A method and apparatus for configuring a drainage network, an electronic device, and a storage medium

CN116455816BActive Publication Date: 2026-08-28BEIJING QINGYUN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310520221.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-09
Publication Date
2026-08-28
Estimated Expiration
2043-05-09

AI Technical Summary

Technical Problem

然而,上述引流网络的配置方法还存在以下问题:引流目标需要配置默认的路由才可以使安全处理后的数据包沿原路径返回,即原路返回的目标是固定的唯一IP,这意味着引流对象和引流目标必须配套使用,进而造成引流目标无法被多个引流对象共享使用,降低了安全资源的使用率

Benefits of technology

[0020]本发明实施例的技术方案,通过设置至少一个引流模块的唯一网络标识和网络地址段,根据网络标识将引流模块的第一网卡配置为请求网络设备,控制引流目标配置对应各请求网络设备的响应网络设备,在各请求网络设备设置地址解析协议请求的响应配置参数以使各网络设备构成引流网络。本发明实施例通过为引流模块分别配置唯一的网络标识和网络地址段,再根据网络标识为各引流模块和各引流目标分别配置对应的请求网络设备和响应网络设备,并按照地址解析协议请求的响应配置参数连通请求网络设备和对应响应网络设备之间的数据链路以生成对应的引流网络,实现了引流对象和引流目标之间的解耦,使得引流目标可以被多个引流对象共享使用,提升了安全资源的利用率。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116455816B_ABST
    Figure CN116455816B_ABST
Patent Text Reader

Abstract

The application discloses a kind of configuration methods, devices, electronic equipment and storage medium of drainage network, comprising: setting the unique network identification and network address section of at least one drainage module, according to the network identification, the first network card of the drainage module is configured as request network device, control drainage target configuration corresponding each request network device response network device, in each request network device response configuration parameter is set to address resolution protocol request to make each network device constitute drainage network.The embodiment of the application is configured by being respectively configured with the unique network identification and network address section for drainage module, then according to network identification, each drainage module and each drainage target is respectively configured with corresponding network device, and according to the response configuration parameter of address resolution protocol request, the data link between request network device and corresponding response network device is set to drainage network, the decoupling between drainage object and drainage target is realized, and the utilization of drainage target is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to a method, apparatus, electronic device, and storage medium for configuring a traffic-driving network. Background Technology

[0002] A cloud platform refers to a hardware-based service that provides users with computing, networking, and storage capabilities. The virtual resources (cloud resources) of a cloud platform require network security protection. Network traffic to these cloud resources can be redirected to security devices for protection. After processing by these devices, malicious or offensive data packets are discarded, while legitimate packets are returned along their original path and ultimately reach the business side.

[0003] Existing referral networks typically configure a Layer 2 network and use Internet Protocol (IP) routing to direct cloud resources (referral targets) to security devices (referral targets) for protection. However, this configuration method has the following problems: the referral target needs to be configured with a default route so that the security-processed data packets can return along the original path. That is, the target returned along the original path is a fixed and unique IP address. This means that the referral target and the referral object must be used together, which prevents multiple referral objects from sharing the same target and reduces the utilization rate of security resources. Summary of the Invention

[0004] This invention provides a method, apparatus, electronic device, and storage medium for configuring a traffic redirection network. By configuring a unique network identifier and network address range for each traffic redirection module, and then configuring corresponding request network devices and response network devices for each traffic redirection module and each traffic redirection target according to the network identifier, and connecting the data links between the request network devices and the corresponding response network devices according to the response configuration parameters requested by the Address Resolution Protocol (ARP) to generate the corresponding traffic redirection network, the decoupling between the traffic redirection object and the traffic redirection target is achieved, allowing the traffic redirection target to be shared by multiple traffic redirection objects, thereby improving the utilization rate of security resources.

[0005] According to one aspect of the present invention, a method for configuring a referral network is provided, the method comprising:

[0006] Set a unique network identifier and network address range for at least one traffic redirection module;

[0007] Configure the first network card of the traffic redirection module as the requesting network device based on the network identifier;

[0008] Configure the corresponding network devices for each requesting network device to control the traffic redirection target;

[0009] Configure the response parameters for Address Resolution Protocol (ARP) requests on each requesting network device to enable the network devices to form a traffic redirection network.

[0010] According to another aspect of the present invention, a configuration device for a traffic diversion network is provided, the device comprising:

[0011] The network settings module is used to set the unique network identifier and network address range for at least one traffic redirection module;

[0012] The request device configuration module is used to configure the first network card of the traffic redirection module as the requesting network device according to the network identifier.

[0013] The response device configuration module is used to control the response network device for each request network device configured for the traffic redirection target;

[0014] The referral network generation module is used to set the response configuration parameters of the Address Resolution Protocol (ARP) request on each requesting network device so that the network devices can form a referral network.

[0015] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:

[0016] At least one processor; and

[0017] A memory communicatively connected to the at least one processor; wherein,

[0018] The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the configuration method of the diversion network according to any embodiment of the present invention.

[0019] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the configuration method of the diversion network according to any embodiment of the present invention.

[0020] The technical solution of this invention, by setting a unique network identifier and network address range for at least one traffic redirection module, configuring the first network card of the traffic redirection module as a requesting network device according to the network identifier, controlling the traffic redirection target to configure the corresponding response network device for each requesting network device, and setting the response configuration parameters of the Address Resolution Protocol (ARP) request in each requesting network device to enable the network devices to form a traffic redirection network. This invention, by configuring a unique network identifier and network address range for each traffic redirection module, configuring corresponding requesting and response network devices for each traffic redirection module and each traffic redirection target according to the network identifier, and connecting the data links between the requesting network devices and the corresponding response network devices according to the response configuration parameters of the ARP request to generate a corresponding traffic redirection network, achieves decoupling between the traffic redirection object and the traffic redirection target, allowing the traffic redirection target to be shared by multiple traffic redirection objects, thus improving the utilization rate of security resources.

[0021] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0022] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 This is a flowchart of a traffic diversion network configuration method provided in Embodiment 1 of the present invention;

[0024] Figure 2 This is a flowchart of a method for configuring a referral network according to Embodiment 2 of the present invention;

[0025] Figure 3 This is an example diagram of a traffic diversion network model provided in Embodiment 3 of the present invention;

[0026] Figure 4 This is an example diagram of another traffic diversion network model provided in Embodiment 3 of the present invention;

[0027] Figure 5 This is a flowchart of a traffic diversion network configuration method provided in Embodiment 3 of the present invention;

[0028] Figure 6 This is a schematic diagram of the configuration device for a diversion network according to Embodiment 4 of the present invention;

[0029] Figure 7 This is a schematic diagram of the structure of an electronic device that implements the configuration method of the diversion network in the embodiments of the present invention. Detailed Implementation

[0030] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0031] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0032] Example 1

[0033] Figure 1 This is a flowchart illustrating a method for configuring a referral network according to Embodiment 1 of the present invention. This embodiment is applicable to configuring a referral network. The method can be executed by a referral network configuration device, which can be implemented in hardware and / or software. Figure 1 As shown in the figure, the configuration method of the traffic diversion network provided in this embodiment includes the following steps:

[0034] S110. Set a unique network identifier and network address range for at least one traffic redirection module.

[0035] The traffic redirection module can be understood as a functional module for processing data packet flow. This module may include a network namespace (Linux network namespace, netns) or other functional modules capable of processing data packet flow. The traffic redirection module can reside on a cloud host, i.e., a virtual machine (VM) on a cloud platform, or on the physical machine where the VM resides, or on other devices running services. This embodiment of the invention does not impose any limitations on this. The network identifier can be an identifier for the traffic redirection network, which may include a Virtual Local Area Network IDentifier (VLAN ID) and a Visual eXtensible Local Area Network IDentifier (VxLAN ID), etc. The network address range can refer to the network addresses assigned to each traffic redirection module using a network allocation mechanism.

[0036] In this embodiment of the invention, each traffic redirection module can be configured with a unique network identifier through the host's network configuration page or using PowerShell scripts, based on the traffic redirection module. The network identifier can be, but is not limited to, VLAN ID and VxLAN ID. Existing network allocation mechanisms, such as variable-length subnet masks and fixed-length subnet masks, are then used to divide the preset network address into several subnets, and each traffic redirection module is configured with a corresponding network address range according to the divided subnets. It is understood that the network identifier and network address range correspond one-to-one with each traffic redirection module. For example, the network identifier and network address range assigned to traffic redirection module 1 can be VLAN1 and network address 1, respectively, and the network identifier and network address range assigned to traffic redirection module 2 can be VLAN2 and network address 2, respectively.

[0037] S120. Configure the first network card of the traffic redirection module as the requesting network device according to the network identifier.

[0038] The first network interface card (NIC) can be understood as the NIC located within the traffic redirection module, and there can be one or more first NICs. The requesting network device can be a network device obtained by configuring the first NIC using a network identifier. The requesting network device can be used to send data packets with traffic redirection requirements and to receive data packets processed by the traffic redirection target.

[0039] In this embodiment of the invention, after assigning a corresponding network identifier to each traffic redirection module, configuration parameters related to the first network interface card in each traffic redirection module can be obtained from a configuration file or configuration table pre-stored on a local or cloud server. Then, a corresponding request network device is created according to the configuration parameters and the network identifier. The number of request network devices can be the same as the number of first network interface cards in the corresponding traffic redirection module, and can be used to send data packets with traffic redirection requirements and to receive data packets processed by the traffic redirection target.

[0040] S130, Control the target traffic to be configured with the corresponding response network devices for each requesting network device.

[0041] In this context, the redirection target can be understood as the destination to which data packets are redirected. For example, the redirection target can be a security device used to perform security protection processing on the data packets. Furthermore, the security device can include various security instances (cloud hosts with security engine software installed) or other physical security protection devices, etc. This embodiment of the invention does not impose any limitations on this. The responding network device can be a network device obtained by configuring the network card in the redirection target using a network identifier. The responding network device can be used to receive data packets with redirection requirements and send the data packets processed by the redirection target.

[0042] In this embodiment of the invention, referring to the method of creating a request network device in S120, corresponding response network devices are configured according to the network cards in each traffic redirection target controlled by the network identifier. The number of traffic redirection targets can be the same as the number of different first network cards in each traffic redirection module, and the number of response network devices can be the same as the number of the same first network cards in each traffic redirection module. The response network devices can be used to receive data packets with traffic redirection requirements and send data packets processed by the traffic redirection targets.

[0043] S140. Configure the response parameters of the Address Resolution Protocol (ARP) request on each requesting network device to enable the network devices to form a traffic redirection network.

[0044] The Address Resolution Protocol (ARP) is a link-layer protocol that obtains the physical address from the IP address. Using ARP requests and correct responses, it's possible to verify whether the data link between the requesting network device and the corresponding responding network device within the redirection target is established. Response configuration parameters can be understood as the response parameters to the ARP request. These parameters can include the Media Access Control Address (MAC) corresponding to each redirection module, each requesting network device, each redirection target, and each responding network device. Network devices can include both requesting and responding network devices. The redirection network can be understood as the network for data communication between the redirection module and the redirection target. The redirection network can be a Layer 2 network. For example, the data link between the requesting network device ge0.vlan1 in redirection module 1 and the responding network device ge0.vlan1 in the redirection target belongs to one redirection network, and the data link between the requesting network device ge1.vlan1 in redirection module 2 and the responding network device ge1.vlan1 in the redirection target also belongs to another redirection network.

[0045] In this embodiment of the invention, ARP response configuration parameters related to each requesting network device in each traffic redirection module can be obtained from configuration files or configuration tables pre-stored on a local or cloud server. The response configuration parameters may include, but are not limited to, the MAC addresses corresponding to each traffic redirection module, each requesting network device, each traffic redirection target, and each response network device. Then, the routing path between each requesting network device and each response network device in the traffic redirection target is configured according to the response configuration parameters, and the data link between the requesting network device and the response network device after configuring the routing path is used as the corresponding traffic redirection network. For example, in the traffic redirection module 1, there is a requesting network device ge1.vlan1, and in the traffic redirection target 1, there is a corresponding responding network device ge1.vlan1. Both network devices belong to the VLAN 1 network. The response configuration parameters, i.e., the MAC address, of the requesting network device ge1.vlan1 or the responding network device ge1.vlan1 can be obtained by using ARP request and response. Then, the routing path between the requesting network device ge1.vlan1 and the responding network device ge1.vlan1 is configured according to the response configuration parameters, and the data link between the requesting network device ge1.vlan1 and the responding network device ge1.vlan1 after configuring the routing path is used as the corresponding traffic redirection network.

[0046] The technical solution of this invention, by setting a unique network identifier and network address range for at least one traffic redirection module, configuring the first network card of the traffic redirection module as a requesting network device according to the network identifier, controlling the traffic redirection target to configure the corresponding response network device for each requesting network device, and setting the response configuration parameters of the Address Resolution Protocol (ARP) request in each requesting network device to enable the network devices to form a traffic redirection network. This invention, by configuring a unique network identifier and network address range for each traffic redirection module, configuring corresponding requesting and response network devices for each traffic redirection module and each traffic redirection target according to the network identifier, and connecting the data links between the requesting network devices and the corresponding response network devices according to the response configuration parameters of the ARP request to generate a corresponding traffic redirection network, achieves decoupling between the traffic redirection object and the traffic redirection target, allowing the traffic redirection target to be shared by multiple traffic redirection objects, thus improving the utilization rate of security resources.

[0047] Example 2

[0048] Figure 2 This is a flowchart illustrating a traffic referral network configuration method provided in Embodiment 2 of the present invention. It is further optimized and extended based on the above embodiments and can be combined with various optional technical solutions in the above embodiments. For example... Figure 2 As shown in the figure, the configuration method of the traffic diversion network provided in this embodiment includes the following steps:

[0049] S210. Assign a unique virtual local area network (VLAN) identifier to the traffic acquisition module according to the preset traffic acquisition identifier association relationship.

[0050] The Virtual LAN ID (VLAN ID) serves as the identifier for a virtual LAN, distinguishing different VLAN networks. The preset referral identifier association can be a pre-configured relationship between referral modules and VLAN IDs. This association can include each referral module corresponding to a unique VLAN ID, and can be represented as a referral identifier association mapping table or a referral identifier association configuration file.

[0051] In this embodiment of the invention, the VLAN ID associated with each traffic redirection module can be found in a pre-configured mapping table or configuration file containing preset traffic redirection identifier association relationships. Each traffic redirection module corresponds to a unique VLAN ID. Then, the corresponding VLAN ID can be configured for each traffic redirection module through the host's network configuration page or by using PowerShell scripts.

[0052] S220: Allocate network address ranges for the traffic redirection module based on variable length subnet mask and preset network address.

[0053] Variable Length Subnet Mask (VLSM) is a network allocation mechanism that can divide a preset network address into multiple subnets. The preset network address can be a pre-configured network address to be assigned for dividing into several subnets. The preset network address can be configured according to actual needs. For example, the preset network address can be 100.64.1.0 / 24.

[0054] In this embodiment of the invention, a preset network address can be pre-selected as needed, and then a variable-length subnet mask technique can be used to divide the preset network address into several subnets. Each traffic redirection module is then configured with a corresponding network address range according to the divided subnets. Thus, each traffic redirection module is configured with a unique VLAN ID and a unique network address range for subsequent traffic redirection network construction.

[0055] Furthermore, based on the above embodiments of the invention, after S220, it may also include: storing the location of the traffic redirection module, the virtual local area network identifier, and the network address range in association with a persistent storage server.

[0056] In this embodiment of the invention, after configuring the corresponding network address range for each traffic redirection module, the location, virtual LAN identifier, and network address range of each traffic redirection module can be stored in a persistent storage server. This facilitates the direct and rapid retrieval of the corresponding information from the persistent storage server when the relevant network configuration of the traffic redirection module is required. The persistent storage server may include, but is not limited to, relational databases such as PostgreSQL and MySQL databases. This embodiment of the invention does not impose any restrictions on this.

[0057] S230. Obtain configuration items from the preset virtual LAN configuration file of the requesting network device in the first network card settings. The configuration items include at least: the name of the first network card, the name of the requesting network device, and the network identifier.

[0058] The preset virtual LAN configuration file can be a pre-configured configuration file for configuring VLAN network devices, i.e., requesting network devices, for the first network card. The preset virtual LAN configuration file can include multiple configuration items, which can include at least: the name of the first network card, the name of the requesting network device, and the network identifier, etc. The number of requesting network devices can be the same as the number of first network cards in the corresponding traction module.

[0059] In this embodiment of the invention, the configuration items corresponding to the first network card can be obtained from a preset virtual local area network configuration file stored on a local or cloud server. For example, the configuration items corresponding to the first network card can be found by using data matching methods, not limited to string matching and fuzzy matching. The configuration items may include at least: the name of the first network card, the name of the requesting network device, and the network identifier.

[0060] S240. Configure the configuration parameters of the configuration items according to the network identifier to complete the configuration of the requested network device.

[0061] The configuration parameters can be parameters corresponding to the configuration items in the preset virtual LAN configuration file. The configuration parameters can include the actual name of the first network card and the actual name of the network device to be created.

[0062] In this embodiment of the invention, configuration parameters can be set according to the configuration items in the preset virtual LAN configuration file. These configuration parameters may include the actual name of the first network interface card (NIC) and the actual name of the requested network device. Then, the first NIC is configured with network device information according to the network identifier and configuration parameters to create the corresponding requested network device. The requested network device has a network identifier corresponding to its respective traffic redirection module. In some embodiments, if the network identifier is VLAN ID = vlan1, and the first NICs in the traffic redirection module are NIC ge0 and NIC ge1, then corresponding VLAN network devices can be configured for NIC ge0 and NIC ge1 according to the network identifier VLAN1 and configuration parameters, thereby creating the requested network devices corresponding to each first NIC. The newly generated requested network devices can be named ge0.vlan1 and ge1.vlan1, respectively, and can be used to identify the network devices of VLAN1. Data packets entering and leaving the requested network devices ge0.vlan1 and ge1.vlan1 will be tagged with the network identifier, i.e., the VLAN1 tag. Therefore, the requested network devices ge0.vlan1 and ge1.vlan1 can carry the traffic of the VLAN1 network.

[0063] S250. Determine the network identifier corresponding to each requesting network device.

[0064] In this embodiment of the invention, the methods for determining the network identifier corresponding to each requesting network device may include, but are not limited to, the following: Since the traffic redirection module and the network identifier are in one-to-one correspondence, and the requesting network device generated according to the first network card in the traffic redirection module also has a network identifier corresponding to the traffic redirection module, the number of traffic redirection modules can be obtained from the preset traffic redirection identifier association relationship, and the network identifier corresponding to each requesting network device can be determined based on the number; After each requesting network device is created, its corresponding network identifier can be stored in a preset database so that the network identifier corresponding to each requesting network device can be obtained from the preset database when needed.

[0065] S260. Configure at least one responsive network device on the second network card of the target network according to each network identifier.

[0066] The second network card can refer to the network card located within the target network.

[0067] In this embodiment of the invention, the method of creating a request network device based on the first network card can be referenced. Corresponding response network devices can be configured according to the second network card in each traffic redirection target, with each network identifier designated as a traffic redirection target. The number of response network devices can be the same as the number of identical first network cards in each traffic redirection module, and the number of traffic redirection targets can be the same as the number of different first network cards in each traffic redirection module. It should be understood that for some special types of traffic redirection targets, such as those from certain vendors, which are internally similar to black boxes and cannot be configured with corresponding response network devices using the above method, corresponding response network devices can be created separately on the network configuration page of the corresponding traffic redirection target according to each network identifier.

[0068] S270. Create an Address Resolution Protocol (ARP) Request / Response (ORR) device in the traffic redirection module, and configure at least one Internet Protocol (IP) address for the ARP Request / Response (ORR) device.

[0069] The Address Resolution Protocol (ARP) request response device can be understood as a network device used to respond to Address Resolution Protocol (ARP) requests. The ARP request response device can be a dummy network device or other types of network devices. The ARP request response device can be located in each traffic redirection module, and there can be one or more of them. The ARP request response device can only be used to respond to the received ARP requests and will not participate in data communication.

[0070] In this embodiment of the invention, corresponding ARP request and response devices can be created in each traffic redirection module according to the device name and preset configuration file of the ARP request and response device, and a corresponding IP address can be configured for each ARP request and response device. The IP addresses configured in the ARP request and response devices in each traffic redirection module can at least include the IP addresses corresponding to each requesting network device in the corresponding traffic redirection module. The purpose of configuring ARP request and response devices in each traffic redirection module is that each ARP request and response device is configured with all the IP addresses of each requesting network device in the corresponding traffic redirection module. When the traffic redirection module receives an ARP request, the ARP request and response device can match and verify the IP address in the ARP request with all the IP addresses it has configured. When a match is found with one of the IP addresses configured in the ARP request and response device, the ARP request and response device can respond.

[0071] It's understandable that configuring ARP request / response devices in each traffic redirection module eliminates the need to configure IP addresses on the corresponding request network devices, thus improving the configuration efficiency of the traffic redirection network. Alternatively, one could choose not to create ARP request / response devices and directly configure the corresponding IP addresses on each request network device in each traffic redirection module. However, this would inevitably increase the configuration workload of the traffic redirection network, thereby reducing its configuration efficiency.

[0072] S280. Configure the path route to the responding network device within the redirection target based on the requesting network device configuration.

[0073] The path routing can be the IP route between the referral module and the referral target. If there are multiple referral targets, the path routing here can be a multipath route.

[0074] In this embodiment of the invention, a path route can be configured from the requesting network device to the responding network device within the traffic redirection target, based on the IP address corresponding to the requesting network device in each traffic redirection module and the IP address corresponding to the responding network device within the traffic redirection target. If there are multiple traffic redirection targets, the route can be a multi-path route. Configuring the path route allows each traffic redirection target to know which requesting network devices it can access. After each requesting network device receives an ARP request sent by a traffic redirection target, the requesting network device with a successfully matched IP address can issue an ARP response and send the ARP response data packet out along the original requesting network device. For example, if the requesting network device ge0.vlan1 in traffic redirection module 1 receives an ARP request sent by a traffic redirection target and the IP address in the ARP request data packet is successfully matched, then the requesting network device ge0.VLAN1 will send the ARP response data packet containing the MAC address corresponding to the requesting network device ge0.vlan1 through its own network port along the original path.

[0075] S290. Use the data link between the requesting network device and the responding network device after configuring path routing as the lead network.

[0076] In this embodiment of the invention, a new network is added to generate a traffic-driving network based on the existing Layer 2 network of the traffic-driving module and the traffic-driving target by overlaying. That is, the data link between the request network device and the response network device after configuring the path routing can be used as the corresponding traffic-driving network. The traffic-driving network can be one or more Layer 2 interconnected networks. The data link between the request network device in each traffic-driving module and the response network device with the same network identifier in each traffic-driving target can be used as the corresponding traffic-driving network based on the network identifier.

[0077] Furthermore, based on the above embodiments of the invention, the second embodiment of this invention provides a method for configuring a referral network, which further includes:

[0078] The business requirement to obtain the corresponding data packet;

[0079] Configure routing strategies for the traffic generation module according to business requirements.

[0080] Here, "business requirements" can refer to the traffic redirection requirements of data packets. These requirements may include the traffic redirection path, the traffic redirection target, and data packet markings. "Route policy" can be understood as the traffic redirection strategy configured according to the business requirements of the data packets. For example, a route policy may include routing a data packet marked 0x1 to traffic redirection target 1 via requesting network device ge0.vlan1, or determining the route to a specific traffic redirection target based on the data packet's source IP address and destination IP address.

[0081] In this embodiment of the invention, business requirements corresponding to data packets can be obtained through means such as business requirement documents, and then corresponding routing strategies can be configured for the traffic redirection module based on these business requirements. It is understood that the routing strategy is related to the business requirements of the data packets and can be configured accordingly based on actual business needs; this embodiment of the invention does not impose any limitations on this.

[0082] The technical solution of this invention involves assigning a unique virtual local area network (VLAN) identifier to the traffic redirection module according to a preset traffic redirection identifier association relationship, allocating a network address range to the traffic redirection module based on a variable-length subnet mask and a preset network address, obtaining configuration items from the preset VLAN configuration file of the requesting network device in the first network interface card (NIC), wherein the configuration items include at least: the name of the first NIC, the name of the requesting network device, and a network identifier, setting the configuration parameters of the configuration items according to the network identifier to complete the configuration of the requesting network device, determining the network identifier corresponding to each requesting network device, configuring at least one response network device in the second NIC of the traffic redirection target according to each network identifier, creating an Address Resolution Protocol (ARP) request-response device in the traffic redirection module, configuring at least one Network Interconnect Protocol (NAT) address for the ARP request-response device, and configuring a path route pointing to the response network device within the traffic redirection target according to the path route configured for the requesting network device, and using the data link between the requesting network device and the response device after configuring the path route as the traffic redirection network. This invention, through configuring unique VLAN IDs and network address ranges for each traffic redirection module, and then configuring corresponding request and response network devices for the first and second network cards in each traffic redirection module and each traffic redirection target based on the VLAN IDs, utilizes ARP request and response devices to configure path routes from the request network devices to the response network devices within the traffic redirection target. Finally, the data link between the request network devices and response network devices after configuring path routes is used as the corresponding traffic redirection network. This decouples the traffic redirection object and the traffic redirection target, allowing multiple traffic redirection objects to share the traffic redirection target, improving the utilization rate of security resources, and enabling data packets to return along the original path after being processed by the traffic redirection target. Simultaneously, the traffic redirection module can be horizontally expanded, thereby enhancing the traffic redirection capability of the cloud platform.

[0083] Example 3

[0084] Figure 3 This is an example diagram of a traffic diversion network model provided in Embodiment 3 of the present invention. Figure 3As shown, this referral network model is an example diagram of an existing referral network model, which includes: physical machines, namely host machines host1 and host2; cloud hosts VM1, VM2, VM3 and VM4; referral module 1 and referral module 2; the first network interface cards ge0 and ge1 in referral module 1, and the first network interface cards ge0 and ge1 in referral module 2; referral target 1 and referral target 2; Layer 2 network 1 represents the Layer 2 referral network between referral module 1 and referral target 1, and Layer 2 network 2 represents the Layer 2 referral network between referral module 1 and referral target 2.

[0085] Depend on Figure 3 It's clear that a default route must be configured for the traffic redirection target to ensure that data packets processed by the target return along the same path. This means the target IP address returned along the original path is a fixed and unique IP address, implying that the traffic redirection object (cloud resource) and the traffic redirection target must be used in pairs. This prevents multiple traffic redirection objects from sharing the target and wastes security resources. For example, the first network interface card in traffic redirection module 2 cannot establish a traffic redirection network with traffic redirection target 1 and traffic redirection target 2 because traffic redirection target 1 and traffic redirection target 2 have already pointed their default routes to a fixed and unique IP address, which is the IP address of the first network interface card in traffic redirection module 1. Furthermore, the existing traffic redirection network has another problem: when a cloud host is migrated, the constraint of the pairing of the traffic redirection object (cloud resource) and the traffic redirection target can prevent some traffic redirection objects (cloud resources) from being redirected and thus unprotected. For instance, if cloud host 1 is migrated but cloud host 2 is still redirecting traffic normally, a decision must be made on which cloud host to redirect traffic to, leading to inconvenience and increased complexity in managing the traffic redirection module.

[0086] Based on the existing traffic redirection network, this embodiment of the invention generates a new traffic redirection network by overlaying a Layer 2 network. This overlayed Layer 2 network can include, but is not limited to, VLANs and VxLANs. Taking a VLAN as an example of the overlayed Layer 2 network... Figure 4 This is an example diagram of another traffic diversion network model provided in Embodiment 3 of the present invention. Figure 4As shown, the traffic redirection network model includes: physical machines, namely host machines host1 and host2; cloud hosts VM1, VM2, VM3, and VM4; traffic redirection module 1 and traffic redirection module 2; first network interface cards ge0 and ge1 in traffic redirection module 1, and first network interface cards ge0 and ge1 in traffic redirection module 2; requesting network devices ge0.vlan1 and ge1.vlan1 in traffic redirection module 1, and requesting network devices ge0.vlan2 and ge1.vlan2 in traffic redirection module 2; traffic redirection target 1 and traffic redirection target 2; second network interface card ge1 in traffic redirection target 1, and second network interface card ge1 in traffic redirection target 2; response network devices ge0.vlan1 and ge0.vlan2 in traffic redirection target 1, and network devices ge1.vlan1 and ge1.vlan2 in traffic redirection target 2; and Layer 2 network 1, representing the Layer 2 connection between traffic redirection target 1 and traffic redirection module 1 and traffic redirection module 2. The referral network, Layer 2 network 2, represents the Layer 2 referral network between referral module 1 and referral module 2 respectively; VLAN 1 network represents the VLAN network between the requesting network device ge0.vlan1 in referral module 1 and the corresponding responding network device ge0.vlan1 in referral target 1, and VLAN 1 network also represents the VLAN network between the requesting network device ge1.vlan1 in referral module 1 and the corresponding responding network device ge1.vlan1 in referral target 2; VLAN 2 network represents the VLAN network between the requesting network device ge0.vlan2 in referral module 2 and the corresponding responding network device ge0.vlan2 in referral target 1, and VLAN 2 network also represents the VLAN network between the requesting network device ge1.vlan2 in referral module 2 and the corresponding responding network device ge1.vlan2 in referral target 2.

[0087] based on Figure 4 The traffic generation network model Figure 5 This is a flowchart illustrating a configuration method for a referral network provided in Embodiment 3 of the present invention, which enables data communication between each referral module and each referral target. For example... Figure 5 As shown, the configuration method of a traffic diversion network provided in Embodiment 3 of the present invention specifically includes the following steps:

[0088] S310: Assign a unique VLAN ID and network address range to each traffic module.

[0089] In this embodiment of the invention, a unique VLAN ID can be assigned to each host machine according to a preset traffic redirection identifier association, and a unique network address range can be assigned to each host machine using a variable-length subnet mask and a preset network address. For example, VLAN 1 can be assigned to host1, and VLAN 2 can be assigned to host2. The preset network address used is 100.64.1.0 / 24. After allocation using variable-length subnet mask technology, the network address range of host1 is 100.64.1.0 / 30, the IP address in traffic redirection module 1 is 100.64.1.1, and the IP address in traffic redirection target 1 is 100.64.1.2. The network address range of host2 is 100.64.1.4 / 30, the IP address in traffic redirection module 2 is 100.64.1.5, and the IP address in traffic redirection target 2 is 100.64.1.6.

[0090] S320. Configure a VLAN network device for the first network card in each traffic redirection module to obtain the corresponding requested network device.

[0091] For example, assuming that VLAN network device configuration is performed on the first network card ge0 in the traffic redirection module 1, the Linux command can be used: ip link add link ge0 name ge0.vlan1 type vlan protocol 802.1Q id 1 to create the corresponding request network device ge0.vlan1. Similarly, request network device ge1.vlan1 can be created. Data packets entering and leaving request network devices ge0.vlan1 and ge1.vlan1 will be marked with the network identifier, i.e., the VLAN 1 tag. That is, request network devices ge0.vlan1 and ge1.vlan1 can be used to carry the traffic of the VLAN 1 network.

[0092] S330. Configure network settings for ARP responses within each traffic redirection module.

[0093] In this embodiment of the invention, a dummy network device can be created first. This dummy network device is only used to respond to received ARP requests and does not participate in data communication. Then, the dummy network device is configured with all the IP addresses of each requesting network device in the corresponding traffic redirection module. When the traffic redirection module receives an ARP request, the dummy network device can match and verify the IP address in the ARP request with all the IP addresses it has configured. When it matches one of the IP addresses configured in the dummy network device, the dummy network device can respond. Then, the IP routes of the traffic redirection targets can be configured. Since there can be multiple traffic redirection targets, multipath routes can be configured at this time. The purpose is to be able to respond to ARP requests normally. Configuring path routes allows each traffic redirection target to know which requesting network devices it can reach. After each requesting network device receives the ARP request sent by the traffic redirection target, the requesting network device with a successful IP match can issue an ARP response and send the ARP response data packet out according to the original requesting network device.

[0094] S340. Configure routing strategies for the traffic generation module according to business requirements.

[0095] In this embodiment of the invention, a corresponding routing strategy can be configured for the traffic redirection module according to the business requirements corresponding to the data packet, so that the data packet is sent to the corresponding traffic redirection target according to the predetermined route.

[0096] S350: Configure VLAN network devices for the second network card in each traffic diversion target to obtain the corresponding response network device.

[0097] S360: Configure routing policies for each traffic redirection target based on VLAN ID.

[0098] In this embodiment of the invention, corresponding routing policies can be configured in each diversion target based on different VLAN IDs to ensure that data packets entering from each responding network device are sent out along the original path of the original responding network device. Taking diversion target 1 as an example, the process of configuring routing policies according to data packet marking and IP routing is as follows:

[0099] 1) Configure the packet tag corresponding to the packet. For example, specify that packets responding to network device ge0.vlan1 are all tagged as 0x1, and packets responding to network device ge0.vlan2 are all tagged as 0x2.

[0100] 2) Save the packet tags corresponding to the configured packets to the connection record (conntrack in Linux).

[0101] 3) Configure routing rules. For example, a packet marked 0x1 will be returned via the response network device ge0.vlan1, and a packet marked 0x2 will be returned via the response network device ge0.vlan2.

[0102] 4) Configure recovery packet tag. When the traffic target 1 finishes processing the packet and is ready to send the packet out, it queries the packet tag corresponding to the packet from the connection record, and then uses the routing rules to determine which response network device the packet should be sent from.

[0103] The data packet processing flow is roughly as follows: Data packet A -> Response network device ge0.vlan1 (inbound) -> Data packet A (0x1) -> Record connection record -> Process traffic redirection target 1 -> Processing ends and data packet A is ready to be sent -> Restore data packet marker in connection record -> Data packet A (0x1) -> Find the corresponding routing rule based on data packet marker -> Response network device ge0.vlan1 (outbound).

[0104] It is understood that the configuration of routing policies in this embodiment of the invention is not specifically limited, as long as it can be achieved that data packets enter from a certain responding network device and then flow out from the corresponding responding network device.

[0105] S370. Use the data link between the requesting network device and the responding network device after configuring path routing as the lead network.

[0106] Next, we will use the Arping tool to verify the connectivity of the referral network. Arping is a tool that initiates MAC address requests, broadcasting requests for the MAC address corresponding to a specific IP address within a Layer 2 network. Assume that the IP address of the requesting network device ge0.vlan1 in referral module 1 is 100.64.1.1, and its corresponding MAC address is e2:67:e1:41:77:46; the IP address of the responding network device in referral target 1 is 100.64.1.2, and its corresponding MAC address is da:ac:24:52:15:27. A verification example is shown below:

[0107] 1) In the traffic redirection module 1, the requesting network device ge0.vlan1 sends an ARP request. The source address of the ARP request is the IP address of traffic redirection module 1, i.e., 100.64.1.1, and the destination address is the IP address of traffic redirection target 1, i.e., 100.64.1.2. Enable Arping:

[0108] ~#arping-i ge0.vlan1-S 100.64.1.1 100.64.1.2ARPING 100.64.1.2

[0109] 42bytes from e2:67:e1:41:77:46(100.64.1.2):index=0time=9.578usec

[0110] As can be seen, the MAC address of the reply is e2:67:e1:41:77:46, which is the same as the MAC address of the requesting network device ge0.vlan1 in target 1, which is in line with the correct expectation and verifies the network connectivity.

[0111] 2) In the traffic redirection module 1, the requesting network device ge0.vlan1 sends an ARP request. The source address of the ARP request is the IP address of the traffic redirection target 1, i.e., 100.64.1.2, and the destination address is the IP address of the traffic redirection module 1, i.e., 100.64.1.1. Enable Arping:

[0112] ~#arping-i ge0.vlan1-S 100.64.1.2 100.64.1.1ARPING 100.64.1.1

[0113] 42bytes from da:ac:24:52:15:27(100.64.1.1):index=0time=8.595usec

[0114] As can be seen, the MAC address of the reply is da:ac:24:52:15:27, which is the same as the MAC address of the requesting network device ge0.vlan1 in the traffic redirection module 1, which is in line with the correct expectation and verifies the network connectivity.

[0115] 3) Packet capture results: In the traffic redirection module 1, the requesting network device ge0.vlan1 sends an ARP request. The source address of the ARP request is the IP address of the traffic redirection target 1, which is 100.64.1.2, and the destination address is the IP address of the traffic redirection module 1, which is 100.64.1.1. Arping is enabled, and packet capture is performed at the requesting network device ge0.vlan1 in the traffic redirection module 1. The packet capture results are as follows: 12:16:58.381364e2:67:e1:41:77:46>ff:ff:ff:ff:ff:ff,ethertype ARP(0x0806),length 58:Request who-has 100.64.1.1tell 100.64.1.2,length 44

[0116] 12:16:58.381392da:ac:24:52:15:27>e2:67:e1:41:77:46,ethertype ARP(0x0806),length 42:Reply 100.64.1.1is-at da:ac:24:52:15:27,length 28

[0117] As can be seen, the first packet is an ARP broadcast packet initiated by the responding network device ge0.vlan1 in target traffic 1, querying this VLAN 1 network for "who has 100.64.1.1 and tells 100.64.1.2". After receiving the packet, the requesting network device ge0.vlan1 in traffic redirection module 1 queries and finds that the dummy network device is configured with the IP address 100.64.1.1, so the system will reply. At the same time, because multi-path routing is configured, the system knows that 100.64.1.2 is a valid route, so it will not discard this ARP request packet and knows how to send it out. The second packet is the system replying that the MAC address of 100.64.1.1 is the MAC address of the requesting network device ge0.vlan1 in traffic redirection module 1.

[0118] The technical solution of this invention assigns a unique VLAN ID and network address range to each traffic redirection module, configures a VLAN network device for the first network card in each traffic redirection module to obtain the corresponding request network device, sets up network configuration for ARP response in each traffic redirection module, configures routing policies for the traffic redirection module according to service requirements, configures a VLAN network device for the second network card in each traffic redirection target to obtain the corresponding response network device, configures routing policies for each traffic redirection target according to the VLAN ID, and uses the data link between the request network device and the response network device after configuring the path routing as the traffic redirection network. This invention, through configuring corresponding request and response network devices for each traffic redirection module and each traffic redirection target, and then using the data link between the configured path-routing request and response network devices as the corresponding traffic redirection network, achieves decoupling between the traffic redirection object and the traffic redirection target. This allows the traffic redirection target to be shared by multiple traffic redirection objects, improving the utilization rate of security resources. It also allows data packets to return along the original path after being processed by the traffic redirection target. The traffic redirection module can be horizontally expanded, thereby enhancing the traffic redirection capability of the cloud platform. Furthermore, it enables a distributed design of the traffic redirection module to meet the traffic redirection needs of cloud resources in different locations.

[0119] Example 4

[0120] Figure 6 This is a schematic diagram of the configuration device for a traffic diversion network provided in Embodiment 4 of the present invention. Figure 6 As shown, the device includes:

[0121] The network settings module 41 is used to set a unique network identifier and network address range for at least one traffic redirection module.

[0122] The request device configuration module 42 is used to configure the first network card of the traffic redirection module as the request network device according to the network identifier.

[0123] The response device configuration module 43 is used to control the configuration of the response network devices corresponding to each request network device in the traffic diversion target configuration.

[0124] The referral network generation module 44 is used to set the response configuration parameters of the Address Resolution Protocol (ARP) request on each requesting network device so that each network device constitutes a referral network.

[0125] The technical solution of this invention involves a network setting module that sets a unique network identifier and network address range for at least one traffic redirection module. A request device configuration module configures the first network interface card (NIC) of the traffic redirection module as a request network device based on the network identifier. A response device configuration module controls the traffic redirection target to configure corresponding response network devices for each request network device. A traffic redirection network generation module sets response configuration parameters for Address Resolution Protocol (ARP) requests on each request network device to form a traffic redirection network. This invention, by configuring unique network identifiers and network address ranges for each traffic redirection module, configuring corresponding request and response network devices for each traffic redirection module and each traffic redirection target based on the network identifier, and connecting the data links between the request network devices and corresponding response network devices according to the ARP response configuration parameters to generate a corresponding traffic redirection network, achieves decoupling between the traffic redirection object and the traffic redirection target. This allows multiple traffic redirection targets to share the traffic redirection target, improving the utilization rate of security resources.

[0126] Furthermore, based on the above embodiments of the invention, the network setting module 41 includes:

[0127] The identifier allocation unit is used to assign a unique virtual local area network identifier to the traffic acquisition module according to the preset traffic acquisition identifier association relationship.

[0128] The address allocation unit is used to allocate network address segments to the traffic redirection module based on the variable-length subnet mask and the preset network address.

[0129] Furthermore, based on the above embodiments of the invention, the request device configuration module 42 includes:

[0130] The configuration acquisition unit is used to acquire configuration items from the preset virtual LAN configuration file of the requesting network device in the first network interface card settings. The configuration items include at least: the name of the first network interface card, the name of the requesting network device, and the network identifier.

[0131] The request device matching unit is used to set the configuration parameters of the configuration items according to the network identifier in order to complete the configuration of the requesting network device.

[0132] Furthermore, based on the above embodiments of the invention, the response device configuration module 43 includes:

[0133] The identifier determination unit is used to determine the network identifier corresponding to each requesting network device.

[0134] The response device configuration unit is used to configure at least one response network device on the second network interface card of the traffic diversion target according to each network identifier.

[0135] Furthermore, based on the above embodiments of the invention, the referral network generation module 44 includes:

[0136] The Address Resolution Protocol Request / Response Device Creation Unit is used to create an Address Resolution Protocol Request / Response Device in the traffic redirection module and configure at least one Internet Protocol address for the Address Resolution Protocol Request / Response Device.

[0137] The routing configuration unit is used to configure path routes to the response network devices within the traffic redirection target based on the requesting network device.

[0138] The referral network generation unit is used to use the data link between the requesting network device and the response network device after configuring the path routing as the referral network.

[0139] Furthermore, based on the above embodiments of the invention, the device further includes:

[0140] The business requirements acquisition module is used to acquire the business requirements of the corresponding data packets.

[0141] The routing strategy configuration module is used to configure routing strategies for the traffic redirection module according to business requirements.

[0142] Furthermore, based on the above embodiments of the invention, the device further includes:

[0143] The associated data storage module is used to associate and store the location, virtual LAN identifier, and network address range of the traffic redirection module to the persistent storage server.

[0144] The configuration device for the traffic diversion network provided in this embodiment of the invention can execute the configuration method for the traffic diversion network provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0145] Example 5

[0146] Figure 7A schematic diagram of an electronic device 50 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0147] like Figure 7 As shown, the electronic device 50 includes at least one processor 51 and a memory, such as a read-only memory (ROM) 52 and a random access memory (RAM) 53, communicatively connected to the at least one processor 51. The memory stores computer programs executable by the at least one processor. The processor 51 can perform various appropriate actions and processes based on the computer program stored in the ROM 52 or loaded into the RAM 53 from storage unit 58. The RAM 53 can also store various programs and data required for the operation of the electronic device 50. The processor 51, ROM 52, and RAM 53 are interconnected via a bus 54. An input / output (I / O) interface 55 is also connected to the bus 54.

[0148] Multiple components in electronic device 50 are connected to I / O interface 55, including: input unit 56, such as keyboard, mouse, etc.; output unit 57, such as various types of monitors, speakers, etc.; storage unit 58, such as disk, optical disk, etc.; and communication unit 59, such as network card, modem, wireless transceiver, etc. Communication unit 59 allows electronic device 50 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0149] Processor 51 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 51 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 51 performs the various methods and processes described above, such as the configuration methods of the routing network.

[0150] In some embodiments, the configuration method for the traffic diversion network can be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 58. In some embodiments, part or all of the computer program can be loaded and / or mounted on electronic device 50 via ROM 52 and / or communication unit 59. When the computer program is loaded into RAM 53 and executed by processor 51, one or more steps of the configuration method for the traffic diversion network described above can be performed. Alternatively, in other embodiments, processor 51 can be configured to perform the configuration method for the traffic diversion network by any other suitable means (e.g., by means of firmware).

[0151] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0152] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0153] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0154] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0155] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0156] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0157] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0158] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A method for configuring a traffic referral network, characterized in that, The method includes: Set a unique network identifier and network address range for at least one traffic redirection module; Configure the first network card of the traffic redirection module as the requesting network device according to the network identifier; Configure the corresponding response network device for each of the requested network devices to control the traffic diversion target; Configure the response parameters of the Address Resolution Protocol (ARP) request on each of the requesting network devices to enable the network devices to form a traffic redirection network; The control diversion target configuration corresponds to the response network device of each of the requesting network devices, including: Determine the network identifier corresponding to each of the requesting network devices; At least one of the aforementioned response network devices is configured on the second network interface card of the traffic diversion target according to each of the aforementioned network identifiers; The step of setting the response configuration parameters for the Address Resolution Protocol (ARP) request in each of the requesting network devices to enable the network devices to form a traffic redirection network includes: In the traffic redirection module, an Address Resolution Protocol Request / Response (ARP) device is created, and at least one Network Interconnection Protocol (NIC) address is configured for the ARP device. Configure the path route to the responding network device within the target traffic destination according to the requesting network device configuration; The data link between the requesting network device and the responding network device after configuring the path routing is used as the referral network.

2. The method according to claim 1, characterized in that, The setting of at least one unique network identifier and network address range for a traffic redirection module includes: A unique virtual local area network (VLAN) identifier is assigned to the traffic referral module according to the preset traffic referral identifier association relationship; The network address range is allocated to the traffic redirection module based on the variable-length subnet mask and the preset network address.

3. The method according to claim 1, characterized in that, The step of configuring the network card of the traffic redirection module as a requesting network device according to the network identifier includes: The configuration items are obtained from the preset virtual LAN configuration file of the requesting network device in the first network card settings, wherein the configuration items include at least: the name of the first network card, the name of the requesting network device, and the network identifier; Configure the configuration parameters of the configuration item according to the network identifier to complete the configuration of the requested network device.

4. The method according to claim 1, characterized in that, Also includes: The business requirement to obtain the corresponding data packet; Configure routing strategies for the traffic generation module according to the aforementioned business requirements.

5. The method according to claim 2, characterized in that, Also includes: The location of the traffic redirection module, the virtual local area network identifier, and the network address range are associated and stored in a persistent storage server.

6. A configuration device for a traffic diversion network, characterized in that, The device includes: The network settings module is used to set the unique network identifier and network address range for at least one traffic redirection module; A request device configuration module is used to configure the first network interface card of the traffic redirection module as a requesting network device according to the network identifier; The response device configuration module is used to control the configuration of the response network devices corresponding to each of the requested network devices for the traffic diversion target; The referral network generation module is used to set the response configuration parameters of the Address Resolution Protocol (ARP) request for each of the requesting network devices so that the network devices constitute a referral network; The response device configuration module includes: An identifier determination unit is used to determine the network identifier corresponding to each of the requesting network devices; A response device configuration unit is configured to configure at least one of the response network devices on the second network interface card of the traffic diversion target according to each of the network identifiers; The referral network generation module includes: The Address Resolution Protocol Request Response Device Creation Unit is used to create an Address Resolution Protocol Request Response Device in the traffic redirection module and configure at least one Network Interconnection Protocol Address for the Address Resolution Protocol Request Response Device. A routing configuration unit is configured to configure a path route to the responding network device within the traffic diversion target based on the requesting network device. The referral network generation unit is used to use the data link between the requesting network device and the responding network device after configuring the path routing as the referral network.

7. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor to enable the at least one processor to perform the configuration method of the diversion network according to any one of claims 1-5.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that, when executed by a processor, implement the configuration method of the diversion network according to any one of claims 1-5.

Citation Information

Patent Citations

  • Network communication management method and device of cloud platform, equipment and storage medium

    CN115664920A

  • Flow control method and device based on security service chain, and storage medium

    CN116055412A