Traffic forwarding method

By adding device identification information to forward traffic, the problem that forward and reverse traffic cannot access the same network devices during cloud migration is solved, and network device consistency and traffic forwarding stability in multi-availability zone scenarios are achieved.

CN115174674BActive Publication Date: 2025-06-06ALIBABA CLOUD COMPUTING CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210784907.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-29
Publication Date
2025-06-06
Estimated Expiration
2042-06-29

AI Technical Summary

Technical Problem

During cloud migration, forward and reverse traffic cannot guarantee access to the same network device, resulting in the user's cloud access process being blocked. Especially in the multi-availability zone or Availability Zone change scenarios, the consistency of network devices is difficult to guarantee.

Method used

By adding device identification information to the forward traffic, the routing access point of the intermediate network can forward it to the network device corresponding to the forward traffic for processing based on the device identification information carried by the reverse traffic, thereby ensuring the consistency of the network devices accessed by the forward and reverse traffic.

Benefits of technology

The consistency of network devices accessed by forward and reverse traffic in multi-availability zone scenarios is achieved, and the problem of inconsistent traffic forwarding caused by Availability Zone changes is avoided.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115174674B_ABST
    Figure CN115174674B_ABST
Patent Text Reader

Abstract

The present specification provides a method for forwarding traffic, the method comprising: receiving forward traffic from a source device in a source network, the forward traffic being sent to a destination device in a destination network; distributing the forward traffic to a destination network device in the intermediate network for processing; sending processed forward traffic carrying device identification information of the destination network device to the destination device, so that the destination device returns reverse traffic to the source device carrying the device identification information of the target network device, the device identification information being used to indicate a virtual switch corresponding to a routing access point in the intermediate network that receives the reverse traffic: forwarding the reverse traffic to the destination network device for processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data transmission, and in particular to a method for forwarding traffic. Background Art

[0002] With the development of cloud technology, more and more users are migrating local network functions to the cloud, including the third-party network devices deployed by users in the cloud. However, during the migration process, the forward and reverse traffic often cannot access the same network device, which hinders the user's cloud migration process.

[0003] In related technologies, technologies such as Gateway Load Balancer (GWLB) are usually used to ensure that forward and reverse traffic passing through the same availability zone access the same network device. However, it is impossible to ensure the consistency of network devices accessed by forward and reverse traffic in multiple availability zones or availability zone change scenarios, thereby limiting users' usage scenarios of complex network devices. Summary of the invention

[0004] In view of this, this specification provides a traffic forwarding method to solve the deficiencies in the related art.

[0005] Specifically, this specification is implemented through the following technical solutions:

[0006] According to a first aspect of an embodiment of the present specification, a traffic forwarding method is provided, which is applied to a virtual switch corresponding to any routing access point in an intermediate network, wherein the intermediate network is deployed in multiple availability zones, and the intermediate network is provided with at least two network devices in different availability zones and a routing access point in the same availability zone as the at least two network devices, the method comprising:

[0007] Receiving forward traffic from a source device in a source network, wherein a sending destination of the forward traffic is a destination device in a destination network;

[0008] Distributing the forward traffic to a target network device in the intermediate network for processing;

[0009] Send processed forward traffic carrying device identification information of the target network device to the destination device, so that the reverse traffic returned by the destination device to the source device carries the device identification information of the target network device, and the device identification information is used to indicate the virtual switch corresponding to the routing access point in the intermediate network that receives the reverse traffic: forward the reverse traffic to the target network device for processing.

[0010] According to a second aspect of an embodiment of this specification, a traffic forwarding method is provided, which is applied to a virtual switch corresponding to a destination device in a destination network, and the method includes:

[0011] Receive processed forward traffic forwarded by an intermediate network, the processed forward traffic carrying device identification information of a target network device, the device identification information being used to indicate that: after receiving the forward traffic sent by the source device, a virtual switch corresponding to any routing access point in the intermediate network distributes the forward traffic to the target network device in the intermediate network for processing; wherein the intermediate network is deployed in multiple availability zones, and the intermediate network is provided with at least two network devices in different availability zones and a routing access point in the same availability zone as the at least two network devices;

[0012] Storing device identification information of the target network device;

[0013] In the case where the destination device needs to return reverse traffic to the source device, the stored device identification information is added to the reverse traffic and then sent out to instruct the virtual switch corresponding to the routing access point in the intermediate network that receives the reverse traffic to forward the reverse traffic to the target network device for processing.

[0014] According to a third aspect of the embodiments of this specification, a computer-readable storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the steps of the method described in the first aspect are implemented.

[0015] According to a fourth aspect of the embodiments of this specification, an electronic device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps of the method described in the first aspect are implemented.

[0016] In the technical solution provided in this specification, by means of adding device identification information to the forward traffic, the routing access point of the intermediate network can forward the reverse traffic to the network device corresponding to the forward traffic for processing according to the device identification information carried by the reverse traffic, thereby ensuring the consistency of the network devices accessed by the forward and reverse traffic while avoiding the impact caused by multiple availability zones.

[0017] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present specification. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the embodiments of this specification or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification, and for ordinary technicians in this field, other drawings can also be obtained based on these drawings.

[0019] Figure 1 is a schematic diagram of the architecture of a traffic forwarding system shown in an exemplary embodiment of this specification;

[0020] Figure 2 It is a flow chart of a method for forwarding traffic shown in an exemplary embodiment of this specification;

[0021] Figure 3 It is a flowchart of another traffic forwarding method shown in an exemplary embodiment of this specification;

[0022] Figure 4a It is a flowchart of a forwarding method of forward traffic shown in an exemplary embodiment of this specification;

[0023] Figure 4b It is a flowchart of a method for forwarding reverse traffic shown in an exemplary embodiment of this specification;

[0024] Figure 5a It is a flowchart of another forwarding method of forward traffic shown in an exemplary embodiment of this specification;

[0025] Figure 5b It is a flowchart of another method for forwarding reverse traffic shown in an exemplary embodiment of this specification;

[0026] Figure 6 is a schematic structural diagram of an electronic device shown in an exemplary embodiment of this specification;

[0027] Figure 7 It is a structural schematic diagram of a traffic forwarding device shown in an exemplary embodiment of this specification;

[0028] Figure 8 It is a structural diagram of another traffic forwarding device shown in an exemplary embodiment of this specification. DETAILED DESCRIPTION

[0029] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementations described in the following exemplary embodiments do not represent all implementations consistent with this specification. Instead, they are merely examples of devices and methods consistent with some aspects of this specification as detailed in the appended claims.

[0030] The terms used in this specification are for the purpose of describing specific embodiments only and are not intended to limit this specification. The singular forms "a", "the" and "the" used in this specification and the appended claims are also intended to include plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more associated listed items.

[0031] It should be understood that although the terms first, second, third, etc. may be used in this specification to describe various information, this information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of this specification, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".

[0032] Figure 1 FIG. 1 is a schematic diagram of the architecture of a traffic forwarding system shown in an exemplary embodiment of this specification. Figure 1 As shown, it may include a source device 11 , a destination device 12 , and a network device group 13 .

[0033] The source device 11 and the destination device 12 refer to electronic devices that support the function of sending and receiving network traffic, and the two are connected to the source network and the destination network respectively, wherein the source network and the destination network are independent of each other, and the traffic between the two needs to be processed by the same network device in the network device group 13 of the intermediate network. During the operation of the system, when the source device 11 initiates forward traffic to the destination device 12, the forward traffic is processed by any network device of the intermediate network and then sent to the destination device 12 of the destination network. When the destination device 12 subsequently needs to return reverse traffic to the source device 11, the reverse traffic is processed again by the above-mentioned network device of the intermediate network (i.e., the network device through which the above-mentioned forward traffic flows) and then sent to the source device 11 of the destination network. Among them, users can use electronic devices such as the following types as source devices 11 and destination devices 12: cloud servers based on virtualization technology, bare metal servers, mobile phones, tablet devices, laptops, PDAs (Personal Digital Assistants), wearable devices (such as smart glasses, smart watches, etc.), among which the above-mentioned cloud servers and bare metal servers based on virtualization technology can be deployed in a data center, and one or more embodiments of this specification are not limited to this.

[0034] The network device group 13 includes one or more network devices, and the network devices are electronic devices that provide network functions in the middle of the network link. Among them, the one or more network devices are configured the same and are respectively set in different availability zones of the intermediate network. Among them, the network devices include but are not limited to: firewalls, traffic analysis components, and load balancing components. The source network, destination network, and intermediate network can be built by a physical server of an independent host, or a virtual server hosted by a host cluster, and this specification does not limit this.

[0035] It should be noted that "source" and "destination" are a set of relative concepts and are not used to specifically refer to specific electronic devices. For example, when describing from the perspective of device 11, the device 11 can be regarded as the source device and the device 12 can be regarded as the destination terminal, and when describing from the perspective of device 12, the device 12 can be regarded as the source device and the device 11 can be regarded as the destination device. Figure 1 The description is taken from the perspective of device 11 as an example, so the description is made using the above-mentioned source device 11 and destination device 12.

[0036] Similarly, "forward" and "reverse" are also a set of relative concepts. The relationship between forward traffic and reverse traffic can be a request and response relationship, or they may not have a necessary functional relationship. For example, forward traffic can be a response to the previous reverse traffic, and reverse traffic can be a new round of requests. "Forward" and "reverse" in this specification are only used to characterize the time sequence of traffic sending. When device 11 first sends traffic to device 12, the traffic is forward traffic, and the traffic that device 12 subsequently returns to device 11 is reverse traffic; when device 12 first sends traffic to device 11, the traffic is forward traffic, and the traffic that device 11 subsequently returns to device 12 is reverse traffic. Figure 1 In the description, the perspective from which device 11 first sends traffic to device 12 is taken as an example, so the description is made in a manner in which device 11 sends forward traffic to device 12, and device 12 sends reverse traffic to device 11.

[0037] The traffic forwarding method in this specification can be applied to a virtual switch corresponding to any routing access point in an intermediate network. The intermediate network is deployed in multiple availability zones, and the intermediate network is provided with at least two network devices located in different availability zones and a routing access point located in the same availability zone as the at least two network devices.

[0038] The above-mentioned routing access points serve as virtual interfaces for each available zone in the intermediate network. Each routing access point corresponds to a virtual switch. The virtual switch of the above-mentioned routing access point can be used to receive traffic from the corresponding available zone, forward the traffic to the network device of the corresponding available zone, and then send the returned traffic after being processed by the network device to other networks. The corresponding relationship between the above-mentioned virtual switch and the above-mentioned routing access point can be designed according to actual needs. For example, the routing access point and the virtual switch in the same available zone can have a "one-to-one", "one-to-many", "many-to-one" or "many-to-many" relationship, which is not limited in this specification.

[0039] Figure 2 FIG. 1 is a flow chart of a method for forwarding traffic as shown in an exemplary embodiment of this specification. Figure 2 As shown, the method is applied to a virtual switch corresponding to any routing access point in the intermediate network, the intermediate network is deployed in multiple availability zones, and the intermediate network is provided with at least two network devices in different availability zones and a routing access point in the same availability zone as the at least two network devices. The method may include the following steps:

[0040] S201, receiving forward traffic from a source device in a source network, wherein a destination of the forward traffic is a destination device in a destination network.

[0041] For example, as mentioned above, the source network and the destination network are independent of each other. When the source device in the source network needs to send traffic to the destination device in the destination network, the traffic will be received as forward traffic by the virtual switch corresponding to any routing access point in the intermediate network to facilitate further processing by the following network devices.

[0042] S202: distribute the forward traffic to a target network device in the intermediate network for processing.

[0043] Since the intermediate network is deployed in multiple availability zones, each availability zone can deploy one or more network devices. Therefore, after receiving the above-mentioned forward traffic, the virtual switch corresponding to any of the above-mentioned routing access points can select one of the multiple network devices in the above-mentioned multiple availability zones as the target network device to process the above-mentioned forward traffic.

[0044] The virtual switch corresponding to any of the above-mentioned routing access points can determine the method of selecting the above-mentioned target network device according to the information carried by the above-mentioned forward traffic itself.

[0045] In one embodiment, the forward traffic does not carry device identification information, and the virtual switch corresponding to any of the routing access points can determine the target network device according to the pre-configured traffic distribution strategy, and forward the forward traffic to the target network device for processing. The device identification information can be used as the unique identifier of the network device. At the same time, the pre-configured traffic distribution strategy includes but is not limited to: a preset routing table or a dynamic allocation algorithm.

[0046] Among them, the above-mentioned preset routing table can be set with several groups of correspondences between destination addresses and forwarding addresses, and the above-mentioned forwarding address can correspond to the network address of the network device. When the address information about the above-mentioned destination device in the above-mentioned forward traffic matches the destination address of any corresponding relationship in the preset routing table, the forward traffic can be forwarded to the network device corresponding to the above-mentioned destination address. However, as a kind of static data, the above-mentioned preset routing table needs to be actively modified, increased or decreased by the system administrator according to the changes of the network equipment, resulting in the above-mentioned preset routing table being unable to make timely changes according to actual needs in a complex and changeable network environment (for example, the available zone is expanded and reduced multiple times, resulting in frequent changes in the network location of related network equipment), thereby affecting the efficiency of traffic forwarding.

[0047] The above-mentioned dynamic allocation algorithm can be regarded as a solution to the defects of the above-mentioned preset routing table, that is, the above-mentioned dynamic allocation algorithm can be used to dynamically allocate traffic according to the operating status of the above-mentioned at least two network devices. It can be understood by those skilled in the art that the above-mentioned operating status may involve multiple dimensions such as the current bandwidth, memory, CPU usage, GPU usage, etc. of the network device, and this specification does not limit this. In addition, the traffic allocation method of the above-mentioned dynamic allocation algorithm is related to its management purpose for the network device. For example, when the above-mentioned management purpose is load balancing, the above-mentioned dynamic allocation algorithm can instruct the virtual switch corresponding to any of the above-mentioned routing access points to evenly distribute the above-mentioned forward traffic to each network device; for example, when the above-mentioned management purpose is to reduce the cost of the network device, the above-mentioned dynamic allocation algorithm can instruct the virtual switch corresponding to any of the above-mentioned routing access points to quantitatively allocate the above-mentioned forward traffic to each of the above-mentioned network devices according to the resource utilization of each network device, so as to ensure that the resource utilization of each network device is kept below the preset threshold. In short, for different management purposes of network devices, the specific implementation method of the above-mentioned dynamic allocation algorithm will also be different, and this specification does not limit this.

[0048] In another embodiment, the forward traffic carries the device identification information of the target network device, and the virtual switch corresponding to any of the routing access points can determine the target network device based on the device identification information, and forward the forward traffic to the target network device for processing. When the target network device experiences an abnormality such as downtime, resulting in the target network device being unavailable despite the device identification information of the target network device being included in the forward traffic, the forward traffic can be forwarded to the reallocated target network device for processing. The reallocation process can be performed based on the previous embodiment.

[0049] For example, as mentioned above, the forward traffic and reverse traffic are a set of relative concepts and may not have a necessary functional relationship. Therefore, when the reverse traffic below passes through the virtual switch corresponding to any routing access point in the intermediate network, and contains the device identification information of the target network device, but the target network device is unavailable, the reverse traffic can also be forwarded to the reallocated target network device for processing.

[0050] S203, sending the processed forward traffic carrying the device identification information of the target network device to the destination device, so that the reverse traffic returned by the destination device to the source device carries the device identification information of the target network device, and the device identification information is used to indicate the virtual switch corresponding to the routing access point in the intermediate network that receives the reverse traffic: forwarding the reverse traffic to the target network device for processing.

[0051] After the target network device processes the forward traffic, the device identification information of the target network device can be added to the forward traffic, so that after receiving the forward traffic, the reverse traffic returned by the destination device to the source device also carries the device identification information of the target network device. The device identification information has a similar effect on the reverse traffic as the forward traffic, that is, it is used to forward the reverse traffic to the target network device in the intermediate network.

[0052] The process of adding the above device identification information to the forward traffic can be set in different operation links according to actual needs.

[0053] In one embodiment, the virtual switch corresponding to the target network device can add the device identification information of the target network device to the forward traffic after the processing. In fact, the operation of adding the device identification information can be performed as soon as the device identification information of the target network device is obtained. Therefore, in the case where the virtual switch corresponding to the target network device stores the device identification information in advance, the device identification information can be directly added before the forward traffic processing, and this specification does not limit this.

[0054] In another embodiment, after receiving the processed forward traffic returned by the target network device after being processed by the target network device, the virtual switch corresponding to the routing access point may add the device identification information of the target network device to the processed forward traffic. Similar to the previous embodiment, in the case where the virtual switch corresponding to the routing access point stores the device identification information in advance, the device identification information may be added to the forward traffic before the forward traffic is sent to the virtual switch corresponding to the target network device, and this specification does not limit this.

[0055] The source network and the destination network are similar to the intermediate network and can also be deployed in multiple availability zones. For the source network, the above-mentioned source device and the routing access point in the source network can be deployed in the same availability zone in the source network, or can be deployed in different availability zones in the source network respectively. The routing access point can be used for the above-mentioned source device to realize cross-network interaction. For example, there are two availability zones 1 and 2 in the source network, and a source device and a routing access point are respectively provided. Then, the source device in availability zone 1 can initiate forward traffic to the destination device of the destination network through the routing access point in availability zone 2, or the source device in availability zone 1 can receive reverse traffic returned by the destination device of the destination network through the routing access point in availability zone 2. For the destination network, the above-mentioned destination device and the routing access point in the destination network can be deployed in the same availability zone in the destination network, or can be deployed in different availability zones in the destination network respectively. Among them, the routing access point can be used for the above-mentioned destination device to realize cross-network interaction. For example, there are two availability zones 1 and 2 in the destination network, and a destination device and a routing access point are respectively provided. Then, the destination device in availability zone 1 can receive the forward traffic returned by the destination device of the destination network through the routing access point of availability zone 2, or the destination device in availability zone 1 can send reverse traffic to the destination device of the destination network through the routing access point of availability zone 2.

[0056] The above-mentioned device identification information can be an identifier used to characterize the uniqueness of the network device, such as Elastic Network Interface (ENI) address information, so that the virtual switch corresponding to the routing access point that receives forward traffic and / or reverse traffic in the intermediate network forwards the above-mentioned forward traffic and / or reverse traffic to a unique network device.

[0057] According to the encapsulation format of the forward traffic and / or the reverse traffic for the device identification information, different adding operations may be performed on the elastic network card ENI address information.

[0058] In one embodiment, the forward traffic and / or reverse traffic may be encapsulated in a virtual extended local area network (VXLAN), and the device identification information may be stored in the inner source MAC address field of the message corresponding to the forward traffic and / or reverse traffic.

[0059] In another embodiment, the forward traffic and / or the reverse traffic may be encapsulated in the network virtualization protocol GENEVE, and the device identification information may be stored in the option field of the message corresponding to the forward traffic and / or the reverse traffic.

[0060] Those skilled in the art will appreciate that this description does not limit the specific encapsulation format used for the forward traffic and / or reverse traffic. This description only requires that the device identification information can be reasonably added to the forward traffic and / or reverse traffic according to the traffic format.

[0061] Figure 3 FIG. 1 is a flow chart of another method for forwarding traffic according to an exemplary embodiment of this specification. Figure 3 As shown, the method is applied to a virtual switch corresponding to a destination device in a destination network, and may include the following steps:

[0062] S301, receiving processed forward traffic forwarded by an intermediate network, wherein the processed forward traffic carries device identification information of a target network device, and the device identification information is used to indicate that after receiving the forward traffic sent by the source device, a virtual switch corresponding to any routing access point in the intermediate network distributes the forward traffic to the target network device in the intermediate network for processing; wherein the intermediate network is deployed in multiple availability zones, and the intermediate network is provided with at least two network devices in different availability zones and a routing access point in the same availability zone as the at least two network devices.

[0063] After the target network device of the intermediate network has processed the above-mentioned forward traffic, the virtual switch corresponding to the destination device in the destination network can receive the above-mentioned processed forward traffic, which contains the device identification information of the target network device, thereby serving as a prerequisite for executing the device identification information adding operation of the reverse traffic below.

[0064] S302: Store the device identification information of the target network device.

[0065] The virtual switch corresponding to the destination device in the destination network can store the device identification information of the above-mentioned target network device in the storage space connected to the virtual switch, or instruct the above-mentioned destination device to store the device identification information of the target network device in the storage space connected to the above-mentioned destination device. This specification does not limit this.

[0066] S303, when the destination device needs to return reverse traffic to the source device, the stored device identification information is added to the reverse traffic and then sent out to instruct the virtual switch corresponding to the routing access point in the intermediate network that receives the reverse traffic: forward the reverse traffic to the target network device for processing.

[0067] When the above-mentioned reverse traffic carries the same device identification information as the above-mentioned forward traffic, the above-mentioned reverse traffic can also be processed by the network device corresponding to the device identification information when passing through the intermediate network, so as to achieve consistency between the forward and reverse traffic. At the same time, this specification does not limit the conditions for the above-mentioned destination device to add the above-mentioned device identification information. For example: only when the above-mentioned destination device sends reverse traffic to the source device that has sent forward traffic to it, the virtual switch corresponding to the above-mentioned destination device adds the above-mentioned stored device identification information to the reverse traffic. For another example: when the above-mentioned destination device sends reverse traffic to any other network device including the above-mentioned source device, the virtual switch corresponding to the above-mentioned destination device adds the above-mentioned stored device identification information to the reverse traffic.

[0068] For example, as mentioned above, since network devices are subject to the risk of abnormal situations such as downtime, even if the above-mentioned destination device receives two forward flows from the source device, the device identification information carried by the two forward flows may be different. Therefore, the virtual switch corresponding to the above-mentioned destination device can update the stored device identification information if the device identification information carried by the forward flow after the above-mentioned processing is inconsistent with the pre-stored device identification information, thereby ensuring the validity of the device identification information.

[0069] It can be seen from the above embodiments that this specification uses the technical means of adding device identification information to the forward traffic, so that the routing access point of the intermediate network can forward the reverse traffic to the network device corresponding to the forward traffic for processing according to the device identification information carried by the reverse traffic, thereby ensuring the consistency of the network devices accessed by the forward and reverse traffic, and avoiding the impact caused by the expansion and contraction of multiple availability zones. At the same time, the design of the destination device, source device and corresponding routing access point in the destination network and source network avoids the limitation of requiring the source device and the destination device to have routing access points in the same availability zone in the related technology.

[0070] Combine the following Figure 4a The illustrated embodiments illustrate the technical solution of this specification. Figure 4a is a flow chart of a forwarding method of forward traffic shown in an exemplary embodiment of this specification, such as Figure 4a As shown in Figure 1, there are active networks, target networks, and intermediate networks. Figure 4a Availability zones 1-6 are located in the same region, and traffic is transmitted between networks through transit routers (TR). In addition, the source network and the target network have a routing access point and a source device and a destination device in different availability zones. At the same time, there are two routing access points and two network devices in the intermediate network, which are set in availability zones 3 and 4 as shown in the figure. The method can be divided into the following steps:

[0071] The source device in availability zone 1 needs to send forward traffic X1 to the destination device. The forward traffic X1 first reaches the virtual router corresponding to the source device, where the forward traffic X1 uses the GENEVE format.

[0072] The virtual router corresponding to the above source device confirms that there is no pre-stored device identification information, so the device identification information adding operation is ignored, and by querying the preset routing table, it is determined and sent that the forwarding address of the above forward traffic X1 is the virtual router corresponding to the routing access point in available zone 2.

[0073] The virtual router corresponding to the routing access point of the above-mentioned availability zone 2 sends the above-mentioned forward traffic X1 to the forwarding router, and the forwarding router forwards the above-mentioned forward traffic X1 to the virtual router corresponding to the routing access point of availability zone 3 according to the preset traffic forwarding strategy, wherein the above-mentioned preset traffic forwarding strategy is used to maintain the traffic forwarding relationship of each routing access point.

[0074] The virtual router corresponding to the routing access point of available zone 3 determines that the forward traffic X1 does not carry device identification information, so it determines the network device 1 in the intermediate network as the target network device according to the preset traffic distribution strategy, and sends the forward traffic X1 to the virtual router corresponding to the target network device.

[0075] After receiving the forward traffic X1, the virtual router corresponding to the network device in the availability zone 3 forwards it to the network device in the availability zone 3 for processing to obtain the forward traffic X2, and sends the forward traffic X2 and the ENI address information of the target network device to the virtual router corresponding to the routing access point in the availability zone 3.

[0076] The virtual router corresponding to the routing access point of the above-mentioned available zone 3 adds the above-mentioned ENI address information to the received forward traffic X2. Among them, since the forward traffic X2 adopts the GENEVE format, the ENI address information of the above-mentioned target network device is stored in the option field of the message corresponding to the forward traffic X2.

[0077] The virtual router corresponding to the routing access point of the above-mentioned availability zone 3 sends the above-mentioned forward traffic X2 to the forwarding router, and the forwarding router forwards the above-mentioned forward traffic X2 to the virtual router corresponding to the routing access point of the above-mentioned availability zone 5 according to the preset traffic forwarding strategy.

[0078] The virtual router corresponding to the routing access point of the above-mentioned available zone 5 sends the above-mentioned forward traffic X2 to the virtual switch of the destination device. At this time, since the above-mentioned forward traffic X2 carries the ENI address information of the above-mentioned target network device, the virtual switch of the destination device can locally save the ENI address information of the above-mentioned target network device.

[0079] Next, combine Figure 4b The embodiments shown in the figure illustrate the technical solution of this specification, wherein Figure 4b and Figure 4a The network structure is basically the same and will not be described in detail in this manual. Figure 4b is a flowchart of a method for forwarding reverse traffic as shown in an exemplary embodiment of this specification. Figure 4b As shown, the method can be divided into the following steps:

[0080] The destination device in available zone 6 needs to send reverse traffic Y1 to the source device. The reverse traffic Y1 first reaches the virtual router corresponding to the destination device, where the reverse traffic Y1 adopts the GENEVE format.

[0081] The virtual router corresponding to the above-mentioned destination device writes the ENI address information of the above-mentioned target network device into the option field of the message corresponding to the above-mentioned reverse traffic Y1 according to the pre-stored device identification information (i.e., the ENI address information of the above-mentioned target network device) and the format of the reverse traffic Y1, and determines and sends the forwarding address of the above-mentioned reverse traffic Y1 to the virtual router corresponding to the routing access point in available zone 5 by querying the preset routing table.

[0082] The virtual router corresponding to the routing access point of the above-mentioned availability zone 5 sends the above-mentioned reverse traffic Y1 to the forwarding router. In this embodiment, it is assumed that the above-mentioned reverse traffic Y1 is forwarded to the virtual router corresponding to the routing access point of availability zone 4. Among them, since the above-mentioned reverse traffic Y1 may be forwarded to different availability zones (i.e., availability zone 3 or availability zone 4) corresponding to the intermediate network, and forwarded to virtual routers in different availability zones, and different virtual routers may select network devices in different ways, the problem that the forward and reverse traffic may be forwarded to different network devices for processing occurs in the related technology. In this embodiment, the forwarding router can forward the above-mentioned reverse traffic Y1 to any virtual router corresponding to the routing access point of availability zone 3 or availability zone 4 according to the preset traffic forwarding strategy, and ensure that the forward and reverse traffic passes through the same network device.

[0083] The virtual router corresponding to the routing access point of available zone 4 determines that the reverse traffic Y1 carries device identification information, and therefore determines the network device corresponding to the device identification information (i.e., the network device of available zone 3) as the target network device according to the preset traffic distribution strategy, and sends the reverse traffic Y1 to the virtual router corresponding to the target network device.

[0084] After receiving the reverse traffic Y1, the virtual router corresponding to the network device in the availability zone 3 forwards it to the network device in the availability zone 3 for processing to obtain the reverse traffic Y2, and sends the reverse traffic Y2 and the ENI address information of the target network device to the virtual router corresponding to the routing access point in the availability zone 4.

[0085] The virtual router corresponding to the routing access point of the above-mentioned availability zone 4 re-adds the above-mentioned ENI address information to the received reverse traffic Y2. Similar to the forward traffic, since the reverse traffic Y2 adopts the GENEVE format, the option field of the message corresponding to the reverse traffic Y2 maintains the ENI address information of the above-mentioned target network device.

[0086] The virtual router corresponding to the routing access point of the above-mentioned availability zone 4 sends the above-mentioned reverse traffic Y2 to the forwarding router, and the forwarding router forwards the above-mentioned reverse traffic Y2 to the virtual router corresponding to the routing access point of the availability zone 2 according to the preset traffic forwarding strategy.

[0087] The virtual router corresponding to the routing access point of the availability zone 2 sends the reverse traffic Y2 to the virtual switch of the source device. At this time, since the reverse traffic Y2 carries the ENI address information of the target network device, the virtual switch of the source device can also save the ENI address information of the target network device locally. Among them, for the traffic of the same flow, if it is sent through the source device, it will also carry the ENI address information of the target network device, thereby ensuring that when the network devices of the intermediate network are expanded or reduced, the forward and reverse traffic still access the same network device.

[0088] Combine the following Figure 5a The illustrated embodiments illustrate the technical solution of this specification. Figure 5a is a flow chart of another forwarding method of forward traffic shown in an exemplary embodiment of this specification, such as Figure 5a As shown in Figure 1, there are active networks, target networks, and intermediate networks. Figure 5a Availability zones 1-6 are located in the same region, and traffic is transmitted between networks through forwarding routers. In addition, the source network and the target network each have a routing access point and a service call device (i.e., devices such as security authentication services and load balancing services deployed), and a payment service processing device in different availability zones. At the same time, there are two routing access points and two firewall devices in the intermediate network, which are set in availability zones 3 and 4 as shown in the figure. The method can be divided into the following steps:

[0089] Assume that a user initiates a payment request to a payment platform by using the e-commerce software in a mobile terminal, and the payment request is received by the cloud server corresponding to the e-commerce software, and the corresponding payment service is called by the service calling device in the cloud server. Then the service calling device in available zone 1 needs to send a call request X1 to the payment service processing device, and the call request X1 first reaches the virtual router corresponding to the service calling device, where the call request X1 uses the GENEVE format.

[0090] The virtual router corresponding to the service calling device confirms that there is no pre-saved device identification information, so the device identification information adding operation is ignored, and by querying the preset routing table, it is determined and sent that the forwarding address of the calling request X1 is the virtual router corresponding to the routing access point in available zone 2.

[0091] The virtual router corresponding to the routing access point of the above-mentioned availability zone 2 sends the above-mentioned call request X1 to the forwarding router, and the forwarding router forwards the above-mentioned call request X1 to the virtual router corresponding to the routing access point of the above-mentioned availability zone 3 according to the preset traffic forwarding strategy.

[0092] The virtual router corresponding to the routing access point of available zone 3 determines that the call request X1 does not carry device identification information, so it sends the call request X1 to the virtual router corresponding to firewall device 1 according to the preset traffic distribution strategy.

[0093] The virtual router corresponding to the firewall device 1 in the above-mentioned availability zone 3 forwards the above-mentioned call request X1 to the firewall device 1 in the above-mentioned availability zone 3 after receiving the above-mentioned call request X1. At the same time, the firewall device 1 records and detects the status of the call request X1, and sends the output call request X2 and the ENI address information of the above-mentioned firewall device 1 to the virtual router corresponding to the routing access point in the above-mentioned availability zone 3.

[0094] The virtual router corresponding to the routing access point of the available zone 3 adds the ENI address information to the received call request X2. Since the call request X2 adopts the GENEVE format, the ENI address information of the firewall device 1 is stored in the option field of the message corresponding to the call request X2.

[0095] The virtual router corresponding to the routing access point of the above-mentioned availability zone 3 sends the above-mentioned call request X2 to the forwarding router, and the forwarding router forwards the above-mentioned call request X2 to the virtual router corresponding to the routing access point of the above-mentioned availability zone 5 according to the preset traffic forwarding strategy.

[0096] The virtual router corresponding to the routing access point of the availability zone 5 sends the call request X2 to the virtual switch of the payment service processing device. At this time, since the call request X2 carries the ENI address information of the firewall device 1, the virtual switch of the payment service processing device can save the ENI address information of the firewall device 1 locally.

[0097] At the same time, the payment service processing device can execute the corresponding payment service after receiving the call request X2.

[0098] Next, combine Figure 5b The embodiments shown in the figure illustrate the technical solution of this specification, wherein Figure 5b and Figure 5a The network structure is basically the same and will not be described in detail in this manual. Figure 5b is a flowchart of a method for forwarding reverse traffic as shown in an exemplary embodiment of this specification. Figure 5b As shown, the method can be divided into the following steps:

[0099] When the payment service processing device in available zone 6 successfully receives and executes the above call request, it can send a call result Y1 to the service calling device. The call result Y1 first reaches the virtual router corresponding to the payment service processing device, where the call result Y1 adopts the GENEVE format.

[0100] The virtual router corresponding to the payment service processing device writes the ENI address information of the firewall device 1 into the option field of the message corresponding to the call result Y1 according to the pre-saved device identification information (i.e., the ENI address information of the firewall device 1) and the format of the call result Y1, and determines and sends the forwarding address of the call result Y1 to the virtual router corresponding to the routing access point in available zone 5 by querying the preset routing table.

[0101] The virtual router corresponding to the routing access point of the above-mentioned availability zone 5 sends the above-mentioned call result Y1 to the forwarding router. In this embodiment, it is assumed that the above-mentioned call result Y1 is forwarded to the virtual router corresponding to the routing access point of availability zone 4. Among them, since the above-mentioned call result Y1 may be forwarded to different availability zones (i.e., availability zone 3 or availability zone 4) corresponding to the intermediate network, and forwarded to virtual routers in different availability zones, and different virtual routers may select firewalls in different ways, the problem of forwarding the call result to different firewalls for processing occurs in the related technology. In this embodiment, the forwarding router can forward the above-mentioned call result Y1 to any virtual router corresponding to the routing access point of availability zone 3 or availability zone 4 according to the preset traffic forwarding strategy, and ensure that the call result passes through the same firewall.

[0102] The virtual router corresponding to the routing access point of available zone 4 determines that the above call result Y1 carries device identification information, so it determines the firewall device 1 corresponding to the above device identification information according to the preset traffic distribution strategy, and sends the above call result Y1 to the virtual router corresponding to the firewall device 1.

[0103] The virtual router corresponding to the firewall device 1 in the above-mentioned availability zone 3 forwards the above-mentioned call result Y1 to the firewall device 1 in the above-mentioned availability zone 3 after receiving the above-mentioned call result Y1. Since the firewall device 1 has previously recorded the status of the above-mentioned call request, the above-mentioned call result will not trigger the security alarm of the firewall device 1. The firewall device 1 can send the output call result Y2 and the ENI address information of the firewall device 1 to the virtual router corresponding to the routing access point in the above-mentioned availability zone 4.

[0104] The virtual router corresponding to the routing access point of the above-mentioned available zone 4 re-adds the above-mentioned ENI address information to the received call result Y2. Similar to the above-mentioned call request, since the call result Y2 adopts the GENEVE format, the option field of the message corresponding to the call result Y2 is kept as the ENI address information of the firewall device 1.

[0105] The virtual router corresponding to the routing access point of the above-mentioned availability zone 4 sends the above-mentioned call result Y2 to the forwarding router, and the forwarding router forwards the above-mentioned call result Y2 to the virtual router corresponding to the routing access point of the availability zone 2 according to the preset traffic forwarding strategy.

[0106] The virtual router corresponding to the routing access point of the above-mentioned availability zone 2 sends the above-mentioned call result Y2 to the virtual switch of the service calling device. The service calling device sends relevant information to the e-commerce software in the above-mentioned mobile device to let the user know that the above-mentioned payment request has been successfully executed. At this time, since the above-mentioned call result Y2 carries the ENI address information of the firewall device 1, the virtual switch of the service calling device can also save the ENI address information of the firewall device 1 locally.

[0107] Those skilled in the art will appreciate that the above-mentioned network device does not necessarily have to be a firewall device. For example, when the above-mentioned payment platform is a data storage platform and the above-mentioned payment request is a page access request, the above-mentioned firewall device can be replaced by a traffic analysis component, and in accordance with the provisions of the relevant privacy policy and with the authorization and permission of the user, the user's usage preferences in the e-commerce software can be analyzed, and personalized service information can be pushed to the user.

[0108] Figure 6 is a schematic structural diagram of an electronic device in an exemplary embodiment. Figure 6At the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and may also include other required hardware. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it, forming a traffic forwarding device at the logical level. Of course, in addition to software implementations, this specification does not exclude other implementations, such as logic devices or a combination of software and hardware, etc., that is to say, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0109] Corresponding to the above-mentioned embodiment of the method for forwarding traffic, this specification also provides an embodiment of a device for forwarding traffic.

[0110] Please refer to Figure 7 , Figure 7 FIG. 1 is a schematic diagram of a structure of a traffic forwarding device shown in an exemplary embodiment. Figure 7 As shown, in a software implementation, the device is applied to a virtual switch corresponding to any routing access point in an intermediate network, the intermediate network is deployed in multiple availability zones, and the intermediate network is provided with at least two network devices in different availability zones and a routing access point in the same availability zone as the at least two network devices. The device may include:

[0111] The traffic receiving unit 701 is used to receive forward traffic from a source device in a source network, where the forward traffic is sent to a destination device in a destination network;

[0112] A traffic processing unit 702, configured to distribute the forward traffic to a target network device in the intermediate network for processing;

[0113] The processed traffic sending unit 703 is used to send processed forward traffic carrying the device identification information of the target network device to the destination device, so that the reverse traffic returned by the destination device to the source device carries the device identification information of the target network device, and the device identification information is used to indicate the virtual switch corresponding to the routing access point in the intermediate network that receives the reverse traffic: forward the reverse traffic to the target network device for processing.

[0114] Optionally, the device further comprises:

[0115] The traffic distribution unit 704 is used to determine the target network device according to a pre-configured traffic distribution strategy when the forward traffic does not carry device identification information, and forward the forward traffic to the target network device for processing;

[0116] In the case where the forward traffic carries the device identification information of the target network device, the target network device is determined according to the device identification information, and the forward traffic is forwarded to the target network device for processing.

[0117] Optionally, the preconfigured traffic allocation strategy includes: a preset routing table or a dynamic allocation algorithm, wherein the dynamic allocation algorithm is used to perform dynamic traffic allocation according to the operating status of the at least two network devices.

[0118] Optionally, the traffic distribution unit 704 is specifically configured to:

[0119] When the forward traffic contains the device identification information of the target network device but the target network device is unavailable, the forward traffic is forwarded to the reallocated target network device for processing.

[0120] Optionally, the device identification information of the target network device is added to the processed forward traffic by a virtual switch corresponding to the target network device; or,

[0121] The device also includes:

[0122] The traffic redistribution unit 705 is used to add the device identification information of the target network device to the processed forward traffic after receiving the processed forward traffic returned after being processed by the target network device.

[0123] Optionally, the source device and a routing access point in the source network are respectively deployed in different availability zones in the source network, and the routing access point is used for the source device to implement cross-network interaction; and / or,

[0124] The destination device and the routing access point in the destination network are respectively deployed in different available zones in the destination network, and the routing access point is used for the destination device to achieve cross-network interaction.

[0125] Optionally, the device identification information is the elastic network card (ENI) address information corresponding to the target network device.

[0126] Please refer to Figure 8 , Figure 8 FIG. 1 is a schematic diagram of the structure of another traffic forwarding device shown in an exemplary embodiment. Figure 8 As shown, in a software implementation, the device is applied to a virtual switch corresponding to a destination device in a destination network, and the device may include:

[0127] The processed traffic receiving unit 801 is used to receive processed forward traffic forwarded by the intermediate network, wherein the processed forward traffic carries device identification information of a target network device, and the device identification information is used to indicate that after receiving the forward traffic sent by the source device, the virtual switch corresponding to any routing access point in the intermediate network distributes the forward traffic to the target network device in the intermediate network for processing; wherein the intermediate network is deployed in multiple availability zones, and the intermediate network is provided with at least two network devices in different availability zones and a routing access point in the same availability zone as the at least two network devices;

[0128] The device identification information storage unit 802 is used to store the device identification information of the target network device;

[0129] The device identification information adding unit 803 is used to add the stored device identification information to the reverse traffic and then send it out when the destination device needs to return reverse traffic to the source device, so as to instruct the virtual switch corresponding to the routing access point in the intermediate network that receives the reverse traffic: forward the reverse traffic to the target network device for processing.

[0130] The device also includes:

[0131] The device identification information updating unit 804 updates the stored device identification information when the device identification information carried by the forward traffic after the processing is inconsistent with the pre-stored device identification information.

[0132] The implementation process of the functions and effects of each unit in the above-mentioned device is specifically described in the implementation process of the corresponding steps in the above-mentioned method, and will not be repeated here.

[0133] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can refer to the partial description of the method embodiments. The device embodiments described above are only schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this specification. Ordinary technicians in this field can understand and implement it without paying creative work.

[0134] The embodiments of the subject matter and functional operations described in this specification may be implemented in the following: digital electronic circuits, tangibly embodied computer software or firmware, computer hardware including the structures disclosed in this specification and their structural equivalents, or a combination of one or more of them. The embodiments of the subject matter described in this specification may be implemented as one or more computer programs, i.e., one or more modules in computer program instructions encoded on a tangible non-temporary program carrier to be executed by a data processing device or to control the operation of the data processing device. Alternatively or additionally, the program instructions may be encoded on an artificially generated propagation signal, such as a machine-generated electrical, optical or electromagnetic signal, which is generated to encode information and transmit it to a suitable receiver device for execution by a data processing device. The computer storage medium may be a machine-readable storage device, a machine-readable storage substrate, a random or serial access memory device, or a combination of one or more of them.

[0135] The processes and logic flows described in this specification can be performed by one or more programmable computers executing one or more computer programs to perform corresponding functions by operating on input data and generating output. The processes and logic flows can also be performed by special purpose logic circuits, such as FPGAs (field programmable gate arrays) or ASICs (application-specific integrated circuits), and the apparatus can also be implemented as special purpose logic circuits.

[0136] Computers suitable for executing computer programs include, for example, general and / or special microprocessors, or any other type of central processing unit. Typically, the central processing unit will receive instructions and data from a read-only memory and / or a random access memory. The basic components of a computer include a central processing unit for implementing or executing instructions and one or more memory devices for storing instructions and data. Typically, the computer will also include one or more large-capacity storage devices for storing data, such as magnetic disks, magneto-optical disks, or optical disks, or the computer will be operably coupled to this large-capacity storage device to receive data from it or to transmit data to it, or both. However, the computer does not necessarily have such a device. In addition, the computer can be embedded in another device, such as a mobile phone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a global positioning system (GPS) receiver, or a portable storage device such as a universal serial bus (USB) flash drive, to name a few.

[0137] Computer readable media suitable for storing computer program instructions and data include all forms of non-volatile memory, media and memory devices, including, for example, semiconductor memory devices (e.g., EPROM, EEPROM and flash memory devices), magnetic disks (e.g., internal hard disks or removable disks), magneto-optical disks, and CD ROM and DVD-ROM disks. The processor and memory may be supplemented by, or incorporated in, special purpose logic circuitry.

[0138] Although this specification includes many specific implementation details, these should not be interpreted as limiting the scope of any invention or the scope of protection claimed, but are mainly used to describe the features of the specific embodiments of specific inventions. Certain features described in multiple embodiments in this specification may also be implemented in combination in a single embodiment. On the other hand, the various features described in a single embodiment may also be implemented separately in multiple embodiments or in any suitable sub-combination. In addition, although features may work in certain combinations as described above and even initially claim protection, one or more features from the claimed combination may be removed from the combination in some cases, and the claimed combination may point to a sub-combination or a variation of a sub-combination.

[0139] Similarly, although operations are depicted in a particular order in the accompanying drawings, this should not be understood as requiring that these operations be performed in the particular order shown or performed sequentially, or requiring that all illustrated operations be performed to achieve the desired results. In some cases, multitasking and parallel processing may be advantageous. In addition, the separation of various system modules and components in the above-described embodiments should not be understood as requiring such separation in all embodiments, and it should be understood that the described program components and systems can generally be integrated together in a single software product, or packaged into multiple software products.

[0140] Thus, specific embodiments of the subject matter have been described. Other embodiments are within the scope of the appended claims. In some cases, the actions recited in the claims can be performed in a different order and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the particular order or sequential order shown to achieve the desired results. In some implementations, multitasking and parallel processing may be advantageous.

[0141] The above description is only a preferred embodiment of this specification and is not intended to limit this specification. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of this specification should be included in the scope of protection of this specification.

Claims

1. A traffic forwarding method, It is characterized in that A virtual switch applied to any routing access point in an intermediate network, wherein the intermediate network is deployed in multiple availability zones, and the intermediate network is provided with at least two network devices in different availability zones and a routing access point in the same availability zone as the at least two network devices, the method comprising: Receiving forward traffic from a source device in a source network, wherein a sending destination of the forward traffic is a destination device in a destination network; Distributing the forward traffic to a target network device in the intermediate network for processing; Sending processed forward traffic carrying device identification information of the target network device to the destination device, so that the reverse traffic returned by the destination device to the source device carries the device identification information of the target network device, and the device identification information is used to indicate the virtual switch corresponding to the routing access point in the intermediate network that receives the reverse traffic: forwarding the reverse traffic to the target network device for processing; The source device and the routing access point in the source network are respectively deployed in different available zones in the source network, and the routing access point is used for the source device to achieve cross-network interaction; and / or, The destination device and the routing access point in the destination network are respectively deployed in different available zones in the destination network, and the routing access point is used for the destination device to achieve cross-network interaction.

2. The method according to claim 1, It is characterized in that The distributing the forward traffic to the target network device for processing includes: In the case where the forward traffic does not carry device identification information, determining the target network device according to a pre-configured traffic distribution strategy, and forwarding the forward traffic to the target network device for processing; In the case where the forward traffic carries the device identification information of the target network device, the target network device is determined according to the device identification information, and the forward traffic is forwarded to the target network device for processing.

3. The method according to claim 2, It is characterized in that The pre-configured traffic distribution strategy includes: a preset routing table or a dynamic distribution algorithm, wherein the dynamic distribution algorithm is used to perform dynamic traffic distribution according to the operating status of the at least two network devices.

4. The method according to claim 2, It is characterized in that The distributing the forward traffic to the target network device for processing includes: When the forward traffic contains the device identification information of the target network device but the target network device is unavailable, the forward traffic is forwarded to the reallocated target network device for processing.

5. The method according to claim 1, It is characterized in that The device identification information of the target network device is added to the processed forward traffic by the virtual switch corresponding to the target network device; or, The method further includes: after receiving the processed forward traffic returned after being processed by the target network device, adding device identification information of the target network device to the processed forward traffic.

6. The method according to claim 1, It is characterized in that The device identification information is the ENI address information corresponding to the target network device.

7. A traffic forwarding method, It is characterized in that Applied to a virtual switch corresponding to a destination device in a destination network, the method comprises: Receive processed forward traffic forwarded by an intermediate network, the processed forward traffic carrying device identification information of a target network device, the device identification information being used to indicate that: after receiving the forward traffic sent by a source device, a virtual switch corresponding to any routing access point in the intermediate network distributes the forward traffic to the target network device in the intermediate network for processing; wherein the intermediate network is deployed in a plurality of availability zones, and the intermediate network is provided with at least two network devices in different availability zones and a routing access point in the same availability zone as the at least two network devices; Storing device identification information of the target network device; In the case where the destination device needs to return reverse traffic to the source device, the stored device identification information is added to the reverse traffic and then sent out to instruct the virtual switch corresponding to the routing access point in the intermediate network that receives the reverse traffic to forward the reverse traffic to the target network device for processing.

8. The method according to claim 7, It is characterized in that Also includes: When the device identification information carried by the forward traffic after the processing is inconsistent with the pre-stored device identification information, the stored device identification information is updated.

9. A computer-readable storage medium having a computer program stored thereon, It is characterized in that When the program is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, It is characterized in that When the processor executes the program, the steps of the method according to any one of claims 1 to 8 are implemented.

Citation Information

Patent Citations

  • Correlating network flows in a routing service for full-proxy network appliances

    US11088948B1

  • Routing bidirectional flows in a stateless routing service

    US11310149B1