The embodiment of the invention discloses a cloud protection method and device based on a tunnel mode. The method comprises the steps of analyzing a first access request sent by a
client, thereby acquiring a first
source address and a first destination address; modifying the
source address of the first access request into an
IP address of a cloud protection node and modifying the destination address of the first access request to the
IP address of a tunnel
receiver, thereby acquiring a second access request; adding an expansion field to the second access request and adding the first
source address and the first destination address to the expansion field, thereby acquiring a third access request; and sending the third access request to the tunnel
receiver, thereby enabling the tunnel receives to forward the third access request to a true
server. The expansion field is added to the access request and the first source address and the first destination address, namely the address of the
client and the address of the true
server, are stored to the expansion field, so the true address of the
client can be acquired, an access mode is simple, the configuration of a great deal of port mapping is avoided, and the operation and maintenance cost is greatly reduced.