway node.
- the first message can be sent to the third gateway node, because the third gateway node can allocate the network address for accessing the external network and the network address for the first message after all network resources are reallocated.
- the port for accessing the external network or, the third gateway node owns and can manage the network address used for accessing the external network card and the port used for accessing the external network allocated to the first message.
- the sending the first message to the external network according to the multiple sessions stored by the third gateway node includes:
- the multiple sessions stored by the third gateway node include the first session, acquiring the first network address and the first port stored in the first session;
- the source address of the first message is mapped to the first network address, and the source port of the first message is mapped to the first port, so as to use the first The network address and the first port send the first message to the external network.
- the third gateway node may first query whether it has stored the first session .
- the first network address is a legal address that can access an external network
- the first port is a legal port that can access an external network
- address resource translation Network Address Translation, NAT
- NAT Network Address Translation
- the source address-source port of the first message is used in the internal network, it will be intercepted by the external network and cannot access the external network. Therefore, it is necessary to map the source address of the first message to the first network address through address resource conversion. , And mapping the source port of the first message to the first port, the first message can be a legal message, and the first message can be sent to the external network. If the multiple sessions stored by the third gateway node include the first session, the first session may be directly read to obtain the first network address and the first port stored in the first session.
- the method further includes:
- the third gateway node If the multiple sessions stored by the third gateway node do not include the first session, select a second network address and a second port from the available network address resources of the third gateway node;
- the multiple sessions stored by the third gateway node do not include the first session, it can be considered that the first session has not been created, and one can be selected from the available network address resources of the third gateway node
- the second network address and the second port through address resource conversion, the source address of the first message is mapped to the second network address, and the source port of the first message is mapped to the second port, and a second session can be created , Used to store information such as the source address of the first message, the source port of the first message, the second network address, the second port, the destination address of the first message, and the destination port of the first message.
- the second session needs to be synchronized to all normal running gateway nodes.
- the method further includes:
- the fourth gateway node When the fourth gateway node receives the second access request sent from the external network to the internal network, it is determined whether the fourth gateway node stores data matching the second message carried in the second access request Third conversation
- the fourth gateway node stores a third session that matches the second message carried in the second access request, map the destination address of the second message to the third network stored in the third session Address, and mapping the destination port of the second message to the third port stored in the third session, and according to the mapped third network address of the second message and the second message
- the first port sends the second message to the internal network.
- the fourth gateway node when the fourth gateway node receives the second message from the external network, it needs to translate the second message into a network address and port that can be recognized by the internal network before the second message can be transferred.
- the message is sent to the internal network, and you can query whether it stores the third session that matches the second message. If the fourth gateway node stores the third session that matches the second message, you can change the destination of the second message The address is mapped to the third network address stored in the third session, and the destination port of the second message is mapped to the third port stored in the third session, so that the second message can be recognized by the internal network. Therefore, the second message can be identified by the internal network. The message is sent to the internal network.
- the method further includes:
- a hash algorithm is used to determine the source address of the second message and the second message.
- the source port of the message determines the fifth gateway node that manages the second message;
- the fourth gateway node does not store the third session that matches the second message carried in the second access request, it is possible that the third session has not been synchronized to the fourth gateway node.
- the Greek algorithm according to the source address of the second message and the source port of the second message, the fifth gateway node that manages the second message is determined. If the third session has been created, the fifth gateway node will store the third Session. If the fifth gateway node is the fourth gateway node, it means that the third session has not been created, or the third session has ended and has been deleted, indicating that the second message cannot be translated into a network address that can be recognized by the internal network. Port, the second packet can be discarded.
- the method further includes:
- the sixth gateway node If the number of sessions stored by the sixth gateway node is greater than the preset number threshold, reallocate all network address resources to the sixth gateway node and all the gateway nodes that are operating normally.
- the preset number threshold may be 90% of the number of sessions stored by any gateway node except the sixth gateway node among all normally operating gateway nodes.
- the sessions stored by all gateway nodes other than the sixth gateway node in the normal operation can be synchronized to the sixth gateway node, so that the sixth gateway node can enter the sixth gateway node.
- the message of the gateway node can be normally sent to the external network or the internal network. If the number of sessions stored by the sixth gateway node is greater than the preset number threshold, all network address resources can be reallocated to the sixth gateway node and all operations are normal Gateway node. Because the total network address resources are limited, each gateway node must have a part of the network address resources, so when a new gateway node goes online, the network address resources need to be redistributed.
- the first gateway node when the first gateway node receives an access request sent from the internal network to the external network, because the Internet Protocol address used by the message carried in the access request from the internal network is an illegal address, it cannot To access the external network, it is necessary to map the illegal address of the message to a legal address according to the information stored in the session, and then you can access the external network. Therefore, it is necessary to determine whether the first gateway node stores a session that matches the message. No session matching the message is stored, and the session matching the message may not be synchronized to the first gateway node or created, and the message needs to be sent to the second gateway node that manages the message, because The second gateway node can use its own network address resource to create a session matching the message.
- the second gateway node If it detects that the second gateway node has failed, it can reallocate the network address resource so that other gateway nodes can create a session originally created by the second gateway node. The session created by the node can then re-determine the third gateway node that manages the message and send the message to the third gateway node. If the third gateway node stores a session matching the message, it can be based on The relevant information stored in the session is sent to the external network to ensure that the internal network can access the external network normally, and the network service quality is improved.
- FIG. 2 is a functional module diagram of a preferred embodiment of a communication device based on multiple networks disclosed in the present application.
- the communication device based on multiple networks runs in an electronic device.
- the communication device based on multiple networks may include multiple functional modules composed of program code segments.
- the program code of each program segment described above may be stored in a memory and executed by at least one processor to execute part or all of the steps in the communication method based on multiple networks described in FIG. 1.
- the communication device based on multiple networks can be divided into multiple functional modules according to the functions it performs.
- the functional modules may include: a judgment module 201, a determination module 202, an allocation module 203, and a sending module 204.
- the module referred to in this application refers to a series of computer-readable instruction segments that can be executed by at least one processor and can complete fixed functions, and are stored in a memory.
- the determining module 201 is configured to determine whether the first gateway node stores the first message carried in the first access request when the first gateway node receives the first access request sent from the internal network to the external network The first session that matches;
- the first gateway node may be any gateway device.
- the session can be a data structure that saves the IP (Internet Protocol, Internet Protocol address) quintuple before entering the gateway node and after entering the gateway node and going through NAT (Network Address Translation, network address translation) processing The mapping relationship of the IP quintuple.
- IP Internet Protocol, Internet Protocol address
- NAT Network Address Translation, network address translation
- the five-tuple can refer to a collection of source IP address, source port, destination IP address, destination port, and transport layer protocol
- the gateway node when the first gateway node receives the first access request sent from the internal network to the external network, because the source address of the first message carried in the first access request is the network address used by the internal network, it cannot To access the external network, the gateway node is required to assign a legal network address and a port to the first message to ensure that the first message can be sent to the external network normally. After the gateway node assigns a legal address and port to the first message, the related information It will be saved in the session. Before the communication connection is disconnected, all packets with the same source address and the same source port can be converted to the network address according to this session, and then sent to the external network normally. Therefore, it is necessary to determine whether the first gateway node stores a session that matches the first message carried in the first access request.
- the determining module 202 is configured to, if the first gateway node does not store a first session that matches the first message carried in the first access request, use a hash algorithm according to the destination address of the first message And the destination port of the first message, determining the second gateway node that manages the first message.
- the first gateway node if the first gateway node does not store the first session that matches the first message carried in the first access request, the first session may not have been created yet, or the first session may not have been synchronized to the first session.
- a gateway node can determine the second gateway node that manages the first packet according to the destination address of the first packet and the destination port of the first packet through a hash algorithm, and the second gateway node can allocate the first packet Used to access the network address and port of the external network, and create a session matching the first message. If the first session has been created, the second gateway node will store the first session. If the first session has not been created, Then the second gateway node can create the first session.
- the source address of the first message may be mapped to the stored value of the first session for accessing the external network.
- Network address, and mapping the source port of the first message to the port stored in the first session for accessing the external network may be mapped to the stored value of the first session for accessing the external network.
- the allocation module 203 is configured to, when a failure of the second gateway node is detected, reallocate all network address resources to the remaining gateway nodes except the second gateway node among all the gateway nodes.
- the determining module 202 is further configured to re-determine the management of the first packet according to the network address resources of the remaining gateway nodes, the destination address of the first packet, and the destination port of the first packet.
- the third gateway node is further configured to re-determine the management of the first packet according to the network address resources of the remaining gateway nodes, the destination address of the first packet, and the destination port of the first packet.
- the third gateway node that manages the first message needs to be re-determined.
- the third gateway node that manages the first message can be determined by performing hash calculation on the destination address of the first message and the destination port of the first message.
- the algorithm used for hash calculation can be a general address hash (IP HASH) algorithm, for example: assuming there are 4 gateway nodes, you can use the address plus the port number to take the remainder of 4, and the result is the node of the gateway node ID, if one gateway node fails and there are 3 gateway nodes, adjust the hash function to address plus port number and take the remainder of 3, and the result is the node ID of the gateway node.
- IP HASH IP HASH
- the sending module 204 is configured to send the first message to the external network according to the multiple sessions stored by the third gateway node.
- the first message can be sent to the third gateway node, because the third gateway node can allocate the network address for accessing the external network and the network address for the first message after all network resources are reallocated.
- the port for accessing the external network or, the third gateway node owns and can manage the network address used for accessing the external network card and the port used for accessing the external network allocated to the first message.
- the sending module 204 sends the first packet to the external network according to the multiple sessions stored by the third gateway node specifically as follows:
- the multiple sessions stored by the third gateway node include the first session, acquiring the first network address and the first port stored in the first session;
- the source address of the first message is mapped to the first network address, and the source port of the first message is mapped to the first port, so as to use the first The network address and the first port send the first message to the external network.
- the third gateway node may first query whether it has stored the first session .
- the first network address is a legal address that can access an external network
- the first port is a legal port that can access an external network
- address resource translation Network Address Translation, NAT
- NAT Network Address Translation
- the source address-source port of the first message is used in the internal network, it will be intercepted by the external network and cannot access the external network. Therefore, it is necessary to map the source address of the first message to the first network address through address resource conversion. , And mapping the source port of the first message to the first port, the first message can be a legal message, and the first message can be sent to the external network. If the multiple sessions stored by the third gateway node include the first session, the first session may be directly read to obtain the first network address and the first port stored in the first session.
- the communication device based on multiple networks may further include:
- a selection module configured to select a second network address and a second port from the available network address resources of the third gateway node if the multiple sessions stored by the third gateway node do not include the first session;
- a mapping module configured to map the source address of the first packet to the second network address and map the source port of the first packet to the second port through the address resource conversion algorithm ;
- a generating module configured to generate a first packet matching the first packet according to the source address of the first packet, the source port of the first packet, the second network address, and the second port Second session
- the first synchronization module is used to synchronize the second session to all normal running gateway nodes.
- the multiple sessions stored by the third gateway node do not include the first session, it can be considered that the first session has not been created, and one can be selected from the available network address resources of the third gateway node
- the second network address and the second port through address resource conversion, the source address of the first message is mapped to the second network address, and the source port of the first message is mapped to the second port, and a second session can be created , Used to store information such as the source address of the first message, the source port of the first message, the second network address, the second port, the destination address of the first message, and the destination port of the first message.
- the second session needs to be synchronized to all normally running gateway nodes.
- the method further includes:
- the judging module 201 is further configured to judge whether the fourth gateway node has stored information related to the second access request sent by the external network to the internal network when the fourth gateway node receives the second access request.
- the sending module 204 is further configured to, if the fourth gateway node stores a third session that matches the second packet carried in the second access request, map the destination address of the second packet to the destination address of the second packet.
- the third network address stored in the third session, and the destination port of the second message is mapped to the third port stored in the third session, and according to the mapped third network address of the second message Address and the first port of the second message, sending the second message to the internal network.
- the fourth gateway node when the fourth gateway node receives the second message from the external network, it needs to translate the second message into a network address and port that can be recognized by the internal network before the second message can be transferred.
- the message is sent to the internal network, and you can query whether it stores the third session that matches the second message. If the fourth gateway node stores the third session that matches the second message, you can change the destination of the second message The address is mapped to the third network address stored in the third session, and the destination port of the second message is mapped to the third port stored in the third session, so that the second message can be recognized by the internal network. Therefore, the second message can be identified by the internal network. The message is sent to the internal network.
- the determining module 202 is further configured to: if the fourth gateway node does not store a third session that matches the second packet carried in the second access request, use a hash An algorithm to determine the fifth gateway node that manages the second message according to the source address of the second message and the source port of the second message;
- the judgment module 201 is further configured to judge whether the fifth gateway node is the fourth gateway node;
- the communication device based on multiple networks may further include:
- the discarding module is further configured to discard the second packet if the fifth gateway node is the fourth gateway node.
- the fourth gateway node does not store the third session that matches the second message carried in the second access request, it is possible that the third session has not been synchronized to the fourth gateway node.
- the Greek algorithm according to the source address of the second message and the source port of the second message, the fifth gateway node that manages the second message is determined. If the third session has been created, the fifth gateway node will store the third Session. If the fifth gateway node is the fourth gateway node, it means that the third session has not been created, or the third session has ended and has been deleted, indicating that the second message cannot be translated into a network address that can be recognized by the internal network. Port, the second packet can be discarded.
- the determining module 201 is further configured to determine the number of timeout heartbeats of the second gateway node after the determining module 202 determines the second gateway node that manages the first message Whether it is greater than the preset threshold of times;
- the determining module 202 is further configured to determine that the second gateway node has a failure if the number of timeout heartbeats of the second gateway node is greater than a preset number threshold.
- the heartbeat may refer to the behavior of periodically sending information between the main server and each device to determine the health status of the device and determine whether the other party is "alive". If you still do not receive the heartbeat information of the device within the specified time, you can suspect that the device is malfunctioning.
- the number of timeout heartbeats for determining device failure can be preset, for example, 3 times. If the number of heartbeat information (timeout heartbeats) of the second gateway node is not received within a specified period of time exceeds 3 times, you can It is considered that the second gateway node has failed, and if the number of times that the heartbeat information of the second gateway node is not received at a specified time does not exceed 3 times, it can be considered that the second gateway node is in a normal operating state.
- the determining module 202 is further configured to determine an intersection session of the remaining gateway nodes, where the intersection session is a session commonly stored by each of the remaining gateway nodes;
- the communication device based on multiple networks may further include:
- a deleting module configured to delete other sessions except the intersection session from the sessions stored in each of the remaining gateway nodes
- the determining module 202 is further configured to re-determine the gateway node that manages each intersection session according to the network address stored in the intersection session and the network address resources of the remaining gateway nodes.
- the remaining gateway nodes need to synchronize the session, and each node gateway can broadcast its own session ID ( Unique identification), and then determine the intersection session of the remaining gateway nodes, and delete other sessions except the intersection session, so as to ensure that the sessions of all gateway nodes are the same. Because the specific network address resource associated with the session is only allocated and released on a fixed gateway node, all sessions are created and deleted on the same gateway node. It is necessary to reallocate all network address resources to the remaining gateway nodes so that the remaining gateway nodes can manage the sessions originally managed by the second gateway node. Therefore, it is also necessary to re-determine the gateway node that manages each intersection session.
- session ID Unique identification
- a session deletion request can be sent to the gateway node that manages the session. If the gateway node that manages the session receives two or more session deletion requests, the session can be deleted. .
- the communication device based on multiple networks may further include:
- the second synchronization module is used for synchronizing the sessions stored by all the gateway nodes in normal operation except for the sixth gateway node to the sixth gateway node when the sixth gateway node is online;
- the judgment module 201 is further configured to judge whether the number of sessions stored by the sixth gateway node is greater than a preset number threshold
- the allocation module 203 is further configured to, if the number of sessions stored by the sixth gateway node is greater than a preset number threshold, reallocate all network address resources to the sixth gateway node and all the normal operating gateway nodes .
- the preset number threshold may be 90% of the number of sessions stored by any gateway node except the sixth gateway node among all normally operating gateway nodes.
- the sessions stored by all gateway nodes other than the sixth gateway node in the normal operation can be synchronized to the sixth gateway node, so that the sixth gateway node can enter the sixth gateway node.
- the message of the gateway node can be normally sent to the external network or the internal network. If the number of sessions stored by the sixth gateway node is greater than the preset number threshold, all network address resources can be reallocated to the sixth gateway node and all operations are normal Gateway node. Because the total network address resources are limited, each gateway node must have a part of the network address resources, so when a new gateway node goes online, the network address resources need to be redistributed.
- the Internet protocol address used by the message carried in the access request from the internal network is It is an illegal address and cannot access the external network. It is necessary to map the illegal address of the message to a legal address based on the information stored in the session to access the external network. Therefore, it is necessary to determine whether the first gateway node stores a session that matches the message. If the first gateway node does not store a session that matches the message, it is possible that the session that matches the message has not been synchronized to the first gateway node or has not been created yet, and the message needs to be sent to the second person who manages the message.
- Second gateway node because the second gateway node can use its own network address resources to create a session matching the message. If it detects that the second gateway node has failed, it can reallocate network address resources so that other gateway nodes can create The session originally created by the second gateway node, then, can re-determine the third gateway node that manages the message, and send the message to the third gateway node, if the third gateway node stores a matching message For the session, the message can be sent to the external network according to the relevant information stored in the session, to ensure that the internal network can access the external network normally, and the network service quality is improved.
- FIG. 3 is a schematic structural diagram of an electronic device in a preferred embodiment of the present application for implementing a communication method based on multiple networks.
- the electronic device 3 includes a memory 31, at least one processor 32, computer readable instructions 33 stored in the memory 31 and executable on the at least one processor 32, and at least one communication bus 34. That is, the electronic device 3 includes a processor 32 and a memory 31, and the processor 32 is configured to execute computer-readable instructions stored in the memory 31 to implement each step of the communication method based on multiple networks in the foregoing embodiment.
- FIG. 3 is only an example of the electronic device 3, and does not constitute a limitation on the electronic device 3. It may include more or less components than those shown in the figure, or a combination. Certain components, or different components, for example, the electronic device 3 may also include input and output devices, network access devices, and so on.
- the at least one processor 32 may be a central processing unit (Central Processing Unit, CPU), or other general-purpose processors, digital signal processors (Digital Signal Processors, DSPs), and application specific integrated circuits (ASICs). ), Field-Programmable Gate Array (FPGA) or other programmable logic devices, transistor logic devices, discrete hardware components, etc.
- the processor 32 can be a microprocessor, or the processor 32 can also be any conventional processor, etc.
- the processor 32 is the control center of the electronic device 3, and connects the entire electronic device 3 through various interfaces and lines. Parts.
- the memory 31 may be used to store the computer-readable instructions 33 and/or modules/units, and the processor 32 runs or executes the computer-readable instructions 33 and/or modules/units stored in the memory 31, And call the data stored in the memory 31 to realize various functions of the electronic device 3.
- the memory 31 may mainly include a storage program area and a storage data area.
- the storage program area may store an operating system, an application program required by at least one function (such as a sound playback function, an image playback function, etc.), etc.; the storage data area may Data (such as audio data, etc.) created according to the use of the electronic device 3 and the like are stored.
- the memory 31 may include non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a Secure Digital (SD) card, a flash memory card (Flash Card), At least one disk storage device, flash memory device, etc.
- non-volatile memory such as a hard disk, a memory, a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a Secure Digital (SD) card, a flash memory card (Flash Card), At least one disk storage device, flash memory device, etc.
- the memory 31 in the electronic device 3 stores multiple instructions to implement a communication method based on multiple networks, and the processor 32 can execute the multiple instructions to achieve:
- the first gateway node When the first gateway node receives the first access request sent from the internal network to the external network, determining whether the first gateway node stores a first session that matches the first message carried in the first access request;
- the first gateway node does not store a first session that matches the first message carried in the first access request, a hash algorithm is used to determine the destination address of the first message and the first message.
- the destination port of the message determines the second gateway node that manages the first message;
- the first gateway node when the first gateway node receives an access request sent from the internal network to the external network, because the Internet Protocol address used by the message carried in the access request from the internal network is an illegal address, The external network cannot be accessed, and the illegal address of the message needs to be mapped to a legal address according to the information stored in the session, so that the external network can be accessed. Therefore, it is necessary to determine whether the first gateway node stores a session that matches the message. The node does not store a session matching the message. It is possible that the session matching the message has not been synchronized to the first gateway node or has not been created, and the message needs to be sent to the second gateway node that manages the message.
- the second gateway node can use its own network address resources to create a session that matches the message, if it detects that the second gateway node has failed, it can reallocate the network address resources so that other gateway nodes can create a session originally created by the second gateway node. The session created by the gateway node can then re-determine the third gateway node that manages the message and send the message to the third gateway node. If the third gateway node stores a session matching the message, it can According to the relevant information stored in the session, the message is sent to the external network to ensure that the internal network can access the external network normally, and the network service quality is improved.
- the integrated module/unit of the electronic device 3 is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer readable storage medium.
- this application implements all or part of the processes in the above-mentioned embodiments and methods, and can also be completed by instructing relevant hardware through computer-readable instructions, and the computer-readable instructions can be stored in a computer-readable storage medium.
- the computer-readable instruction when executed by the processor, it can implement the steps of the foregoing method embodiments.
- the computer-readable instruction includes computer-readable instruction code
- the computer-readable instruction code may be in the form of source code, object code, executable file, or some intermediate form.
- the computer-readable medium may include: any entity or device capable of carrying the computer-readable instruction code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM, Read-Only Memory).
- modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the objectives of the solutions of the embodiments.
- the functional modules in the various embodiments of the present application may be integrated into one processing unit, or each unit may exist alone physically, or two or more units may be integrated into one unit.
- the above-mentioned integrated unit may be implemented in the form of hardware, or may be implemented in the form of hardware plus software functional modules.
- one or more readable storage media storing computer readable instructions are provided.
- the computer readable storage medium stores computer readable instructions, and the computer readable instructions are executed by one or more processors. During execution, the one or more processors are executed to implement the communication method based on multiple networks in the foregoing embodiment. In order to avoid repetition, details are not described herein again.
- the readable storage medium in this embodiment includes a non-volatile readable storage medium and a volatile readable storage medium.
- a person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing relevant hardware through computer-readable instructions, which can be stored in a non-volatile readable storage.
- the medium may also be stored in a volatile readable storage medium, and when the computer readable instructions are executed, they may include the processes of the above-mentioned method embodiments.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
一种基于多个网络的通信方法,所述方法包括:当第一网关节点接收到第一访问请求时,若第一网关节点未存储第一会话,确定管理第一报文的第二网关节点;当检测到第二网关节点出现故障时,将所有网络地址资源重新分配至所有网关节点中除了第二网关节点外的剩余网关节点;重新确定管理第一报文的第三网关节点;将第一报文发送至第三网关节点;若第三网关节点存储的多个会话包括第一会话,获取第一会话存储的第一网络地址以及第一端口;将第一报文的源地址映射为第一网络地址,以及将第一报文的源端口映射为第一端口,将第一报文发送至外部网络。本申请还提供一种基于多个网络的通信装置、电子设备以及存储介质。本申请能提高网络服务质量。
Description
本申请以2020年03月18日提交的申请号为202010193483.7,名称为“基于多个网络的通信方法、装置、电子设备及存储介质”的中国发明申请为基础,并要求其优先权。
本申请涉及网络通信技术领域,尤其涉及一种基于多个网络的通信方法、装置、电子设备及存储介质。
目前,内部网络访问外部网络时,需要通过NAT(Network Address Translation,网络地址转换)处理将内部网络请求的互联网协议地址映射为合法的地址,才可以访问外部网络。在访问的过程中,会建立一个与访问请求相关的Session(会话),通过会话来保存相关信息。但在实践中发现,如果在访问过程中的某个网关节点发生了故障,该网关节点就无法继续处理用户的访问请求,需要将用户的访问请求发送到其他网关节点,以由其他网关节点为用户处理该访问请求。发明人意识到由于其他网关节点没有与这个访问请求相关的会话,因此,无法使用其他网关节点来继续处理该访问请求的相关业务,导致网络服务质量较差。因此,如何确保用户的访问请求的正常处理以提高网络服务质量是一个亟需解决的技术问题。
发明内容
鉴于以上内容,有必要提供一种基于多个网络的通信方法、装置、电子设备及存储介质,能够确保内部网络可以正常访问外部网络,提高了网络服务质量。
一种基于多个网络的通信方法,包括:
当第一网关节点接收到由内部网络发往外部网络的第一访问请求时,判断所述第一网关节点是否存储有与所述第一访问请求携带的第一报文匹配的第一会话;
若所述第一网关节点未存储有与所述第一访问请求携带的第一报文匹配的第一会话,通过哈希算法,根据所述第一报文的目的地址以及所述第一报文的目的端口,确定管理所述第一报文的第二网关节点;
当检测到所述第二网关节点出现故障时,将所有网络地址资源重新分配至所有网关节点中除了所述第二网关节点外的剩余网关节点;
根据所述剩余网关节点的网络地址资源以及所述第一报文的目的地址以及所述第一报文的目的端口,重新确定管理所述第一报文的第三网关节点;
根据所述第三网关节点存储的多个会话,将所述第一报文发送至所述外部网络。
一种基于多个网络的通信装置,包括:
判断模块,用于当第一网关节点接收到由内部网络发往外部网络的第一访问请求时,判断所述第一网关节点是否存储有与所述第一访问请求携带的第一报文匹配的第一会话;
确定模块,用于若所述第一网关节点未存储有与所述第一访问请求携带的第一报文匹配的第一会话,通过哈希算法,根据所述第一报文的目的地址以及所述第一报文的目的端口,确定管理所述第一报文的第二网关节点;
分配模块,用于当检测到所述第二网关节点出现故障时,将所有网络地址资源重新分配 至所有网关节点中除了所述第二网关节点外的剩余网关节点;
所述确定模块,还用于根据所述剩余网关节点的网络地址资源以及所述第一报文的目的地址以及所述第一报文的目的端口,重新确定管理所述第一报文的第三网关节点;
发送模块,用于根据所述第三网关节点存储的多个会话,将所述第一报文发送至所述外部网络。
一种电子设备,所述电子设备包括处理器和存储器,所述处理器用于执行存储器中存储的计算机可读指令以实现如下步骤:
当第一网关节点接收到由内部网络发往外部网络的第一访问请求时,判断所述第一网关节点是否存储有与所述第一访问请求携带的第一报文匹配的第一会话;
若所述第一网关节点未存储有与所述第一访问请求携带的第一报文匹配的第一会话,通过哈希算法,根据所述第一报文的目的地址以及所述第一报文的目的端口,确定管理所述第一报文的第二网关节点;
当检测到所述第二网关节点出现故障时,将所有网络地址资源重新分配至所有网关节点中除了所述第二网关节点外的剩余网关节点;
根据所述剩余网关节点的网络地址资源以及所述第一报文的目的地址以及所述第一报文的目的端口,重新确定管理所述第一报文的第三网关节点;
根据所述第三网关节点存储的多个会话,将所述第一报文发送至所述外部网络。
一个或多个存储有计算机可读指令的可读存储介质,所述计算机可读存储介质存储有计算机可读指令,所述计算机可读指令被一个或多个处理器执行时,使得所述一个或多个处理器执行如下步骤:
当第一网关节点接收到由内部网络发往外部网络的第一访问请求时,判断所述第一网关节点是否存储有与所述第一访问请求携带的第一报文匹配的第一会话;
若所述第一网关节点未存储有与所述第一访问请求携带的第一报文匹配的第一会话,通过哈希算法,根据所述第一报文的目的地址以及所述第一报文的目的端口,确定管理所述第一报文的第二网关节点;
当检测到所述第二网关节点出现故障时,将所有网络地址资源重新分配至所有网关节点中除了所述第二网关节点外的剩余网关节点;
根据所述剩余网关节点的网络地址资源以及所述第一报文的目的地址以及所述第一报文的目的端口,重新确定管理所述第一报文的第三网关节点;
根据所述第三网关节点存储的多个会话,将所述第一报文发送至所述外部网络。
当第一网关节点接收到由内部网络发往外部网络的访问请求时,因为来自内部网络的访问请求携带的报文使用的互联网协议地址属于非法地址,不能访问外部网络,需要根据会话存储的信息,将报文的非法地址映射为合法地址,才可以访问外部网络,所以需要判断第一网关节点是否存储有与报文匹配的会话,若第一网关节点不存储有与报文匹配的会话,可能与该报文匹配的会话还没同步到第一网关节点或还没被创建,则需要将报文发送给管理该报文的第二网关节点,因为第二网关节点可以使用自身的网络地址资源来创建与该报文匹配的会话,若检测到第二网关节点发生故障了,可以重新分配网络地址资源,使得其他网关节点可以创建原本由第二网关节点创建的会话,然后,可以重新确定管理该报文的第三网关节点,并将该报文发送至第三网关节点,若第三网关节点存储有与该报文匹配的会话,则可以根据会话存储的相关信息,将该报文发送至外部网络,确保内部网络可以正常访问外部网络,提高了网络服务质量。
图1是本申请公开的一种基于多个网络的通信方法的较佳实施例的流程图。
图2是本申请公开的一种基于多个网络的通信装置的较佳实施例的功能模块图。
图3是本申请实现基于多个网络的通信方法的较佳实施例的电子设备的结构示意图。
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本申请保护的范围。
除非另有定义,本文所使用的所有的技术和科学术语与属于本申请的技术领域的技术人员通常理解的含义相同。本文中在本申请的说明书中所使用的术语只是为了描述具体的实施例的目的,不是旨在于限制本申请。
本申请实施例的基于多个网络的通信方法应用在电子设备中,也可以应用在电子设备和通过网络与所述电子设备进行连接的服务器所构成的硬件环境中,由服务器和电子设备共同执行。网络包括但不限于:广域网、城域网或局域网。
所述电子设备是一种能够按照事先设定或存储的指令,自动进行数值计算和/或信息处理的设备,其硬件包括但不限于微处理器、专用集成电路(ASIC)、现场可编程门阵列(FPGA)、数字处理器(DSP)、嵌入式设备等。所述电子设备还可包括网络设备和/或用户设备。其中,所述网络设备包括但不限于单个网络设备、多个网络设备组成的服务器组或基于云计算(Cloud Computing)的由大量主机或网络设备构成的云,其中,云计算是分布式计算的一种,由一群松散耦合的计算机集组成的一个超级虚拟计算机。所述用户设备包括但不限于任何一种可与用户通过键盘、鼠标、遥控器、触摸板或声控设备等方式进行人机交互的电子产品,例如,个人计算机、平板电脑、智能手机、个人数字助理PDA等。
请参见图1,图1是本申请公开的一种基于多个网络的通信方法的较佳实施例的流程图。其中,根据不同的需求,该流程图中步骤的顺序可以改变,某些步骤可以省略。
S11、当第一网关节点接收到由内部网络发往外部网络的第一访问请求时,电子设备判断所述第一网关节点是否存储有与所述第一访问请求携带的第一报文匹配的第一会话,若否,执行步骤S12,若是,结束本流程。
其中,所述第一网关节点可以为任意一台网关设备。
其中,会话(Session)可以是一种数据结构,保存着进入网关节点前的IP(Internet Protocol,互联网协议地址)五元组和进入网关节点并经过NAT(Network Address Translation,网络地址转换)处理后的IP五元组的映射关系。
其中,五元组可以指源IP地址,源端口,目的IP地址,目的端口,和传输层协议组成的一个集合
本申请实施例中,当第一网关节点接收到有内部网络发往外部网络的第一访问请求时,因为第一访问请求携带的第一报文的源地址是内部网络使用的网络地址,无法访问外部网络,需要网关节点给第一报文分配一个合法网络地址以及一个端口,确保第一报文可以正常发送至外部网络,网关节点给第一报文分配合法地址以及端口后,相关的信息会保存在会话中,在通信连接断开前,凡是具有相同的源地址以及相同的源端口的报文都可以根据这个会话来进行网络地址转换,从而正常发往外部网络。因此,需要判断第一网关节点是否存储有与第一访问请求携带的第一报文匹配的会话。
S12、电子设备通过哈希算法,根据所述第一报文的目的地址以及所述第一报文的目的端口,确定管理所述第一报文的第二网关节点。
本申请实施例中,若第一网关节点未存储有与第一访问请求携带的第一报文匹配的 第一会话,可能第一会话还未被创建,或,第一会话还未同步至第一网关节点,可以通过哈希算法,根据第一报文的目的地址以及第一报文的目的端口,确定管理第一报文的第二网关节点,第二网关节点可以为第一报文分配用于访问外部网络的网络地址以及端口,并创建与第一报文匹配的会话,若第一会话已被创建,则第二网关节点会存储有第一会话,若第一会话未被创建,则第二网关节点可以创建第一会话。
可选的,若第一网关节点存储有与第一访问请求携带的第一报文匹配的第一会话,可以将第一报文的源地址映射为第一会话存储的用于访问外部网络的网络地址,以及将第一报文的源端口映射为第一会话存储的用于访问外部网络的端口。
作为一种可选的实施方式,步骤S12之后,所述方法还包括:
判断所述第二网关节点的超时心跳的次数是否大于预设次数阈值;
若所述第二网关节点的超时心跳的次数大于预设次数阈值,确定所述第二网关节点出现故障。
其中,心跳可以指主服务器与各设备之间通过周期性发送信息,判断设备的健康状况,判断对方是否“存活”的行为。如果在指定的时间内仍没有收到设备的心跳信息,就可以怀疑此设备发生故障。
本申请实施例中,可以预先设置一个判定设备故障的超时心跳的次数,比如3次,如果在指定时间内没有收到第二网关节点的心跳信息(超时心跳)的次数超过3次,则可以认为第二网关节点出现了故障,如果在指定时间没有收到第二网关节点的心跳信息的次数不超过3次,则可以认为第二网关节点处于正常运行的状态。
作为一种可选的实施方式,所述确定所述第二网关节点出现故障之后,所述方法还包括:
确定所述剩余网关节点的交集会话,其中,所述交集会话为每个所述剩余网关节点所共同存储的会话;
从每个所述剩余网关节点存储的会话中,删除所述交集会话之外的其他会话;
根据所述交集会话存储的网络地址以及所述剩余网关节点的网络地址资源,重新确定管理每个所述交集会话的网关节点。
在该可选的实施方式中,因为在确定第二网关节点出现故障后,为了保证网络间的通信连接可以正常通信,需要剩余网关节点同步会话,每个节点网关可以广播自己的会话的ID(唯一身份标识),进而确定剩余网关节点的交集会话,删除交集会话之外的其他会话,从而保证所有网关节点的会话都相同。因为会话关联的特定网络地址资源只在一个固定的网关节点上分配和释放,所有会话的创建和删除在同一个网关节点上。需要将所有的网络地址资源重新分配至剩余网关节点,使得剩余网关节点可以管理原本由第二网关节点管理的会话。因此还需要重新确定管理每个交集会话的网关节点。
可选的,当会话定时器超时的时侯,可以向管理该会话的网关节点发送会话删除请求,若管理该会话的网关节点接收到两个或两个以上的会话删除请求,则可以将该会话删除。
S13、当检测到所述第二网关节点出现故障时,电子设备将所有网络地址资源重新分配至所有网关节点中除了所述第二网关节点外的剩余网关节点。
本申请实施例中,当检测到第二网关节点出现故障时,因为会话关联的特定网络地址资源只在一个固定的网关节点上分配和释放,所有会话的创建和删除在同一个网关节点上。需要将所有的网络地址资源重新分配至剩余网关节点,使得剩余网关节点可以管理原本由第二网关节点管理的会话。
S14、电子设备根据所述剩余网关节点的网络地址资源以及所述第一报文的目的地址以及所述第一报文的目的端口,重新确定管理所述第一报文的第三网关节点。
本申请实施中,因为网络地址资源被重新分配了,因此,会话关联的特定网络地址 资源可能会由别的的网关节点管理,因此,需要重新确定管理第一报文的第三网关节点。可以通过对第一报文的目标地址以及第一报文的目的端口进行哈希计算,确定管理第一报文的第三网关节点。其中,哈希计算用的算法可以是通用的地址哈希(IP HASH)算法,比如:假设有4个网关节点,可以使用地址加端口号对4取余数,得出的结果为网关节点的节点ID,若有一个网关节点故障了,剩3个网关节点,则调整哈希函数为地址加端口号对3取余数,得出的结果为网关节点的节点ID。
S15、电子设备根据所述第三网关节点存储的多个会话,将所述第一报文发送至所述外部网络。
本申请实施例中,可以将第一报文发送至第三网关节点,因为第三网关节点在所有网络资源重新分配后,可以为第一报文分配用于访问外部网络的网络地址以及用于访问外部网络的端口,或,第三网关节点拥有并可以管理已分配给第一报文的用于访问外部网卡的网络地址以及用于访问外部网络的端口。
具体的,所述根据所述第三网关节点存储的多个会话,将所述第一报文发送至所述外部网络包括:
将所述第一报文发送至所述第三网关节点;
判断所述第三网关节点存储的多个会话是否包括所述第一会话;
若所述第三网关节点存储的多个会话包括所述第一会话,获取所述第一会话存储的第一网络地址以及第一端口;
通过地址资源转换算法,将所述第一报文的源地址映射为所述第一网络地址,以及将所述第一报文的源端口映射为所述第一端口,以使用所述第一网络地址以及所述第一端口,将所述第一报文发送至所述外部网络。
在该可选的实施方式中,因为第一会话可能在之前已被创建并被存储至第三网关节点,第三网关节点接收到第一报文后,可以先查询自身是否存储有第一会话。
其中,所述第一网络地址为可以访问外部网络的合法地址,所述第一端口为可以访问外部网络的合法端口。
其中,地址资源转换(Network Address Translation,NAT)可以用来更换报文的网络地址以及端口。因为第一报文的源地址一源端口是在内部网络中使用,会被外部网络拦截,访问不了外部网络,所以需要通过地址资源转换,将第一报文的源地址映射为第一网络地址,以及将第一报文的源端口映射为第一端口,第一报文就可以属于合法报文,可以将第一报文发送至外部网络。若第三网关节点存储的多个会话包括第一会话,则可以直接读取第一会话,获取第一会话存储的第一网络地址以及第一端口。
作为一种可选的实施方式,所述方法还包括:
若所述第三网关节点存储的多个会话未包括所述第一会话,从所述第三网关节点的可用网络地址资源中选择第二网络地址以及第二端口;
通过所述地址资源转换算法,将所述第一报文的源地址映射为所述第二网络地址,以及将所述第一报文的源端口映射为所述第二端口;
根据所述第一报文的源地址、所述第一报文的源端口、所述第二网络地址以及所述第二端口,生成与所述第一报文匹配的第二会话;
将所述第二会话同步至所有正常运行的网关节点。
在该可选的实施方式中,若第三网关节点存储的多个会话没有包括第一会话,则可以认为第一会话还没被创建,可以从第三网关节点的可用网络地址资源中选取一个第二网络地址以及第二端口,通过地址资源转换,将第一报文的源地址映射为第二网络地址,以及将第一报文的源端口映射为第二端口,并可以创建第二会话,用于保存第一报文的源地址、第一报文的源端口、第二网络地址、第二端口、第一报文的目的地址以及第一报文的目的端口等信息。为了使任意一个正常运行的网关节点都可以进行转发都可以发送与第一报文具有相同源 地址以及相同源端口的报文,需要将第二会话同步至所有正常运行的网关节点。
作为一种可选的实施方式,所述方法还包括:
当第四网关节点接收到由所述外部网络发送至所述内部网络的第二访问请求时,判断所述第四网关节点是否存储有与所述第二访问请求携带的第二报文匹配的第三会话;
若所述第四网关节点存储有与所述第二访问请求携带的第二报文匹配的第三会话,将所述第二报文的目的地址映射为所述第三会话存储的第三网络地址,以及将所述第二报文的目的端口映射为所述第三会话存储的第三端口,并根据映射后的所述第二报文的第三网络地址以及所述第二报文的第一端口,将所述第二报文发送至所述内部网络。
在该可选的实施方式中,当第四网关节点接收到来自外部网络的第二报文时,需要将第二报文能翻译成内部网络可以识别的网络地址和端口,才可以将第二报文发送至内部网络,可以查询自身是否存储由于第二报文匹配的第三会话,若第四网关节点存储有与第二报文匹配的第三会话,则可以将第二报文的目的地址映射为第三会话存储的第三网络地址,以及将第二报文的目的端口映射为第三会话存储的第三端口,让第二报文可以被内部网络识别,因此,可以将第二报文发送至内部网络。
作为一种可选的实施方式,所述方法还包括:
若所述第四网关节点未存储有与所述第二访问请求携带的第二报文匹配的第三会话,通过哈希算法,根据所述第二报文的源地址以及所述第二报文的源端口,确定管理所述第二报文的第五网关节点;
判断所述第五网关节点是否为所述第四网关节点;
若所述第五网关节点为所述第四网关节点,将所述第二报文丢弃。
在该可选的实施方式中,若第四网关节点未存储有与第二访问请求携带的第二报文匹配的第三会话,可能第三会话还未同步至第四网关节点,可以通过哈希算法,根据第二报文的源地址以及第二报文的源端口,确定管理第二报文的第五网关节点,若第三会话已被创建,则第五网关节点会存储有第三会话,若第五网关节点就是第四网关节点,则说明第三会话未被创建,或,第三会话已经结束,被删除了,表明第二报文不能翻译成内部网络可以识别的网络地址和端口,可以将第二报文丢弃。
作为一种可选的实施方式,所述方法还包括:
当第六网关节点上线时,将所有正常运行的网关节点中除了所述第六网关节点之外的网关节点存储的会话同步至所述第六网关节点;
判断所述第六网关节点存储的会话的数量是否大于预设数量阈值;
若所述第六网关节点存储的会话的数量大于预设数量阈值,将所有网络地址资源重新分配至所述第六网关节点以及所述所有正常运行的网关节点。
其中,所述预设数量阈值可以为所有正常运行的网关节点中除了第六网关节点之外的任意一个网关节点存储的会话的数量的90%。
在该可选的实施方式中,当第六网关节点上线时,可以将所有正常运行的网关节点中除了第六网关节点之外的网关节点存储的会话同步至第六网关节点,使得进入第六网关节点的报文可以被正常发送至外部网络或内部网络,若第六网关节点存储的会话的数量大于预设数量阈值时,可以将所有网络地址资源重新分配至第六网关节点以及所有运行正常的网关节点。因为总的网络地址资源是有限,每个网关节点都要拥有一部分网络地址资源,所以有新的网关节点上线,需要重新分配网络地址资源。
在图1所描述的方法流程中,当第一网关节点接收到由内部网络发往外部网络的访问请求时,因为来自内部网络的访问请求携带的报文使用的互联网协议地址属于非法地址,不能访问外部网络,需要根据会话存储的信息,将报文的非法地址映射为合法地址,才可以访问外部网络,所以需要判断第一网关节点是否存储有与报文匹配的会话,若第一网关节点不存储有与报文匹配的会话,可能与该报文匹配的会话还没同步到第一网关 节点或还没被创建,则需要将报文发送给管理该报文的第二网关节点,因为第二网关节点可以使用自身的网络地址资源来创建与该报文匹配的会话,若检测到第二网关节点发生故障了,可以重新分配网络地址资源,使得其他网关节点可以创建原本由第二网关节点创建的会话,然后,可以重新确定管理该报文的第三网关节点,并将该报文发送至第三网关节点,若第三网关节点存储有与该报文匹配的会话,则可以根据会话存储的相关信息,将该报文发送至外部网络,确保内部网络可以正常访问外部网络,提高了网络服务质量。
以上所述,仅是本申请的具体实施方式,但本申请的保护范围并不局限于此,对于本领域的普通技术人员来说,在不脱离本申请创造构思的前提下,还可以做出改进,但这些均属于本申请的保护范围。
请参见图2,图2是本申请公开的一种基于多个网络的通信装置的较佳实施例的功能模块图。
在一些实施例中,所述基于多个网络的通信装置运行于电子设备中。所述基于多个网络的通信装置可以包括多个由程序代码段所组成的功能模块。所述中的各个程序段的程序代码可以存储于存储器中,并由至少一个处理器所执行,以执行图1所描述的基于多个网络的通信方法中的部分或全部步骤。
本实施例中,所述基于多个网络的通信装置根据其所执行的功能,可以被划分为多个功能模块。所述功能模块可以包括:判断模块201、确定模块202、分配模块203及发送模块204。本申请所称的模块是指一种能够被至少一个处理器所执行并且能够完成固定功能的一系列计算机可读指令段,其存储在存储器中。
判断模块201,用于当第一网关节点接收到由内部网络发往外部网络的第一访问请求时,判断所述第一网关节点是否存储有与所述第一访问请求携带的第一报文匹配的第一会话;
其中,所述第一网关节点可以为任意一台网关设备。
其中,会话(Session)可以是一种数据结构,保存着进入网关节点前的IP(Internet Protocol,互联网协议地址)五元组和进入网关节点并经过NAT(Network Address Translation,网络地址转换)处理后的IP五元组的映射关系。
其中,五元组可以指源IP地址,源端口,目的IP地址,目的端口,和传输层协议组成的一个集合
本申请实施例中,当第一网关节点接收到有内部网络发往外部网络的第一访问请求时,因为第一访问请求携带的第一报文的源地址是内部网络使用的网络地址,无法访问外部网络,需要网关节点给第一报文分配一个合法网络地址以及一个端口,确保第一报文可以正常发送至外部网络,网关节点给第一报文分配合法地址以及端口后,相关的信息会保存在会话中,在通信连接断开前,凡是具有相同的源地址以及相同的源端口的报文都可以根据这个会话来进行网络地址转换,从而正常发往外部网络。因此,需要判断第一网关节点是否存储有与第一访问请求携带的第一报文匹配的会话。
确定模块202,用于若所述第一网关节点未存储有与所述第一访问请求携带的第一报文匹配的第一会话,通过哈希算法,根据所述第一报文的目的地址以及所述第一报文的目的端口,确定管理所述第一报文的第二网关节点。
本申请实施例中,若第一网关节点未存储有与第一访问请求携带的第一报文匹配的第一会话,可能第一会话还未被创建,或,第一会话还未同步至第一网关节点,可以通过哈希算法,根据第一报文的目的地址以及第一报文的目的端口,确定管理第一报文的第二网关节点,第二网关节点可以为第一报文分配用于访问外部网络的网络地址以及端口,并创建与第一报文匹配的会话,若第一会话已被创建,则第二网关节点会存储有第一会话,若第一会话未被创建,则第二网关节点可以创建第一会话。
可选的,若第一网关节点存储有与第一访问请求携带的第一报文匹配的第一会话,可以将第一报文的源地址映射为第一会话存储的用于访问外部网络的网络地址,以及将第一报文的源端口映射为第一会话存储的用于访问外部网络的端口。
分配模块203,用于当检测到所述第二网关节点出现故障时,将所有网络地址资源重新分配至所有网关节点中除了所述第二网关节点外的剩余网关节点。
本申请实施例中,当检测到第二网关节点出现故障时,因为会话关联的特定网络地址资源只在一个固定的网关节点上分配和释放,所有会话的创建和删除在同一个网关节点上。需要将所有的网络地址资源重新分配至剩余网关节点,使得剩余网关节点可以管理原本由第二网关节点管理的会话。
所述确定模块202,还用于根据所述剩余网关节点的网络地址资源以及所述第一报文的目的地址以及所述第一报文的目的端口,重新确定管理所述第一报文的第三网关节点。
本申请实施中,因为网络地址资源被重新分配了,因此,会话关联的特定网络地址资源可能会由别的的网关节点管理,因此,需要重新确定管理第一报文的第三网关节点。可以通过对第一报文的目标地址以及第一报文的目的端口进行哈希计算,确定管理第一报文的第三网关节点。其中,哈希计算用的算法可以是通用的地址哈希(IP HASH)算法,比如:假设有4个网关节点,可以使用地址加端口号对4取余数,得出的结果为网关节点的节点ID,若有一个网关节点故障了,剩3个网关节点,则调整哈希函数为地址加端口号对3取余数,得出的结果为网关节点的节点ID。
发送模块204,用于根据所述第三网关节点存储的多个会话,将所述第一报文发送至所述外部网络。
本申请实施例中,可以将第一报文发送至第三网关节点,因为第三网关节点在所有网络资源重新分配后,可以为第一报文分配用于访问外部网络的网络地址以及用于访问外部网络的端口,或,第三网关节点拥有并可以管理已分配给第一报文的用于访问外部网卡的网络地址以及用于访问外部网络的端口。
作为一种可选的实施方式,所述发送模块204根据所述第三网关节点存储的多个会话,将所述第一报文发送至所述外部网络的方式具体为:
将所述第一报文发送至所述第三网关节点;
判断所述第三网关节点存储的多个会话是否包括所述第一会话;
若所述第三网关节点存储的多个会话包括所述第一会话,获取所述第一会话存储的第一网络地址以及第一端口;
通过地址资源转换算法,将所述第一报文的源地址映射为所述第一网络地址,以及将所述第一报文的源端口映射为所述第一端口,以使用所述第一网络地址以及所述第一端口,将所述第一报文发送至所述外部网络。
在该可选的实施方式中,因为第一会话可能在之前已被创建并被存储至第三网关节点,第三网关节点接收到第一报文后,可以先查询自身是否存储有第一会话。
其中,所述第一网络地址为可以访问外部网络的合法地址,所述第一端口为可以访问外部网络的合法端口。
其中,地址资源转换(Network Address Translation,NAT)可以用来更换报文的网络地址以及端口。因为第一报文的源地址一源端口是在内部网络中使用,会被外部网络拦截,访问不了外部网络,所以需要通过地址资源转换,将第一报文的源地址映射为第一网络地址,以及将第一报文的源端口映射为第一端口,第一报文就可以属于合法报文,可以将第一报文发送至外部网络。若第三网关节点存储的多个会话包括第一会话,则可以直接读取第一会话,获取第一会话存储的第一网络地址以及第一端口。
作为一种可选的实施方式,所述基于多个网络的通信装置还可以包括:
选择模块,用于若所述第三网关节点存储的多个会话未包括所述第一会话,从所述第三网关节点的可用网络地址资源中选择第二网络地址以及第二端口;
映射模块,用于通过所述地址资源转换算法,将所述第一报文的源地址映射为所述第二网络地址,以及将所述第一报文的源端口映射为所述第二端口;
生成模块,用于根据所述第一报文的源地址、所述第一报文的源端口、所述第二网络地址以及所述第二端口,生成与所述第一报文匹配的第二会话;
第一同步模块,用于将所述第二会话同步至所有正常运行的网关节点。
在该可选的实施方式中,若第三网关节点存储的多个会话没有包括第一会话,则可以认为第一会话还没被创建,可以从第三网关节点的可用网络地址资源中选取一个第二网络地址以及第二端口,通过地址资源转换,将第一报文的源地址映射为第二网络地址,以及将第一报文的源端口映射为第二端口,并可以创建第二会话,用于保存第一报文的源地址、第一报文的源端口、第二网络地址、第二端口、第一报文的目的地址以及第一报文的目的端口等信息。为了使任意一个正常运行的网关节点都可以进行转发都可以发送与第一报文具有相同源地址以及相同源端口的报文,需要将第二会话同步至所有正常运行的网关节点。
作为一种可选的实施方式,所述方法还包括:
所述判断模块201,还用于当第四网关节点接收到由所述外部网络发送至所述内部网络的第二访问请求时,判断所述第四网关节点是否存储有与所述第二访问请求携带的第二报文匹配的第三会话;
所述发送模块204,还用于若所述第四网关节点存储有与所述第二访问请求携带的第二报文匹配的第三会话,将所述第二报文的目的地址映射为所述第三会话存储的第三网络地址,以及将所述第二报文的目的端口映射为所述第三会话存储的第三端口,并根据映射后的所述第二报文的第三网络地址以及所述第二报文的第一端口,将所述第二报文发送至所述内部网络。
在该可选的实施方式中,当第四网关节点接收到来自外部网络的第二报文时,需要将第二报文能翻译成内部网络可以识别的网络地址和端口,才可以将第二报文发送至内部网络,可以查询自身是否存储由于第二报文匹配的第三会话,若第四网关节点存储有与第二报文匹配的第三会话,则可以将第二报文的目的地址映射为第三会话存储的第三网络地址,以及将第二报文的目的端口映射为第三会话存储的第三端口,让第二报文可以被内部网络识别,因此,可以将第二报文发送至内部网络。
作为一种可选的实施方式,所述确定模块202,还用于若所述第四网关节点未存储有与所述第二访问请求携带的第二报文匹配的第三会话,通过哈希算法,根据所述第二报文的源地址以及所述第二报文的源端口,确定管理所述第二报文的第五网关节点;
所述判断模块201,还用于判断所述第五网关节点是否为所述第四网关节点;
所述基于多个网络的通信装置还可以包括:
丢弃模块,还用于若所述第五网关节点为所述第四网关节点,将所述第二报文丢弃。
在该可选的实施方式中,若第四网关节点未存储有与第二访问请求携带的第二报文匹配的第三会话,可能第三会话还未同步至第四网关节点,可以通过哈希算法,根据第二报文的源地址以及第二报文的源端口,确定管理第二报文的第五网关节点,若第三会话已被创建,则第五网关节点会存储有第三会话,若第五网关节点就是第四网关节点,则说明第三会话未被创建,或,第三会话已经结束,被删除了,表明第二报文不能翻译成内部网络可以识别的网络地址和端口,可以将第二报文丢弃。
作为一种可选的实施方式,所述判断模块201,还用于所述确定模块202确定管理所述第一报文的第二网关节点之后,判断所述第二网关节点的超时心跳的次数是否大于预设次数阈值;
所述确定模块202,还用于若所述第二网关节点的超时心跳的次数大于预设次数阈值,确定所述第二网关节点出现故障。
其中,心跳可以指主服务器与各设备之间通过周期性发送信息,判断设备的健康状况,判断对方是否“存活”的行为。如果在指定的时间内仍没有收到设备的心跳信息,就可以怀疑此设备发生故障。
本申请实施例中,可以预先设置一个判定设备故障的超时心跳的次数,比如3次,如果在指定时间内没有收到第二网关节点的心跳信息(超时心跳)的次数超过3次,则可以认为第二网关节点出现了故障,如果在指定时间没有收到第二网关节点的心跳信息的次数不超过3次,则可以认为第二网关节点处于正常运行的状态。
作为一种可选的实施方式,所述确定模块202,还用于确定所述剩余网关节点的交集会话,其中,所述交集会话为每个所述剩余网关节点所共同存储的会话;
所述基于多个网络的通信装置还可以包括:
删除模块,用于从每个所述剩余网关节点存储的会话中,删除所述交集会话之外的其他会话;
所述确定模块202,还用于根据所述交集会话存储的网络地址以及所述剩余网关节点的网络地址资源,重新确定管理每个所述交集会话的网关节点。
在该可选的实施方式中,因为在确定第二网关节点出现故障后,为了保证网络间的通信连接可以正常通信,需要剩余网关节点同步会话,每个节点网关可以广播自己的会话的ID(唯一身份标识),进而确定剩余网关节点的交集会话,删除交集会话之外的其他会话,从而保证所有网关节点的会话都相同。因为会话关联的特定网络地址资源只在一个固定的网关节点上分配和释放,所有会话的创建和删除在同一个网关节点上。需要将所有的网络地址资源重新分配至剩余网关节点,使得剩余网关节点可以管理原本由第二网关节点管理的会话。因此还需要重新确定管理每个交集会话的网关节点。
可选的,当会话定时器超时时,可以向管理该会话的网关节点发送会话删除请求,若管理该会话的网关节点接收到两个或两个以上的会话删除请求,则可以将该会话删除。
作为一种可选的实施方式,所述基于多个网络的通信装置还可以包括:
第二同步模块,用于当第六网关节点上线时,将所有正常运行的网关节点中除了所述第六网关节点之外的网关节点存储的会话同步至所述第六网关节点;
所述判断模块201,还用于判断所述第六网关节点存储的会话的数量是否大于预设数量阈值;
所述分配模块203,还用于若所述第六网关节点存储的会话的数量大于预设数量阈值,将所有网络地址资源重新分配至所述第六网关节点以及所述所有正常运行的网关节点。
其中,所述预设数量阈值可以为所有正常运行的网关节点中除了第六网关节点之外的任意一个网关节点存储的会话的数量的90%。
在该可选的实施方式中,当第六网关节点上线时,可以将所有正常运行的网关节点中除了第六网关节点之外的网关节点存储的会话同步至第六网关节点,使得进入第六网关节点的报文可以被正常发送至外部网络或内部网络,若第六网关节点存储的会话的数量大于预设数量阈值时,可以将所有网络地址资源重新分配至第六网关节点以及所有运行正常的网关节点。因为总的网络地址资源是有限,每个网关节点都要拥有一部分网络地址资源,所以有新的网关节点上线,需要重新分配网络地址资源。
在图2所描述的基于多个网络的通信装置中,当第一网关节点接收到由内部网络发往外部网络的访问请求时,因为来自内部网络的访问请求携带的报文使用的互联网协议地址属于非法地址,不能访问外部网络,需要根据会话存储的信息,将报文的非法地址映射为合法地址,才可以访问外部网络,所以需要判断第一网关节点是否存储有与报文 匹配的会话,若第一网关节点不存储有与报文匹配的会话,可能与该报文匹配的会话还没同步到第一网关节点或还没被创建,则需要将报文发送给管理该报文的第二网关节点,因为第二网关节点可以使用自身的网络地址资源来创建与该报文匹配的会话,若检测到第二网关节点发生故障了,可以重新分配网络地址资源,使得其他网关节点可以创建原本由第二网关节点创建的会话,然后,可以重新确定管理该报文的第三网关节点,并将该报文发送至第三网关节点,若第三网关节点存储有与该报文匹配的会话,则可以根据会话存储的相关信息,将该报文发送至外部网络,确保内部网络可以正常访问外部网络,提高了网络服务质量。
如图3所示,图3是本申请实现基于多个网络的通信方法的较佳实施例的电子设备的结构示意图。所述电子设备3包括存储器31、至少一个处理器32、存储在所述存储器31中并可在所述至少一个处理器32上运行的计算机可读指令33及至少一条通讯总线34。即电子设备3包括处理器32和存储器31,处理器32用于执行存储器31中存储的计算机可读指令以实现上述实施例中基于多个网络的通信方法的各个步骤。
本领域技术人员可以理解,图3所示的示意图仅仅是所述电子设备3的示例,并不构成对所述电子设备3的限定,可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件,例如所述电子设备3还可以包括输入输出设备、网络接入设备等。
所述至少一个处理器32可以是中央处理单元(Central Processing Unit,CPU),还可以是其他通用处理器、数字信号处理器(Digital Signal Processor,DSP)、专用集成电路(Application Specific Integrated Circuit,ASIC)、现场可编程门阵列(Field-Programmable Gate Array,FPGA)或者其他可编程逻辑器件、晶体管逻辑器件、分立硬件组件等。该处理器32可以是微处理器或者该处理器32也可以是任何常规的处理器等,所述处理器32是所述电子设备3的控制中心,利用各种接口和线路连接整个电子设备3的各个部分。
所述存储器31可用于存储所述计算机可读指令33和/或模块/单元,所述处理器32通过运行或执行存储在所述存储器31内的计算机可读指令33和/或模块/单元,以及调用存储在存储器31内的数据,实现所述电子设备3的各种功能。所述存储器31可主要包括存储程序区和存储数据区,其中,存储程序区可存储操作系统、至少一个功能所需的应用程序(比如声音播放功能、图像播放功能等)等;存储数据区可存储根据电子设备3的使用所创建的数据(比如音频数据等)等。此外,存储器31可以包括非易失性存储器,例如硬盘、内存、插接式硬盘,智能存储卡(Smart Media Card,SMC),安全数字(Secure Digital,SD)卡,闪存卡(Flash Card)、至少一个磁盘存储器件、闪存器件等。
结合图1,所述电子设备3中的所述存储器31存储多个指令以实现一种基于多个网络的通信方法,所述处理器32可执行所述多个指令从而实现:
当第一网关节点接收到由内部网络发往外部网络的第一访问请求时,判断所述第一网关节点是否存储有与所述第一访问请求携带的第一报文匹配的第一会话;
若所述第一网关节点未存储有与所述第一访问请求携带的第一报文匹配的第一会话,通过哈希算法,根据所述第一报文的目的地址以及所述第一报文的目的端口,确定管理所述第一报文的第二网关节点;
当检测到所述第二网关节点出现故障时,将所有网络地址资源重新分配至所有网关节点中除了所述第二网关节点外的剩余网关节点;
根据所述剩余网关节点的网络地址资源以及所述第一报文的目的地址以及所述第一报文的目的端口,重新确定管理所述第一报文的第三网关节点;
根据所述第三网关节点存储的多个会话,将所述第一报文发送至所述外部网络。
具体地,所述处理器32对上述指令的具体实现方法可参考图1对应实施例中相关步 骤的描述,在此不赘述。
在图3所描述的电子设备3中,当第一网关节点接收到由内部网络发往外部网络的访问请求时,因为来自内部网络的访问请求携带的报文使用的互联网协议地址属于非法地址,不能访问外部网络,需要根据会话存储的信息,将报文的非法地址映射为合法地址,才可以访问外部网络,所以需要判断第一网关节点是否存储有与报文匹配的会话,若第一网关节点不存储有与报文匹配的会话,可能与该报文匹配的会话还没同步到第一网关节点或还没被创建,则需要将报文发送给管理该报文的第二网关节点,因为第二网关节点可以使用自身的网络地址资源来创建与该报文匹配的会话,若检测到第二网关节点发生故障了,可以重新分配网络地址资源,使得其他网关节点可以创建原本由第二网关节点创建的会话,然后,可以重新确定管理该报文的第三网关节点,并将该报文发送至第三网关节点,若第三网关节点存储有与该报文匹配的会话,则可以根据会话存储的相关信息,将该报文发送至外部网络,确保内部网络可以正常访问外部网络,提高了网络服务质量。
所述电子设备3集成的模块/单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本申请实现上述实施例方法中的全部或部分流程,也可以通过计算机可读指令来指令相关的硬件来完成,所述的计算机可读指令可存储于一计算机可读存储介质中,该计算机可读指令在被处理器执行时,可实现上述各个方法实施例的步骤。其中,所述计算机可读指令包括计算机可读指令代码,所述计算机可读指令代码可以为源代码形式、对象代码形式、可执行文件或某些中间形式等。所述计算机可读介质可以包括:能够携带所述计算机可读指令代码的任何实体或装置、记录介质、U盘、移动硬盘、磁碟、光盘、计算机存储器、只读存储器(ROM,Read-Only Memory)。
在本申请所提供的几个实施例中,应该理解到,所揭露的系统,装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述模块的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式。
所述作为分离部件说明的模块可以是或者也可以不是物理上分开的,作为模块显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部模块来实现本实施例方案的目的。
另外,在本申请各个实施例中的各功能模块可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用硬件加软件功能模块的形式实现。
在一实施例中,提供一个或多个存储有计算机可读指令的可读存储介质,所述计算机可读存储介质存储有计算机可读指令,所述计算机可读指令被一个或多个处理器执行时,使得所述一个或多个处理器执行时实现上述实施例中基于多个网络的通信方法,为避免重复,这里不再赘述。本实施例中的可读存储介质包括非易失性可读存储介质和易失性可读存储介质。本领域普通技术人员可以理解实现上述实施例方法中的全部或部分流程,是可以通过计算机可读指令来指令相关的硬件来完成,该计算机可读指令可存储于一非易失性可读存储介质也可以存储在易失性可读存储介质中,该计算机可读指令在执行时,可包括如上述各方法的实施例的流程。
对于本领域技术人员而言,显然本申请不限于上述示范性实施例的细节,而且在不背离本申请的精神或基本特征的情况下,能够以其他的具体形式实现本申请。因此,无论从哪一点来看,均应将实施例看作是示范性的,而且是非限制性的,本申请的范围由所附权利要求而不是上述说明限定,因此旨在将落在权利要求的等同要件的含义和范围内的所有变化涵括在本申请内。不应将权利要求中的任何附关联图标记视为限制所涉及的权利要求。此外,显然“包括”一词不排除其他单元或步骤,单数不排除复数。系统 权利要求中陈述的多个单元或装置也可以由一个单元或装置通过软件或者硬件来实现。第二等词语用来表示名称,而并不表示任何特定的顺序。
最后应说明的是,以上实施例仅用以说明本申请的技术方案而非限制,尽管参照较佳实施例对本申请进行了详细说明,本领域的普通技术人员应当理解,可以对本申请的技术方案进行修改或等同替换,而不脱离本申请技术方案的精神和范围。
Claims (20)
- 一种基于多个网络的通信方法,其中,所述方法包括:当第一网关节点接收到由内部网络发往外部网络的第一访问请求时,判断所述第一网关节点是否存储有与所述第一访问请求携带的第一报文匹配的第一会话;若所述第一网关节点未存储有与所述第一访问请求携带的第一报文匹配的第一会话,通过哈希算法,根据所述第一报文的目的地址以及所述第一报文的目的端口,确定管理所述第一报文的第二网关节点;当检测到所述第二网关节点出现故障时,将所有网络地址资源重新分配至所有网关节点中除了所述第二网关节点外的剩余网关节点;根据所述剩余网关节点的网络地址资源以及所述第一报文的目的地址以及所述第一报文的目的端口,重新确定管理所述第一报文的第三网关节点;根据所述第三网关节点存储的多个会话,将所述第一报文发送至所述外部网络。
- 根据权利要求1所述的方法,其中,所述根据所述第三网关节点存储的多个会话,将所述第一报文发送至所述外部网络包括:将所述第一报文发送至所述第三网关节点;判断所述第三网关节点存储的多个会话是否包括所述第一会话;若所述第三网关节点存储的多个会话包括所述第一会话,获取所述第一会话存储的第一网络地址以及第一端口;通过地址资源转换算法,将所述第一报文的源地址映射为所述第一网络地址,以及将所述第一报文的源端口映射为所述第一端口,以使用所述第一网络地址以及所述第一端口,将所述第一报文发送至所述外部网络。
- 根据权利要求2所述的方法,其中,所述方法还包括:若所述第三网关节点存储的多个会话未包括所述第一会话,从所述第三网关节点的可用网络地址资源中选择第二网络地址以及第二端口;通过所述地址资源转换算法,将所述第一报文的源地址映射为所述第二网络地址,以及将所述第一报文的源端口映射为所述第二端口;根据所述第一报文的源地址、所述第一报文的源端口、所述第二网络地址以及所述第二端口,生成与所述第一报文匹配的第二会话;将所述第二会话同步至所有正常运行的网关节点。
- 根据权利要求1所述的方法,其中,所述方法还包括:当第四网关节点接收到由所述外部网络发送至所述内部网络的第二访问请求时,判断所述第四网关节点是否存储有与所述第二访问请求携带的第二报文匹配的第三会话;若所述第四网关节点存储有与所述第二访问请求携带的第二报文匹配的第三会话,将所述第二报文的目的地址映射为所述第三会话存储的第三网络地址,以及将所述第二报文的目的端口映射为所述第三会话存储的第三端口,并根据映射后的所述第二报文的第三网络地址以及所述第二报文的第一端口,将所述第二报文发送至所述内部网络。
- 根据权利要求4所述的方法,其中,所述方法还包括:若所述第四网关节点未存储有与所述第二访问请求携带的第二报文匹配的第三会话,通过哈希算法,根据所述第二报文的源地址以及所述第二报文的源端口,确定管理所述第二报文的第五网关节点;判断所述第五网关节点是否为所述第四网关节点;若所述第五网关节点为所述第四网关节点,将所述第二报文丢弃。
- 根据权利要求1所述的方法,其中,所述确定管理所述第一报文的第二网关节点之后, 所述方法还包括:判断所述第二网关节点的超时心跳的次数是否大于预设次数阈值;若所述第二网关节点的超时心跳的次数大于预设次数阈值,确定所述第二网关节点出现故障。
- 根据权利要求6所述的方法,其中,所述确定所述第二网关节点出现故障之后,所述方法还包括:确定所述剩余网关节点的交集会话,其中,所述交集会话为每个所述剩余网关节点所共同存储的会话;从每个所述剩余网关节点存储的会话中,删除所述交集会话之外的其他会话;根据所述交集会话存储的网络地址以及所述剩余网关节点的网络地址资源,重新确定管理每个所述交集会话的网关节点。
- 一种基于多个网络的通信装置,其中,所述基于多个网络的通信装置包括:判断模块,用于当第一网关节点接收到由内部网络发往外部网络的第一访问请求时,判断所述第一网关节点是否存储有与所述第一访问请求携带的第一报文匹配的第一会话;确定模块,用于若所述第一网关节点未存储有与所述第一访问请求携带的第一报文匹配的第一会话,通过哈希算法,根据所述第一报文的目的地址以及所述第一报文的目的端口,确定管理所述第一报文的第二网关节点;分配模块,用于当检测到所述第二网关节点出现故障时,将所有网络地址资源重新分配至所有网关节点中除了所述第二网关节点外的剩余网关节点;所述确定模块,还用于根据所述剩余网关节点的网络地址资源以及所述第一报文的目的地址以及所述第一报文的目的端口,重新确定管理所述第一报文的第三网关节点;发送模块,用于根据所述第三网关节点存储的多个会话,将所述第一报文发送至所述外部网络。
- 一种电子设备,其中,所述电子设备包括处理器和存储器,所述处理器用于执行存储器中存储的计算机可读指令以实现如下步骤:当第一网关节点接收到由内部网络发往外部网络的第一访问请求时,判断所述第一网关节点是否存储有与所述第一访问请求携带的第一报文匹配的第一会话;若所述第一网关节点未存储有与所述第一访问请求携带的第一报文匹配的第一会话,通过哈希算法,根据所述第一报文的目的地址以及所述第一报文的目的端口,确定管理所述第一报文的第二网关节点;当检测到所述第二网关节点出现故障时,将所有网络地址资源重新分配至所有网关节点中除了所述第二网关节点外的剩余网关节点;根据所述剩余网关节点的网络地址资源以及所述第一报文的目的地址以及所述第一报文的目的端口,重新确定管理所述第一报文的第三网关节点;根据所述第三网关节点存储的多个会话,将所述第一报文发送至所述外部网络。
- 根据权利要求9所述的电子设备,其中,所述根据所述第三网关节点存储的多个会话,将所述第一报文发送至所述外部网络包括:将所述第一报文发送至所述第三网关节点;判断所述第三网关节点存储的多个会话是否包括所述第一会话;若所述第三网关节点存储的多个会话包括所述第一会话,获取所述第一会话存储的第一网络地址以及第一端口;通过地址资源转换算法,将所述第一报文的源地址映射为所述第一网络地址,以及将所述第一报文的源端口映射为所述第一端口,以使用所述第一网络地址以及所述第一端口,将所述第一报文发送至所述外部网络。
- 根据权利要求10所述的电子设备,其中,所述处理器还用于执行存储器中存储的计 算机可读指令以实现如下步骤:若所述第三网关节点存储的多个会话未包括所述第一会话,从所述第三网关节点的可用网络地址资源中选择第二网络地址以及第二端口;通过所述地址资源转换算法,将所述第一报文的源地址映射为所述第二网络地址,以及将所述第一报文的源端口映射为所述第二端口;根据所述第一报文的源地址、所述第一报文的源端口、所述第二网络地址以及所述第二端口,生成与所述第一报文匹配的第二会话;将所述第二会话同步至所有正常运行的网关节点。
- 根据权利要求9所述的电子设备,其中,所述处理器还用于执行存储器中存储的计算机可读指令以实现如下步骤:当第四网关节点接收到由所述外部网络发送至所述内部网络的第二访问请求时,判断所述第四网关节点是否存储有与所述第二访问请求携带的第二报文匹配的第三会话;若所述第四网关节点存储有与所述第二访问请求携带的第二报文匹配的第三会话,将所述第二报文的目的地址映射为所述第三会话存储的第三网络地址,以及将所述第二报文的目的端口映射为所述第三会话存储的第三端口,并根据映射后的所述第二报文的第三网络地址以及所述第二报文的第一端口,将所述第二报文发送至所述内部网络。
- 根据权利要求12所述的电子设备,其中,所述处理器还用于执行存储器中存储的计算机可读指令以实现如下步骤:若所述第四网关节点未存储有与所述第二访问请求携带的第二报文匹配的第三会话,通过哈希算法,根据所述第二报文的源地址以及所述第二报文的源端口,确定管理所述第二报文的第五网关节点;判断所述第五网关节点是否为所述第四网关节点;若所述第五网关节点为所述第四网关节点,将所述第二报文丢弃。
- 根据权利要求9所述的电子设备,其中,所述确定管理所述第一报文的第二网关节点之后,所述电子设备还包括:判断所述第二网关节点的超时心跳的次数是否大于预设次数阈值;若所述第二网关节点的超时心跳的次数大于预设次数阈值,确定所述第二网关节点出现故障。
- 一个或多个存储有计算机可读指令的可读存储介质,所述计算机可读存储介质存储有计算机可读指令,其中,所述计算机可读指令被一个或多个处理器执行时,使得所述一个或多个处理器执行如下步骤:当第一网关节点接收到由内部网络发往外部网络的第一访问请求时,判断所述第一网关节点是否存储有与所述第一访问请求携带的第一报文匹配的第一会话;若所述第一网关节点未存储有与所述第一访问请求携带的第一报文匹配的第一会话,通过哈希算法,根据所述第一报文的目的地址以及所述第一报文的目的端口,确定管理所述第一报文的第二网关节点;当检测到所述第二网关节点出现故障时,将所有网络地址资源重新分配至所有网关节点中除了所述第二网关节点外的剩余网关节点;根据所述剩余网关节点的网络地址资源以及所述第一报文的目的地址以及所述第一报文的目的端口,重新确定管理所述第一报文的第三网关节点;根据所述第三网关节点存储的多个会话,将所述第一报文发送至所述外部网络。
- 根据权利要求15所述的可读存储介质,其中,所述根据所述第三网关节点存储的多个会话,将所述第一报文发送至所述外部网络包括:将所述第一报文发送至所述第三网关节点;判断所述第三网关节点存储的多个会话是否包括所述第一会话;若所述第三网关节点存储的多个会话包括所述第一会话,获取所述第一会话存储的第一网络地址以及第一端口;通过地址资源转换算法,将所述第一报文的源地址映射为所述第一网络地址,以及将所述第一报文的源端口映射为所述第一端口,以使用所述第一网络地址以及所述第一端口,将所述第一报文发送至所述外部网络。
- 根据权利要求16所述的可读存储介质,其中,所述计算机可读指令被一个或多个处理器执行时,使得所述一个或多个处理器还执行如下步骤:若所述第三网关节点存储的多个会话未包括所述第一会话,从所述第三网关节点的可用网络地址资源中选择第二网络地址以及第二端口;通过所述地址资源转换算法,将所述第一报文的源地址映射为所述第二网络地址,以及将所述第一报文的源端口映射为所述第二端口;根据所述第一报文的源地址、所述第一报文的源端口、所述第二网络地址以及所述第二端口,生成与所述第一报文匹配的第二会话;将所述第二会话同步至所有正常运行的网关节点。
- 根据权利要求15所述的可读存储介质,其中,所述计算机可读指令被一个或多个处理器执行时,使得所述一个或多个处理器还执行如下步骤:当第四网关节点接收到由所述外部网络发送至所述内部网络的第二访问请求时,判断所述第四网关节点是否存储有与所述第二访问请求携带的第二报文匹配的第三会话;若所述第四网关节点存储有与所述第二访问请求携带的第二报文匹配的第三会话,将所述第二报文的目的地址映射为所述第三会话存储的第三网络地址,以及将所述第二报文的目的端口映射为所述第三会话存储的第三端口,并根据映射后的所述第二报文的第三网络地址以及所述第二报文的第一端口,将所述第二报文发送至所述内部网络。
- 根据权利要求18所述的可读存储介质,其中,所述计算机可读指令被一个或多个处理器执行时,使得所述一个或多个处理器还执行如下步骤:若所述第四网关节点未存储有与所述第二访问请求携带的第二报文匹配的第三会话,通过哈希算法,根据所述第二报文的源地址以及所述第二报文的源端口,确定管理所述第二报文的第五网关节点;判断所述第五网关节点是否为所述第四网关节点;若所述第五网关节点为所述第四网关节点,将所述第二报文丢弃。
- 根据权利要求15所述的可读存储介质,其中,所述确定管理所述第一报文的第二网关节点之后,所述计算机可读指令被一个或多个处理器执行时,使得所述一个或多个处理器还执行如下步骤:判断所述第二网关节点的超时心跳的次数是否大于预设次数阈值;若所述第二网关节点的超时心跳的次数大于预设次数阈值,确定所述第二网关节点出现故障。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202010193483.7 | 2020-03-18 | ||
| CN202010193483.7A CN111585887B (zh) | 2020-03-18 | 2020-03-18 | 基于多个网络的通信方法、装置、电子设备及存储介质 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2021184551A1 true WO2021184551A1 (zh) | 2021-09-23 |
Family
ID=72111478
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2020/093312 Ceased WO2021184551A1 (zh) | 2020-03-18 | 2020-05-29 | 基于多个网络的通信方法、装置、电子设备及存储介质 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN111585887B (zh) |
| WO (1) | WO2021184551A1 (zh) |
Cited By (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN114785737A (zh) * | 2022-04-11 | 2022-07-22 | 阿里巴巴(中国)有限公司 | 报文处理方法、网关设备、服务器及存储介质 |
| CN115037602A (zh) * | 2022-04-12 | 2022-09-09 | 新华三技术有限公司 | 一种故障处理方法及装置 |
| CN115633044A (zh) * | 2022-07-20 | 2023-01-20 | 广州汽车集团股份有限公司 | 报文的处理方法、装置、电子设备及存储介质 |
| CN115834528A (zh) * | 2022-11-23 | 2023-03-21 | 东软集团股份有限公司 | 数据转发方法、装置、电子设备和存储介质 |
| CN116032880A (zh) * | 2022-12-19 | 2023-04-28 | 北京百度网讯科技有限公司 | 一种会话同步的系统、方法、电子设备及存储介质 |
| CN117675753A (zh) * | 2023-11-24 | 2024-03-08 | 新华三技术有限公司 | 一种控制会话的处理方法和路由设备 |
| CN117914649A (zh) * | 2023-12-22 | 2024-04-19 | 曙光云计算集团股份有限公司 | 网络通信系统、方法及装置 |
Families Citing this family (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN112822262B (zh) * | 2021-01-04 | 2022-11-22 | 北京知道创宇信息技术股份有限公司 | 报文处理方法和装置、报文处理设备及存储介质 |
| CN113225389A (zh) * | 2021-04-26 | 2021-08-06 | 上海仪电(集团)有限公司中央研究院 | 一种基于fpga的反向网络代理服务器的方法及装置 |
| CN114143251B (zh) * | 2021-12-08 | 2023-10-13 | 北京天融信网络安全技术有限公司 | 智能选路方法、装置、电子设备及计算机可读存储介质 |
| CN115086274B (zh) * | 2022-06-10 | 2023-12-22 | 北京启明星辰信息安全技术有限公司 | 一种网络流量分配方法、装置、设备和存储介质 |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101383778A (zh) * | 2008-10-27 | 2009-03-11 | 杭州华三通信技术有限公司 | 基于网络双出口的报文传输方法和出口路由器 |
| CN101702657A (zh) * | 2009-12-04 | 2010-05-05 | 杭州华三通信技术有限公司 | 一种nat业务的热备份方法和设备 |
| US20150304427A1 (en) * | 2014-04-22 | 2015-10-22 | Alcatel-Lucent Canada, Inc. | Efficient internet protocol security and network address translation |
Family Cites Families (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2007181079A (ja) * | 2005-12-28 | 2007-07-12 | Mitsubishi Electric Corp | 通信経路制御システム |
| CN101043447B (zh) * | 2007-04-23 | 2010-05-26 | 重庆大学 | 基于ddns和nat的服务器内外网动态映射方法 |
| WO2013161172A1 (ja) * | 2012-04-27 | 2013-10-31 | 日本電気株式会社 | 通信システム及び経路制御方法 |
| CN103888277B (zh) * | 2012-12-19 | 2018-09-04 | 中国移动通信集团公司 | 一种网关容灾备份方法、装置和系统 |
| CN104426699B (zh) * | 2013-08-30 | 2017-11-28 | 华为技术有限公司 | 通信方法、服务器及通信系统 |
| US20150244630A1 (en) * | 2014-02-23 | 2015-08-27 | Telefonaktiebolaget L M Ericsson (Publ) | IPoE DUAL-STACK SUBSCRIBER FOR ROUTED RESIDENTIAL GATEWAY CONFIGURATION |
| CN106789141B (zh) * | 2015-11-24 | 2020-12-11 | 阿里巴巴集团控股有限公司 | 一种网关设备故障处理方法及装置 |
| CN110166432B (zh) * | 2019-04-17 | 2023-10-17 | 平安科技(深圳)有限公司 | 对内网目标服务的访问方法、提供内网目标服务的方法 |
-
2020
- 2020-03-18 CN CN202010193483.7A patent/CN111585887B/zh active Active
- 2020-05-29 WO PCT/CN2020/093312 patent/WO2021184551A1/zh not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101383778A (zh) * | 2008-10-27 | 2009-03-11 | 杭州华三通信技术有限公司 | 基于网络双出口的报文传输方法和出口路由器 |
| CN101702657A (zh) * | 2009-12-04 | 2010-05-05 | 杭州华三通信技术有限公司 | 一种nat业务的热备份方法和设备 |
| US20150304427A1 (en) * | 2014-04-22 | 2015-10-22 | Alcatel-Lucent Canada, Inc. | Efficient internet protocol security and network address translation |
Cited By (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN114785737A (zh) * | 2022-04-11 | 2022-07-22 | 阿里巴巴(中国)有限公司 | 报文处理方法、网关设备、服务器及存储介质 |
| CN115037602A (zh) * | 2022-04-12 | 2022-09-09 | 新华三技术有限公司 | 一种故障处理方法及装置 |
| CN115633044A (zh) * | 2022-07-20 | 2023-01-20 | 广州汽车集团股份有限公司 | 报文的处理方法、装置、电子设备及存储介质 |
| CN115633044B (zh) * | 2022-07-20 | 2024-01-19 | 广州汽车集团股份有限公司 | 报文的处理方法、装置、电子设备及存储介质 |
| CN115834528A (zh) * | 2022-11-23 | 2023-03-21 | 东软集团股份有限公司 | 数据转发方法、装置、电子设备和存储介质 |
| CN116032880A (zh) * | 2022-12-19 | 2023-04-28 | 北京百度网讯科技有限公司 | 一种会话同步的系统、方法、电子设备及存储介质 |
| CN117675753A (zh) * | 2023-11-24 | 2024-03-08 | 新华三技术有限公司 | 一种控制会话的处理方法和路由设备 |
| CN117914649A (zh) * | 2023-12-22 | 2024-04-19 | 曙光云计算集团股份有限公司 | 网络通信系统、方法及装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN111585887A (zh) | 2020-08-25 |
| CN111585887B (zh) | 2022-07-15 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2021184551A1 (zh) | 基于多个网络的通信方法、装置、电子设备及存储介质 | |
| CN109688235B (zh) | 虚拟网络业务处理方法、装置和系统,控制器,存储介质 | |
| US10764111B2 (en) | Preventing concurrent distribution of network data to a hardware switch by multiple controllers | |
| US9722950B2 (en) | Processing resource access request in network | |
| CN110290174A (zh) | 一种主主集群的控制方法以及控制节点 | |
| CN109981493B (zh) | 一种用于配置虚拟机网络的方法和装置 | |
| WO2014190791A1 (zh) | 一种网关设备身份设置的方法及管理网关设备 | |
| US10742559B2 (en) | Eliminating data traffic redirection in scalable clusters | |
| CN114095430B (zh) | 一种访问报文的处理方法、系统及工作节点 | |
| CN110881007A (zh) | 一种容器集群网络接入的方法和装置 | |
| WO2022111313A1 (zh) | 一种请求处理方法及微服务系统 | |
| CN114745413B (zh) | 服务端的访问控制方法、装置、计算机设备及存储介质 | |
| WO2020253631A1 (zh) | Ip地址的配置方法、设备及系统 | |
| CN115941493B (zh) | 基于组播的云场景nat网关集群的多活分配方法及装置 | |
| CN110633046A (zh) | 一种分布式系统的存储方法、装置、存储设备及存储介质 | |
| EP4191907A1 (en) | Vnf instantiation method and apparatus | |
| CN110636149B (zh) | 远程访问方法、装置、路由器及存储介质 | |
| WO2024207752A1 (zh) | 一种负载均衡方法、装置、设备及非易失性可读存储介质 | |
| WO2024078427A1 (zh) | 一种无服务器函数配置系统、方法及装置 | |
| CN114301872B (zh) | 基于域名的访问方法及装置、电子设备、存储介质 | |
| CN114553771B (zh) | 用于虚拟路由器加载的方法及相关设备 | |
| CN108390784B (zh) | 一种资源回收的方法及装置 | |
| CN114244768A (zh) | 二层未知组播的转发方法、装置、设备及存储介质 | |
| CN119201416A (zh) | 多作业分布式训练系统及方法 | |
| JP6909218B2 (ja) | ラック内のノードのための分散型オペレーティング・システム機能 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 20925847 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS (EPO FORM 1205A DATED 17.01.2023) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 20925847 Country of ref document: EP Kind code of ref document: A1 |