Method for refreshing flow table of network address translation and related device

By generating a deletion list to record the sequence number of the IP address to be deleted and deleting invalid flow table data in a timed refresh task, the problem of packet forwarding performance degradation caused by traditional network address translation flow table update methods is solved, achieving high efficiency and stability of flow table updates.

CN117834584BActive Publication Date: 2025-11-28CHINA TELECOM CLOUD TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202311712867.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-13
Publication Date
2025-11-28
Estimated Expiration
2043-12-13

AI Technical Summary

Technical Problem

Traditional network address translation flow table update methods can lead to the deletion of valid flow table data, affecting packet forwarding performance.

Method used

By generating a deletion list to record the configuration sequence number of the IP address to be deleted, and deleting invalid flow table data based on these sequence numbers in a timed refresh task, we can avoid affecting packet forwarding.

Benefits of technology

Updating the flow table does not affect packet forwarding performance, ensuring the stability and efficiency of packet forwarding.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117834584B_ABST
    Figure CN117834584B_ABST
Patent Text Reader

Abstract

The application provides a network address conversion flow table refreshing method and related equipment, including: based on the obtained address update configuration information, determining a target conversion IP address in a conversion IP address configuration table, and deleting the target conversion IP address from the conversion IP address configuration table, and generating a deletion chain table corresponding to the address update configuration information; deleting the configuration serial number of the target conversion IP address corresponding to the address update configuration information in the deletion chain table; executing a timing refreshing task, deleting invalid flow table data in the flow table according to the configuration serial number of the target conversion IP address in each deletion chain table, completing flow table refreshing, and the flow table containing flow table data generated after a message triggers network address conversion. The configuration serial number of the deleted conversion IP address is used to generate a deletion chain table, and invalid flow table data in the flow table is deleted according to the deletion chain table, and the process of refreshing the flow table does not affect message forwarding, and the message forwarding performance is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the computer technical field, in particular to a network address translation flow table refreshing method and related equipment. BACKGROUND

[0002] Network address translation is a relatively mature network technology, which is widely used in networking environments in various industries. Using network address translation can save legal IP addresses, hide the internal network, and improve network security.

[0003] The configuration of network address translation technology is generally complex, and many converted IP addresses need to be configured. In network address translation services, the fast forwarding of messages after IP address conversion is achieved by flow tables. When some converted IP addresses are changed, the flow table needs to be updated in a timely manner. The traditional way to update the flow table is to invalidate and delete the existing flow table, and update the network connection by triggering the creation of a flow table through messages. This method will also delete the valid flow table, and the valid network connection needs to be re-established, which reduces the message forwarding performance. SUMMARY

[0004] Therefore, the embodiments of the present application provide a network address translation flow table refreshing method and related equipment. Based on the configuration sequence number of the deleted converted IP address, a deletion linked list is generated, and then the flow table data in the flow table is deleted based on the deletion linked list, so that the flow table can be refreshed without affecting message forwarding, and the performance of message forwarding is guaranteed.

[0005] To achieve the above object, the embodiments of the present application provide the following technical scheme:

[0006] A network address translation flow table refreshing method comprises the following steps:

[0007] Obtain at least one address update configuration information;

[0008] For each address update configuration information, determine a target converted IP address in a preset converted IP address configuration table, delete the target converted IP address from the converted IP address configuration table, and generate a deletion linked list corresponding to the address update configuration information. The deletion linked list contains the configuration sequence number of the target converted IP address corresponding to the address update configuration information.

[0009] Perform a preset timing refreshing task, delete invalid flow table data in the flow table according to the configuration sequence number of the target converted IP address in each deletion linked list, complete flow table refreshing, and the flow table contains flow table data generated after message triggers network address translation.

[0010] The method, optionally, comprises the following steps of:

[0011] Obtaining the configuration changed address in the address update configuration information.

[0012] For each configuration changed address, determining the target conversion IP address corresponding to the configuration changed address in the conversion IP address configuration table as the target conversion IP address.

[0013] The method, optionally, comprises the following steps of:

[0014] For each deletion chain table, obtaining each configuration serial number in the deletion chain table.

[0015] For each configuration serial number, determining whether the flow table data corresponding to the configuration serial number exists in the flow table, when the flow table data corresponding to the configuration serial number exists in the flow table, determining the flow table data corresponding to the configuration serial number as invalid flow table data, and deleting the invalid flow table data.

[0016] The method, optionally, comprises the following steps of:

[0017] When the received packet meets the preset flow table data generation condition, matching the conversion IP address for the packet in the conversion IP address configuration table, determining the matched conversion IP address for the packet as the target address.

[0018] Applying the target address to the packet for network address conversion, and generating the flow table data containing the configuration serial number of the target address.

[0019] The method, optionally, comprises the following steps of:

[0020] Receiving a packet.

[0021] Determining whether the packet is a first packet.

[0022] If the packet is a first packet, determining that the packet meets the preset flow table data generation condition.

[0023] If the packet is not a first packet, determining whether the flow table data corresponding to the packet exists in the flow table.

[0024] If the flow table data corresponding to the packet does not exist in the flow table, determining that the packet meets the preset flow table data generation condition.

[0025] The method further comprises the following steps:

[0026] If the flow table data corresponding to the message exists in the flow table, it is determined that the message does not satisfy the flow table data generation condition, and the message is forwarded by applying the flow table data corresponding to the message.

[0027] A flow table refreshing device for network address translation comprises the following steps:

[0028] An obtaining unit is configured to obtain at least one address update configuration information.

[0029] A first generating unit is configured to, for each of the address update configuration information, determine a target translation IP address in a preset translation IP address configuration table, delete the target translation IP address from the translation IP address configuration table, and generate a deletion chain table corresponding to the address update configuration information; the deletion chain table contains a configuration serial number of the target translation IP address corresponding to the address update configuration information.

[0030] A deleting unit is configured to execute a preset timing refreshing task, delete invalid flow table data in a flow table according to the configuration serial numbers of the target translation IP addresses in each of the deletion chain tables, and complete flow table refreshing; the flow table contains flow table data generated after a message triggers network address translation.

[0031] The device further comprises the following steps:

[0032] A first obtaining subunit is configured to obtain a configuration changed address in the address update configuration information.

[0033] A first determining subunit is configured to, for each of the configuration changed addresses, determine a translation IP address corresponding to the configuration changed address in the translation IP address configuration table as a target translation IP address.

[0034] The device further comprises the following steps:

[0035] A second obtaining subunit is configured to, for each of the deletion chain tables, obtain each configuration serial number in the deletion chain table.

[0036] A second determining subunit is configured to, for each of the configuration serial numbers, determine whether flow table data corresponding to the configuration serial number exists in the flow table; when the flow table data corresponding to the configuration serial number exists in the flow table, the flow table data corresponding to the configuration serial number is determined as invalid flow table data, and the invalid flow table data is deleted.

[0037] The device further comprises the following steps:

[0038] The matching unit is configured to match a converted IP address for the received packet in the converted IP address configuration table when the received packet meets a preset flow table data generation condition, and determine the matched converted IP address for the received packet as a target address.

[0039] The second generating unit is configured to perform network address translation on the packet by using the target address, and generate flow table data containing a configuration sequence number of the target address.

[0040] The device described above, optionally, further comprises:

[0041] The receiving unit is configured to receive a packet.

[0042] The first determining unit is configured to determine whether the packet is a first packet.

[0043] The second determining unit is configured to determine that the packet meets a preset flow table data generation condition if the packet is the first packet.

[0044] The third determining unit is configured to determine whether there is flow table data corresponding to the packet in the flow table if the packet is not the first packet.

[0045] The fourth determining unit is configured to determine that the packet meets the preset flow table data generation condition if there is no flow table data corresponding to the packet in the flow table.

[0046] The device described above, optionally, further comprises:

[0047] The fifth determining unit is configured to determine that the packet does not meet the flow table data generation condition if there is flow table data corresponding to the packet in the flow table, and forward the packet by using the flow table data corresponding to the packet.

[0048] A storage medium comprises stored instructions, wherein the instructions, when executed, control a device in which the storage medium is located to perform the network address translation flow table refreshing method described above.

[0049] An electronic device comprises a memory, and one or more instructions, wherein the one or more instructions are stored in the memory and configured to be executed by one or more processors to perform the network address translation flow table refreshing method described above.

[0050] Compared with the prior art, the present application has the following advantages:

[0051] The application provides a network address conversion flow table refreshing method and related equipment, which comprises the following steps: obtaining at least one address update configuration information; determining a target conversion IP address in a preset conversion IP address configuration table for each address update configuration information, and deleting the target conversion IP address from the conversion IP address configuration table; and generating a deletion chain table corresponding to the address update configuration information; deleting the configuration serial number of the target conversion IP address corresponding to the address update configuration information in the deletion chain table; and executing a preset timing refreshing task, deleting invalid flow table data in the flow table according to the configuration serial number of the target conversion IP address in each deletion chain table, completing flow table refreshing, and the flow table comprising flow table data generated after a message triggers network address conversion. In the scheme, when the flow table is updated, the configuration serial number of the deleted conversion IP address is used to generate a deletion chain table based on the configuration serial number of the conversion IP address, so that the deleted conversion IP address is recorded, then the corresponding invalid flow table data is searched in the flow table according to the deletion chain table, and then the invalid flow table data is deleted, so that the effective flow table data is not deleted in the whole process, and the message forwarding is not affected, and the message forwarding performance is not reduced. BRIEF DESCRIPTION OF DRAWINGS

[0052] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description are only the embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor based on the provided drawings.

[0053] Figure 1 A method flowchart of a network address conversion flow table refreshing method provided by the embodiment of the present application;

[0054] Figure 2 A method flowchart of determining a target conversion IP address in a preset conversion IP address configuration table for each address update configuration information provided by the embodiment of the present application;

[0055] Figure 3 A method flowchart of flow table data in a flow table provided by the embodiment of the present application, which is flow table data generated after a message triggers network address conversion;

[0056] Figure 4 Another flowchart of a network address conversion flow table refreshing method provided by the embodiment of the present application;

[0057] Figure 5 A scene example diagram of refreshing a flow table provided by the embodiment of the present application;

[0058] Figure 6 A structure schematic diagram of a network address conversion flow table refreshing device provided by the embodiment of the present application;

[0059] Figure 7 A structural schematic diagram of an electronic device is provided for an embodiment of the present application. DETAILED DESCRIPTION

[0060] The technical solutions in the embodiments of the present application will be clearly and completely described with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative effort belong to the scope of protection of the present application.

[0061] In the present application, the terms "comprising", "containing" or any other variants thereof are intended to cover the non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the sentence "including a" does not exclude the presence of other identical elements in the process, method, article or device including the element.

[0062] In updating the flow table, in addition to the updating mode described in the background art, there is another conventional updating mode of refreshing the flow table data while changing the converted IP address, which can cause resource flow table competition and reduce the message forwarding performance.

[0063] Therefore, the conventional updating mode of the flow table has the problem of reducing the message forwarding performance. In order to solve the above problem, the present application provides a flow table refreshing mode for network address conversion. The present application records the deleted converted IP address, and then performs full traversal of the flow table data through a timing mechanism. By comparing the recorded information, the invalid flow table is found and deleted, so as to as little as possible affect the message forwarding performance, and at the same time, the effect of accurately deleting the invalid flow table is achieved.

[0064] The present application can be used in many general or special computing device environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor devices, distributed computing environments including any of the above devices or devices, etc. The execution subject of the present application is a processor, preferably, the execution subject of the present application can be a processor in a gateway.

[0065] Reference Figure 1 A method flow chart of a flow table refreshing method for network address conversion is provided for an embodiment of the present application, and the specific description is as follows.

[0066] S101. Obtain at least one address update configuration information.

[0067] The address update configuration information is user input information, and the address update configuration information includes information of an IP address that needs to be deleted by the user.

[0068] It should be noted that the user can input the address update configuration information through the interaction module.

[0069] When multiple address update configuration information is obtained, the address update configuration information can be provided by multiple users or by one user.

[0070] S102. For each address update configuration information, determine a target conversion IP address in a preset conversion IP address configuration table, delete the target conversion IP address from the conversion IP address configuration table, and generate a deletion chain table corresponding to the address update configuration information; the deletion chain table includes a configuration serial number of the target conversion IP address corresponding to the address update configuration information.

[0071] Referring to Figure 2 The method flow chart for determining a target conversion IP address in a preset conversion IP address configuration table for each address update configuration information provided by the embodiment of the present application is described in detail as follows.

[0072] S201. Obtain a configuration change address in the address update configuration information.

[0073] For each received address update configuration information, the address update configuration information is parsed to obtain a configuration change address in the address update configuration information.

[0074] The configuration change address in the address update configuration information is a conversion IP address that needs to be deleted.

[0075] S202. For each configuration change address, determine a conversion IP address corresponding to the configuration change address in the conversion IP address configuration table as a target conversion IP address.

[0076] It should be noted that the conversion IP address configuration table is previously set with multiple conversion IP addresses for address conversion when forwarding the packet. Further, each conversion IP address in the conversion IP address configuration table has a preset configuration serial number, and the configuration serial number of each conversion IP address is unique.

[0077] For each configuration change address, the configuration change address is traversed through each conversion IP address in the conversion IP address configuration table, and a conversion IP address consistent with the configuration change address is determined as a target conversion IP address.

[0078] After the conversion IP address configuration table determines each target conversion IP address corresponding to the address configuration information, each target conversion IP address is deleted from the conversion IP address configuration table, so that the deletion chain table corresponding to the address configuration information can be obtained.

[0079] It should be noted that each address update configuration information has a corresponding deletion chain table, and the deletion chain table contains the configuration serial numbers of each target conversion IP address corresponding to the address update configuration information.

[0080] The present application deletes the conversion IP address to be deleted in the conversion IP address configuration table, and generates a deletion chain table based on the configuration serial number of the deleted IP address, so that the conversion IP address to be deleted can be recorded for subsequent flow table refreshing.

[0081] S103, execute the preset timing refreshing task, delete the invalid flow table data in the flow table according to the configuration serial number of the target conversion IP address in each deletion chain table, complete the flow table refreshing, and the flow table contains the flow table data generated after the network address conversion triggered by the message.

[0082] It should be noted that the execution of the timing refreshing task can be triggered by a timer, and the flow table will be refreshed according to each deletion chain table after the execution of the timing refreshing task.

[0083] For example, the timer can be set to execute the timing refreshing task every hour, and after the execution of the timing refreshing task, each deletion chain table is obtained, and then each invalid flow table data in the flow table is deleted according to the configuration serial number of each target conversion IP address in each deletion chain table, so as to refresh the flow table.

[0084] The flow table contains the flow table data generated after the network address conversion triggered by the message, and the flow table contains a plurality of flow table data, preferably, the flow table data contains the configuration serial number of the conversion IP address applied when the network address conversion triggered by the message.

[0085] Further, the process of deleting the invalid flow table data in the flow table according to the configuration serial number of the target conversion IP address in each deletion chain table is as follows: for each deletion chain table, obtain each configuration serial number in the deletion chain table; for each configuration serial number, determine whether there is flow table data corresponding to the configuration serial number in the flow table, when there is flow table data corresponding to the configuration serial number in the flow table, the flow table data corresponding to the configuration serial number is determined as invalid flow table data, and the invalid flow table data is deleted.

[0086] Preferably, for each configuration serial number in the deletion chain table, each flow table data in the flow table is traversed, and the flow table data corresponding to the configuration serial number in the flow table is determined as invalid flow table data; further, the flow table data contains a configuration serial number, and when the deletion chain table contains the same configuration serial number as the configuration serial number of the flow table data, the flow table data is invalid flow table data.

[0087] It should be noted that the deletion chain table can contain multiple configuration serial numbers, so that the flow table data in the flow table can be deleted in batches, and then the flow table can be refreshed quickly and timely. Preferably, after refreshing the flow table using the chain table, the deletion chain table can be deleted, thereby saving memory resources.

[0088] In the method provided by the embodiment of the application, at least one address update configuration information is obtained, for each address update configuration information, a target conversion IP address is determined in a preset conversion IP address configuration table, and the target conversion IP address is deleted from the conversion IP address configuration table, a deletion chain table corresponding to the address update configuration information is generated; the deletion chain table contains the configuration serial number of the target conversion IP address corresponding to the address update configuration information; a preset timing refresh task is executed, invalid flow table data is deleted from the flow table according to the configuration serial number of the target conversion IP address in each deletion chain table, the flow table refresh is completed, and the flow table contains flow table data generated after the network address conversion triggered by the message. In the present scheme, when updating the flow table, the configuration serial number of the deleted conversion IP address is recorded by generating a deletion chain table using the configuration serial number of the deleted conversion IP address based on the configuration serial number of the conversion IP address, and then the corresponding invalid flow table data is searched in the flow table according to the deletion chain table, and then the invalid flow table data is deleted. The entire process does not delete the valid flow table data, thereby not affecting the forwarding of the message and not reducing the forwarding performance of the message.

[0089] Preferably, the flow table is used for forwarding the message after the network address conversion of the message. Figure 3 The flow table data in the flow table provided by the embodiment of the application is the flow table data generated after the network address conversion triggered by the message, and the method flow chart is described as follows.

[0090] S301, receiving a message.

[0091] The message is received by a communication device, and the communication device can be any computer terminal or intelligent device that can establish a communication connection with the processor.

[0092] Preferably, the communication device establishes a communication connection with the processor.

[0093] S302, determining whether the message is a first message; if the message is the first message, performing S303; if the message is not the first message, performing S306.

[0094] In the judgment of whether the message is the first message, it can be judged whether the message is the first message sent after the communication device and the processor establish the connection. Preferably, if it is judged that the message is not the first message sent after the communication device and the processor establish the connection, it can be determined that the message is the subsequent message of the communication device after sending the first message.

[0095] S303, determine whether the message meets the preset flow table data generation condition.

[0096] After determining that the message meets the preset flow table data generation condition, S304 is executed.

[0097] S304, match the converted IP address for the message in the converted IP address configuration table, and determine the matched converted IP address for the message as the target address.

[0098] Preferably, when matching the converted IP address for the message, an idle converted IP address can be randomly selected as the converted IP address matched for the message, or the converted IP address can be matched in the converted IP address configuration table based on the destination address carried in the message. For example, based on the destination address carried in the message, the target device to which the message needs to be sent is determined, the converted IP address capable of establishing a connection with the target device is determined in the converted IP address configuration table, and the converted IP address is taken as the converted IP address matched for the message, that is, the target address is determined.

[0099] S305, apply the target address to the message for network address translation to generate the flow table data containing the configuration sequence number of the target address.

[0100] After determining the target address, the target address is applied to the message for network address translation, and then the flow table data containing the configuration sequence number of the target address is generated, and then the flow table data is saved in the converted IP address configuration table, so that the communication device uses the flow table data to forward the message when sending the message subsequently.

[0101] Preferably, after using the target address to perform network address translation on the message, the message can be forwarded, and preferably, the message is forwarded to the network or device corresponding to the target address. At this time, the device can be determined as the target device.

[0102] Preferably, the flow table data can be associated with the source address of the message, and the source address is the address applied by the communication device sending the message.

[0103] S306, determine whether there is flow table data corresponding to the message in the flow table; if there is no flow table data corresponding to the message in the flow table, S303 is executed; if there is flow table data corresponding to the message in the flow table, S307 is executed.

[0104] When it is determined that the packet is not the first packet, it is needed to determine whether there is flow table data corresponding to the packet in the flow table, for example, the source address in the packet is acquired, it is determined whether there is flow table data associated with the source address in the flow table, if there is flow table data associated with the source address in the flow table, S307 is executed; if there is no flow table data associated with the source address in the flow table, it is indicated that the flow table has deleted the flow table data associated with the source address when refreshing, and thus it is determined that the packet meets the flow table data generation condition, that is, S303 is returned to regenerate the flow table data, so as to subsequently perform network address translation.

[0105] S307, it is determined that the packet does not meet the flow table data generation condition, and the packet is forwarded by using the flow table data corresponding to the packet.

[0106] When it is determined that the packet does not meet the flow table data generation condition, the packet is forwarded by using the flow table data corresponding to the packet, which can specifically be that the translated IP address is determined based on the configuration serial number in the flow table data corresponding to the packet, and then the packet is sent to the device corresponding to the translated IP address.

[0107] In the method provided by the embodiment of the application, after receiving the packet, it is first determined whether the packet meets the preset flow table data generation condition, if yes, the translated IP address is matched for the packet in the translated IP address configuration table, and then the flow table data is generated based on the configuration serial number of the matched translated IP address, thereby the corresponding flow table data can be generated in time after the corresponding flow table data is deleted, so as to forward the packet by using the flow table data, thereby the forwarding of the packet can be avoided from being affected, and the performance of the packet forwarding is ensured. In the method provided by the application, the process of forwarding the packet and refreshing the flow table can be simultaneously performed, when the corresponding flow table data cannot be detected in the flow table, it can be indicated that the translated IP address needed by the packet is deleted in the refreshed flow table, and then the network address translation service can be triggered again, the translated IP address is matched for the packet again, and then the packet is forwarded, the whole process does not affect the forwarding of the packet, and the performance of the packet forwarding is ensured.

[0108] Reference Figure 4 Another flow chart of the network address translation flow table refreshing method provided by the embodiment of the application is provided, which is specifically described as follows.

[0109] S401, a configuration serial number is added for each translated IP address.

[0110] The translated IP address configuration function is added in the network address translation function, the configuration serial number is added for each translated IP address, and the configuration serial number is globally unique, that is, it has uniqueness.

[0111] The translated IP address is saved in the translated IP address configuration table.

[0112] S402, the packet generates flow table data after network address translation, records the flow table data in the flow table, and the flow table data contains the configuration sequence number of the translated IP address related thereto.

[0113] The flow table data contains the configuration sequence number of the translated IP address used when the packet is subjected to network address translation.

[0114] S403, triggering the translated IP address configuration change, recording the configuration sequence number of the deleted translated IP address.

[0115] Upon receiving the address update configuration information sent by the user, the translated IP address configuration change is triggered, at which time the translated IP address in the translated IP address configuration table is deleted according to the address update configuration information, and then the configuration sequence number of the deleted translated IP address is recorded.

[0116] S404, generating a deletion chain table, and the deletion chain table caches the configuration sequence number of the deleted translated IP address.

[0117] Based on the recorded configuration sequence number of the deleted translated IP address, a deletion chain table is generated.

[0118] S405, executing a timing refresh task, determining whether the configuration sequence number in the deletion chain table has corresponding flow table data in the flow table, and if so, deleting the flow table data corresponding to the configuration sequence number in the deletion chain table in the flow table.

[0119] The timing refresh task is executed, and then it is determined whether the configuration sequence number in the deletion chain table has corresponding flow table data in the flow table, and if so, the flow table data corresponding to the configuration sequence number in the deletion chain table in the flow table is deleted, and thus the refresh of the flow table is completed.

[0120] Reference Figure 5 The scene example graph for refreshing the flow table provided by the embodiment of the present application is described as follows.

[0121] 1. The first packet triggers the generation of flow table data through network address translation, such as ③ in the above. Figure 5

[0122] 2. The user inputs the first batch and the second batch of configuration changes, such as ① in the above. Figure 5

[0123] One batch of configuration changes contains a translated IP address that needs to be deleted, and one batch of configuration changes can be regarded as one address change configuration information.

[0124] 3. When the configuration change is recorded, the configuration sequence number of the deleted translated IP address is recorded, the first batch records configuration sequence numbers 2 and 5, and the second batch records configuration sequence numbers 1, 4 and 6, such as ② in the above. Figure 5

[0125] ​​​4. Two configuration changes generate delete-link1 and delete-link2 respectively, as shown in Figure 5 ④ in FIG. 4; different configuration changes have different delete links.

[0126] 5. The timer traverses the delete-link1 and delete-link2 one by one, retrieves and deletes the invalid flow table from the flow table.

[0127] 6. If the subsequent packet cannot find a matching flow table, it needs to go through the first packet process again to match the network address translation service, hit and generate new flow table data.

[0128] The present scheme can accurately find the related flow table data by marking the configuration sequence number of the converted IP address, and retrieve and delete the invalid flow table data. By traversing the flow table through the timing mechanism and only operating the flow table related to the deleted converted IP address configuration, the invalid operation on the flow table can be effectively reduced (i.e., the effective flow table will not be affected), further reducing the impact on the flow table forwarding performance. Since the converted IP address can be batched when changed, i.e., deleting several converted IP address configurations at a time, if the user operates multiple times, multiple deleted converted IP address configurations will be generated, and when the data volume is large, it will be slow to retrieve one by one and cannot refresh the flow table in time. The method adopted here is that the user will construct a delete link (delete-link) for the deleted converted IP address configurations each time. Multiple operations will construct multiple delete links (delete-link). The timer refreshes the flow table data in link table units each time. This can ensure the quick and timely refresh of the flow table state.

[0129] The traditional way to refresh the flow table is to update the converted IP address and refresh the flow table data at the same time, which will cause competition for access to flow table resources, resulting in the inability to forward the packet in time and seriously reducing the packet forwarding performance; or by invalidating and deleting all existing flow tables, and then creating flow tables through packet triggering to update the network connection, which is actually a process of disconnecting all network connections and rebuilding network connections, which will generate a large number of new flow process services, thereby increasing resource consumption and reducing packet forwarding performance.

[0130] The above two traditional ways to refresh the flow table cannot guarantee that the packet is forwarded through the flow table quickly while only removing the invalid flow table information. In the scheme provided by the present application, by recording the deleted converted IP address first, and then traversing the flow table data in full through the timing mechanism, the invalid flow table data is found and deleted through comparison, which achieves the effect of as little as possible affecting the packet forwarding performance while accurately deleting the invalid flow table.

[0131] and Figure 1Corresponding to the method, the application further provides a flow table refreshing device for network address translation, which is used for supporting Figure 1 The device can be arranged in a gateway or a server.

[0132] With reference to Figure 6 A structure diagram of a flow table refreshing device for network address translation is provided for an embodiment of the application, and the specific description is as follows.

[0133] The obtaining unit 601 is configured to obtain at least one address update configuration information.

[0134] The first generating unit 602 is configured to, for each of the address update configuration information, determine a target translation IP address in a preset translation IP address configuration table, delete the target translation IP address from the translation IP address configuration table, and generate a deletion chain table corresponding to the address update configuration information; the deletion chain table contains a configuration serial number of the target translation IP address corresponding to the address update configuration information.

[0135] The deleting unit 603 is configured to execute a preset timing refreshing task, delete invalid flow table data in a flow table according to the configuration serial number of the target translation IP address in each of the deletion chain tables, complete flow table refreshing, and the flow table contains flow table data generated after network address translation triggered by a message.

[0136] In the device provided by the embodiment of the application, at least one address update configuration information is obtained, for each of the address update configuration information, a target translation IP address in a preset translation IP address configuration table is determined, the target translation IP address is deleted from the translation IP address configuration table, and a deletion chain table corresponding to the address update configuration information is generated; the deletion chain table contains a configuration serial number of the target translation IP address corresponding to the address update configuration information; a preset timing refreshing task is executed, invalid flow table data in a flow table is deleted according to the configuration serial number of the target translation IP address in each of the deletion chain tables, flow table refreshing is completed, and the flow table contains flow table data generated after network address translation triggered by a message. In the scheme, when the flow table is updated, the configuration number of the translation IP address is used to generate the deletion chain table by using the configuration number of the deleted translation IP address, so that the deleted translation IP address is recorded, then the corresponding invalid flow table data is searched in the flow table according to the deletion chain table, and then the invalid flow table data is deleted. The whole process does not delete the valid flow table data, so that the message forwarding is not affected and the message forwarding performance is not reduced.

[0137] In the device provided by the embodiment of the application, the first generating unit 602 of the device includes:

[0138] The first obtaining subunit is configured to obtain a configuration changed address in the address update configuration information.

[0139] The first determining sub-unit is configured to determine, for each of the configuration changed address, a converted IP address corresponding to the configuration changed address in the converted IP address configuration table as a target converted IP address.

[0140] In the apparatus provided by the embodiment of the present application, the deleting unit 603 of the apparatus comprises:

[0141] The second obtaining sub-unit is configured to obtain, for each of the deleting chain table, each configuration serial number in the deleting chain table.

[0142] The second determining sub-unit is configured to determine, for each of the configuration serial number, whether there is flow table data corresponding to the configuration serial number in the flow table, and when there is flow table data corresponding to the configuration serial number in the flow table, determine the flow table data corresponding to the configuration serial number as invalid flow table data and delete the invalid flow table data.

[0143] In the apparatus provided by the embodiment of the present application, the apparatus further comprises:

[0144] The matching unit is configured to match a converted IP address for the received message in the converted IP address configuration table when the received message meets a preset flow table data generation condition, and determine the matched converted IP address for the message as a target address.

[0145] The second generating unit is configured to apply the target address to the message for network address conversion and generate flow table data containing a configuration serial number of the target address.

[0146] In the apparatus provided by the embodiment of the present application, the apparatus further comprises:

[0147] The receiving unit is configured to receive a message.

[0148] The first determining unit is configured to determine whether the message is a first message.

[0149] The second determining unit is configured to determine that the message meets a preset flow table data generation condition if the message is the first message.

[0150] The third determining unit is configured to determine whether there is flow table data corresponding to the message in the flow table if the message is not the first message.

[0151] The fourth determining unit is configured to determine that the message meets the preset flow table data generation condition if there is no flow table data corresponding to the message in the flow table.

[0152] In the apparatus provided by the embodiment of the present application, the apparatus further comprises:

[0153] The fifth determining unit is configured to determine that the packet does not satisfy the flow table data generation condition if the flow table data corresponding to the packet exists in the flow table, and to forward the packet according to the flow table data corresponding to the packet.

[0154] The embodiment of the present application further provides a storage medium, which comprises stored instructions, wherein the instructions are used to control a device where the storage medium is located to execute the flow table refreshing method for network address translation.

[0155] The embodiment of the present application further provides an electronic device, a structural schematic diagram of which is shown in the figure. Figure 7 The electronic device comprises a memory 701 and one or more instructions 702, wherein the one or more instructions 702 are stored in the memory 701 and are configured to be executed by one or more processors 703 to execute the flow table refreshing method for network address translation.

[0156] It should be noted that the information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of the related data need to comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0157] The specific implementation process of each of the above embodiments and its derivative mode are all within the protection scope of the present application.

[0158] Each of the embodiments in the specification is described in a progressive manner, and the same and similar parts between each of the embodiments can be referred to each other, and each of the embodiments mainly describes the difference from other embodiments. Especially, for the system or system embodiment, since it is basically similar to the method embodiment, it is described more simply, and the related parts can be referred to the part of the description of the method embodiment. The above described system and system embodiment are only illustrative, wherein the units described as separate components can be or can not be physically separated, and the components displayed as units can be or can not be physical units, that is, they can be located in one place or distributed on multiple network units. According to the actual needs, part or all of the modules can be selected to achieve the purpose of the embodiment scheme. Those skilled in the art can understand and implement without creative labor.

[0159] Those skilled in the art will further realize that the mechanisms of the various examples described herein are capable of being implemented using any number of combinations of the described features. Accordingly, these examples are not limited to the mechanisms described herein, but rather, the intent is to cover all modifications and alternatives equivalent thereto. The preceding description of the examples is illustrative, and not restrictive. Many other examples will be apparent to those of skill in the art upon reviewing the above description. The scope of the examples should, therefore, be determined not with reference to the above description, but instead should be given to the appended claims, along with their full scope of equivalents.

[0160] The above description of disclosed examples is intended to be illustrative, and not restrictive. Many other examples will be apparent to those of skill in the art upon reviewing the above description. The scope of the examples should, therefore, be determined not with reference to the above description, but instead should be given to the appended claims, along with their full scope of equivalents.

Claims

1. A method for flow table refresh of network address translation, the method comprising: The method comprises the following steps: obtaining at least one address update configuration information; for each of the address update configuration information, determining a target translation IP address in a preset translation IP address configuration table, and deleting the target translation IP address from the translation IP address configuration table to generate a deletion chain table corresponding to the address update configuration information; the deletion chain table contains the configuration serial number of the target translation IP address corresponding to the address update configuration information; performing a preset timing refresh task, deleting invalid flow table data in a flow table according to the configuration serial number of the target translation IP address in each of the deletion chain tables, and completing flow table refresh; the flow table contains flow table data generated after network address translation triggered by a message; the step of determining a target translation IP address in a preset translation IP address configuration table for each of the address update configuration information comprises the following steps: obtaining a configuration changed address in the address update configuration information; for each of the configuration changed address, determining a translation IP address corresponding to the configuration changed address in the translation IP address configuration table as a target translation IP address.

2. The method of claim 1, wherein, the step of deleting invalid flow table data in a flow table according to the configuration serial number of the target translation IP address in each of the deletion chain tables comprises the following steps: for each of the deletion chain table, obtaining each configuration serial number in the deletion chain table; for each of the configuration serial number, determining whether there is flow table data corresponding to the configuration serial number in the flow table; when there is flow table data corresponding to the configuration serial number in the flow table, determining the flow table data corresponding to the configuration serial number as invalid flow table data, and deleting the invalid flow table data.

3. The method of claim 1, wherein, the process of generating flow table data after network address translation triggered by a message comprises the following steps: when a received message meets a preset flow table data generation condition, matching a translation IP address for the message in the translation IP address configuration table, and determining the matched translation IP address for the message as a target address; applying the target address to perform network address translation on the message to generate flow table data containing the configuration serial number of the target address.

4. The method of claim 3, wherein, the process of determining that a message meets a preset flow table data generation condition comprises the following steps: receiving a message; determining whether the message is a first message; if the message is a first message, determining that the message meets a preset flow table data generation condition; if the message is not a first message, determining whether there is flow table data corresponding to the message in the flow table; if there is no flow table data corresponding to the message in the flow table, determining that the message meets the preset flow table data generation condition.

5. The method of claim 4, wherein, the method further comprises the following steps: if there is flow table data corresponding to the message in the flow table, determining that the message does not meet the flow table data generation condition, and applying the flow table data corresponding to the message to forward the message.

6. A network address translation flow table refresh apparatus, characterized by, The method comprises the following steps: an obtaining unit is configured to obtain at least one address update configuration information; The first generating unit is configured to determine a target converted IP address in a preset converted IP address configuration table for each of the address update configuration information, delete the target converted IP address from the converted IP address configuration table, and generate a delete chain table corresponding to the address update configuration information; the delete chain table contains a configuration serial number of the target converted IP address corresponding to the address update configuration information; The deleting unit is configured to execute a preset timing refresh task, delete invalid flow table data in a flow table according to the configuration serial number of the target converted IP address in each of the delete chain tables, and complete flow table refresh; the flow table contains flow table data generated after a network address conversion triggered by a message. The first generating unit comprises: A first obtaining sub-unit configured to obtain a configuration changed address in the address update configuration information; A first determining sub-unit configured to determine, for each of the configuration changed addresses, a converted IP address corresponding to the configuration changed address in the converted IP address configuration table as a target converted IP address.

7. A storage medium, characterized by The storage medium comprises stored instructions, wherein the instructions, when executed, control a device in which the storage medium is located to perform the flow table refresh method for network address conversion according to any one of claims 1-5.

8. An electronic device, comprising: The computer program product comprises a memory and one or more instructions, wherein the one or more instructions are stored in the memory and configured to be executed by one or more processors to perform the flow table refresh method for network address conversion according to any one of claims 1-5.

Citation Information

Patent Citations

  • Flow monitoring method

    CN103023728A

  • Multi-core SDN switch flow table management method and system based on batch updating

    CN112260948A

  • Resource allocation method and device, equipment and storage medium

    CN116192808A