Traffic orchestration method, service chain orchestration platform and storage medium

By configuring address translation policies in traffic orchestration devices, the problem of increasing the amount of data carried by IP addresses in network traffic is solved, and efficient traffic transmission is achieved.

CN116668400BActive Publication Date: 2025-10-03QI AN XIN TECHNOLOGY GROUP INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310579751.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-22
Publication Date
2025-10-03
Estimated Expiration
2043-05-22

AI Technical Summary

Technical Problem

In the prior art, network traffic carries various IP addresses and their corresponding relationships, which increases the data volume of the network traffic and reduces transmission efficiency.

Method used

By configuring the address translation policy in the traffic orchestration device and determining the address translation timing, the first address information of the sending device is converted into the second address information of the network where the receiving device is located. During the transmission process, only the first address information of the sending network is carried, thereby reducing the amount of data in the traffic.

Benefits of technology

It improves the transmission efficiency of network traffic, ensures that the traffic can reach the receiving device correctly, and reduces the amount of transmitted data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116668400B_ABST
    Figure CN116668400B_ABST
Patent Text Reader

Abstract

The present application provides a traffic orchestration method, a service chain orchestration platform, and a storage medium. The traffic orchestration method includes: a sending device sends a first traffic to a traffic orchestration device, wherein the first traffic contains first address information of a sending network where the sending device is located; the traffic orchestration device determines an address conversion timing, and when the address conversion timing is reached, based on an address conversion strategy, converts the first address information in the first traffic into second address information of a receiving network where a receiving device is located, thereby obtaining a second traffic; the traffic orchestration device sends the second traffic to the receiving device based on the second address information. In this way, while ensuring that the traffic transmitted by the sending device can correctly reach the receiving device, the transmitted traffic no longer needs to carry the second address information of the receiving network where the receiving device is located, and only needs to carry the first address information of the sending network, thereby reducing the amount of data in the transmitted traffic and improving the transmission efficiency of the orchestrated traffic.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of traffic orchestration, and in particular to a traffic orchestration method, a service chain orchestration platform, and a storage medium. Background Art

[0002] With the rapid development of cloud computing, the Internet of Things, and mobile smart devices, network traffic is rapidly increasing, and a variety of network elements are proliferating. Traditional network architectures are increasingly unable to meet the dynamic demands of network traffic and network elements, leading to the emergence of service chaining technology. Service Function Chaining (SFC) refers to the process of routing network traffic through various network elements (NFs) in a user-defined sequence based on business logic requirements, thereby forming an orderly network service combination. Users use traffic orchestration devices to orchestrate service chains.

[0003] The specific process for controlling network traffic flow through various network elements using a traffic orchestration device is as follows: When a service logic requirement exists, for example, network traffic needs to flow from a sending device through network element A, then through network element B, and finally to a receiving device, the user connects the traffic orchestration device to the sending device, network element A, network element B, and the receiving device, and configures the order in which network traffic is forwarded to each network element in the traffic orchestration device. When the sending device has network traffic to send to the receiving device, the sending device sends the traffic to the traffic orchestration device. The traffic orchestration device forwards the traffic to network element A. After processing the traffic, network element A sends the processed traffic to the traffic orchestration device. The traffic orchestration device forwards the processed traffic to network element B. After processing the traffic, network element B sends the processed traffic to the traffic orchestration device. The traffic orchestration device ultimately forwards the processed traffic to the receiving device.

[0004] The Internet Protocol (IP) addresses used by the network element device and the traffic orchestration device may be different. The network traffic that the network element device needs to transmit needs to undergo address translation after it flows to the traffic orchestration device, and the network traffic transmitted by the traffic orchestration device also needs to undergo address translation after it flows to the network element device. This requires Network Address Translation (NAT), which includes source address translation and destination address translation. When network traffic is forwarded step by step through the traffic orchestration device, the network traffic needs to carry the IP address of each network element device before and after conversion, so that the traffic orchestration device can forward the network traffic step by step based on the IP addresses carried in the network traffic. However, carrying each IP address and their corresponding relationship in the network traffic will increase the data volume of the network traffic, thereby reducing the transmission efficiency of the network traffic. Summary of the Invention

[0005] The purpose of the embodiments of the present application is to provide a traffic orchestration method, a service chain orchestration platform and a storage medium to improve the transmission efficiency of network traffic.

[0006] To solve the above technical problems, the embodiments of the present application provide the following technical solutions:

[0007] In a first aspect, the present application provides a traffic orchestration method, which is applied to a service chain orchestration platform, wherein the service chain orchestration platform includes: a sending device, a traffic orchestration device, and a receiving device, wherein the traffic orchestration device is configured with an address conversion policy for converting an address under a sending network into an address under a receiving network, and the method includes: the sending device sends a first traffic to the traffic orchestration device, wherein the first traffic includes first address information under the sending network where the sending device is located; the traffic orchestration device determines an address conversion timing, and when the address conversion timing is reached, converts the first address information in the first traffic into second address information under the receiving network where the receiving device is located based on the address conversion policy to obtain a second traffic; and the traffic orchestration device sends the second traffic to the receiving device based on the second address information.

[0008] The second aspect of the present application provides a service chain orchestration platform, which includes: a sending device, a traffic orchestration device and a receiving device, wherein the traffic orchestration device is configured with an address conversion strategy for converting an address under a sending network into an address under a receiving network; the sending device is configured to send a first traffic to the traffic orchestration device, wherein the first traffic includes first address information under the sending network where the sending device is located; the traffic orchestration device is configured to determine an address conversion timing, and when the address conversion timing is reached, convert the first address information in the first traffic into second address information under the receiving network where the receiving device is located based on the address conversion strategy to obtain a second traffic; the traffic orchestration device is further configured to send the second traffic to the receiving device based on the second address information.

[0009] A third aspect of the present application provides a computer-readable storage medium, the storage medium comprising: a stored program; wherein, when the program is executed, the device where the storage medium is located is controlled to execute the method in the first aspect.

[0010] Compared to the prior art, the traffic orchestration method provided in the first aspect of this application is that after the traffic orchestration device receives the first traffic sent by the sending device, it determines the address conversion timing of the first address information in the first traffic, and when the address conversion timing is reached, the first address information is converted into the second address information of the receiving network where the receiving device is located, and then the second traffic containing the second address information is sent to the receiving device. In this way, on the basis of ensuring that the traffic transmitted by the sending device can correctly reach the receiving device, the transmitted traffic does not need to carry more context information, that is, it does not need to carry the second address information of the receiving network where the receiving device is located, and only the first address information of the sending network is required. This can reduce the amount of data in the transmitted traffic and thus improve the transmission efficiency of the orchestrated traffic.

[0011] The service chain orchestration platform provided in the second aspect of this application and the computer-readable storage medium provided in the third aspect have the same or similar beneficial effects as the traffic orchestration method provided in the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] The above and other objects, features and advantages of the exemplary embodiments of the present application will become readily understood by reading the detailed description below with reference to the accompanying drawings. In the accompanying drawings, several embodiments of the present application are shown in an exemplary and non-limiting manner, and the same or corresponding reference numerals represent the same or corresponding parts, wherein:

[0013] Figure 1 Schematic diagram of the overall architecture of the traffic orchestration method in an embodiment of the present application;

[0014] Figure 2 Schematic diagram of the flow of the traffic arrangement method in the embodiment of the present application;

[0015] Figure 3 Schematic diagram of the traffic orchestration process in an embodiment of the present application;

[0016] Figure 4 This is a structural diagram of the service chain orchestration platform in an embodiment of the present application. DETAILED DESCRIPTION

[0017] The following describes exemplary embodiments of the present application in more detail with reference to the accompanying drawings. Although exemplary embodiments of the present application are shown in the accompanying drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments described herein. Instead, these embodiments are provided to enable a more thorough understanding of the present application and to fully convey the scope of the present application to those skilled in the art.

[0018] It should be noted that, unless otherwise specified, the technical or scientific terms used in this application should have the common meanings understood by those skilled in the art to which this application belongs.

[0019] At present, if the traffic needs to be NAT converted on the traffic orchestration device, the traffic orchestration device needs to confirm: 1. Whether the traffic currently forwarded to the service chain network element has been NAT converted. 2. After the traffic orchestration device receives the traffic from the service chain network element, how to find the original forwarding path information of the traffic based on the traffic information. In patent CN111158864A, the corresponding approach is given, specifically: 1. The traffic sent to the service chain network element is the original source address and the real destination address, that is, the address before SNAT and after DNAT. However, this method cannot support NAT46 and NAT64 conversion, and is not friendly to the support of the application layer gateway (ALG). 2. By modifying the MAC address of the data packet, the context of the forwarding path is carried. However, this method modifies the original MAC information, and the service chain network element cannot perceive the real MAC information.

[0020] After research, the inventors found that if the following two sequences can be controlled by the traffic orchestration device: 1. The order in which the traffic orchestration device forwards to the service chain network element and performs NAT conversion. 2. The order of interfaces sent to the service chain network element. By stipulating the order of 1 and 2 by rules, the traffic orchestration device can clearly determine whether the current traffic has passed through NAT after receiving the traffic from the service chain network element, so that it can match the context of the forwarding path according to the five-tuple information of the data packet (source address, destination address, source port, destination port, protocol). In this way, repetitive work (for example: five-tuple information conversion, etc.) is handed over to the traffic orchestration device for execution, and the network element device focuses on specific security services. On the one hand, it can improve the efficiency of traffic transmission, and on the other hand, the network element device can be flexibly deployed and easy to troubleshoot problems.

[0021] In view of this, an embodiment of the present application provides a traffic orchestration method, a service chain orchestration platform, and a storage medium. After a sending device in the service chain orchestration platform sends a first traffic flow containing first address information of a sending network where the sending device is located to the traffic orchestration device, the traffic orchestration device in the platform determines an address conversion timing, and when the address conversion timing is reached, based on the address conversion strategy, converts the first address information in the first traffic flow into second address information of a receiving network where the receiving device is located, obtains a second traffic flow, and sends the second traffic flow to the receiving device based on the second address information. In this way, on the basis of ensuring that the traffic transmitted by the sending device can correctly reach the receiving device, the transmitted traffic does not need to carry more context information, that is, it does not need to carry the second address information of the receiving network where the receiving device is located, and only the first address information of the sending network is required. This can reduce the amount of data in the transmitted traffic flow, thereby improving the transmission efficiency of the orchestrated traffic flow.

[0022] First, the overall architecture of the traffic orchestration method provided in the embodiment of the present application is described.

[0023] Figure 1 This is a schematic diagram of the overall architecture of the traffic orchestration method in the embodiment of the present application, see Figure 1 As shown, the architecture may include: a sending device, a network element device, a traffic orchestration device, and a receiving device. The traffic orchestration device includes an address translation module.

[0024] The sending device is the device that produces the traffic to be transmitted.

[0025] A network element device is a device that the traffic to be transmitted needs to pass through after it is sent from the sending device to the receiving device.

[0026] The traffic orchestration device is connected to the two interfaces of the network element device, receives the traffic sent by the sending device, and forwards the traffic to the network element device, and then receives the traffic sent by the network element device and forwards the traffic to the receiving device. Through the traffic orchestration device, the order of one or more network element devices that need to be passed between the sending device and the receiving device can be orchestrated. In addition, the traffic orchestration device also includes an address conversion module. The traffic orchestration device can process traffic according to different traffic forwarding and address conversion orders based on the different transmission directions of the traffic. That is, when traffic is sent from inside to outside, the traffic is first transmitted according to the preset transmission path and then the address information in the traffic is converted. When traffic is sent from outside to inside, the address information in the traffic is first converted and then the traffic is transmitted according to the preset transmission path.

[0027] The receiving device is the device that ultimately receives the traffic.

[0028] Next, based on the above architecture, the traffic orchestration method provided in the embodiment of the present application is described in detail.

[0029] Figure 2 This is a flow chart of the traffic orchestration method in the embodiment of the present application, see Figure 1 As shown, the method is applied to a service chain orchestration platform. The service chain orchestration platform includes: a sending device, a traffic orchestration device, and a receiving device. The traffic orchestration device is configured with an address translation policy for translating an address under a sending network into an address under a receiving network.

[0030] The method may include:

[0031] S201: A sending device sends first traffic to a traffic orchestration device.

[0032] The first traffic includes first address information of the sending network where the sending device is located.

[0033] The address information here may refer to five-tuple information, namely, source address, destination address, source port, destination port, and protocol.

[0034] When a sending device needs to transmit data to a receiving device, it doesn't send the traffic directly to the receiving device. Instead, it passes through several devices, called network elements. The order in which traffic is transmitted among these network elements is orchestrated by a traffic orchestration device. When a sending device needs to send a first flow of traffic to a receiving device, it sends the first flow. The traffic orchestration device receives the first flow and forwards it to each network element according to the order of traffic transmission and address translation, as well as the forwarding order pre-arranged by the traffic orchestration device. Finally, the first flow of traffic is delivered to the receiving device.

[0035] The network on which the sending device resides is called the sending network. When the sending device needs to send the first traffic to the receiving device, the sending device must include the sending device's address information on the sending network, namely, the source address, source port, and other information, as well as the receiving device's address information on the sending network, namely, the destination address, destination port, and other information, in the first traffic. In this way, after the traffic orchestration device completes forwarding the first traffic and converting the address information, it can send the first traffic to the receiving device based on the receiving device's address information on the receiving network. Subsequently, the receiving device can feed back the corresponding traffic to the sending device based on the sending device's address information on the receiving network.

[0036] S202: The traffic orchestration device determines an address conversion timing, and when the address conversion timing is reached, converts the first address information in the first traffic into second address information of the receiving network where the receiving device is located based on the address conversion policy to obtain second traffic.

[0037] After receiving the first traffic, the traffic orchestration device undergoes two processing stages. One stage forwards the first traffic along the pre-set transmission path among the network elements. The other stage converts the first address information in the first traffic into the second address information for the receiving device's network. The order in which these two stages are executed affects the accuracy of the final traffic orchestration. The decision on which stage to execute first, and therefore the timing of the address conversion, is based on the first address information in the first traffic.

[0038] From the first address information, the transmission direction of the first traffic can be determined. There are two transmission directions of the first traffic: from the intranet to the extranet and from the extranet to the intranet. Different transmission directions of the first traffic correspond to different processing flows. When the first address information corresponds to the transmission direction from the intranet to the extranet, the corresponding processing flow is to first transmit the first traffic and then convert the first address information in the first traffic. When the first address information corresponds to the transmission direction from the extranet to the intranet, the corresponding processing flow is to first convert the first address information in the first traffic to obtain the second address information. Accordingly, due to the change in the address information in the first traffic, the first traffic becomes the second traffic, and then the second traffic is transmitted. The second traffic contains the second address information of the receiving network where the receiving device is located.

[0039] After determining the conversion timing of the first address in the first traffic, the first traffic can be processed based on the conversion timing. When the traffic is transmitted first and the address information in the traffic is converted, the first traffic can be transmitted in the network element device according to the preset transmission path, and the first address information in the first traffic can be converted into the second address information of the receiving network where the receiving device is located, thereby obtaining the second traffic containing the second address information of the receiving network. When the address information is converted first and the traffic is transmitted, the first address information in the first traffic can be converted into the second address information of the receiving network where the receiving device is located, and then the second traffic containing the second address information can be transmitted in the network element device according to the preset transmission path.

[0040] Regardless of whether transmission or conversion is performed first, the address information in the second traffic finally obtained becomes the receiving network where the receiving device is located. In this way, the first traffic after transmission and conversion, that is, the second traffic, can be transmitted to the receiving device according to the address information under the receiving network, and the receiving device can know which sending device sent the data.

[0041] S203: The traffic orchestration device sends the second traffic to the receiving device based on the second address information.

[0042] After the first traffic completes the transmission of the network element device and the conversion of the address information to obtain the second traffic, the traffic orchestration device can correctly forward the second traffic to the receiving device according to the address information in the second traffic to complete the traffic orchestration from the sending device to the receiving device.

[0043] As can be seen from the above content, in the traffic orchestration method provided by the embodiment of the present application, after the sending device in the service chain orchestration platform sends the first traffic containing the first address information of the sending network where the sending device is located to the traffic orchestration device, the traffic orchestration device in the platform determines the address conversion timing, and when the address conversion timing is reached, based on the address conversion strategy, converts the first address information in the first traffic into the second address information of the receiving network where the receiving device is located, obtains the second traffic, and sends the second traffic to the receiving device based on the second address information. In this way, on the basis of ensuring that the traffic transmitted by the sending device can correctly reach the receiving device, the transmitted traffic does not need to carry more context information, that is, it does not need to carry the second address information of the receiving network where the receiving device is located, and only the first address information of the sending network is required, which can reduce the amount of data in the transmitted traffic and thereby improve the transmission efficiency of the orchestrated traffic.

[0044] Furthermore, as a refinement of the above step S202, when determining the transmission order of the first traffic and the order of address conversion according to the first address information, it can be determined according to session information (session) in the session record of the traffic orchestration device.

[0045] Specifically, the above step S202 may include:

[0046] Step A1: extracting first address information from first traffic.

[0047] The address information here may refer to five-tuple information, for example, from which address and port, to which address and port the first traffic is sent, and the protocol used.

[0048] Step A2: Determine whether session information including the first address information exists in the traffic orchestration device. If yes, execute step A3; if no, execute step A4.

[0049] The session log stores multiple session information. Each session information includes different address information between the sending and receiving devices, from the intranet to the extranet, and from the extranet to the intranet. The sending device can correspond to either the intranet or the extranet, and the receiving device can correspond to either the extranet or the intranet. Address information from the intranet to the extranet corresponds to the process of first transmitting, then converting, while address information from the extranet to the intranet corresponds to the process of first converting, then transmitting.

[0050] When determining whether session information containing the address information of the first traffic flow exists in its session records, the traffic orchestration device compares the address information of the first traffic flow with each session information in the session records. If the address information exists, the traffic orchestration device determines the transmission direction corresponding to the address information from the existing session information, i.e., whether it is from the intranet to the extranet or from the extranet to the intranet. The device then determines the timing of address conversion based on the transmission direction, i.e., from the intranet to the extranet, the address information is first transmitted and then converted, and from the extranet to the intranet, the address information is first converted and then transmitted. If the address information does not exist, the device searches for a NAT conversion policy, converts the address information based on the conversion policy, and establishes a new session information. The new session information stores the address information of the first traffic flow and the transmission direction from the intranet to the extranet, as well as the converted address information and the transmission direction from the extranet to the intranet.

[0051] In other words, a session contains five-tuple information for both inbound and outbound directions. When a new packet arrives, the five-tuple in the new packet is matched against the session. If the inbound-to-outbound five-tuple matches the session, the new packet is transmitted from the intranet to the extranet. If the outbound-to-inbound five-tuple matches the session, the new packet is transmitted from the extranet to the intranet. If a match does not occur in the session, new address information and its transmission direction are created, along with the converted address information and its transmission direction. A new session is then created based on the forwarding path.

[0052] Step A3: Determine the transmission direction corresponding to the first address information from the session information, and determine the address conversion timing according to the transmission direction.

[0053] The session information includes each address and its corresponding transmission direction. When the transmission direction is from the intranet to the extranet, the corresponding address translation timing is to first transmit traffic, then perform address translation. When the transmission direction is from the extranet to the intranet, the corresponding address translation timing is to first perform address translation, then perform traffic transmission.

[0054] Step A4: establishing new session information based on the first address information, and determining the address conversion timing according to the transmission direction corresponding to the first address information in the new session information.

[0055] Among them, the new session information includes the first address information and its corresponding transmission direction, the converted address information (i.e., the second address information) and its corresponding transmission direction and transmission path. The converted address information is determined by the conversion strategy, and the transmission direction corresponding to the address information and the transmission direction corresponding to the converted address information and the subsequent transmission path are all determined by the diversion strategy and are all recorded in the new session information. When the transmission direction is from the intranet to the extranet, the corresponding address conversion timing is to perform traffic transmission first and then address conversion. When the transmission direction is from the extranet to the intranet, the corresponding address conversion timing is to perform address conversion first and then traffic transmission.

[0056] For example, assume that session information A records the source address X0, destination address Y0, and transmission direction from the intranet to the extranet in the sending network, and the source address Y1, destination address X1, and transmission direction from the extranet to the intranet in the receiving network. If the source address in the first flow is X0 and the destination address is Y0, the address information of the first flow is matched with session information A, and the transmission direction of the first flow is determined to be from the intranet to the extranet. If the source address in the first flow is A0 and the destination address is B0, the address information of the first flow is matched with session information A, and if there is no match, it is necessary to establish new session information for the address information of the first flow based on the conversion strategy and diversion strategy. Based on the conversion strategy, the source address A0 and destination address B0 in the first flow are converted to source address B1 and destination address A1, and based on the diversion strategy, the transmission direction is determined to be from the extranet to the intranet, and the transmission path is network element device 3-network element device 2-network element device 1.

[0057] The above only takes the address in the five-tuple information of the first transmission data as an example. When performing consistency matching with the session information in the session record, all information in the five-tuple information of the first transmission data is required.

[0058] From the above content, it can be seen that by matching the first address information in the first traffic with the session information in the traffic orchestration device, the transmission direction of the first traffic between the intranet and the extranet can be easily and quickly determined, and then the address conversion timing of the first address information in the traffic orchestration device can be determined to ensure the accurate transmission of the traffic.

[0059] Furthermore, as a refinement of step S202, during the transmission of the first traffic, in addition to determining the conversion timing of the first address information in the first traffic, it is also necessary to determine the transmission path of the first traffic between the network element devices. This can be determined based on session information in the session record of the traffic orchestration device. The session information is a data connection session, and the transmission path in the data connection session is obtained from the control connection session associated with it. Searching for the control connection session associated with the data connection session can be implemented by an application layer gateway (ALG).

[0060] Specifically, the above step S202 may include:

[0061] Step B1: extracting first address information from the first traffic.

[0062] The address information here may refer to five-tuple information, for example, from which address and port, to which address and port the first traffic is sent, and the protocol used.

[0063] Step B2: Determine whether a data connection session containing the first address information exists in the traffic orchestration device. If so, execute step B3; if not, execute step B4.

[0064] The session record stores multiple session information. Different session information includes the order in which each network element device transmits traffic between different sending devices and receiving devices, that is, the transmission path.

[0065] When determining whether a data connection session containing the first address information exists in its session record, the traffic orchestration device compares the first address information with the address information of each data connection session in the session record. If the address information exists, the traffic orchestration device determines the transmission path corresponding to the address information from the existing data connection session. If the address information does not exist, the traffic orchestration device searches for a traffic diversion policy, determines the transmission path for the first traffic based on the traffic diversion policy, and establishes a new data connection session. The address information of the first traffic and the determined transmission path are stored in the new data connection session.

[0066] Step B3: Determine the transmission path between the network element devices corresponding to the first address information from the data connection session.

[0067] The data connection session includes each address information and a transmission path between corresponding network element devices. The transmission path between network element devices corresponding to each address information is obtained from a control connection session related to the data connection session.

[0068] Step B4: adding a transmission path of the first address information between network element devices in the new data connection session based on the traffic diversion strategy.

[0069] The traffic diversion strategy here can be based on pre-set criteria for selecting network elements, such as selecting network elements with all current functions or selecting currently idle network elements, as well as pre-set criteria for sorting network elements based on their functions and relationships. This allows for the rapid generation of a transmission path, allowing the first traffic to complete its transmission process within the network elements.

[0070] For example, suppose data connection session A records the source address X0 and destination address Y0 on the sending network, along with the corresponding transmission path NE 1-NE 2-NE 3. Data connection session B records the source address W0 and destination address Z0 on the sending network, along with the corresponding transmission path NE 4-NE 5-NE 6. If the source address and destination address of the first flow on the sending network are X0 and X0, and the address information of the first flow is matched against the two data connection sessions, and a match is found with data connection session A, the transmission path between the first flow's network elements is determined to be NE 1-NE 2-NE 3. If the source address and destination address of the first flow on the sending network are H0 and K0, and the address information of the first flow is matched against the two data connection sessions, and no match is found, then the transmission path for the first flow must be generated based on the traffic diversion policy.

[0071] The above only takes the address in the five-tuple information of the first transmission data as an example. When performing consistency matching with the session information in the session record, all information in the five-tuple information of the first transmission data is required.

[0072] Step B5: Control the transmission of the first flow / the second flow between network element devices based on the transmission path.

[0073] After determining the transmission path, if the first traffic needs to be transmitted first and then address translated, then the first traffic will be transmitted along the transmission path. If the first traffic needs to be translated first and then transmitted, then the first address in the first traffic will be translated into the second address first, and the first traffic will become the second traffic accordingly, and the second traffic will be transmitted along the transmission path.

[0074] From the above content, it can be seen that before transmitting the first traffic in each network element device, it is first determined whether there is a data connection session in the session record that contains the first address information in the first traffic. If so, the first traffic can be transmitted directly based on the transmission path in the data connection session without generating the transmission path again, thereby reducing the number of times the transmission path is generated, speeding up the data transmission process, and improving traffic orchestration efficiency.

[0075] Furthermore, as a refinement of the above-mentioned step B5, after determining the transmission direction of the first traffic, that is, from the intranet to the external network, or from the external network to the intranet, and determining the transmission path of the first traffic, that is, the connection order between the network element devices that transmit the traffic, since the transmission path stored in the traffic orchestration device is only in a certain direction, the traffic orchestration device next needs to determine from which end of the transmission path to start the transmission of the first traffic.

[0076] Specifically, the above step B5 may include:

[0077] Step C1: Determine a starting network element device in a transmission path of the first traffic according to a transmission direction of the first traffic.

[0078] Among them, when the transmission direction is from the intranet to the extranet, the starting network element device is the first network element device in the transmission path; when the transmission direction is from the extranet to the intranet, the starting network element device is the last network element device in the transmission path.

[0079] The transmission direction of the first traffic can be from the intranet to the extranet or from the extranet to the intranet.

[0080] The transmission path of the first traffic refers to the network elements that the traffic needs to pass through in sequence between the sending device and the receiving device. The transmission path here does not include the network element from which the traffic starts.

[0081] The transmission direction of the first traffic flow can be determined by the first address information in the first traffic flow. The transmission path of the first traffic flow is also determined by the address information in the first traffic flow. The specific determination method has been previously described in detail in steps A3, A4 and steps B3, B4, and will not be repeated here.

[0082] After determining the transmission direction of the first traffic flow, we can determine which network element device along the transmission path to start data transmission from. For example, if the transmission path is network element device a, network element device b, and network element device c, and the first traffic flow is from the intranet to the extranet, the starting network element device is network element device a, and the data is transmitted in the order of network element device a, network element device b, and network element device c. If the first traffic flow is from the extranet to the intranet, the starting network element device is network element device c, and the data is transmitted in the order of network element device c, network element device b, and network element device a.

[0083] Step C2: Starting from the starting network element device, control the transmission of the first flow / the second flow between the network element devices.

[0084] In general, when the sending device needs to send the first traffic to the receiving device, the sending device first sends the first traffic to the traffic orchestration device. The traffic orchestration device determines the transmission direction through the first address information in the first traffic, and determines the order of conversion of traffic orchestration and five-tuple information such as address according to the transmission direction. When performing traffic orchestration, the starting end is determined in the preset transmission path according to the transmission direction of the first traffic. The starting end is the starting network element device, and the first traffic is forwarded to the starting network element device. After the starting network element device processes the first traffic, it sends the processed data back to the traffic orchestration device. The traffic orchestration device selects the next network element device in the transmission path according to the transmission direction to send the first traffic.

[0085] For example, assume the traffic orchestration device orchestrates the corresponding service chains for network element devices 1, 2, and 3. The sending device needs to send data a to the receiving device. The sending device first sends data a to the traffic orchestration device. The traffic orchestration device determines that data a is from the intranet to the extranet and, therefore, transmits data a first, then converts the address and other quintuple information in data a. Before transmitting data a, it determines that data a begins transmission from network element device 1. Data a is first transmitted to network element device 1. After processing data a, network element device 1 sends data a back to the traffic orchestration device. The traffic orchestration device then sends data a to network element device 2, and so on.

[0086] From the above content, it can be seen that the starting network element device is determined in the corresponding transmission path according to the transmission direction of the first flow, and the first flow / second flow is transmitted to the starting network element device to ensure that the flow can be transmitted in the correct direction in the transmission path.

[0087] Furthermore, as a refinement of the above-mentioned step C2, when the traffic orchestration device sends traffic to the starting network element device in the transmission path, it needs to send traffic to the starting network element device through different types of interfaces, intranet interfaces or extranet interfaces, depending on the different transmission directions corresponding to the traffic.

[0088] Specifically, the above step C2 may include:

[0089] Step D1: Determine the interface type for sending the first traffic / second traffic to the starting network element device according to the transmission direction of the first traffic.

[0090] Among them, when the transmission direction is from the intranet to the extranet, the interface type for sending the first traffic in the traffic orchestration device is the intranet interface; when the transmission direction is from the extranet to the intranet, the interface type for sending the second traffic in the traffic orchestration device is the extranet interface.

[0091] After determining the transmission direction of the first traffic and the starting network element device in the transmission path of the first traffic, when the transmission direction of the first traffic is from the intranet to the extranet, determining to send the first traffic to the starting network element device through the intranet interface. When the transmission direction of the first traffic is from the extranet to the intranet, determining to send the second traffic to the starting network element device through the extranet interface.

[0092] Step D2: Send the first traffic / second traffic to the starting network element device through the interface corresponding to the determined interface type.

[0093] When determining to send the first traffic to the starting network element device through the intranet interface, since the first traffic is transmitted from the intranet to the external network, the first traffic is first transmitted and then the address is converted. During the traffic transmission process, the first address information in the first traffic has not yet been converted into the second address information, so the first traffic is transmitted. The first traffic is sent to the network element device through the intranet interface connected to the network element device by the traffic orchestration device, and then the first traffic sent back by the network element device is received through the external network interface connected to the network element device.

[0094] When determining to send the second traffic to the starting network element device through the external network interface, since the first traffic is transmitted from the external network to the internal network, the first traffic is first address converted and then traffic is transmitted. During the traffic transmission process, the first address information in the first traffic has been converted into the second address information, so the second traffic is transmitted. The second traffic is sent to the network element device through the external network interface connected to the network element device by the traffic orchestration device, and then the second traffic sent back by the network element device is received through the internal network interface connected to the network element device.

[0095] That is, on the network element, the pair of interfaces that connect to the intranet and extranet interfaces of the traffic orchestration device must be configured in Layer 2 interconnection mode. Data sent to the network element is sent from one of the interfaces in this pair and received back from the traffic orchestration device through the other interface.

[0096] From the above content, it can be seen that the interface type for sending the first flow or the second flow to the starting network element device is determined according to the transmission direction of the first flow, and the first flow or the second flow is sent to the starting network element device through the interface of this interface type, ensuring that the first flow or the second flow can be transmitted in the correct direction in the transmission path.

[0097] Furthermore, as a refinement of the above step B5, each time the traffic orchestration device receives traffic sent back by a network element device, it needs to determine the transmission direction of the traffic in the session information, and then determine the transmission path of the traffic, and then determine the next forwarding network element device from the transmission path, until all network element devices in the transmission path complete data forwarding.

[0098] Specifically, the above step B5 may include:

[0099] Step E1: Determine the interface type for receiving the first flow / the second flow from the current network element device.

[0100] The interface type includes at least one of an intranet interface and an extranet interface.

[0101] Each network element device is connected to the traffic orchestration device through two interfaces. These interfaces are configured as a Layer 2 interconnect on the network element device. The interfaces connecting the traffic orchestration device and the network element device are labeled as internal network interfaces and external network interfaces, respectively. The internal network interface of the traffic orchestration device can send data to and receive data from the network element device. The external network interface of the traffic orchestration device can also send data to and receive data from the network element device.

[0102] Step E2: When the interface type is an external network interface, match the first address information in the first flow with the address information in the session information, and use the next network element device of the current network element device in the transmission path corresponding to the successfully matched address information as the next network element device for transmitting the first flow, and send the first flow to the internal network interface connected to the next network element device.

[0103] Step E3: When the interface type is an intranet interface, the source address information and the destination address information in the second address information in the second traffic are swapped, the swapped second address information is matched with each address information in the session information, and the previous network element device of the current network element device in the transmission path corresponding to the matched address information is used as the next network element device for transmitting the first traffic, and the second traffic is sent to the external network interface connected to the next network element device.

[0104] After receiving traffic from a network element, the traffic orchestration device first determines whether the interface receiving the traffic is an intranet or extranet interface. If it is an extranet interface, the traffic is transmitted from the intranet to the extranet, and its address information is untranslated. The device can directly match the address information with the session information to find the transmission path corresponding to the address information. Furthermore, based on the internal-to-external transmission direction, the device can determine the next network element in the transmission path in the forward direction and transmit the traffic through the intranet interface connected to the next network element. If it is an intranet interface, the traffic is transmitted from the extranet to the intranet, and its address information has been translated. The device must first reverse the source and destination address information in the address information, then match it with the session information to find the transmission path corresponding to the address information. Based on the external-to-inside transmission direction, the device can determine the next network element in the transmission path in the reverse direction and transmit the traffic through the extranet interface connected to the next network element.

[0105] For example, session information includes source address X0 and destination address Y0 on the intranet, along with information from the intranet to the extranet, and source address Y1 and destination address X1 on the extranet, along with information from the extranet to the intranet, with the transmission path being NE 1, NE 2, and NE 3. When data a is received from NE 2, and the external interface receives data a, the address information X0->Y0 in data a is obtained and directly matched with the session information. This determines that the next sender is NE 3, and data a is sent to NE 3 via the intranet interface connected to NE 3. When data a is received from NE 2, and the internal interface receives data a, the address information Y0->X0 in data a is obtained. This is obtained by first converting Y1->X1, and the source and destination information is first reversed to X0->Y0. This is then matched with the session information to determine that the next sender is NE 1, and data a is sent to NE 1 via the external interface connected to NE 1.

[0106] After the next network element completes processing the traffic and sends it back to the traffic orchestration device, the traffic orchestration device continues to determine the next network element in the same manner as described above and sends the traffic to the next network element through the corresponding interface, until it reaches the last network element in the transmission path. After receiving the traffic from the last network element, the traffic orchestration device can then send the traffic to the receiving device or convert the address information in the traffic and send it to the receiving device.

[0107] From the above content, it can be seen that by receiving the interface type of the traffic from the network element device, it is determined whether the address information in the traffic is converted, and then the address information or the converted address information is matched with the session information, so that the corresponding address information can be successfully matched, and then the next network element device in the transmission path is determined to ensure the accuracy of data transmission in the transmission path.

[0108] Furthermore, as a refinement of step S202, the conversion strategy for converting the address information can be a simple method for processing the address, or a strategy for directly obtaining the converted address information from a certain location. The session information corresponding to the address information records the address information before conversion and its corresponding converted address information, and the address information in the traffic can be converted based on the session record.

[0109] Specifically, the above step S202 may include:

[0110] Step F1: Acquire target session information including first address information from the session information.

[0111] The target session information includes an address translation policy, which at least includes address information before translation and its corresponding address information after translation.

[0112] When the first address information in the first traffic needs to be converted, the first address information can be compared with the address information before and after conversion in each session information in the session record. If the comparison is successful, the session information in the session record that is consistent with the comparison is the target session information.

[0113] Step F2: Determine the second address information corresponding to the first address information according to the address translation policy in the target session information, and translate the first address information in the first traffic into the second address information of the receiving network where the receiving device is located.

[0114] For example, suppose a session record contains session information X0->Y0 (source and destination address information from the intranet to the extranet), and Y1->X1 (source and destination address information from the extranet to the intranet). If the address information in data a is X0->Y0, then it can be matched with the above session information. From this session information, the converted address information Y1->X1 can be directly obtained.

[0115] Furthermore, in practical applications, the traffic orchestration device is provided with an address translation module, which executes the address translation policy. The address translation module includes at least one of a NAT address translation module and an ALG address translation module. In other words, the traffic orchestration device in the embodiments of the present application can well support both NAT translation and ALG translation.

[0116] From the above content, it can be seen that the first address information in the first traffic is converted by recording the address information before and after the conversion in the session information. The conversion can be completed by searching in the session information, thereby improving the conversion efficiency of the address information and further improving the traffic orchestration efficiency.

[0117] Finally, the traffic orchestration method provided in this application is further explained with a complete embodiment.

[0118] For example, when client A transmits data to client B, the traffic orchestration device orchestrates a service function chaining (SFC) between client A and client B. The SFC consists of two network function elements (NFs), NF1 and NF2. Client A, NF1, and NF2 are considered to be on the intranet, while client B is considered to be on the extranet. To facilitate describing data direction, LAN2WAN represents "intranet to extranet," and WAN2LAN represents "extranet to intranet."

[0119] Figure 3 This is a schematic diagram of the flow arrangement process in the embodiment of this application, see Figure 3 As shown, when client A needs to send traffic to client B, client A sends the traffic to the traffic orchestration device, and the traffic orchestration device searches for the existence of the corresponding session based on the address information in the traffic (source, destination address, port and other five-tuple information). Session, or session, is a common component of stateful data communication equipment, used to store context information of the connection, including request five-tuple, response five-tuple, etc., with five-tuple information as index matching). If it does not exist, the NAT policy is searched to convert the address information in the traffic, and the transmission direction of the traffic is determined according to the diversion policy, that is, from the intranet to the extranet, or from the extranet to the intranet, and the transmission path of the traffic in each network element device is obtained, thereby establishing a session. Then the traffic direction is determined. If it exists, the traffic direction is directly determined.

[0120] Traffic direction can be determined based on the matching of address information in the traffic with address information in both directions within the session. For example, in a session, X0:m0->Y0:n0 corresponds to LAN2WAN, and Y1:n1->X1:m1 corresponds to WAN2LAN. If the address information in the traffic is X0:m0->Y0:n0, the traffic direction is LAN2WAN. If the address information in the traffic is Y1:n1->X1:m1, the traffic direction is WAN2LAN.

[0121] After determining the traffic direction, if the traffic is LAN2WAN, it first passes through the service chain, then undergoes NAT, ALG translation, and subsequent forwarding. If the traffic is WAN2LAN, it first passes through NAT, ALG translation, then passes through the service chain, and then passes through the service chain again. For example, in a NAT scenario, if the traffic is LAN2WAN, the traffic orchestration device receives traffic from X0:m0 to Y0:n0, and sends it to the service chain from X0:m0 to Y0:n0. If the traffic is WAN2LAN, the traffic orchestration device receives traffic from Y1:n1 to X1:m1, and after NAT and ALG processing, sends it to the service chain from Y0:n0 to X0:m0.

[0122] In a service chain, NF1 and NF2 are connected in series and recorded in the corresponding session. LAN-to-WAN traffic flows in the direction of NF1->NF2, while WAN-to-LAN traffic flows in the direction of NF2->NF1. If the traffic flows in the direction of LAN-to-WAN, it flows through the service chain in the order of NF1->NF2. If the traffic flows in the direction of WAN-to-LAN, it flows through the service chain in the order of NF2->NF1.

[0123] When sending traffic to a service chain, the traffic orchestration device sends the traffic to the NEs in the service chain through the interfaces connected to the NEs in the service chain. If the traffic is directed LAN2WAN, the traffic is sent to the service chain's internal network interface LAN1, which is connected to interface E1 of the first NE NF1 in the service chain. If the traffic is directed WAN2LAN, the traffic is sent to the service chain's external network interface WAN2, which is connected to interface E2 of the first NE NF2 in the service chain.

[0124] When receiving traffic from a service chain NE, if the traffic is received from the service chain's external network interface (WAN1, which connects to NF1, and WAN2, which connects to NF2) (carrying the pattern X0:m0->Y0:n0), the session is directly matched. If the traffic is received from the service chain's internal network interface (LAN2, which connects to NF2, and LAN1, which connects to NF1) (carrying the pattern Y1:n1->X1:m1 after NAT translation to Y0:n0->X0:m0), the session is matched by reversing the source, destination, and port quintuple information, using X0:m0->Y0:n0. The session is then matched based on the information recorded in the session. If the traffic is at the last NF in the service chain, it is forwarded through NAT, ALG translation, or subsequent processes. If the traffic is at an intermediate NF in the service chain, it is sent to the next NF based on the traffic direction. If the direction of the traffic is LAN2WAN, it is sent to the service chain intranet interface (LAN) connected to the next NF. If the direction of the traffic is WAN2LAN, it is sent to the service chain extranet interface (WAN) connected to the next NF.

[0125] After the traffic passes through the service chain, if it is received from the service chain's external network interface (WAN), the traffic direction is LAN2WAN, and NAT and ALG are then performed to forward it. If the traffic is received from the service chain's internal network interface (LAN), the traffic direction is WAN2LAN, and no NAT and ALG processing is required, and it is forwarded directly.

[0126] Based on the same inventive concept, as an implementation of the above method, the embodiment of the present application also provides a service chain orchestration platform. Figure 4 This is a schematic diagram of the structure of the service chain orchestration platform in the embodiment of this application, see Figure 4 As shown, the service chain orchestration platform may include: a sending device 401, a traffic orchestration device 402, and a receiving device 403. The traffic orchestration device 402 is configured with an address translation policy for translating an address in a sending network into an address in a receiving network.

[0127] The sending device 401 is configured to send first traffic to the traffic orchestration device 402, where the first traffic includes first address information of a sending network where the sending device is located;

[0128] The traffic orchestration device 402 is configured to determine an address conversion opportunity, and when the address conversion opportunity is reached, convert the first address information in the first traffic into second address information of a receiving network where the receiving device is located based on the address conversion policy, to obtain second traffic;

[0129] The traffic orchestration device 402 is further configured to send the second traffic to the receiving device 403 based on the second address information.

[0130] Furthermore, the traffic orchestration device is specifically used to extract the first address information from the first traffic; determine whether there is session information containing the first address information in the traffic orchestration device; if so, determine the transmission direction corresponding to the first address information from the session information, the session information includes each address information and its corresponding transmission direction, and determine the address conversion timing according to the transmission direction, wherein, when the transmission direction is from the intranet to the extranet, the corresponding address conversion timing is to first perform traffic transmission and then perform address conversion; when the transmission direction is from the extranet to the intranet, the corresponding address conversion timing is to first perform address conversion and then perform traffic transmission; if not, establish new session information based on the first address information, the new session information includes the first address information and its corresponding transmission direction, and determine the address conversion timing according to the transmission direction corresponding to the first address information in the new session information.

[0131] Furthermore, the traffic orchestration device is also used to extract the first address information from the first traffic; determine whether there is a data connection session containing the first address information in the traffic orchestration device; if so, determine the transmission path between the network element devices corresponding to the first address information from the data connection session, and the data connection session includes the transmission path between each address information and its corresponding network element device, and the transmission path between the network element devices corresponding to each address information is obtained from the control connection session related to the data connection session; if not, add the transmission path of the first address information between the network element devices in the new data connection session based on the diversion strategy; and control the transmission of the first traffic / second traffic between the network element devices based on the transmission path.

[0132] Furthermore, the traffic orchestration device is specifically used to determine the starting network element device in the transmission path of the first traffic according to the transmission direction of the first traffic. When the transmission direction is from the intranet to the external network, the starting network element device is the first network element device in the transmission path; when the transmission direction is from the external network to the intranet, the starting network element device is the last network element device in the transmission path; starting from the starting network element device, the first traffic / the second traffic is controlled to be transmitted between network element devices.

[0133] Furthermore, the traffic orchestration device is specifically used to determine the interface type for sending the first traffic / the second traffic to the starting network element device based on the transmission direction of the first traffic. When the transmission direction is from the intranet to the extranet, the interface type is the intranet interface; when the transmission direction is from the extranet to the intranet, the interface type is the extranet interface; the first traffic / the second traffic is sent to the starting network element device through the interface corresponding to the determined interface type.

[0134] Furthermore, the traffic orchestration device is specifically used to determine the interface type for receiving the first traffic / the second traffic from the current network element device, and the interface type includes at least one of an intranet interface and an extranet interface; when the interface type is an extranet interface, the first address information in the first traffic is matched with each address information in the session information, and the network element device after the current network element device in the transmission path corresponding to the successfully matched address information is used as the next network element device for transmitting the first traffic, and the first traffic is sent to the intranet interface connected to the next network element device; when the interface type is an intranet interface, the source address information and the destination address information in the second address information in the second traffic are swapped, the swapped second address information is matched with each address information in the session information, and the network element device before the current network element device in the transmission path corresponding to the successfully matched address information is used as the next network element device for transmitting the second traffic, and the second traffic is sent to the extranet interface connected to the next network element device.

[0135] Furthermore, the address conversion strategy is recorded in the session information, and the traffic orchestration device is specifically used to obtain target session information including the first address information from the session information, the target session information includes the address conversion strategy, and the address conversion strategy at least includes the address information before conversion and its corresponding address information after conversion; according to the address conversion strategy in the target session information, the second address information corresponding to the first address information is determined, and the first address information in the first traffic is converted into the second address information under the receiving network where the receiving device is located.

[0136] Furthermore, the traffic orchestration device is provided with an address translation module, and the address translation policy is executed by the address translation module, wherein the address translation module includes at least one of a NAT address translation module and an ALG address translation module.

[0137] It should be noted that the description of the above platform embodiment is similar to the description of the above method embodiment and has similar beneficial effects as the method embodiment. For technical details not disclosed in the platform embodiment of this application, please refer to the description of the method embodiment of this application for understanding.

[0138] Based on the same inventive concept, an embodiment of the present application also provides a computer-readable storage medium, which may include: a stored program; wherein, when the program is running, the device where the storage medium is located is controlled to execute the method in one or more of the above embodiments.

[0139] It should be noted that the description of the above storage medium embodiment is similar to the description of the above method embodiment and has similar beneficial effects as the method embodiment. For technical details not disclosed in the storage medium embodiment of this application, please refer to the description of the method embodiment of this application for understanding.

[0140] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A traffic scheduling method, characterized in that: The method is applied to a service chain orchestration platform, the service chain orchestration platform including: a sending device, a traffic orchestration device, and a receiving device, wherein the traffic orchestration device is configured with an address conversion strategy for converting an address under a sending network into an address under a receiving network, and the method includes: The sending device sends first traffic to the traffic orchestration device, where the first traffic includes first address information of a sending network where the sending device is located; The traffic orchestration device determines an address conversion timing, and when the address conversion timing is reached, converts the first address information in the first traffic into second address information of a receiving network where the receiving device is located based on the address conversion policy, thereby obtaining a second traffic; The traffic orchestration device sends the second traffic to the receiving device based on the second address information.

2. The method according to claim 1, characterized in that The traffic orchestration device determines the address conversion timing, including: extracting the first address information from the first traffic; Determining whether session information including the first address information exists in the traffic orchestration device; If so, determining the transmission direction corresponding to the first address information from the session information, the session information including each address information and its corresponding transmission direction, and determining the address conversion timing according to the transmission direction, wherein, when the transmission direction is from the intranet to the extranet, the corresponding address conversion timing is to first perform traffic transmission and then perform address conversion; when the transmission direction is from the extranet to the intranet, the corresponding address conversion timing is to first perform address conversion and then perform traffic transmission; If not, new session information is established based on the first address information, the new session information including the first address information and its corresponding transmission direction, and the address conversion timing is determined according to the transmission direction corresponding to the first address information in the new session information.

3. The method according to claim 1, characterized in that Before the traffic orchestration device sends the second traffic to the receiving device based on the second address information, the method further includes: extracting the first address information from the first traffic; Determining whether a data connection session containing the first address information exists in the traffic orchestration device; If so, determining a transmission path between network element devices corresponding to the first address information from the data connection session, where the data connection session includes each piece of address information and a transmission path between the corresponding network element devices, and the transmission path between the network element devices corresponding to each piece of address information is obtained from a control connection session related to the data connection session; If not, adding a transmission path of the first address information between network element devices in the new data connection session based on the diversion strategy; The first flow / the second flow is controlled to be transmitted between network element devices based on the transmission path.

4. The method according to claim 3, characterized in that The controlling the transmission of the first flow / the second flow between network element devices based on the transmission path includes: Determine a starting network element device in a transmission path of the first traffic according to a transmission direction of the first traffic, where when the transmission direction is from the intranet to the extranet, the starting network element device is the first network element device in the transmission path; and when the transmission direction is from the extranet to the intranet, the starting network element device is the last network element device in the transmission path; Starting from the starting network element device, the first flow / the second flow is controlled to be transmitted between network element devices.

5. The method according to claim 4, characterized in that Starting from the starting network element device, controlling the first flow / the second flow to be transmitted between network element devices includes: Determine, according to the transmission direction of the first traffic, the interface type for sending the first traffic / the second traffic to the starting network element device; when the transmission direction is from the intranet to the extranet, the interface type is the intranet interface; when the transmission direction is from the extranet to the intranet, the interface type is the extranet interface; The first flow / the second flow is sent to the starting network element device through an interface corresponding to the determined interface type.

6. The method according to claim 3, characterized in that The controlling the transmission of the first flow / the second flow between network element devices based on the transmission path includes: Determine an interface type for receiving the first flow / the second flow from a current network element device, where the interface type includes at least one of an intranet interface and an extranet interface; When the interface type is an external network interface, matching the first address information in the first flow with each address information in the session information, using the next network element device after the current network element device in the transmission path corresponding to the successfully matched address information as the next network element device for transmitting the first flow, and sending the first flow to the internal network interface connected to the next network element device; When the interface type is an intranet interface, the source address information and the destination address information in the second address information in the second traffic are swapped, the swapped second address information is matched with each address information in the session information, and the previous network element device of the current network element device in the transmission path corresponding to the successfully matched address information is used as the next network element device for transmitting the second traffic, and the second traffic is sent to the external network interface connected to the next network element device.

7. The method according to claim 1, characterized in that The address translation policy is recorded in the session information, and the converting, based on the address translation policy, the first address information in the first traffic into the second address information of the receiving network where the receiving device is located includes: Acquire target session information including the first address information from the session information, wherein the target session information includes the address translation policy, and the address translation policy includes at least the address information before translation and its corresponding address information after translation; According to the address translation policy in the target session information, second address information corresponding to the first address information is determined, and the first address information in the first traffic is translated into second address information in a receiving network where a receiving device is located.

8. The method according to any one of claims 1 to 7, characterized in that The traffic orchestration device is provided with an address translation module, and the address translation policy is executed by the address translation module, wherein the address translation module includes at least one of a NAT translation module and an ALG translation module.

9. A service chain orchestration platform, characterized in that: The service chain orchestration platform includes: a sending device, a traffic orchestration device and a receiving device, wherein the traffic orchestration device is configured with an address conversion strategy for converting an address under a sending network into an address under a receiving network; A sending device, configured to send first traffic to the traffic orchestration device, where the first traffic includes first address information of a sending network where the sending device is located; a traffic orchestration device, configured to determine an address conversion opportunity, and when the address conversion opportunity is reached, convert the first address information in the first traffic into second address information of a receiving network where a receiving device is located based on the address conversion policy, to obtain a second traffic; The traffic orchestration device is further configured to send the second traffic to a receiving device based on the second address information.

10. A computer-readable storage medium, characterized in that The storage medium includes: a stored program; wherein, when the program is running, the device where the storage medium is located is controlled to execute the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Data processing method, device, system, medium and program

    CN111158864A

  • Message forwarding method and device, medium and product

    CN114900458A