Implementation methods, devices, electronic equipment, and storage media for edge cloud NAT gateways
By establishing management and business networks in the cloud platform and creating a dedicated primary/backup NAT gateway, the shortcomings of traditional hardware and shared NAT gateways are solved, enabling flexible and low-cost NAT gateway management and meeting the needs of small-scale edge clouds.
Patent Information
- Application Number
- CN202310341764.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-31
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2043-03-31
AI Technical Summary
Existing NAT gateways cannot meet the needs of small-scale edge clouds. Traditional hardware NAT solutions are costly and limited in number. Shared NAT gateways cannot achieve resource isolation and are complex to manage, and cannot be uniformly managed with the cloud platform.
Establish management and business networks in the cloud platform, create primary and backup dedicated NAT gateways according to user specifications, and configure communication connections and address translation rules through the NAT gateway management module.
It enables flexible and low-cost NAT gateway management, supports NAT gateways of different specifications, improves network management efficiency and security, and meets the needs of small-scale edge clouds.
Smart Images

Figure CN116546012B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cloud computing technology, and in particular to a method, apparatus, electronic device, and storage medium for implementing an edge cloud NAT gateway. Background Technology
[0002] A NAT gateway is a network address translation device that translates internal private IP addresses into public IP addresses for internet access. A NAT gateway allows multiple private IP addresses to share a single public IP address, thus conserving elastic public IP resources.
[0003] With the continuous development of cloud computing technology, current NAT gateways can no longer meet user needs. Traditional hardware NAT solutions can only create a limited number of NAT gateways, on the order of single digits, and are very expensive, making them unsuitable for small-scale edge clouds. Existing shared NAT gateway cloudification solutions have several drawbacks: first, they cannot truly achieve resource isolation; second, NAT management is completely separated from cloud platform management, preventing unified management and increasing user complexity; and third, the management plane and the business plane are not isolated.
[0004] In summary, the problems existing in the current technology urgently need to be solved. Summary of the Invention
[0005] This invention provides a method, apparatus, electronic device, and storage medium for implementing an edge cloud NAT gateway, which addresses the deficiencies in the prior art and can implement NAT gateways of different specifications according to the actual needs of users.
[0006] This invention provides a method for implementing an edge cloud NAT gateway, comprising:
[0007] Obtain pre-set gateway creation information, which includes management bridge data, service bridge data, NAT gateway image data, and flavor specification data;
[0008] A management network is established in the cloud platform based on the management bridge data. The management network is used by the NAT gateway management module in the cloud platform to manage the NAT gateway.
[0009] The service network is established by calling the service bridge data;
[0010] Based on the user's specifications, the NAT gateway image data, and the flavor specification data, NAT gateways are created for the management network and the service network. The NAT gateways include a main gateway and sub-gateways.
[0011] According to the implementation method of an edge cloud NAT gateway provided by the present invention, after establishing a service network by calling the service bridge, the method further includes:
[0012] The NAT gateway management module controls the management network to call the NAT gateway's API interface to establish a communication connection with the business network.
[0013] According to the implementation method of an edge cloud NAT gateway provided by the present invention, the gateway creation information further includes an egress gateway image. After creating the NAT gateway under the management network and the service network according to the user's specification requirements, the NAT gateway image, and the flavor specification, the method further includes:
[0014] Multiple egress gateway instances are created on the business network based on the egress gateway mirror; the egress gateway is a master-master shared egress gateway.
[0015] Configure a corresponding IP address for each egress gateway to establish communication connections between each egress gateway, between NAT gateways and egress gateways, and between egress gateways and physical switches.
[0016] According to the implementation method of an edge cloud NAT gateway provided by the present invention, after creating the NAT gateway under the management network and the service network according to the user's specification requirements, the NAT gateway image, and the flavor specification, the method further includes:
[0017] Get the address translation rules sent by the user;
[0018] The NAT gateway management module sends the address translation rules to the NAT gateway for IP address translation.
[0019] According to the implementation method of an edge cloud NAT gateway provided by the present invention, a management network is established in the cloud platform based on the management bridge, specifically including:
[0020] Based on the management bridge data, establish a management bridge in the cloud platform;
[0021] Configure a corresponding IP address for the management bridge to establish a communication connection with the NAT gateway management module in the cloud platform;
[0022] The management bridge is used as the network connection of the management network, and the management network is established through the cloud platform.
[0023] According to the implementation method of an edge cloud NAT gateway provided by the present invention, the service network is established by calling the service bridge data, specifically including:
[0024] Based on the business bridge data, establish a business bridge in the cloud platform;
[0025] Configure a corresponding IP address for the service bridge to establish a communication connection with the service network;
[0026] The service bridge is used as the network connection of the service network, and the service network is established through the cloud platform.
[0027] According to a method for implementing an edge cloud NAT gateway provided by the present invention, a NAT gateway is created under the management network and the service network based on the user's specification requirements, the NAT gateway image, and the flavor specification, specifically including:
[0028] Create a NAT virtual machine instance based on the NAT gateway image;
[0029] Based on the specified requirements and the flavor specifications, allocate corresponding computing resources to the NAT virtual machine instance.
[0030] The present invention also provides an implementation apparatus for an edge cloud NAT gateway, comprising:
[0031] The information acquisition unit is used to acquire pre-set gateway creation information, which includes management bridge data, service bridge data, NAT gateway image data, and flavor specification data.
[0032] A management network establishment unit is used to establish a management network in the cloud platform based on the management bridge data. The management network is used for the NAT gateway management module in the cloud platform to manage the NAT gateway.
[0033] A service network establishment unit is used to call the service bridge data to establish a service network;
[0034] The NAT gateway creation unit is used to create a NAT gateway under the management network and the service network according to the user's specification requirements, the NAT gateway image data and the flavor specification data. The NAT gateway includes a main gateway and a sub-gateway.
[0035] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the edge cloud NAT gateway implementation method as described above.
[0036] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the implementation method of the edge cloud NAT gateway as described above.
[0037] This invention provides a method, apparatus, electronic device, and storage medium for implementing an edge cloud NAT gateway. The method involves acquiring pre-set gateway creation information including a management bridge, a service bridge, a NAT gateway image, and flavor specifications. Next, a management network is established in the cloud platform based on the management bridge for the NAT gateway management module to manage the NAT gateway. This management network is then used by the NAT gateway management module in the cloud platform to manage the NAT gateway. Subsequently, a service network is established by calling the service bridge data. Then, the specification requirements sent by the user are acquired, and based on the user's specification requirements, the NAT gateway image data, and the flavor specification data, a NAT gateway is created under the management network and the service network. The NAT gateway includes a main gateway and sub-gateways. This invention extends the NAT gateway management module based on the cloud platform architecture and hosts the NAT gateway in the form of a cloud platform virtual machine. It can realize NAT gateways of different specifications, such as small, medium, and large, providing users with multiple choices and reducing user costs. Attached Figure Description
[0038] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0039] Figure 1 This is a flowchart illustrating the implementation method of the edge cloud NAT gateway provided by the present invention;
[0040] Figure 2 This is a schematic diagram of the modules for implementing the edge cloud NAT gateway provided by the present invention;
[0041] Figure 3 This is a schematic diagram of the structure of the edge cloud NAT gateway implementation device provided by the present invention;
[0042] Figure 4 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation
[0043] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0044] Traditional hardware NAT solutions implement network address translation using dedicated hardware devices. This hardware, often called NAT routers or NAT gateways, translates internal private IP addresses into public IP addresses for internet access. Traditional hardware NAT solutions typically use either static NAT or dynamic NAT. Static NAT specifies a fixed mapping, assigning each internal private IP address to a unique public IP address. Dynamic NAT, on the other hand, uses a pool of available public IP addresses, dynamically allocating them as needed. The drawbacks of this approach are obvious: high deployment and maintenance costs, a limited number of NAT gateways that can be created, and unsuitability for small-scale edge clouds. Furthermore, traditional hardware NAT solutions cannot flexibly adapt to changes in network traffic, hindering rapid response to business needs.
[0045] A shared NAT gateway is a cloud-based network address translation solution where multiple users share the same NAT gateway. However, this solution also has some drawbacks. First, because multiple users share the same NAT gateway, true resource isolation cannot be achieved, potentially posing security risks. Second, NAT management is completely separated from cloud platform management, resulting in a lack of unified management and increasing user complexity. Finally, the performance and reliability of a shared NAT gateway are limited by cloud platform resources, and may not meet the demands for high performance and high reliability.
[0046] To address the problems existing in the prior art, reference Figure 1 This invention proposes an implementation method for an edge cloud NAT gateway, which includes, but is not limited to, the following steps:
[0047] Step 110: Obtain the pre-set gateway creation information, which includes management bridge data, service bridge data, NAT gateway image data, and flavor specification data.
[0048] Step 120: Establish a management network in the cloud platform based on the management bridge data. The management network is used for the NAT gateway management module in the cloud platform to manage the NAT gateway.
[0049] Step 130: Establish a service network by calling the service bridge data.
[0050] Step 140: Based on the user's specifications, the NAT gateway image data, and the flavor specification data, create NAT gateways for the management network and the service network. The NAT gateways include a main gateway and sub-gateways.
[0051] When a user device needs to connect to the internet, it typically requires a public IP address to access network resources. However, within a local area network (LAN), private IP addresses are usually assigned to devices. To enable these devices to access the internet, Network Address Translation (NAT) is required. NAT is a technology that maps private IP addresses to public IP addresses, allowing multiple devices to share a single public IP address. In cloud platforms, NAT gateways can be used to provide NAT services.
[0052] Specifically, in step 110, it is necessary to first obtain the pre-configured gateway creation information, including the management bridge, service bridge, NAT gateway image, and flavor specification. The management bridge is a dedicated network used to manage the NAT gateway, the service bridge is a network used to connect user devices and the cloud platform, the NAT gateway image is a pre-configured NAT gateway image file, and the flavor specification is used to specify the computing resource specifications of the NAT gateway.
[0053] In step 120, a management network is established in the cloud platform based on the management bridge, which is used by the NAT gateway management module to manage the NAT gateway. This management network can only be accessed by the NAT gateway management module and is not allowed to be accessed by other tenants.
[0054] In step 130, a service network is established based on the service bridge. This service network connects the cloud platform tenant's end devices to the Internet, allowing the tenant's end devices to communicate with the Internet.
[0055] In step 140, the specification requirements sent by the user are obtained. The user can specify the computing resource specifications of the NAT gateway, such as parameters like CPU and memory.
[0056] Based on the specifications, NAT gateway image, and flavor specifications, create dedicated primary and backup NAT gateways within the business network. Dedicated primary and backup NAT gateways mean that each NAT gateway has a primary and backup node pair, ensuring high availability and fault tolerance. When creating NAT gateways, appropriate computing resource specifications can be selected according to user needs, and NAT gateway instances can be created based on the NAT gateway image. These NAT gateway instances will be deployed in the business network to provide NAT services.
[0057] According to the implementation method of an edge cloud NAT gateway provided by the present invention, after establishing a service network by calling the service bridge, the method further includes:
[0058] The NAT gateway management module calls the API interface of the management network to establish a communication connection between the management network and the business network.
[0059] In this embodiment, the NAT gateway management module uses the management plane to call the standard RESTful API to establish the business plane link and configure business parameters, thereby enabling users to access services.
[0060] In this embodiment, the NAT gateway service is configured through a cloud platform or other management tools, including parameters such as the NAT gateway image, specifications, and business network. Based on the user's configuration, the NAT gateway management module calls the RESTful API provided by the management plane to create a NAT gateway service instance and deploy it to the business network. The NAT gateway management module also calls the RESTful API provided by the business plane to establish network connectivity, enabling user services to access the internet or other networks through the NAT gateway service. The NAT gateway management module can dynamically configure and manage the NAT gateway service instance by calling the RESTful API provided by the management plane, including adjusting NAT policies, monitoring traffic, and logging. Furthermore, the NAT gateway management module can monitor and troubleshoot the NAT gateway service instance by calling the RESTful API provided by the management plane, including handling network anomalies, performance issues, and security incidents.
[0061] In this way, the NAT gateway management module can respond quickly and flexibly to users' business needs, provide high-quality NAT gateway services, and ensure smooth business operation.
[0062] As a further optional embodiment, the gateway creation information also includes an egress gateway image. After creating a NAT gateway under the management network and the service network according to the user's specifications, the NAT gateway image, and the flavor specification, it further includes:
[0063] Multiple egress gateway instances are created on the business network based on the egress gateway mirror; the egress gateway is a master-master shared egress gateway.
[0064] Configure a corresponding IP address for each egress gateway to establish communication connections between each egress gateway, between NAT gateways and egress gateways, and between egress gateways and physical switches.
[0065] refer to Figure 2 Specifically, creating a shared egress gateway in master-master mode can be done by following these steps:
[0066] Create a management bridge and a service bridge under the virtual switch (VSwitch). The management bridge connects to the management network interface card (NIC) of the compute node, and the service bridge connects to the service NIC of the compute node.
[0067] A management network is created based on a management bridge, and a service network is created based on a service bridge.
[0068] Using the aforementioned management and service networks, create two ECS instances based on the egress gateway mirror. These instances will serve as the egress gateway. Furthermore, connect the service network interface cards (NICs) of these two instances to two separate physical switches to achieve logical interconnection with the ports of two external physical switches.
[0069] Configure the necessary network services in the egress gateway ECS instance, such as NAT gateway routing and EIP routing, to enable the egress access links for these cloud resources.
[0070] This embodiment reduces external interconnection links and shields internal network complexity by using a shared egress gateway. Here, EIP stands for Elastic Public IP.
[0071] As a further optional embodiment, after creating the NAT gateway under the management network and the service network according to the user's specification requirements, the NAT gateway image, and the flavor specification, the method further includes:
[0072] Get the address translation rules sent by the user;
[0073] The NAT gateway management module sends the address translation rules to the NAT gateway for IP address translation.
[0074] In this embodiment, the address translation rules include SNAT and DNAT rules, which are network rules used for address translation.
[0075] SNAT (Source NAT) rules are typically used to translate a source IP address into another IP address so that internal hosts can access the external network. For example, when an internal host accesses the external network, the egress gateway can use an SNAT rule to replace the source IP address of the internal host with the public IP address of the egress gateway, so that the external network sees the source IP address of the traffic as the public IP address of the egress gateway.
[0076] DNAT (Destination NAT) rules are typically used to translate a destination IP address into another IP address so that an external network can access an internal host. For example, when an external host accesses an internal network, the egress gateway can use DNAT rules to replace the destination IP address of the external host with the private IP address of the internal host, thus allowing the external network to access the internal host.
[0077] SNAT and DNAT rules are typically configured on the NAT gateway and can match and translate based on different conditions such as port, protocol, and IP address. These rules can effectively protect the security and privacy of the internal network, while also enabling access control between the internal network and the external network.
[0078] Specifically, log in to the NAT gateway management platform or use the API interface, and select the corresponding business management function. Choose the type of rule to be issued, including SNAT rules and DNAT rules, and fill in the corresponding rule information, including source address, destination address, port, etc. Then, click the "Issue Rule" or "Submit" button to submit the rule information to the NAT gateway management module. The NAT gateway management module will verify the validity of the rule and issue it to the corresponding NAT gateway, thereby realizing functions such as address translation and traffic scheduling. Users can view and manage the issued rules through the NAT gateway management platform or API interface, including operations such as modification and deletion.
[0079] By providing interfaces for using SNAT and DNAT rules, users can flexibly manage and control network traffic, enabling more efficient network applications and services. At the same time, this interface also improves the efficiency and reliability of network management, providing users with a better network experience and services.
[0080] As a further optional embodiment, a management network is established in the cloud platform based on the management bridge, specifically including:
[0081] Based on the management bridge data, establish a management bridge in the cloud platform;
[0082] The management bridge is used as the network connection of the management network, and the management network is established through the cloud platform.
[0083] Specifically, the steps for creating a management network based on a management bridge are as follows:
[0084] Create a management bridge: Use commands or a web interface to create a new management bridge. This management bridge needs to communicate with the NAT gateway management module in the network virtualization management platform of the cloud platform.
[0085] Creating a management network: When creating a management network, you need to select a management bridge as its network connection. You can create a management network through the cloud platform console or via the API. When creating a management network, you need to specify parameters such as name, CIDR block, subnet mask, gateway, and DNS server.
[0086] Assign IP addresses: Assign one or more IP addresses in the management network so that the NAT gateway management module in the cloud platform can use these IP addresses to communicate with the NAT gateway.
[0087] Configure Routing: Configure the routing for the management network so that it can be connected to other networks. Here, you need to specify the networks that need to be routed to the management network, the CIDR block, and the gateway address.
[0088] Testing: After completing the above steps, testing is required to ensure the management network is functioning correctly. Ping or other network testing tools can be used to test the management network and ensure it can communicate with the NAT gateway management module.
[0089] In summary, creating a management network based on a management bridge requires a series of configurations and settings for the network and IP addresses to ensure that the management network can function properly and communicate with the NAT gateway management module.
[0090] As a further optional embodiment, establishing a service network by invoking the service bridge data specifically includes:
[0091] Based on the business bridge data, establish a business bridge in the cloud platform;
[0092] The service bridge is used as the network connection of the service network, and the service network is established through the cloud platform.
[0093] Specifically, creating a service network based on a service bridge can be done by following these steps:
[0094] In the network virtualization management platform of the cloud platform, a business bridge is created according to business needs, and a business network is created based on the business bridge.
[0095] Configure the appropriate network card and address information on the virtual machine that needs to use the service network, and connect it to the service bridge to complete the access of the virtual machine to the service network.
[0096] It is important to note that when creating a business network, performance and bandwidth requirements should be considered, and appropriate network equipment, hardware specifications, and service providers should be selected to ensure the stability and reliability of the business network. Simultaneously, regarding the security management of the business network, it is necessary to strengthen the configuration and management of security measures such as network access control and firewalls to protect the security and privacy of business operations.
[0097] As a further optional embodiment, a NAT gateway is created under the management network and the service network according to the user's specification requirements, the NAT gateway image, and the flavor specification, specifically including:
[0098] Create a NAT virtual machine instance based on the NAT gateway image;
[0099] Based on the specified requirements and the flavor specifications, allocate corresponding computing resources to the NAT virtual machine instance.
[0100] In this embodiment, before creating a dedicated NAT gateway, it is necessary to ensure that a service network has been created and a service bridge has been created within the service network.
[0101] Specifically, to create a primary / standby dedicated NAT gateway based on the NAT gateway management module within the cloud platform's architecture, according to the NAT gateway image and flavor specifications, the following steps can be followed:
[0102] Create a NAT virtual machine instance based on the NAT gateway image provided by the cloud platform.
[0103] Allocate sufficient computing, memory, and storage resources to the NAT virtual machine according to the flavor specification.
[0104] Configure the basic parameters and network parameters of the NAT gateway using the NAT gateway management module provided by the cloud platform.
[0105] Based on the architectural characteristics of the cloud platform itself, a master-slave mode is adopted, deploying two NAT virtual machine instances on different physical hosts to improve high availability and fault tolerance.
[0106] Configure the primary / standby status of the NAT virtual machine instance, and test and verify the primary / standby switchover.
[0107] It is important to note that when creating a dedicated NAT gateway, a thorough understanding of the business network topology is necessary to ensure that the deployment and configuration of the NAT gateway meet actual business needs and network security requirements. Simultaneously, appropriate NAT gateway specifications and flavor specifications should be selected based on actual business volume and network traffic to guarantee the stability and performance of the NAT gateway.
[0108] The following describes the implementation apparatus for the edge cloud NAT gateway provided by the present invention, such as... Figure 3 As shown, the implementation device of the edge cloud NAT gateway described below and the implementation method of the edge cloud NAT gateway described above can be referred to in correspondence.
[0109] The information acquisition unit 310 is used to acquire pre-set gateway creation information, which includes management bridge data, service bridge data, NAT gateway image data, and flavor specification data.
[0110] The management network establishment unit 320 is used to establish a management network in the cloud platform based on the management bridge data. The management network is used for the NAT gateway management module in the cloud platform to manage the NAT gateway.
[0111] The service network establishment unit 330 is used to call the service bridge data to establish a service network;
[0112] The NAT gateway creation unit 340 is used to create a NAT gateway under the management network and the service network according to the user's specification requirements, the NAT gateway image data and the flavor specification data. The NAT gateway includes a main gateway and a sub-gateway.
[0113] Figure 4 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 4 As shown, the electronic device may include: a processor 410, a communications interface 420, a memory 430, and a communication bus 440, wherein the processor 410, the communications interface 420, and the memory 430 communicate with each other through the communication bus 440. The processor 410 can call logical instructions in the memory 430 to execute an implementation method of the edge cloud NAT gateway, the method including:
[0114] Obtain pre-set gateway creation information, which includes management bridge data, service bridge data, NAT gateway image data, and flavor specification data;
[0115] A management network is established in the cloud platform based on the management bridge data. The management network is used by the NAT gateway management module in the cloud platform to manage the NAT gateway.
[0116] The service network is established by calling the service bridge data;
[0117] Based on the user's specifications, the NAT gateway image data, and the flavor specification data, a NAT gateway is created under the management network and the service network. The NAT gateway includes a main gateway and sub-gateways.
[0118] Furthermore, the logical instructions in the aforementioned memory 430 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0119] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to perform the implementation method of the edge cloud NAT gateway provided by the above methods, the method comprising:
[0120] Obtain pre-set gateway creation information, which includes management bridge data, service bridge data, NAT gateway image data, and flavor specification data;
[0121] A management network is established in the cloud platform based on the management bridge data. The management network is used by the NAT gateway management module in the cloud platform to manage the NAT gateway.
[0122] The service network is established by calling the service bridge data;
[0123] Based on the user's specifications, the NAT gateway image data, and the flavor specification data, a NAT gateway is created under the management network and the service network. The NAT gateway includes a main gateway and sub-gateways.
[0124] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0125] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0126] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for implementing an edge cloud NAT gateway, characterized in that, include: Obtain pre-set gateway creation information, which includes management bridge data, service bridge data, NAT gateway image data, and flavor specification data; A management network is established in the cloud platform based on the management bridge data. The management network is used by the NAT gateway management module in the cloud platform to manage the NAT gateway. The service network is established by calling the service bridge data; Based on the user's specifications, the NAT gateway image data, and the flavor specification data, a NAT gateway is created under the management network and the service network. The NAT gateway includes a main gateway and a sub-gateway. The gateway creation information also includes egress gateway mirror data. After creating a NAT gateway under the management network and the service network according to the user's specifications, the NAT gateway mirror data, and the flavor specification data, it also includes: Multiple egress gateway instances are created on the business network based on the egress gateway mirror data; the egress gateway is a master-master shared egress gateway. Configure a corresponding IP address for each egress gateway to establish communication connections between each egress gateway, between NAT gateways and egress gateways, and between egress gateways and physical switches.
2. The implementation method of the edge cloud NAT gateway according to claim 1, characterized in that, After establishing the service network by invoking the service bridge data, the process also includes: The NAT gateway management module controls the management network to call the NAT gateway's API interface to establish a communication connection with the business network.
3. The implementation method of the edge cloud NAT gateway according to claim 1, characterized in that, After creating a NAT gateway under the management network and the service network based on the user's specifications, the NAT gateway image data, and the flavor specification data, the process further includes: Get the address translation rules sent by the user; The NAT gateway management module sends the address translation rules to the NAT gateway for IP address translation.
4. The implementation method of the edge cloud NAT gateway according to claim 1, characterized in that, Establishing a management network in the cloud platform based on the management bridge data specifically includes: Based on the management bridge data, establish a management bridge in the cloud platform; Configure a corresponding IP address for the management bridge to establish a communication connection with the NAT gateway management module in the cloud platform; The management bridge is used as the network connection of the management network, and the management network is established through the cloud platform.
5. The implementation method of the edge cloud NAT gateway according to claim 1, characterized in that, Establishing a service network by invoking the service bridge data specifically includes: Based on the business bridge data, establish a business bridge in the cloud platform; Configure a corresponding IP address for the service bridge to establish a communication connection with the service network; The service bridge is used as the network connection of the service network, and the service network is established through the cloud platform.
6. The implementation method of the edge cloud NAT gateway according to claim 1, characterized in that, Based on the user's specifications, the NAT gateway image data, and the flavor specification data, a NAT gateway is created under the management network and the service network, specifically including: Create a NAT virtual machine instance based on the NAT gateway image; Based on the specified requirements and the flavor specification data, allocate corresponding computing resources to the NAT virtual machine instance.
7. An implementation device for an edge cloud NAT gateway, characterized in that, include: The information acquisition unit is used to acquire pre-set gateway creation information, which includes management bridge data, service bridge data, NAT gateway image data, and flavor specification data. A management network establishment unit is used to establish a management network in the cloud platform based on the management bridge data. The management network is used for the NAT gateway management module in the cloud platform to manage the NAT gateway. A service network establishment unit is used to call the service bridge data to establish a service network; A NAT gateway creation unit is used to create a NAT gateway under the management network and the service network according to the user's specification requirements, the NAT gateway image data and the flavor specification data. The NAT gateway includes a main gateway and a sub-gateway. The gateway creation information also includes egress gateway mirror data. After creating a NAT gateway under the management network and the service network according to the user's specifications, the NAT gateway mirror data, and the flavor specification data, the device is further used to: Multiple egress gateway instances are created on the business network based on the egress gateway mirror data. The egress gateway is a master-master shared egress gateway; Configure a corresponding IP address for each egress gateway to establish communication connections between each egress gateway, between NAT gateways and egress gateways, and between egress gateways and physical switches.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the edge cloud NAT gateway implementation method as described in any one of claims 1 to 6.
9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method for implementing the edge cloud NAT gateway as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Method for cloud host intercommunication between different virtual private networks and implementation architecture
CN113965505A
Heterogeneous virtual gateway management system and method in edge computing scene
CN114979139A