Heat Migration Method, First Network Element, Service Device, Communication System, and Storage Medium

When migrating service access traffic between network devices, the negotiation mechanism between the first network element and the service device is used to adjust the five-tuple response packets to realize the hot migration of traffic, solving the interruption problem that may be caused by traffic migration and improving the user experience.

CN116962490BActive Publication Date: 2025-06-13SHENZHEN HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310943842.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-28
Publication Date
2025-06-13
Estimated Expiration
2043-07-28

AI Technical Summary

Technical Problem

In the case of equipment upgrade and maintenance or bandwidth resources tight, how to ensure that traffic migration during service access will not be interrupted and improve user experience.

Method used

The first mapping information sent by the second network element is received through the first network element, and the first indication information is sent to the service device, instructing the service device to set the five-tuple group of the first response message corresponding to the first application to the fourth address - the fourth port - the fifth address - the fifth port - the first protocol to send it to the first network element, thereby realizing the hot migration of traffic.

Benefits of technology

Ensure that traffic connected to the same session will not be interrupted when migrating between network devices, improving user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116962490B_ABST
    Figure CN116962490B_ABST
Patent Text Reader

Abstract

The present application discloses a hot migration method, a first network element, a service device, a communication system, and a storage medium. The first network element receives first mapping information sent by a second network element, where the first mapping information indicates the correspondence between a first address - a first port - a second address - a second port - a first protocol and a third address - a third port - a fourth address - a fourth port - a first protocol. The first network element and the second network element are configured with different address segments, and the third address belongs to the address segment of the second network element; the first network element sends first indication information to the service device, and the first indication information is used to instruct the service device to set the five-tuple of the first response message corresponding to the first application program to the fourth address - the fourth port - the fifth address - the fifth port - the first protocol and then send it to the first network element, where the fifth address belongs to the address segment of the first network element. The solution of the present application can ensure that the traffic of the same session connection will not be interrupted when migrating between network devices, improving the user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a hot migration method, a first network element, a service device, a communication system, and a storage medium. Background Art

[0002] A virtual private cloud (VPC) is an isolated and private virtual network environment applied by a user on the cloud. The user can freely configure the network segments of the VPC and deploy its own services (businesses) within the VPC. There may be overlapping network segments between different VPCs. To achieve service mutual access between different VPCs without changing the VPC network segment configuration, currently, network address translation (NAT) technology can be used to perform network address translation between VPCs, so as to achieve the accessibility of services in one VPC in other VPCs.

[0003] For example, as Figure 1 shown, VPC1 and VPC2 are two different VPCs. A certain service device 200 in VPC2 deploys a certain application program (APP), which is used to provide a certain service (such as a database service, a web service, etc.). The IP address of the service device 200 in VPC2 is IP4, and the port corresponding to the application program in the service device 200 is z. Assume that the service provided by the above application program in VPC2 is mapped by the group of "IP address + port" of IP2:y in VPC1. A certain process X in a certain terminal device 100 in VPC1 wants to access the above application program in VPC2, so it sends a request message externally. The quadruple of this request message (that is, the source IP address, the source port, the destination IP address, and the destination port, which will be represented by the source IP address: source port → destination IP address: destination port for easy description later) is IP1:x → IP2:y, and the protocol type of this request message is the TCP protocol. Among them, IP1 is the IP address of the terminal device 100 in VPC1, and x is the port number corresponding to the process X in the terminal device 100. Then, based on the NAT technology, the network device 300 replaces the quadruple of this request message with IP3:w → IP4:z and sends it to the service device 200, so as to achieve accessing the service in VPC2 in VPC1. Among them, IP3 is an address in the address pool configured by the network device 300, and IP3:w is used to map the process X in VPC1 in VPC2.

[0004] Due to reasons such as equipment upgrade and maintenance or tight bandwidth resources, the traffic during the above service access process may need to be migrated from network device 300 to another network device for corresponding network address translation, forwarding, etc. At this time, how to ensure that the above service access does not interrupt to improve the user experience has become an urgent problem to be solved. Summary of the Invention

[0005] This application provides a hot migration method, a first network element, a service device, a communication system, and a storage medium, which can ensure that the traffic of the same session connection does not interrupt during migration between network devices, thereby improving the user experience.

[0006] In a first aspect, this application provides a hot migration method. The first network element receives first mapping information sent by the second network element, where the first mapping information indicates the correspondence between a first address - first port - second address - second port - first protocol and a third address - third port - fourth address - fourth port - first protocol. The first network element and the second network element are configured with different address segments, the third address belongs to the address segment of the second network element, and the fourth address and the fourth port correspond to a first application program on the service device; the first network element sends first indication information to the service device, where the first indication information is used to instruct the service device to set the five-tuple of the first response message corresponding to the first application program to the fourth address - fourth port - fifth address - fifth port - first protocol and then send it to the first network element. The five-tuple includes the source IP address, source port, destination IP address, destination port, and protocol type in sequence, and the fifth address belongs to the address segment configured by the first network element; the first network element receives the first response message sent by the service device, replaces the five-tuple of the first response message with the second address, second port, first address, first port, and first protocol to obtain a second response message, and sends the second response message.

[0007] It should be noted that the five-tuple in the embodiments of this application includes the source IP address, source port, destination IP address, destination port, and protocol type, and has a sequential relationship. The five-tuple of a certain message is a tuple formed by extracting the above five pieces of information from the message and arranging them in the current order, but it does not mean that these five pieces of information were originally arranged in the above order in the message.

[0008] In this solution, the first address - first port in the first mapping information corresponds to a certain process on a certain terminal device (denoted as process X), and the fourth address - fourth port corresponds to a certain application on a certain service device (i.e., the first application, abbreviated as APP1), and APP1 is used to provide a certain service, which is not limited here. The second address - second port is a set of "IP address + port number" configured to map the fourth address - fourth port, and the third address - third port is a set of "IP address + port number" selected by the second network element to map the first address - first address. The five - tuple of the packet with the first address - first port - second address - second port - first protocol corresponds to the same session connection.

[0009] When the first mapping information migrates from the second network element to the first network element, the first network element will send the first indication information to the service device corresponding to the fourth address and fourth port in the first mapping information, so as to indicate that the service device will set the five - tuple of the first response packet corresponding to APP1 to the fourth address - fourth port - fifth address - fifth port and then send it to the first network element. Since the fifth address is an IP address in the address pool configured by the first network element, the first response packet corresponding to APP1 can be forwarded to the first network element (not to the second network element). Furthermore, the first network element can process the first response packet based on the first mapping information to obtain the second response packet. Since the destination IP address and destination port in the second response packet are the first address and first port, the second response packet can be forwarded to the node (the source node that requests to access APP1) corresponding to the first address and first port, so as to ensure that the traffic of the same session connection will not be interrupted after migration (i.e., realize traffic hot migration), thereby improving the user experience.

[0010] Based on the first aspect, in a possible implementation, before the first network element receives the first mapping information sent by the second network element, the second network element can, according to the first mapping information, replace the five - tuple of the received first packet with the third address, third port, fourth address, fourth port, and first protocol, so as to obtain the replaced packet, and then send the replaced packet to the service device. The five - tuple of the first packet includes the first address, first port, second address, second port, and first protocol. Before the first network element receives the first mapping information sent by the second network element, the second network element can also, according to the first mapping information, replace the five - tuple of the response packet sent by the service device with the second address, second port, first address, first port, and first protocol, so as to obtain the replaced response packet, and then send the replaced response packet. The five - tuple of the response packet includes the fourth address, fourth port, third address, third port, and first protocol.

[0011] That is to say, before the first mapping information is migrated from the second network element to the first network element, the second network element is responsible for processing (including operations such as NAT address translation and packet forwarding) packets related to the first mapping information, thereby enabling the node corresponding to the first address and the first port to access APP1 in the service device.

[0012] Based on the first aspect, in a possible implementation, the first network element receives a second packet, and the five-tuple of the second packet includes a first address, a first port, a second address, a second port, and a first protocol. Then, the first network element replaces the four-tuple of the second packet with a third address, a third port, a fourth address, and a fourth port according to the first mapping information to obtain a third packet, and the third packet includes first indication information. Subsequently, the first network element sends the third packet to the service device.

[0013] In this solution, the five-tuple of the second packet includes a first address, a first port, a second address, a second port, and a first protocol, representing that the node corresponding to the "first address and the first port" requests to access the "second address + second port". When the first network element receives the first mapping information sent by the second network element and then receives the second packet, it is found that the second packet belongs to the traffic of the session connection corresponding to the first address - first port - second address - second port - first protocol. Therefore, the first network element can, based on the first mapping information, replace the four-tuple of the second packet with a third address, a third port, a fourth address, and a fourth port to obtain a third packet, and add the first indication information to the third packet. Subsequently, the first indication information will be sent to the service device along with the third packet, enabling the service device to perform corresponding operations based on the first indication information carried in the third packet, that is, based on the first indication information, set the five-tuple of the corresponding first response packet for APP1 to the fourth address, the fourth port, the fifth address, the fifth port, and the first protocol, and then send the first response packet to the first network element.

[0014] Based on the first aspect, in a possible implementation, the third packet includes a first optional field, and the information in the first optional field includes a fifth address and a fifth port, and the first indication information includes the information in the first optional field.

[0015] That is to say, a first optional field can be added to the third packet, and part or all of the first indication information can be written in the first optional field. For example, the first indication information may include a third address, a third port, a fifth address, and a fifth port. All of the above content can be written in the first optional field, or only the fifth address and the fifth port (i.e., a new set of "IP address + port") in the first indication information can be written in the first optional field. At this time, the third address and the third port in the first indication information are located in the source IP address and source port fields in the header of the third packet.

[0016] Based on the first aspect, in a possible implementation, before the first network element sends the third message to the service device, the first network element may record the first replacement state between the third address-third port and the fifth address-fifth port. Then, when the first network element receives the first response message sent by the service device, the first network element may change the recorded first replacement state to a second replacement state, and replace the five-tuple of the first response message with the second address, the second port, the first address, the first port, and the first protocol to obtain a second response message, and send the second response message. Subsequently, the first network element receives the fourth message, and replaces the five-tuple of the fourth message with the fifth address, the fifth port, the fourth address, the fourth port, and the first protocol according to the recorded second replacement state to obtain a fifth message, and sends the fifth message to the service device. Among them, the five-tuple of the fourth message includes the first address, the first port, the second address, the second port, and the first protocol.

[0017] In this solution, the first network element sends the third message carrying the first indication information to the service device for negotiation with the service device, and locally records the first replacement state between the third address-third port and the fifth address-fifth port, indicating that the first network element wants to perform this replacement, but is still in negotiation and has not received confirmation from the service device whether it is allowed to perform this replacement (in order to be compatible with service devices that do not support NAT replacement, negotiation is required). Then, when the first network element receives the first response message sent by the service device, and confirms that the five-tuple of the first response message includes the fourth address, the fourth port, the fifth address, the fifth port, and the first protocol, it means that the service device supports performing this replacement. At this time, the first network element can change the recorded first replacement state to a second replacement state, indicating that the first network element has successfully negotiated with the service device, and the service device allows / supports performing the replacement operation between the third address-third port and the fifth address-fifth port. Subsequently, when the first network element receives the fourth message, and confirms that the five-tuple of the fourth message is the first address, the first port, the second address, the second port, and the first protocol, it can replace the five-tuple of the fourth message with the fifth address, the fifth port, the fourth address, the fourth port, and the first protocol according to the first mapping information and the second replacement state, so as to obtain a fifth message, and then send the fifth message to the service device. It should be understood that if it is in the first replacement state, indicating that the negotiation is not successful, the first network element will only perform the corresponding replacement on the fourth message based on the first mapping information, rather than replacing it with the fifth address + fifth port.

[0018] Based on the first aspect, in a possible implementation, the fifth message includes second indication information, where the second indication information is used to instruct the service device to send the source IP address and source port in the fifth message to the first application program after replacing them with the third address and the third port respectively, or the second indication information is used to instruct the service device to send the application layer information in the fifth message to the first application program.

[0019] Based on the first aspect, in a possible implementation, the fifth message includes a second optional field, the information in the second optional field includes a third address and the third port, and the second indication information includes the information in the second optional field.

[0020] In this solution, the fifth message may include a second optional field, and the information in the second optional field includes a third address and a third port (i.e., the old set of "IP address + port"), so that when the service device receives the fifth message, it can directly replace the source IP address and source port in the fifth message based on the information in the second optional field of the fifth message, and then send the application layer information in the fifth message to APP1.

[0021] Based on the first aspect, in a possible implementation, the first network element receives a second message, replaces the quadruple of the second message with a fifth address, a fifth port, a fourth address, and a fourth port to obtain a sixth message. The quintuple of the second message includes a first address, a first port, a second address, a second port, and a first protocol. The sixth message includes first indication information, and the first indication information is further used to instruct the service device to send the source IP address and source port in the sixth message to a first application program after replacing them with a third address and a third port respectively, or the first indication information is further used to instruct the service device to send the application layer information in the sixth message to the first application program. The first network element sends the sixth message to the service device.

[0022] In this solution, when the first network element receives the first mapping information sent by the second network element and then receives the second message, it is found that the second message belongs to the traffic of the session connection corresponding to the first address - first port - second address - second port - first protocol. Therefore, the first network element can select an IP address from its configured address pool as the fifth address and select a port as the fifth port, and then use "fifth address + fifth port" to replace "third address + third port" in the first mapping information. Furthermore, the five-tuple of the second message is replaced with the fifth address, fifth port, fourth address, fourth port, and first protocol to obtain the sixth message, and the first indication information is added to the sixth message. Subsequently, the first indication information is sent to the service device along with the sixth message, enabling the service device to perform corresponding operations based on the first indication information carried in the third message. It should be understood that the first network element and the service device in this solution do not negotiate whether the third address - third port can be replaced with the fifth address - fifth port (the negotiation process is omitted to improve efficiency). The first network element defaults that the service device supports the above replacement. Therefore, here the first network element directly replaces the source IP address + source port of the second message with "fifth address + fifth port" to obtain the sixth message, and carries the first indication information in the sixth message to inform the service device that the first network element has performed the corresponding replacement on the sixth network element. After the service device can perform the reverse replacement process on the sixth message based on the first indication information, the application layer information of the sixth message can be sent to APP1, thus ensuring that service access is not interrupted.

[0023] Based on the first aspect, in a possible implementation, the sixth message includes a second optional field, and the information in the second optional field includes the third address and the third port. The first indication information includes the information in the second optional field.

[0024] Based on the first aspect, in a possible implementation, the first address and the fourth address belong to the first private network and the second private network respectively, and there is an overlap in network segments (address conflict) between the first private network and the second private network.

[0025] That is to say, this solution can be used for service mutual access between different private networks with overlapping network segments. The private network can be a virtual private cloud (VPC) or other types of autonomous networks, which are not specifically limited here.

[0026] In a second aspect, the present application also provides a thermal migration method. The service device receives first indication information sent by a first network element. The service device includes a first application, and the five-tuple corresponding to the first application includes a third address, a third port, a fourth address, a fourth port, and a first protocol. Then, the service device sets the five-tuple of a first response message corresponding to the first application to the fourth address - fourth port - fifth address - fifth port - first protocol according to the first indication information. The five-tuple of the first response message includes the fourth address, the fourth port, the third address, the third port, and the first protocol. The five-tuple sequentially includes a source IP address, a source port, a destination IP address, a destination port, and a protocol type. The first network element and the second network element are configured with different address segments, and the third address and the fifth address belong to the address segments of the first network element and the second network element respectively. Subsequently, the service device sends the first response message to the first network element.

[0027] That is to say, when the service device receives the first indication information from the first network element, the service device, according to the requirements of the first indication information, sets the five-tuple in the first response message corresponding to APP1 to the fourth address - fourth port - fifth address - fifth port - first protocol and then sends it out. The fifth address belongs to the address pool of the first network element. Therefore, the first response message can be forwarded to the first network element. Then, the first network element can perform corresponding NAT processing on the first response message to obtain a second response message. Then, the second response message can be forwarded to the corresponding terminal device, ensuring that the traffic of the same session connection will not be interrupted.

[0028] Based on the second aspect, in a possible implementation, before the service device receives the first indication information sent by the first network element, the method further includes: the service device receives a replaced message sent by the second network element, and sends the replaced message or the application layer information in the above replaced message to the first application. The five-tuple of the replaced message includes the third address, the third port, the fourth address, the fourth port, and the first protocol; the service device sends a response message corresponding to the first application to the second network element, and the five-tuple of the response message includes the fourth address, the fourth port, the third address, the third port, and the first protocol.

[0029] Based on the second aspect, in a possible implementation, the service device receives a third message sent by the first network element. The five-tuple of the third message includes the third address, the third port, the fourth address, the fourth port, and the first protocol, and the third message contains the first indication information.

[0030] That is to say, the first indication information can be carried to the first network element along with the third message sent by the first network element. Then, the service device can, according to the requirements of the first indication information in the third message, replace the five-tuple of the first response message corresponding to APP1 with the fourth address - the fourth port - the fifth address - the fifth port - the first protocol and then send it to the first network element.

[0031] Based on the second aspect, in a possible implementation, the third message includes a first optional field, and the information in the first optional field includes the fifth address and the fifth port, and the first indication information includes the information in the first optional field.

[0032] Based on the second aspect, in a possible implementation, after the service device receives the third message sent by the first network element, the service device receives a fifth message sent by the first network element. The five-tuple of the fifth message includes the fifth address, the fifth port, the fourth address, the fourth port, and the first protocol. Then, the service device replaces the source IP address and the source port in the fifth message with the third address and the third port respectively and sends it to the first application. Alternatively, the service device sends the application layer information in the fifth message to the first application.

[0033] Based on the second aspect, in a possible implementation, the fifth message contains second indication information. The service device can, according to the second indication information in the fifth message, replace the source IP address and the source port in the fifth message with the third address and the third port respectively and send it to the first application. That is to say, the second indication information in the fifth message can directly trigger the service device to perform the above replacement. Alternatively, the service device can send the application layer information in the fifth message to the first application according to the second indication information.

[0034] Based on the second aspect, in a possible implementation, the fifth message includes a second optional field, and the information in the second optional field includes the third address and the third port, and the second indication information includes the information in the second optional field.

[0035] Based on the second aspect, in a possible implementation, the service device receives a sixth message sent by the first network element. The five-tuple of the sixth message includes the fifth address, the fifth port, the fourth address, the fourth port, and the first protocol, and the sixth message contains the first indication information. Then, the service device replaces the source IP address and the source port in the sixth message with the third address and the third port respectively according to the first indication information and then sends it to the first application. Alternatively, the service device sends the application layer information in the sixth message to the first application according to the first indication information.

[0036] Based on the second aspect, in a possible implementation, the sixth message includes a second optional field, the information in the second optional field includes a third address and a third port, and the second indication information includes the information in the second optional field.

[0037] Based on the second aspect, in a possible implementation, the first address and the fourth address belong to the first private network and the second private network respectively, and there is an overlap in network segments (address conflict) between the first private network and the second private network.

[0038] In a third aspect, the present application further provides a first network element (i.e., a network device), including a transceiver module and a processing module. The transceiver module is configured to receive first mapping information sent by a second network element, where the first mapping information indicates the correspondence between a first address - a first port - a second address - a second port - a first protocol and a third address - a third port - a fourth address - a fourth port - a first protocol. The first network element and the second network element are configured with different address segments, the third address belongs to the address segment of the second network element, and the fourth address and the fourth port correspond to a first application program on a service device; the transceiver module is further configured to send first indication information to the service device, where the first indication information is used to instruct the service device to set the five-tuple of the first response message corresponding to the first application program to the fourth address - the fourth port - the fifth address - the fifth port - the first protocol and then send it to the first network element. The five-tuple includes, in sequence, the source IP address, the source port, the destination IP address, the destination port, and the protocol type, and the fifth address belongs to the address segment configured by the first network element; the transceiver module is further configured to receive the first response message sent by the service device; the processing module is configured to replace the five-tuple of the first response message with the second address, the second port, the first address, the first port, and the first protocol to obtain a second response message; the transceiver module is further configured to send the second response message. The first network element in the third aspect may further include more modules, which are not limited here. The first network element in the third aspect is specifically configured to execute the method of any implementation in the first aspect. For details, refer to the previous introduction and will not be elaborated here.

[0039] In a fourth aspect, the present application further provides another first network element, including a processor and a memory. The processor is configured to execute instructions stored in the memory so that the first network element executes the method of any implementation in the first aspect.

[0040] Fifth aspect, the present application further provides a service device, including a transceiver module and a processing module. The transceiver module is configured to receive first indication information sent by a first network element, wherein the five-tuple corresponding to a first application program on the service device includes a third address, a third port, a fourth address, a fourth port, and a first protocol; the processing module is configured to set the five-tuple of a first response message corresponding to the first application program to a fourth address - fourth port - fifth address - fifth port - first protocol according to the first indication information, where the five-tuple sequentially includes a source IP address, a source port, a destination IP address, a destination port, and a protocol type, the first network element and the second network element are configured with different address segments, and the fifth address and the third address belong to the address segments of the first network element and the second network element respectively; the transceiver module is further configured to send the first response message to the first network element. The above service device may further include more modules, which are not limited herein. The service device in the fifth aspect is specifically configured to execute the method of any implementation scheme in the first aspect, which can be referred to the previous introduction and will not be elaborated herein.

[0041] Sixth aspect, the present application further provides a service device, including a processor and a memory, and the processor is configured to execute instructions stored in the memory to enable the service device to execute the method of any implementation scheme in the second aspect.

[0042] Seventh aspect, the present application further provides a communication system, including a first network element, a second network element in any implementation scheme of the third aspect or the fourth aspect, and a service device in any implementation scheme of the fifth aspect or the sixth aspect.

[0043] Eighth aspect, the present application further provides a computer-readable storage medium, including computer program instructions, and when the computer program instructions are executed by a computing device, the computing device executes the method of any implementation scheme in the first aspect or the second aspect. Description of the Drawings

[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for description in the embodiments will be briefly introduced below.

[0045] Figure 1 It is a schematic diagram of realizing service mutual access between different VPCs based on the NAT technology provided in the embodiment of the present application;

[0046] Figure 2 It is a schematic diagram of an application scenario provided in the embodiment of the present application;

[0047] Figure 3 It is a schematic diagram of the structure of a service device provided in the embodiment of the present application;

[0048] Figure 4It is a schematic diagram of a scenario after the migration of a NAT instance provided in an embodiment of the present application;

[0049] Figure 5 It is an interaction flowchart before traffic migration provided in an embodiment of the present application;

[0050] Figure 6 It is an interaction flowchart of a hot migration method provided in an embodiment of the present application;

[0051] Figure 7 It is an interaction flowchart of another hot migration method provided in an embodiment of the present application;

[0052] Figure 8 It is a schematic diagram of the processing process before and after hot migration provided in an embodiment of the present application;

[0053] Figure 9 It is a schematic diagram of the structure of a first network element provided in an embodiment of the present application;

[0054] Figure 10 It is a schematic diagram of the structure of another service device provided in an embodiment of the present application. Detailed implementation manners

[0055] Please refer to Figure 2 , Figure 2 It is a schematic diagram of an application scenario provided in an embodiment of the present application, including a terminal device 100, a service device 200, and a network device 300, which will be introduced separately below.

[0056] The terminal device 100 may be a device such as a personal computer (such as a laptop computer, a desktop computer, etc.), a server, or a mobile device, and the embodiments of the present application do not make specific limitations.

[0057] One or more applications (application, APP) are deployed on the service device 200, corresponding to different ports on the service device 200 respectively. Each application (or service software) is used to provide corresponding services, such as database services, web services, object storage services, load balancing services, data backup services, etc., and the embodiments of the present application do not make specific limitations on the types of services. The service device 200 may be a server, a network device, etc., and the embodiments of the present application also do not make specific limitations.

[0058] Optionally, a terminal device 100 and a service device 200 where the service it needs to access is located may be in different private networks or in the same private network. The above private network may be a virtual private cloud (VPC) or other types of autonomous / proprietary networks, which are not specifically limited in the embodiments of the present application. Among them, a VPC is a private network on the cloud built based on a cloud data center, which can build an isolated and private virtual network environment for cloud virtual instance resources such as cloud service devices (such as virtual machines), cloud containers, and cloud databases on the cloud data center for tenants. Different VPCs are logically isolated. Tenants can perform some tenant configurations for their VPCs on the console. For example, tenants can customize the VPC network segment, divide subnets as needed in the VPC, configure routing forwarding rules, bandwidth packages, etc., and can also ensure network security by configuring access control rules such as security group rules and network access control list (ACL) rules.

[0059] The network device 300 may be a device such as a router, a switch, a firewall, a gateway, or a server, or may also be a cluster composed of multiple devices, which is not specifically limited in the embodiments of the present application. The network device 300 is configured with a corresponding IP address pool (which may include one or more address segments) for providing NAT functions and packet forwarding functions to help the terminal device 100 access the services deployed on the service device 200.

[0060] Specifically, one or more NAT service instances (hereinafter referred to as instances) may be deployed on the network device 300, and each instance is assigned a corresponding network segment. Optionally, different instances on the same network device 300 may be assigned different network segments from the IP address pool of the network device 300, that is, each instance is separately assigned a network segment (or network interface), and the network segments assigned to different instances do not overlap. Or, multiple instances on the same network device 300 may be assigned the same network segment from the IP address pool of the network device 300, that is, multiple instances share a network segment (or network interface).

[0061] For each NAT instance, it is associated with two pairs of "IP address + port (number)". The first pair of "IP address + port" can be used to determine a certain application program (for providing a certain service) on a certain service device 200, and the second pair of "IP address + port" is used to map the first pair of "IP address + port", so that accessing the second pair of "IP address + port" is equivalent to accessing the first pair of "IP address + port". This NAT instance is used to perform corresponding source network address translation (SNAT) and destination network address translation (DNAT) on packets with the destination address + destination port being the second pair of "IP address + port", so as to realize accessing the above application program corresponding to the first pair of "IP address + port". Among them, the above source address translation is to replace the source IP address + source port in the packet with an IP address + a certain port in the network segment allocated by this instance, and the above destination address translation is to replace the destination address and destination port in the packet with the first pair of "IP address + port".

[0062] For example, as Figure 2 shown, assume that an application program is deployed on a service device n (i.e., a certain service device 200), and this application program is used to provide database services. The IP address of the service device n in its VPC is mIPn, and the port number corresponding to this application program in the service device n is portz, then mIPn + portz is used to determine this application program on the service device n. Multiple instances (instance 1 to instance n) are deployed on a certain network device 1 (i.e., a certain network device 300), and the above multiple instances share a certain IP address segment (denoted as natx) in the IP address pool configured by this network device 1.

[0063] For instance n, it corresponds to "mIPn + portz" and "vIPn + portw". Among them, this pair of IP address and port "mIPn + portz" is used to determine the above application program in the service device n, and this pair of IP address + port "vIP1 + portx" is used to map "mIPn + portz", that is, the terminal device 100 accessing "vIPn + portw" is equivalent to accessing the above application program.

[0064] Suppose Figure 2A certain process in the terminal device n needs to access the above-mentioned application program in the service device n. Therefore, the source IP address and source port of the request message are respectively set to the IP address of the terminal device n and the port number corresponding to this process in the terminal device n. And the destination IP address and destination port in the request message are respectively set to vIPn and portw. Then the terminal device n sends the request message. Since vIPn belongs to the address pool of the network device 1, the request message will arrive at the network device 1 after network forwarding.

[0065] The instance n in the network device 1 replaces the source IP address + source port in the request message with an address + a port in the address segment natx allocated by the instance n (i.e., the SNAT function), that is, uses a new set of "IP address + port" to map the above-mentioned process in the terminal device n. At the same time, the destination IP address + destination port in the request message is replaced with "mIPn + portz" (i.e., the DNAT function). Then the message obtained after the above operations is sent to the service device n.

[0066] As Figure 3 shown, Figure 3 is a schematic structural diagram of a service device 200 provided by an embodiment of the present application, including a kernel and an application program (APP) for providing a certain service. Among them, the kernel includes a protocol stack (including TCP / IP protocol stack), and may also include a NAT module. The NAT module can be implemented based on the eBPF (extented Berkeley Packet Filter) technology. eBPF is a technology that can run programs written by users in the Linux kernel without modifying the kernel code or loading kernel modules. When the network card of the service device n receives the above message, the message flows into the protocol stack in the kernel and then flows to the APP for processing, so as to realize the access of the process in the terminal device n1 to the above-mentioned application program of the service device 200. Or, the above NAT module can be set in the APP instead of in the kernel of the service device 200. When the network card of the service device 200 receives the above message, it can bypass the kernel based on technologies such as Direct Memory Access (DMA) and Data Plane Development Kit (DPDK). The message does not flow through the kernel, and all message processing is completed by the APP.

[0067] Similarly, when other processes (located in terminal device n or other terminal devices) need to access the above application program of service device n, they can also send a packet for accessing "vIPn + portw" externally. Then, instance n performs a similar replacement operation on this packet (selecting a new set of "IP address + port" from address segment natx to map this process, which is different from the "IP address + port" mapping the previous process), so that the packet can be sent to service device n, and further realize the access to the above application program of service device n.

[0068] When the network device 300 where the NAT instance is located cannot meet its bandwidth growth requirement, or for reasons such as device upgrade and maintenance, the NAT instance needs to be migrated to other network devices 300. For example, as Figure 4 shown, Figure 4 in the network device 1 in cannot meet the bandwidth growth requirement of instance n, so instance n needs to be migrated to other network devices 300 (other instances sharing address segment natx with instance n do not need to be migrated together, which is simple to operate and helps to simplify network planning). Assume that it is selected to be migrated to network device 2. Continuing with the previous example, when instance n is migrated from network device 1 to network device 2 and becomes instance n', instance n' corresponds to the two sets of "IP address + port", namely "mIPn + portz" and "vIPn + portw". The function of instance n' is basically the same as that of instance n before, but the address segment natx configured by instance n before will not be migrated to network device 2 together. Instead, a certain address segment (denoted as naty) in the IP address pool of network device 2 will be allocated to instance n', and instance n' performs corresponding SNAT and DNAT functions based on address segment naty.

[0069] That is to say, when an instance is migrated from one network device to another network device, the address segment allocated to the instance in the first network device will not be migrated to the second network device together with the instance. The instance is allocated a corresponding address segment based on the network device where it is located. Therefore, the relationship between the instance and the address segment allocated to it is weakly correlated.

[0070] Based on the description of the above application scenarios, the interaction process before traffic hot migration is introduced below.

[0071] It should be noted that the five-tuple in the embodiments of this application includes the source IP address, source port, destination IP address, destination port, and protocol type, and has a sequential relationship. The five-tuple of a certain packet is a tuple formed by extracting the above five pieces of information, namely the source IP address, source port, destination IP address, destination port, and protocol type, in the packet and arranging them in the current order, but it does not mean that these five pieces of information must be arranged in the above order in the packet originally.

[0072] Figure 5It is an interaction flow chart before traffic migration provided by an embodiment of the present application, including steps S501 to S508.

[0073] S501. The terminal device 100 sends a first message for accessing APP1 to the second network element.

[0074] Among them, the five-tuple of the first message includes a first address, a first port, a second address, a second port, and a first protocol (such as the TCP protocol). The first address + the first port are used to determine a certain session (socket) of a certain process (denoted as process X) in a certain terminal device 100. The first address can be the IP address of the terminal device 100, and the first port can be the port number corresponding to process X on the terminal device 100. The IP address of a certain service device 200 is the fourth address, and the port bound to a certain application program (i.e., the first application program, abbreviated as APP1) on the service device 200 is the fourth port. Therefore, the fourth address + the fourth port can be used to determine APP1 (or the first application program) on the service device 200.

[0075] APP1 is a certain application program (or service software) deployed on the service device 200 and is used to provide a certain specific service. The embodiment of the present application does not make specific limitations on the type of service. The above second address + second port is a set of "IP address + port" set in the second network element for mapping the fourth address + fourth port. When the terminal device 100 accesses the second address + second port, it is equivalent to accessing APP1 corresponding to the fourth address + fourth port (specifically, refer to the introduction later).

[0076] S502. The second network element processes the first message according to the first mapping information to obtain a replaced message.

[0077] Specifically, the above first mapping information indicates the correspondence between the first address - first port - second address - second port - first protocol (denoted as five-tuple A) and the third address - third port - fourth address - fourth port - first protocol (denoted as five-tuple B). That is to say, the first mapping information indicates the correspondence between two different five-tuples. When the second network element receives the first message sent by the terminal device 100 and confirms that the five-tuple in the first message is five-tuple A, it will replace the five-tuple of the first message from five-tuple A with five-tuple B according to the first mapping information to obtain a replaced message.

[0078] In this embodiment, the first address - first port in the first mapping information corresponds to a certain socket in process X on the terminal device 100, and the fourth address - fourth port corresponds to APP1 on the service device 200. The second address + second port is a set of "IP address + port number" configured to map the fourth address + fourth port, and the third address - third port is a set of "IP address + port number" selected by the second network element to map the first address + first address. It should be understood that a packet with the five-tuple of first address - first port - second address - second port - first protocol corresponds to the same session connection.

[0079] S503. The second network element sends the replaced packet to the service device 200.

[0080] As introduced above, the destination IP address and destination port of the replaced packet obtained in step S502 are the fourth address (the IP address of the service device 200) and the fourth port respectively. Based on the above destination IP address, the replaced packet will be routed and forwarded to the service device 200.

[0081] S504. The kernel of the service device 200 sends the replaced packet to APP1.

[0082] Optionally, after the above replaced packet is forwarded through the network, it can be received by the physical network card on the service device 200. The physical network card sends the packet to the kernel, and the protocol stack in the kernel then sends the packet to APP1. Therefore, the source IP address and source port of the packet received by APP1 are the third address and the third port respectively.

[0083] Optionally, after the network card of the service device 200 receives the above replaced packet sent by the second network element, it can flow the packet to APP1 for processing without passing through the kernel.

[0084] Optionally, the kernel of the service device 200 does not send the above replaced packet to APP1, but sends the application layer information (i.e., the transport layer payload) in the above replaced packet to APP1. For example, the kernel first determines the corresponding socket according to the five-tuple of the above replaced packet (i.e., the third address - third port - fourth address - fourth port - first protocol), and then calls the interface of the operating system to send the application layer information in the above replaced packet to the socket, and then the socket sends the above application layer information to APP1.

[0085] S505. APP1 in the service device 200 sends a response message to the kernel.

[0086] Optionally, APP1 generates response information for the transport layer payload in step S504, and then sends it to the socket corresponding to APP1 (the corresponding five-tuple is the third address - the third port - the fourth address - the fourth port - the first protocol). The socket then transfers the response information to the kernel. The kernel adds a packet header to the above response information to obtain a response packet, and then the network card of the service device 200 sends the response packet to the second network element. Among them, the five-tuple in the packet header includes the fourth address - the fourth port - the third address - the third port - the first protocol.

[0087] S506. The service device 200 generates a response packet according to the response information and sends the response packet to the second network element.

[0088] Optionally, after receiving the above-mentioned replaced packet in step S504, APP1 can process the content in the replaced packet to generate a corresponding response packet (without passing through the kernel), and then transfer the response packet to the network card. The five-tuple of the response packet is the fourth address, the fourth port, the third address, the third port, the first protocol. Subsequently, the network card of the service device 200 can send the response packet to the second network element.

[0089] S507. The second network element processes the response packet according to the first mapping information to obtain a replaced response packet.

[0090] Specifically, as introduced above, the first mapping information indicates the correspondence between the first address - the first port - the second address - the second port - the first protocol and the third address - the third port - the fourth address - the fourth port - the first protocol. When the second network element receives the response packet sent by the service device 200, it confirms that the five-tuple of the response packet includes the fourth address, the fourth port, the third address, the third port, and the first protocol. Then, according to the first mapping information, it can replace the five-tuple of the response packet with the second address, the second port, the first address, the first port, and the first protocol, thereby obtaining a replaced response packet, and then sending the above-mentioned replaced response packet to the terminal device 100 corresponding to the first address.

[0091] S508. The second network element sends the replaced response packet to the terminal device 100.

[0092] Among them, the five-tuple of the replaced response packet includes the second address, the second port, the first address, the first port, and the first protocol. The application layer information of the replaced response packet will ultimately be sent to process X for processing, realizing the access of process X in the terminal device 100 to APP1 in the service device 200.

[0093] Based on Figure 5 the above introduction, the first embodiment of the hot migration method provided by the present application is introduced below.

[0094] Please refer to Figure 6 , Figure 6 which is an interaction flowchart of a hot migration method provided by an embodiment of the present application, including steps S601 to S616.

[0095] S601. The second network element sends first mapping information to the first network element.

[0096] Regarding the first mapping information, reference can be made to the introduction in step S501, which will not be elaborated here. The first network element and the second network element are configured with different address segments. The above third address belongs to the address segment configured by the second network element, and the fifth address belongs to the address segment configured by the first network element.

[0097] Optionally, Figure 6 the terminal device 100 and the service device 200 in Figure 6 may be located in different private networks (such as VPC), and there may be overlapping network segments between different private networks. Or,

[0098] the terminal device 100 and the service device 200 in

[0099] may also be located in the same private network.

[0100] It should be understood that the first packet in step S501 and the second packet in step S602 have the same five-tuple and belong to the traffic of the same session connection (a certain socket in process X accessing the service of APP1).

[0101] S603. The first network element processes the second packet according to the first mapping information to obtain a third packet containing first indication information, and records the first replacement status between the fifth address - fifth port and the third address - third port.

[0102] Among them, the first indication information is used to instruct the service device 200 to set the five-tuple of the first response packet corresponding to the first application program to the fourth address - fourth port - fifth address - fifth port - first protocol and then send it to the first network element. The fifth address is an IP address in the address segment configured by the first network element. The first replacement status is used to indicate whether replacement is allowed between the fifth address - fifth port and the third address - third port, which needs to be negotiated with the service device 200 and has not yet been confirmed by the service device 200, that is, the current negotiation is still in progress.

[0103] Optionally, the third message includes a first optional field, the information in the first optional field includes a fifth address and a fifth port, and the first indication information includes the information in the first optional field. That is to say, a first optional field can be added to the third message, and part or all of the first indication information can be written in the first optional field. For example, the first indication information may include a third address, a third port, a fifth address, and a fifth port. The above content can all be written in the first optional field, or only the fifth address and the fifth port in the first indication information (i.e., a new set of "IP address + port") can be written in the first optional field. At this time, the third address and the third port in the first indication information are located in the source IP address and source port fields in the header of the third message.

[0104] Optionally, the first optional field may be an option field in the transmission control protocol (TCP).

[0105] S604. The first network element sends a third message to the service device 200.

[0106] S605. The service device 200 records the replacement relationship between the fifth address - fifth port and the third address - third port.

[0107] Specifically, when the network card on the service device 200 receives the third message, the third message arrives at the kernel, and then according to the first indication information in the third message, the replacement relationship between the fifth address - fifth port and the third address - third port can be recorded in the service device 200 for message return.

[0108] S606. The kernel of the service device 200 sends the third message to APP1.

[0109] It should be understood that the source IP address and source port of the third message received by APP1 are the third address and the third port respectively. The destination address and destination port of the return message (i.e., the first response message in step S607) generated by APP1 for the third message will be set to the above-mentioned third address and third port.

[0110] Optionally, after the network card of the service device 200 receives the third message sent by the first network element, it can flow the third message to APP1 for processing without passing through the kernel. APP1 may include a NAT module, and the NAT module can record the first indication information carried in the third message in the service device 200.

[0111] Optionally, instead of sending the complete third message to APP1, the kernel of the service device 200 sends the application layer information (i.e., the transport layer payload) in the third message to APP1. For example, the kernel first determines the corresponding socket according to the five-tuple of the third message (i.e., the third address - the third port - the fourth address - the fourth port - the first protocol), and then calls the interface of the operating system to send the application layer information of the third message to the socket, and then the socket sends the above application layer information to APP1.

[0112] Regarding the sequence order between steps S605 and S606, the embodiments of the present application do not make specific limitations. For example, S605 and S606 can be executed successively, or S606 and S605 can be executed successively, and the two can also be executed in parallel.

[0113] S607. APP1 of the service device 200 sends response information to the kernel.

[0114] S608. The kernel of the service device 200 generates a first response message according to the recorded replacement relationship and the response information.

[0115] Among them, the first response message corresponds to APP1.

[0116] Optionally, the kernel of the service device 200 includes a NAT module (based on eBPF), which can, based on the replacement relationship recorded in step S608, set the five-tuple of the first response message to the fourth address, the fourth port, the fifth address, the fifth port, and the first protocol, and then send the first response message to the first network element. Among them, the application layer information of the first response message includes the above response information.

[0117] Optionally, APP1 in the service device 200 may include a NAT module, and the NAT module can generate a first response message based on the replacement relationship and the response information recorded in step S608. Then APP1 streams the first response message to the network card (without passing through the kernel), and the network card then sends the first response message to the second network element.

[0118] Optionally, APP1 generates application layer response information for the transport layer payload in S606, and then sends it to the socket corresponding to APP1 (the corresponding five-tuple is the third address - the third port - the fourth address - the fourth port - the first protocol), and the socket then transfers the application layer response information to the kernel. The kernel adds a message header to the above application layer response information according to the replacement relationship recorded in step S608 to obtain a second response message. Among them, the five-tuple in the message header includes the fourth address - the fourth port - the fifth address - the fifth port - the first protocol.

[0119] S609. The service device 200 sends the first response message to the first network element.

[0120] S610. The first network element changes the recorded first replacement state to a second replacement state, and processes the first response message according to the second replacement state to obtain a second response message.

[0121] As can be seen from step S603, the first replacement state is used to indicate whether the replacement between the fifth address - fifth port and the third address - third port is allowed and is still negotiating with the service device 200, without obtaining the confirmation of the service device 200, that is, it is still in the negotiation process. When the first network element receives the first response message and finds that the five-tuple of the first response message includes the fifth address, the fifth port, the fourth address, the fourth port, and the first protocol, it indicates that the first response message is generated by the service device 200 according to the first indication information sent by the first network element before. At this time, the first network element confirms that the service device 200 allows the replacement between the fifth address - fifth port and the third address - third port, and then changes the previously recorded first replacement state to a second replacement state. The second replacement state is used to indicate that the replacement between the fifth address - fifth port and the third address - third port is allowed and the negotiation with the service device 200 has been successful.

[0122] It should be understood that when the service device 200 in step S605 records the first indication information, it means that it supports performing corresponding processing according to the first indication information in step S608, and the first response message obtained by the processing will be sent to the first network element. Then, the first network element in step S610 can determine that the service device 200 supports performing the above replacement according to the received first response message. If the service device 200 does not support performing the above replacement, the service device 200 in step S605 may not record the first indication information. Then, the service device 200 will not set the five-tuple of the first response message to the fourth address - fourth port - fifth address - fifth port - first protocol in step S608, but will set it to the fourth address - fourth port - third address - third port - first protocol. Since the destination IP address in the first response message is the third address at this time and the third address belongs to the address segment configured by the second network element, the first response message will be forwarded to the second network element for processing instead of being forwarded to the first network element.

[0123] S611. The first network element sends the second response message to the terminal device 100.

[0124] S612. The terminal device 100 sends a fourth message for accessing APP1 to the first network element.

[0125] Among them, the five-tuple of the fourth packet includes a first address, a first port, a second address, a second port, and a first protocol. It can be seen from steps S501 and S602 that the first packet, the second packet, and the fourth packet have the same five-tuple, and the first address and the first port correspond to a certain socket in process X in the terminal device 100, and the second address and the second port are used to map APP1 in the service device 200. The fourth packet, like the first packet and the second packet, belongs to the service access traffic of process X to APP1.

[0126] S613. The first network element processes the fourth packet according to the first mapping information and the second replacement status to obtain a fifth packet.

[0127] Specifically, the first network element replaces the source IP address and the source port in the fourth packet with a fifth address and a fifth port respectively according to the first mapping information and the second replacement status, and replaces the destination IP address and the destination port in the fourth packet with a fourth address and a fourth port respectively, thereby obtaining a fifth packet.

[0128] Optionally, the fifth packet includes a second optional field, and the information in the second optional field includes a third address and a third port, so that the service device 200 in step S615 can directly perform corresponding replacements based on the information in the second optional field of the fifth packet, which helps to improve the processing speed.

[0129] S614. The first network element sends the fifth packet to the service device 200.

[0130] S615. The kernel of the service device 200 processes the fifth packet to obtain a sixth packet.

[0131] Among them, the five-tuple of the sixth packet includes a third address, a third port, a fourth address, a fourth port, and a first protocol.

[0132] In one implementation, the kernel of the service device 200 can replace the source IP address and the source port in the fifth packet with a third address and a third port respectively according to the replacement relationship recorded in step S605 before, thereby obtaining a sixth packet.

[0133] In another implementation, the information in the second optional field of the fifth packet includes a third address and a third port. The service device 200 can directly replace the source IP address and the source port in the fifth packet with a third address and a third port respectively according to the information in the second optional field, thereby obtaining a sixth packet. Compared with the previous implementation, this implementation does not need to search for the previously recorded replacement relationship, but directly performs corresponding replacements based on the content carried in the fifth packet, which helps to improve the processing speed on the side of the service device 200.

[0134] The kernel of the service device 200 sends the sixth message to APP1.

[0135] Optionally, steps S615 and S616 may also be: after obtaining the fifth message, the kernel determines the corresponding socket according to the five-tuple of the fifth message (i.e., the fifth address - the fifth port - the fourth address - the fourth port - the first protocol), and then calls the interface of the operating system to send the transport layer payload (i.e., the application layer information) of the fifth message to the socket, and the socket then sends the above application layer information to APP1.

[0136] The second embodiment of the hot migration method provided by the present application is introduced below.

[0137] Please refer to Figure 7 , Figure 7 which is an interaction flowchart of a hot migration method provided by an embodiment of the present application, including steps S701 to S707.

[0138] S701. The second network element sends the first mapping information to the first network element. Correspondingly, the first network element receives the first mapping information sent by the second network element.

[0139] Among them, the first mapping information indicates the correspondence between the first address - the first port - the second address - the second port - the first protocol and the third address - the third port - the fourth address - the fourth port - the first protocol. The second network element and the first network element are configured with different address segments. The above third address belongs to the address segment of the second network element, and the fourth address and the fourth port correspond to the first application program (denoted as APP1) deployed on the service device 200.

[0140] Optionally, the first address and the fourth address belong to the first private network and the second private network respectively, and there is an overlap (address conflict) between the network segments of the first private network and the second private network. The private network may be a VPC or other autonomous network, and the embodiments of the present application do not make specific limitations.

[0141] It should be noted that, before step S701, the second network element may replace the five-tuple in the received first message with the third address, the third port, the fourth address, the fourth port, and the first protocol according to the first mapping information to obtain the replaced message, and then send the replaced message to the service device 200. Correspondingly, the service device 200 receives the above replaced message sent by the second network element and then sends it to APP1. Among them, the five-tuple of the first message includes the first address, the first port, the second address, the second port, and the first protocol. For specific details, please refer to Figure 5 the relevant introduction, which will not be elaborated here.

[0142] Before step S701, the service device 200 may also send a response message generated by APP1 to the second network element. The five-tuple of the response message includes a fourth address, a fourth port, a third address, a third port, and a first protocol. Correspondingly, the second network element may replace the five-tuple in the above response message with a second address, a second port, a first address, a first port, and a first protocol according to the first mapping information and then send it out. For specific details, please refer to Figure 5 the relevant introduction, which will not be elaborated here.

[0143] S702. The first network element sends first indication information to the service device 200. Correspondingly, the service device 200 receives the first indication information sent by the first network element.

[0144] The first indication information is used to instruct the service device 200 to set the five-tuple of the first response message corresponding to the first application program as the fourth address - the fourth port - the fifth address - the fifth port - the first protocol and then send it to the first network element.

[0145] Specifically, when the first network element receives the first mapping information, it can know how the second network element processed the relevant messages based on the first mapping information before (please refer to Figure 5 for the introduction). Since the third address in the first mapping information belongs to the second network element, in order to ensure that the traffic of the same session (that is, a certain socket in process X in the terminal device 100 accesses APP1 in the service device 200) is not interrupted, the first network element needs to select an IP address (i.e., the fifth address) and a port (i.e., the fifth port) from the address segment configured by itself, and then send the first indication information to the service device 200 to instruct the service device 200 to replace the destination IP address + destination port in the first response message (used to reply to process X) generated by APP1 from the third address + the third port with the fifth address + the fifth port.

[0146] The present application embodiment does not make specific limitations on the specific content and representation form of the first indication information. For example, the first network element may send the first indication information to the service device 200 separately, or carry the first indication information in the message that needs to be forwarded to the service device 200.

[0147] In the first implementation, a first network element receives a second packet. The five-tuple of the second packet includes a first address, a first port, a second address, a second port, and a first protocol. Then, the first network element replaces the five-tuple in the second packet with a third address, a third port, a fourth address, a fourth port, and the first protocol according to the first mapping information, thereby obtaining a third packet, and carrying first indication information in the third packet. Then, the first network element sends the third packet to the service device 200. When the service device 200 receives the third packet sent by the first network element, it can record the first indication information. That is to say, when the first network element receives the second packet, it can complete the corresponding replacement according to the requirements of the first mapping information to obtain the third packet, and carry the first indication information in the third packet, so that the first indication information can be sent to the service device 200 along with the third packet, without the need to separately send the first indication information to the service device 200.

[0148] Optionally, the first indication information includes the information of a first optional field in the third packet, and the information in the first optional field includes a fifth address and a fifth port. For example, the first indication information may include the information of the first optional field in the third packet, and also include the source IP address and source port (i.e., the third address and the third port) in the third packet. At this time, the first indication information can indicate the replacement relationship between the third address - third port and the fifth address - fifth port, and can be used to instruct the service device 200 to perform the corresponding replacement. For another example, the first indication information may be entirely located in the first optional field of the third packet, that is, the first optional field of the third packet may contain the third address, the third port, the fifth address, and the fifth port, so as to be used to instruct the service device 200 to perform the corresponding replacement.

[0149] Optionally, before the first network element sends the third packet to the service device 200, the first network element may record the first replacement status between the third address - third port and the fifth address - fifth port. For the introduction of the first replacement status, reference can be made to the description in step S603, which will not be elaborated here.

[0150] In the second implementation, the first network element receives a second message, replaces the five-tuple in the second message with a fifth address, a fifth port, a fourth address, a fourth port, and a first protocol to obtain a sixth message, and then sends the sixth message to the service device 200. The five-tuple of the second message includes a first address, a first port, a second address, a second port, and a first protocol. The sixth message contains first indication information, and the first indication information is used to instruct the service device 200 to set the five-tuple of the first response message corresponding to APP1 to the fourth address - fourth port - fifth address - fifth port - first protocol and then send it to the first network element. The first indication information is further used to instruct the service device 200 to replace the source IP address and source port in the sixth message with a third address and a third port respectively and then send it to APP1. Alternatively, the first indication information is further used to instruct the service device 200 to send the application layer information in the sixth message to APP1.

[0151] Optionally, the first indication information includes the information of a second optional field in the sixth message, and the information in the second optional field includes a third address and a third port. For example, the first indication information may include the information of the second optional field in the sixth message and also include the source IP address and source port in the sixth message (i.e., the fifth address and the fifth port). At this time, the first indication information can indicate the replacement relationship between the third address - third port and the fifth address - fifth port, and thus can be used to instruct the service device 200 to perform corresponding replacement processing. Again, the second indication information may be entirely located in the second optional field of the sixth message, that is, the second optional field of the sixth message may include the third address, the third port, the fifth address, and the fifth port, so as to play the above role of the first indication information.

[0152] S703. APP1 in the service device 200 sends response information to the kernel.

[0153] Among them, APP1 can send response information to the associated socket (the corresponding five-tuple is the third address - third port - fourth address - fourth port - first protocol), and then the socket sends the response information to the kernel.

[0154] S704. The kernel in the service device 200 generates a first response message according to the first indication information and the response information.

[0155] Among them, the first response message corresponds to APP1. The five-tuple of the first response message includes the fourth address, the fourth port, the fifth address, the fifth port, and the first protocol. The application layer information of the first response message includes the above-mentioned response information. That is to say, when the kernel of the service device 200 receives the response information sent by APP1, it can set the five-tuple of the first response message to the fourth address, the fourth port, the fifth address, the fifth port, and the first protocol according to the requirements of the first indication information, and then send the first response message to the first network element.

[0156] Corresponding to the first implementation in step S702, when the service device 200 receives the third message sent by the first network element, it can record the first indication information in the third message. Among them, the third message contains the first indication information, and the five-tuple of the third message includes the third address, the third port, the fourth address, the fourth port, and the first protocol. Then, in step S704, the service device 200 can set the five-tuple of the first response message corresponding to APP1 to the fourth address, the fourth port, the fifth address, the fifth port, and the first protocol based on the recorded first indication information.

[0157] Corresponding to the second implementation in step S702, when the service device 200 receives the sixth message sent by the first network element (the sixth message contains the first indication information), it can replace the source IP address and source port in the sixth message with the third address and the third port respectively according to the first indication information and then send it to APP1, or send the application layer information in the sixth message to APP1 according to the first indication information. In step S704, the service device 200 can also set the five-tuple of the first response message corresponding to APP1 to the fourth address, the fourth port, the fifth address, the fifth port, and the first protocol according to the first indication information in the sixth message.

[0158] Optionally, APP1 in the service device 200 may include a NAT module. The NAT module can set the five-tuple of the first response message to the fourth address, the fourth port, the fifth address, the fifth port, and the first protocol based on the first indication information obtained in step S702. Then APP1 streams the first response message to the network card (without passing through the kernel), and the network card then sends the first response message to the first network element.

[0159] Optionally, steps S703 and S704 may be: APP1 sends response information to the associated socket (the corresponding five-tuple is the third address - the third port - the fourth address - the fourth port - the first protocol), and the socket then transfers the response information flow to the kernel. The kernel adds a message header to the above response information according to the indication information in step S702, thereby obtaining the first response message. Among them, the five-tuple in the above message header includes the fourth address - the fourth port - the fifth address - the fifth port - the first protocol, and the application layer information of the first response message includes the above response information.

[0160] S705. The service device 200 sends the first response message to the first network element.

[0161] S706. The first network element processes the first response message to obtain a second response message.

[0162] Specifically, when the first network element receives the first response message, according to the recorded replacement relationship between the fifth address + the fifth port and the third address + the third port and the first mapping information, the five-tuple in the first response message can be replaced with the second address, the second port, the first address, the first port, and the first protocol, thereby obtaining the second response message. It can be understood that the destination IP address and destination port in the second response message are the first address and the first port. The first address is used to determine the terminal device 100, and the first address + the first port are used to determine a certain socket in the process X of the terminal device 100. Therefore, the second response message can be forwarded from the first network element to the terminal device 100, and further, the application layer information of the second response message can be sent to the process X.

[0163] In some implementation schemes, when the first replacement state is recorded in step S702, step S706 may be: the first network element changes the recorded first replacement state to the second replacement state, and after replacing the five-tuple in the first response message with the second address, the second port, the first address, the first port, and the first protocol, it is sent out (it can be sent to the terminal device 100). When the first network element receives the fourth message, the five-tuple in the fourth message can be replaced with the fifth address, the fifth port, the fourth address, the fourth port, and the first protocol according to the locally recorded second replacement state to obtain the fifth message, and then the fifth message is sent to the service device 200. Correspondingly, the service device 200 receives the fifth message sent by the first network element, replaces the source IP address and source port in the fifth message with the third address and the third port respectively according to the first indication information and then sends it to APP1, or the service device 200 sends the application layer information in the fifth message to APP1 according to the first indication information.

[0164] Among them, the five-tuple of the fourth message includes a first address, a first port, a second address, a second port, and a first protocol. For the specific content of this implementation solution, reference can be made to the relevant introduction in step S613, which will not be elaborated here.

[0165] Optionally, the fifth message includes second indication information, which is used to instruct the service device 200 to send the fifth message to APP1 after replacing the source IP address and source port in the fifth message with a third address and a third port respectively. Therefore, when the service device 200 receives the fifth message, it can replace the source IP address and source port in the fifth message with the third address and the third port according to the second indication information and then send it to APP1. Alternatively, the service device 200 can send the application layer information in the fifth message to APP1 according to the second indication information.

[0166] S707. The first network element sends a second response message to the terminal device 100.

[0167] Among them, the destination IP address and destination port of the second response message are the first address and the first port respectively. The first address + the first port is used to determine a certain socket in process X on the terminal device 100. Therefore, process X can finally receive the content of the second response message.

[0168] In summary, through the negotiation and cooperation between the first network element and the service device 200, the embodiment of the present application can realize the hot migration of the traffic corresponding to the same session, thereby improving the user experience.

[0169] Next, in combination with Figure 8 , for Figure 7 the hot migration method of the embodiment is illustrated by way of example.

[0170] Please refer to Figure 8 , Figure 8 which is a schematic diagram of the processing process before and after hot migration provided by the embodiment of the present application.

[0171] For the sake of convenience of description, hereinafter, IP1, IP2, IP3, IP4, and IP5 are used to represent the first address, the second address, the third address, the fourth address, and the fifth address in the foregoing respectively, and port1, port2, port3, port4, and port5 are used to represent the first port, the second port, the third port, the fourth port, and the fifth port in the foregoing respectively. The first protocol is the TCP protocol (protocol number).

[0172] (1) Before the first mapping information is migrated from the second network element to the first network element (i.e., step (4))

[0173] Before the first mapping information is migrated from the second network element to the first network element, or before the NAT instance associated with the first mapping information is migrated from the second network element to the first network element, the process of the process X in the terminal device 100 accessing the APP1 in the service device 200 can refer to Figure 8 Steps (1) to (3) in. The NAT instance associated with the first mapping information refers to the NAT instance that performs corresponding packet processing based on the first mapping information.

[0174] Specifically, as Figure 8 shown, the IP address of the terminal device 100 is IP1, a certain process in the terminal device 100 (denoted as process X) corresponds to port1, and IP1 + port1 can be used to determine a certain socket in the process X in the terminal device 100. The IP address of the service device 200 is IP4, and the port corresponding to a certain application program (used to provide a certain service, denoted as APP1) in the service device 200 is port4, and IP4 + port4 can be used to determine the APP1 in the service device 200.

[0175] When the process X in the terminal device 100 needs to access the APP1 in the service device 200, the terminal device 100 sends a first packet to the second network element (i.e., step (1)). Among them, the five-tuple of the first packet includes IP1, port1, IP2, port2, and TCP protocol in sequence. "IP2 + port2" is a set of IP address + port set in the second network element for mapping "IP4 + port4". By accessing "IP2 + port2", the terminal device 100 equivalently accesses the APP1 corresponding to "IP4 + port4". Based on the destination IP address of the first packet, the first packet will be forwarded to the second network element. Then, the second network element replaces the five-tuple of the first packet with IP3, port3, IP4, port4, and TCP protocol based on the first mapping information to obtain the replaced packet, and then sends the replaced packet to the service device 200 (i.e., step (2)). Among them, "IP3 + port3" is a set of new IP address + port selected by the second network element for mapping "IP1 + port1", and IP3 belongs to the address pool of the second network element. By performing the above replacement, the second network element makes the access of "IP1 + port1" to "IP2 + port2" equivalent to the access of "IP3 + port3" to "IP4 + port4". Then, the kernel of the service device 200 receives the above replaced packet and sends the application layer information in the above replaced packet to APP1 (i.e., step (3)).

[0176] (2) After the first mapping information is migrated from the second network element to the first network element

[0177] In the first possible solution (involving steps (5) to (11)), after the first mapping information is migrated from the second network element to the first network element (i.e., step (4)), the first network element will be responsible for performing the corresponding NAT function and forwarding function during the service access process between process X in the terminal device 100 and APP1 in the service device 200.

[0178] As Figure 8 shown, the first network element receives the packet sent by the terminal device 100 (i.e., step (5)). The five-tuple of this packet includes IP1, port1, IP2, port2, and the TCP protocol. It can be understood that this packet has the same five-tuple as the packet sent by the terminal device 100 to the second network element in step (1), corresponding to the same session connection. Then, based on the first mapping information migrated from the second network element, the first network element replaces the five-tuple of this packet with IP3, port3, IP4, port4, and the TCP protocol, and carries IP5 and port5 in the first optional field in the packet to obtain a new packet. Among them, "IP3 + port3" is a set of IP addresses + ports previously selected by the second network element to map "IP1 + port1". IP3 belongs to the address pool within the second network element. "IP5 + port5" is a new set of IP addresses + ports selected by the first network element to map "IP1 + port1". IP5 belongs to the address pool of the first network element. That is to say, the first network element now expects to use "IP5 + port5" to replace "IP3 + port3" in the first mapping information. Then, the first network element sends the new packet obtained after the above operation to the service device 200 corresponding to its destination address (i.e., IP4) (step (6)), and locally records the first replacement status between "IP3 + port3" and "IP5 + port5". The first replacement status indicates that whether the replacement between the above two sets of "IP addresses + ports" can be done is still under negotiation and has not been confirmed by the service device 200.

[0179] When the service device 200 receives the message in step (6), the message is transferred to the kernel. The NAT module in the kernel confirms that the received message contains the first optional field, and then triggers the service device 200 to perform a recording operation, recording the mapping relationship between the content in the first optional field (i.e., IP5 + port5) and the source IP address and source port (i.e., IP3 + port3) in the message. The protocol stack in the kernel of the service device 200 sends the application layer information in the message to APP1 (i.e., step (7)). APP1 sends the response information obtained after processing the above application layer information to the kernel (i.e., step (8)). The kernel generates a first response message according to the mapping relationship and response information recorded by the NAT module before. The application layer information (i.e., the transport layer payload) in the first response message includes the response information, and the five-tuple of the first response message is IP4, port4, IP5, port5, TCP protocol. Subsequently, the service device 200 sends the first response message to the first network element (step (9)).

[0180] The first network element confirms that the five-tuple of the first response message received from the service device 200 includes IP4, port4, IP5, port5, TCP protocol. Combining with the first replacement state recorded locally before between "IP3 + port3" and "IP5 + port5", it can be confirmed that the service device 200 supports the above replacement, and the first response message is the result after replacement. Therefore, the first network element can change the first replacement state recorded locally to the second replacement state, and the second replacement state indicates that the negotiation has been completed, and "IP5 + port5" can replace "IP3 + port3". The first network element replaces the five-tuple of the first response message received from step ⑨ with IP2, port2, IP1, port1, TCP protocol to obtain a second response message, and then sends the second response message to the terminal device 100.

[0181] Subsequently, the terminal device 100 sends a message with a five-tuple of IP1, port1, IP2, port2, TCP protocol to the first network element (i.e., step (5)). The first network element replaces the five-tuple of the message with IP5, port5, IP4, port4, TCP protocol according to the first mapping information and the recorded second replacement state, and then sends the message obtained after the above processing to the service device 200 (i.e., step (10)). Optionally, the second optional field in the above message contains IP3 and port3.

[0182] When the service device 200 receives the message in step (10), if the above message does not have the second optional field, the service device 200 can replace the source IP address + source port in the message with IP3 + port3 according to the locally recorded mapping relationship and then send it to APP1 (i.e., step (11)), or send the application layer information in the message to APP1. If the above message contains the second optional field, the service device 200 does not need to look up the previously recorded mapping relationship, and can directly trigger the replacement of the source IP address + source port in the message with IP3 + port3 according to the second optional field in the message, which helps to improve the processing speed, and then send the message obtained after replacement or the application layer information in the message obtained after replacement to

[0183] In the second possible solution (involving steps (5), (10) and (11)), after the first mapping information is migrated from the second network element to the first network element (i.e., step (4)), the first network element is responsible for performing the corresponding NAT function and forwarding function during the service access process between process X in the terminal device 100 and APP1 in the service device 200.

[0184] The first network element receives a certain message from the terminal device 100 (i.e., step (5)), and the five-tuple of this message includes IP1, port1, IP2, port2, and TCP protocol in sequence. According to the first mapping information, the first network element knows that the second network element previously mapped "IP1 + port1" with "IP3 + port3". In order to enable the return message of APP1 to be sent to the first network element, the first network element needs to use a new set of IP address + port to map "IP1 + port1". Therefore, the first network element selects a certain IP address (i.e., IP5) from its own configured address pool, and at the same time selects a port (i.e., port5), that is, the first network element selects to map "IP1 + port1" with "IP5 + port5". At this time, the first network element can replace the five-tuple in the message sent in step (5) with IP5, port5, IP4, port4, and TCP protocol, and add a second optional field to the message, and the content of the second optional field is IP3 and port3, and then send the obtained message to the service device 200 (i.e., step (10)).

[0185] When the service device 200 receives the message in step (10), the message is transferred to the kernel. The NAT module in the kernel confirms that the received message contains the second optional field, and then triggers the service device 200 to record that there is a replacement relationship between "IP5 + port5" and "IP3 + port3". After that, the source IP address and source port in the above message are replaced with IP3 and port3 respectively and then sent to APP1 (i.e., step (11)). Alternatively, step (11) can send the application layer information in the above message to APP1. The processing process of the return journey (from APP1 to process X) can refer to the relevant introductions in steps (8) and (9) of the first solution, which will not be elaborated here.

[0186] Please refer to Figure 9 , Figure 9 FIG. Figure 9 is a schematic structural diagram of a first network element provided by an embodiment of the present application, including a transceiver module 901 and a processing module 902.

[0187] The transceiver module 901 is configured to receive first mapping information sent by a second network element. The first mapping information indicates the correspondence between a first address - a first port - a second address - a second port - a first protocol and a third address - a third port - a fourth address - a fourth port - a first protocol. Different address segments are configured for the first network element and the second network element. The third address belongs to the address segment of the second network element, and the fourth address and the fourth port correspond to a first application program on the service device 200.

[0188] The transceiver module 901 is further configured to send first indication information to the service device 200. The first indication information is used to instruct the service device to set the five-tuple of a first response message corresponding to the first application program to the fourth address - the fourth port - the fifth address - the fifth port - the first protocol and then send it to the first network element. The fifth address belongs to the address segment configured by the first network element.

[0189] The transceiver module 901 is further configured to receive a first response message sent by the service device 200.

[0190] The processing module 902 is configured to replace the five-tuple of the first response message with the second address, the second port, the first address, the first port, and the first protocol to obtain a second response message.

[0191] The transceiver module 901 is further configured to send the second response message.

[0192] Optionally, the transceiver module 901 is configured to receive a second message, where the five-tuple of the second message includes a first address, a first port, a second address, a second port, and a first protocol. The processing module 902 is configured to replace the five-tuple of the second message with a third address, a third port, a fourth address, a fourth port, and the first protocol according to the first mapping information to obtain a third message, where the third message includes first indication information. The transceiver module 901 is configured to send the third message to the service device 200.

[0193] Optionally, the third message includes a first optional field, and the information in the first optional field includes a fifth address and a fifth port, and the first indication information includes the information in the first optional field.

[0194] Optionally, the processing module 902 is further configured to record a first replacement status between the third address - third port and the fifth address - fifth port. Specifically, the processing module 902 is configured to replace the five-tuple of the second response message with a second address, a second port, a first address, a first port, and the first protocol to obtain a second response message, and change the recorded first replacement status to a second replacement status. The transceiver module 901 is configured to send the second response message and is further configured to receive a fourth message. The processing module 902 is configured to replace the five-tuple in the fourth message with a fifth address, a fifth port, a fourth address, a fourth port, and the first protocol according to the recorded second replacement status to obtain a fifth message, where the five-tuple of the fourth message includes a first address, a first port, a second address, a second port, and the first protocol. The transceiver module 901 is configured to send the fifth message to the service device 200.

[0195] Optionally, the fifth message includes second indication information, where the second indication information is used to instruct the service device 200 to replace the source IP address and the source port in the fifth message with the third address and the third port respectively and send them to the first application. Alternatively, the second indication information is used to instruct the service device 200 to send the application layer information in the fifth message to the first application.

[0196] Optionally, the fifth message includes a second optional field, and the information in the second optional field includes the third address and the third port, and the second indication information includes the information in the second optional field.

[0197] Optionally, the transceiver module 901 is configured to receive a second message, and the processing module 902 is configured to replace the five-tuple of the second message with a fifth address, a fifth port, a fourth address, a fourth port, and a first protocol to obtain a sixth message. The five-tuple of the second message includes a first address, a first port, a second address, a second port, and a first protocol. The sixth message includes first indication information, and the first indication information is further configured to instruct the service device 200 to send the sixth message to a first application after replacing the source IP address and the source port in the sixth message with a third address and a third port, respectively, or the first indication information is further configured to instruct the service device 200 to send the application layer information in the sixth message to the first application. The transceiver module 901 is configured to send the sixth message to the service device 200.

[0198] Optionally, the sixth message includes a second optional field, and the information in the second optional field includes a third address and a third port. The first indication information includes the information in the second optional field.

[0199] Optionally, the first address and the fourth address belong to a first private network and a second private network, respectively, and there is an overlapping network segment (address conflict) between the first private network and the second private network. The private network may be a VPC or other autonomous network, and the embodiments of the present application do not make specific limitations.

[0200] Figure 9 The first network element is specifically configured to execute Figure 6 , Figure 7 or Figure 8 The method (steps) on the first network element side in the embodiment can be referred to the foregoing introduction and will not be elaborated here.

[0201] The embodiment of the present application further provides another first network element, including a processor and a memory. The processor is configured to execute the instructions stored in the memory to enable the first network element to execute Figure 6 , Figure 7 or Figure 8 The method (steps) on the first network element side in the embodiment.

[0202] Please refer to Figure 10 , Figure 10 which is a schematic structural diagram of a service device 200 provided in the embodiment of the present application, including a transceiver module 1001 and a processing module 1002.

[0203] The transceiver module 1001 is configured to receive the first indication information sent by the first network element. The five-tuple corresponding to the first application on the service device 200 includes a third address, a third port, a fourth address, a fourth port, and a first protocol.

[0204] The processing module 1002 is configured to set the five-tuple of the first response message corresponding to the first application to the fourth address - the fourth port - the fifth address - the fifth port - the first protocol according to the first indication information, where the first network element and the second network element are configured with different address segments, and the fifth address and the third address belong to the address segment of the first network element and the address segment of the second network element, respectively.

[0205] The transceiver module 1001 is further configured to send the first response message to the first network element.

[0206] Optionally, before the service device 200 receives the first indication information sent by the first network element, the transceiver module 1001 is further configured to receive the replaced message sent by the second network element or the application layer information in the above-mentioned replaced message, and send the replaced message to the first application. The transceiver module 1001 is further configured to send the response message corresponding to the first application to the second network element, where the five-tuple of the response message includes the fourth address, the fourth port, the third address, the third port, and the first protocol.

[0207] Optionally, the transceiver module 1001 is configured to receive a third message sent by the first network element, where the five-tuple of the third message includes the third address, the third port, the fourth address, the fourth port, and the first protocol, and the third message contains the first indication information.

[0208] Optionally, the third message includes a first optional field, the information in the first optional field includes the fifth address and the fifth port, and the first indication information includes the information in the first optional field.

[0209] Optionally, after the service device 200 receives the third message sent by the first network element, the transceiver module 1001 is further configured to receive a fifth message sent by the first network element, where the five-tuple of the fifth message includes the fifth address, the fifth port, the fourth address, the fourth port, and the first protocol. The processing module 1002 is configured to replace the source IP address and the source port in the fifth message with the third address and the third port, respectively, and then send them to the first application. Alternatively, the processing module 1002 is further configured to send the application layer information in the fifth message to the first application.

[0210] Optionally, the fifth message contains a second indication information, and the processing module 1002 replaces the source IP address and the source port in the fifth message with the third address and the third port according to the second indication information, and then sends them to the first application. Alternatively, the processing module 1002 is configured to send the application layer information in the fifth message to the first application according to the second indication information.

[0211] Optionally, the fifth message includes a second optional field, the information in the second optional field includes a third address and a third port, and the second indication information includes the information in the second optional field.

[0212] Optionally, the transceiver module 1001 is configured to receive a sixth message sent by a first network element. The five-tuple of the sixth message includes a fifth address, a fifth port, a fourth address, a fourth port, and a first protocol, and the sixth message contains the first indication information. The processing module 1002 is configured to send the source IP address and source port in the sixth message to a first application program after replacing them with the third address and the third port respectively according to the first indication information. Alternatively, the processing module 1002 is configured to send the application layer information in the sixth message to the first application program according to the first indication information.

[0213] Optionally, the sixth message includes a second optional field, the information in the second optional field includes a third address and a third port, and the second indication information includes the information in the second optional field.

[0214] Optionally, the first address and the fourth address belong to a first private network and a second private network respectively, and there is an overlap in network segments (address conflict) between the first private network and the second private network. The private network can be a VPC or other autonomous network, which is not specifically limited in the embodiments of the present application.

[0215] Figure 10 The service device 200 is specifically configured to execute Figure 6 、 Figure 7 or Figure 8 The method (steps) on the service device 200 side in the embodiments can be referred to the foregoing introduction and will not be elaborated here.

[0216] The embodiments of the present application further provide another service device 200, including a processor and a memory. The processor is configured to execute the instructions stored in the memory, so that the service device 200 executes Figure 6 、 Figure 7 or Figure 8 The method (steps) on the service device 200 side in the embodiments.

[0217] The embodiments of the present application further provide a communication system, including a first network element, a second network element, and a service device 200. The first network element is used for Figure 6 、 Figure 7 or Figure 8 The method (steps) on the first network element side in the embodiments, the service device 200 is used for executing Figure 6 、 Figure 7 or Figure 8 The method (steps) on the service device 200 side in the embodiments, and the second network element is used for executing Figures 5 to 8 The method (steps) on the second network element side in the embodiments, which can be specifically referred to the foregoing introduction and will not be elaborated here.

[0218] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above various methods. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), etc.

[0219] The above-disclosed is only a preferred embodiment of the present application. Of course, it cannot be used to limit the scope of rights of the present application. Those of ordinary skill in the art can understand all or part of the processes of the above embodiments, and the equivalent changes made according to the claims of the present application still fall within the scope covered by the invention.

Claims

1. A thermal migration method, characterized in that, the method includes: A first network element receives first mapping information sent by a second network element. Among them, the first mapping information indicates the correspondence between a first address - a first port - a second address - a second port - a first protocol and a third address - a third port - a fourth address - a fourth port - the first protocol. The first network element and the second network element are configured with different address segments. The third address belongs to the address segment of the second network element. The fourth address and the fourth port correspond to a first application on a service device; The first network element sends first indication information to the service device. Among them, the first indication information is used to instruct the service device to set the five-tuple of the first response message corresponding to the first application to the fourth address - the fourth port - a fifth address - a fifth port - the first protocol and then send it to the first network element. The five-tuple includes a source IP address, a source port, a destination IP address, a destination port, and a protocol type in sequence. The first indication information includes the third address, the third port, the fifth address, and the fifth port. The fifth address belongs to the address segment configured by the first network element; The first network element receives the first response message sent by the service device, replaces the five-tuple of the first response message with the second address, the second port, the first address, the first port, and the first protocol to obtain a second response message, and sends the second response message.

2. The method according to claim 1, characterized in that, before the first network element receives the first mapping information sent by the second network element, the method further includes: The second network element replaces the five-tuple of the received first message with the third address, the third port, the fourth address, the fourth port, and the first protocol according to the first mapping information to obtain a replaced message, and sends the replaced message to the service device. Among them, the five-tuple of the first message includes the first address, the first port, the second address, the second port, and the first protocol; The second network element replaces the five-tuple of the response message sent by the service device with the second address, the second port, the first address, the first port, and the first protocol according to the first mapping information to obtain a replaced response message, and sends the replaced response message, where the five-tuple of the response message includes the fourth address, the fourth port, the third address, the third port, and the first protocol.

3. The method according to claim 1, characterized in that, the first network element sending the first indication information to the service device includes: The first network element receives a second message, where the five-tuple of the second message includes the first address, the first port, the second address, the second port, and the first protocol; The first network element replaces the five-tuple of the second message with the third address, the third port, the fourth address, the fourth port, and the first protocol according to the first mapping information to obtain a third message, where the third message includes the first indication information; The first network element sends the third message to the service device.

4. The method according to claim 3, wherein, The third message includes a first optional field, and the information in the first optional field includes the fifth address and the fifth port, and the first indication information includes the information in the first optional field.

5. The method according to claim 3 or 4, wherein, Before the first network element sends the third message to the service device, the method further includes: The first network element records a first replacement state between the third address - the third port and the fifth address - the fifth port; The replacing the five-tuple of the first response message with the second address, the first address, the second port, the first port, and the first protocol to obtain a second response message and sending the second response message includes: The first network element replaces the five-tuple of the first response message with the second address, the second port, the first address, the first port, and the first protocol to obtain the second response message, and changes the recorded first replacement state to a second replacement state, and sends the second response message; The first network element receives a fourth message, and replaces the five-tuple of the fourth message with the fifth address, the fifth port, the fourth address, the fourth port, and the first protocol according to the recorded second replacement state to obtain a fifth message, where the five-tuple of the fourth message includes the first address, the first port, the second address, the second port, and the first protocol; The first network element sends the fifth message to the service device.

6. The method according to claim 5, wherein, The fifth message includes second indication information, where the second indication information is used to instruct the service device to replace the source IP address and the source port in the fifth message with the third address and the third port respectively and then send them to the first application program, or the second indication information is used to instruct the service device to send the application layer information in the fifth message to the first application program.

7. The method according to claim 6, wherein, The fifth message includes a second optional field, and the information in the second optional field includes the third address and the third port, and the second indication information includes the information in the second optional field.

8. The method according to claim 1, wherein, The first network element sending the first indication information to the service device includes: The first network element receives a second message, replaces the five-tuple of the second message with the fifth address, the fifth port, the fourth address, the fourth port, and the first protocol to obtain a sixth message, where the five-tuple of the second message includes the first address, the first port, the second address, the second port, and the first protocol, the sixth message contains the first indication information, and the first indication information is further used to instruct the service device to send the source IP address and source port in the sixth message to the first application after replacing them with the third address and the third port respectively, or the first indication information is further used to instruct the service device to send the application layer information in the sixth message to the first application; The first network element sends the sixth message to the service device.

9. The method according to claim 8, wherein, the sixth message includes a second optional field, the information in the second optional field includes the third address and the third port, and the first indication information includes the information in the second optional field.

10. The method according to any one of claims 1, 2, 3, 4, 8, and 9, wherein, the first address and the fourth address belong to a first private network and a second private network respectively, and there is an overlapping network segment between the first private network and the second private network.

11. A hot migration method, wherein, the method includes: The service device receives first indication information sent by the first network element, where the service device includes a first application, the five-tuple corresponding to the first application includes the third address, the third port, the fourth address, the fourth port, and the first protocol, and the first indication information includes the third address, the third port, the fifth address, and the fifth port; The service device sets the five-tuple of the first response message corresponding to the first application to the fourth address - the fourth port - the fifth address - the fifth port - the first protocol according to the first indication information, where the five-tuple includes the source IP address, the source port, the destination IP address, the destination port, and the protocol type in sequence, different address segments are configured for the first network element and the second network element, and the fifth address and the third address belong to the address segment of the first network element and the address segment of the second network element respectively; The service device sends the first response message to the first network element.

12. The method according to claim 11, wherein, before the service device receives the first indication information sent by the first network element, the method further includes: The service device receives the replaced message sent by the second network element, and sends the replaced message or the application layer information in the replaced message to the first application, where the five-tuple of the replaced message includes the third address, the third port, the fourth address, the fourth port, and the first protocol; The service device sends a response message corresponding to the first application to the second network element, where the five-tuple of the response message includes the fourth address, the fourth port, the third address, the third port, and the first protocol.

13. The method according to claim 11, wherein, the service device receiving the first indication information sent by the first network element includes: the service device receives a third message sent by the first network element, where the five-tuple of the third message includes the third address, the third port, the fourth address, the fourth port, and the first protocol, and the third message contains the first indication information.

14. The method according to claim 13, wherein, the third message includes a first optional field, and the information in the first optional field includes the fifth address and the fifth port, and the first indication information includes the information in the first optional field.

15. The method according to claim 13 or 14, wherein, after the service device receives the third message sent by the first network element, the method further includes: the service device receives a fifth message sent by the first network element, where the five-tuple of the fifth message includes the fifth address, the fifth port, the fourth address, the fourth port, and the first protocol; the service device replaces the source IP address and the source port in the fifth message with the third address and the third port respectively and then sends them to the first application, or the service device sends the application layer information in the fifth message to the first application.

16. The method according to claim 15, wherein, the fifth message contains second indication information, and the service device replacing the source IP address and the source port in the fifth message with the third address and the third port respectively and then sending them to the first application includes: the service device replaces the source IP address and the source port in the fifth message with the third address and the third port according to the second indication information and then sends them to the first application, or the service device sends the application layer information in the fifth message to the first application according to the second indication information.

17. The method according to claim 16, wherein, the fifth message includes a second optional field, and the information in the second optional field includes the third address and the third port, and the second indication information includes the information in the second optional field.

18. The method according to claim 11, wherein, the service device receiving the first indication information sent by the first network element includes: the service device receives a sixth message sent by the first network element, where the five-tuple of the sixth message includes the fifth address, the fifth port, the fourth address, the fourth port, and the first protocol, and the sixth message contains the first indication information; The service device sends the source IP address and source port in the sixth message to the first application after replacing them with the third address and the third port respectively according to the first indication information, or the service device sends the application layer information in the sixth message to the first application according to the first indication information.

19. The method according to claim 18, wherein, the sixth message includes a second optional field, the information in the second optional field includes the third address and the third port, and the second indication information includes the information in the second optional field.

20. The method according to any one of claims 11, 12, 13, 14, 18, and 19, wherein, the first address and the fourth address belong to a first private network and a second private network respectively, and there is an overlapping network segment between the first private network and the second private network.

21. A first network element, wherein, it includes a transceiver module and a processing module, the transceiver module is configured to receive first mapping information sent by a second network element, where the first mapping information indicates the correspondence between a first address - first port - second address - second port - first protocol and a third address - third port - fourth address - fourth port - the first protocol, different address segments are configured for the first network element and the second network element, the third address belongs to the address segment of the second network element, and the fourth address and the fourth port correspond to a first application on the service device; the transceiver module is further configured to send first indication information to the service device, where the first indication information is used to instruct the service device to set the five - tuple of the first response message corresponding to the first application to the fourth address - the fourth port - fifth address - fifth port - the first protocol and then send it to the first network element, the five - tuple includes a source IP address, a source port, a destination IP address, a destination port, and a protocol type in sequence, the first indication information includes the third address, the third port, the fifth address, and the fifth port, and the fifth address belongs to the address segment configured for the first network element; the transceiver module is further configured to receive the first response message sent by the service device; the processing module is configured to replace the five - tuple of the first response message with the second address, the second port, the first address, the first port, and the first protocol to obtain a second response message; the transceiver module is further configured to send the second response message.

22. A first network element, wherein, it includes a processor and a memory, and the processor is configured to execute instructions stored in the memory so that the first network element executes the method according to any one of claims 1 to 10.

23. A service device, wherein, it includes a transceiver module and a processing module, The transceiver module is configured to receive first indication information sent by a first network element. The five-tuple corresponding to a first application program on the service device includes a third address, a third port, a fourth address, a fourth port, and a first protocol. The first indication information includes the third address, the third port, a fifth address, and a fifth port. The processing module is configured to set the five-tuple of a first response message corresponding to the first application program to the fourth address - the fourth port - the fifth address - the fifth port - the first protocol according to the first indication information. The five-tuple includes a source IP address, a source port, a destination IP address, a destination port, and a protocol type in sequence. Different address segments are configured for the first network element and the second network element. The fifth address and the third address belong to the address segment of the first network element and the address segment of the second network element respectively. The transceiver module is further configured to send the first response message to the first network element.

24. A service device Characterized in that it includes a processor and a memory. The processor is configured to execute instructions stored in the memory, so that the service device executes the method according to any one of claims 11 to 20.

25. A communication system Characterized in that it includes the first network element, the second network element according to any one of claims 1 - 10 or 21 - 22, and the service device according to any one of claims 11 - 20 or 23 - 24.

26. A computer-readable storage medium Characterized in that it includes computer program instructions. When the computer program instructions are executed by a computing device, the computing device executes the method according to any one of claims 1 - 10 or 11 - 20.

Citation Information

Patent Citations

  • Cluster working method and device based on open virtual network

    CN113630444A

  • Implementation method of FULL NAT (Network Address Translation) local IP (Internet Protocol)

    CN115277628A